diff --git a/advisories/unreviewed/2022/05/GHSA-75f9-mm5v-2rgm/GHSA-75f9-mm5v-2rgm.json b/advisories/unreviewed/2022/05/GHSA-75f9-mm5v-2rgm/GHSA-75f9-mm5v-2rgm.json index c0863aef3ba..beab73828c5 100644 --- a/advisories/unreviewed/2022/05/GHSA-75f9-mm5v-2rgm/GHSA-75f9-mm5v-2rgm.json +++ b/advisories/unreviewed/2022/05/GHSA-75f9-mm5v-2rgm/GHSA-75f9-mm5v-2rgm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-75f9-mm5v-2rgm", - "modified": "2022-05-26T00:01:23Z", + "modified": "2025-04-16T18:31:25Z", "published": "2022-05-24T19:06:54Z", "aliases": [ "CVE-2021-34527" @@ -27,6 +27,14 @@ "type": "WEB", "url": "https://www.kb.cert.org/vuls/id/383432" }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/cve-2021-34527-printnightmare-detection-script" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/cve-2021-34527-printnightmare-mitigation-script" + }, { "type": "WEB", "url": "http://packetstormsecurity.com/files/167261/Print-Spooler-Remote-DLL-Injection.html" diff --git a/advisories/unreviewed/2022/05/GHSA-g24w-7v2m-52xh/GHSA-g24w-7v2m-52xh.json b/advisories/unreviewed/2022/05/GHSA-g24w-7v2m-52xh/GHSA-g24w-7v2m-52xh.json index 6462a11b3b1..fa021ae826a 100644 --- a/advisories/unreviewed/2022/05/GHSA-g24w-7v2m-52xh/GHSA-g24w-7v2m-52xh.json +++ b/advisories/unreviewed/2022/05/GHSA-g24w-7v2m-52xh/GHSA-g24w-7v2m-52xh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g24w-7v2m-52xh", - "modified": "2022-05-24T19:15:44Z", + "modified": "2025-04-16T18:31:25Z", "published": "2022-05-24T19:15:44Z", "aliases": [ "CVE-2021-20035" ], "details": "Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user which potentially leads to DoS.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/12/GHSA-3799-j5gp-4x56/GHSA-3799-j5gp-4x56.json b/advisories/unreviewed/2022/12/GHSA-3799-j5gp-4x56/GHSA-3799-j5gp-4x56.json index 8489691f499..5052e9eb548 100644 --- a/advisories/unreviewed/2022/12/GHSA-3799-j5gp-4x56/GHSA-3799-j5gp-4x56.json +++ b/advisories/unreviewed/2022/12/GHSA-3799-j5gp-4x56/GHSA-3799-j5gp-4x56.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3799-j5gp-4x56", - "modified": "2022-12-29T21:30:30Z", + "modified": "2025-04-16T18:31:36Z", "published": "2022-12-22T21:30:30Z", "aliases": [ "CVE-2022-22741" diff --git a/advisories/unreviewed/2022/12/GHSA-3f36-r4c3-hh86/GHSA-3f36-r4c3-hh86.json b/advisories/unreviewed/2022/12/GHSA-3f36-r4c3-hh86/GHSA-3f36-r4c3-hh86.json index e48a9cb60fb..8601757bdc3 100644 --- a/advisories/unreviewed/2022/12/GHSA-3f36-r4c3-hh86/GHSA-3f36-r4c3-hh86.json +++ b/advisories/unreviewed/2022/12/GHSA-3f36-r4c3-hh86/GHSA-3f36-r4c3-hh86.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3f36-r4c3-hh86", - "modified": "2022-12-24T06:30:24Z", + "modified": "2025-04-16T18:31:35Z", "published": "2022-12-22T21:30:30Z", "aliases": [ "CVE-2022-1887" diff --git a/advisories/unreviewed/2022/12/GHSA-3hgj-xg7g-48mq/GHSA-3hgj-xg7g-48mq.json b/advisories/unreviewed/2022/12/GHSA-3hgj-xg7g-48mq/GHSA-3hgj-xg7g-48mq.json index d456c8c7401..b5a9e9dc11c 100644 --- a/advisories/unreviewed/2022/12/GHSA-3hgj-xg7g-48mq/GHSA-3hgj-xg7g-48mq.json +++ b/advisories/unreviewed/2022/12/GHSA-3hgj-xg7g-48mq/GHSA-3hgj-xg7g-48mq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3hgj-xg7g-48mq", - "modified": "2022-12-29T21:30:30Z", + "modified": "2025-04-16T18:31:36Z", "published": "2022-12-22T21:30:30Z", "aliases": [ "CVE-2022-22743" diff --git a/advisories/unreviewed/2022/12/GHSA-3jgp-624h-phx4/GHSA-3jgp-624h-phx4.json b/advisories/unreviewed/2022/12/GHSA-3jgp-624h-phx4/GHSA-3jgp-624h-phx4.json index aa291040c13..399c3b34c0f 100644 --- a/advisories/unreviewed/2022/12/GHSA-3jgp-624h-phx4/GHSA-3jgp-624h-phx4.json +++ b/advisories/unreviewed/2022/12/GHSA-3jgp-624h-phx4/GHSA-3jgp-624h-phx4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3jgp-624h-phx4", - "modified": "2022-12-29T18:30:24Z", + "modified": "2025-04-16T18:31:35Z", "published": "2022-12-22T21:30:31Z", "aliases": [ "CVE-2022-0566" diff --git a/advisories/unreviewed/2022/12/GHSA-3qrc-jgqf-vg35/GHSA-3qrc-jgqf-vg35.json b/advisories/unreviewed/2022/12/GHSA-3qrc-jgqf-vg35/GHSA-3qrc-jgqf-vg35.json index 75b7bd9e8a9..ace8e47a959 100644 --- a/advisories/unreviewed/2022/12/GHSA-3qrc-jgqf-vg35/GHSA-3qrc-jgqf-vg35.json +++ b/advisories/unreviewed/2022/12/GHSA-3qrc-jgqf-vg35/GHSA-3qrc-jgqf-vg35.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3qrc-jgqf-vg35", - "modified": "2022-12-29T18:30:24Z", + "modified": "2025-04-16T18:31:35Z", "published": "2022-12-22T21:30:30Z", "aliases": [ "CVE-2022-1520" @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-326" + "CWE-326", + "CWE-346" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-4989-6q5w-wjgw/GHSA-4989-6q5w-wjgw.json b/advisories/unreviewed/2022/12/GHSA-4989-6q5w-wjgw/GHSA-4989-6q5w-wjgw.json index d91c9b09293..53a02562287 100644 --- a/advisories/unreviewed/2022/12/GHSA-4989-6q5w-wjgw/GHSA-4989-6q5w-wjgw.json +++ b/advisories/unreviewed/2022/12/GHSA-4989-6q5w-wjgw/GHSA-4989-6q5w-wjgw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4989-6q5w-wjgw", - "modified": "2022-12-29T21:30:30Z", + "modified": "2025-04-16T18:31:36Z", "published": "2022-12-22T21:30:30Z", "aliases": [ "CVE-2022-22744" @@ -38,6 +38,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-116", "CWE-77" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/12/GHSA-4q79-fg6h-v56p/GHSA-4q79-fg6h-v56p.json b/advisories/unreviewed/2022/12/GHSA-4q79-fg6h-v56p/GHSA-4q79-fg6h-v56p.json index 7e240602850..bdb4ae2e2a2 100644 --- a/advisories/unreviewed/2022/12/GHSA-4q79-fg6h-v56p/GHSA-4q79-fg6h-v56p.json +++ b/advisories/unreviewed/2022/12/GHSA-4q79-fg6h-v56p/GHSA-4q79-fg6h-v56p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4q79-fg6h-v56p", - "modified": "2022-12-28T18:30:21Z", + "modified": "2025-04-16T18:31:29Z", "published": "2022-12-20T21:30:19Z", "aliases": [ "CVE-2022-46912" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46912" }, + { + "type": "WEB", + "url": "https://hackmd.io/%40slASVrz_SrW7NQCsunofeA/Sk6sfbTPi" + }, { "type": "WEB", "url": "https://hackmd.io/@slASVrz_SrW7NQCsunofeA/Sk6sfbTPi" diff --git a/advisories/unreviewed/2022/12/GHSA-4qmj-r3wp-mpm8/GHSA-4qmj-r3wp-mpm8.json b/advisories/unreviewed/2022/12/GHSA-4qmj-r3wp-mpm8/GHSA-4qmj-r3wp-mpm8.json index 7f4621deea5..15f49ce29ab 100644 --- a/advisories/unreviewed/2022/12/GHSA-4qmj-r3wp-mpm8/GHSA-4qmj-r3wp-mpm8.json +++ b/advisories/unreviewed/2022/12/GHSA-4qmj-r3wp-mpm8/GHSA-4qmj-r3wp-mpm8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4qmj-r3wp-mpm8", - "modified": "2022-12-29T18:30:25Z", + "modified": "2025-04-16T18:31:35Z", "published": "2022-12-22T21:30:30Z", "aliases": [ "CVE-2022-22736" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-427" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-4rpw-8wx9-fp4x/GHSA-4rpw-8wx9-fp4x.json b/advisories/unreviewed/2022/12/GHSA-4rpw-8wx9-fp4x/GHSA-4rpw-8wx9-fp4x.json index 30ca45a02a5..2c97b66bba6 100644 --- a/advisories/unreviewed/2022/12/GHSA-4rpw-8wx9-fp4x/GHSA-4rpw-8wx9-fp4x.json +++ b/advisories/unreviewed/2022/12/GHSA-4rpw-8wx9-fp4x/GHSA-4rpw-8wx9-fp4x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4rpw-8wx9-fp4x", - "modified": "2022-12-29T21:30:30Z", + "modified": "2025-04-16T18:31:35Z", "published": "2022-12-22T21:30:31Z", "aliases": [ "CVE-2022-1196" diff --git a/advisories/unreviewed/2022/12/GHSA-4v77-vppr-hv2g/GHSA-4v77-vppr-hv2g.json b/advisories/unreviewed/2022/12/GHSA-4v77-vppr-hv2g/GHSA-4v77-vppr-hv2g.json index 855094cf3bb..c9ed1968dc1 100644 --- a/advisories/unreviewed/2022/12/GHSA-4v77-vppr-hv2g/GHSA-4v77-vppr-hv2g.json +++ b/advisories/unreviewed/2022/12/GHSA-4v77-vppr-hv2g/GHSA-4v77-vppr-hv2g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4v77-vppr-hv2g", - "modified": "2022-12-29T21:30:30Z", + "modified": "2025-04-16T18:31:35Z", "published": "2022-12-22T21:30:31Z", "aliases": [ "CVE-2022-0843" diff --git a/advisories/unreviewed/2022/12/GHSA-4vgm-pr2v-749c/GHSA-4vgm-pr2v-749c.json b/advisories/unreviewed/2022/12/GHSA-4vgm-pr2v-749c/GHSA-4vgm-pr2v-749c.json index 4d4e1ee1c15..90f6b16fde1 100644 --- a/advisories/unreviewed/2022/12/GHSA-4vgm-pr2v-749c/GHSA-4vgm-pr2v-749c.json +++ b/advisories/unreviewed/2022/12/GHSA-4vgm-pr2v-749c/GHSA-4vgm-pr2v-749c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4vgm-pr2v-749c", - "modified": "2022-12-29T21:30:30Z", + "modified": "2025-04-16T18:31:34Z", "published": "2022-12-22T21:30:31Z", "aliases": [ "CVE-2022-0517" diff --git a/advisories/unreviewed/2022/12/GHSA-542f-pr3h-p3h7/GHSA-542f-pr3h-p3h7.json b/advisories/unreviewed/2022/12/GHSA-542f-pr3h-p3h7/GHSA-542f-pr3h-p3h7.json index b9c994bc8d5..41ae41609a3 100644 --- a/advisories/unreviewed/2022/12/GHSA-542f-pr3h-p3h7/GHSA-542f-pr3h-p3h7.json +++ b/advisories/unreviewed/2022/12/GHSA-542f-pr3h-p3h7/GHSA-542f-pr3h-p3h7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-542f-pr3h-p3h7", - "modified": "2022-12-28T21:30:22Z", + "modified": "2025-04-16T18:31:30Z", "published": "2022-12-20T21:30:19Z", "aliases": [ "CVE-2022-46434" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46434" }, + { + "type": "WEB", + "url": "https://hackmd.io/%40slASVrz_SrW7NQCsunofeA/rJl69Icws" + }, { "type": "WEB", "url": "https://hackmd.io/@slASVrz_SrW7NQCsunofeA/rJl69Icws" diff --git a/advisories/unreviewed/2022/12/GHSA-55r4-xqfm-9443/GHSA-55r4-xqfm-9443.json b/advisories/unreviewed/2022/12/GHSA-55r4-xqfm-9443/GHSA-55r4-xqfm-9443.json index c073799b18f..a94bfeef4da 100644 --- a/advisories/unreviewed/2022/12/GHSA-55r4-xqfm-9443/GHSA-55r4-xqfm-9443.json +++ b/advisories/unreviewed/2022/12/GHSA-55r4-xqfm-9443/GHSA-55r4-xqfm-9443.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-55r4-xqfm-9443", - "modified": "2022-12-29T21:30:30Z", + "modified": "2025-04-16T18:31:36Z", "published": "2022-12-22T21:30:30Z", "aliases": [ "CVE-2022-22742" diff --git a/advisories/unreviewed/2022/12/GHSA-5c5f-g48v-mx2x/GHSA-5c5f-g48v-mx2x.json b/advisories/unreviewed/2022/12/GHSA-5c5f-g48v-mx2x/GHSA-5c5f-g48v-mx2x.json index b28602dd182..b4a7182f23a 100644 --- a/advisories/unreviewed/2022/12/GHSA-5c5f-g48v-mx2x/GHSA-5c5f-g48v-mx2x.json +++ b/advisories/unreviewed/2022/12/GHSA-5c5f-g48v-mx2x/GHSA-5c5f-g48v-mx2x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5c5f-g48v-mx2x", - "modified": "2022-12-28T18:30:20Z", + "modified": "2025-04-16T18:31:29Z", "published": "2022-12-20T21:30:19Z", "aliases": [ "CVE-2022-46430" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46430" }, + { + "type": "WEB", + "url": "https://hackmd.io/%40slASVrz_SrW7NQCsunofeA/BJxlw2Pwi" + }, { "type": "WEB", "url": "https://hackmd.io/@slASVrz_SrW7NQCsunofeA/BJxlw2Pwi" diff --git a/advisories/unreviewed/2022/12/GHSA-5hr7-vh78-qh58/GHSA-5hr7-vh78-qh58.json b/advisories/unreviewed/2022/12/GHSA-5hr7-vh78-qh58/GHSA-5hr7-vh78-qh58.json index d3d1e00eaee..8a61d8c5746 100644 --- a/advisories/unreviewed/2022/12/GHSA-5hr7-vh78-qh58/GHSA-5hr7-vh78-qh58.json +++ b/advisories/unreviewed/2022/12/GHSA-5hr7-vh78-qh58/GHSA-5hr7-vh78-qh58.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5hr7-vh78-qh58", - "modified": "2022-12-29T18:30:24Z", + "modified": "2025-04-16T18:31:35Z", "published": "2022-12-22T21:30:31Z", "aliases": [ "CVE-2022-1097" diff --git a/advisories/unreviewed/2022/12/GHSA-5hrv-4r6h-jgxc/GHSA-5hrv-4r6h-jgxc.json b/advisories/unreviewed/2022/12/GHSA-5hrv-4r6h-jgxc/GHSA-5hrv-4r6h-jgxc.json index 4c1b3753b8f..b7ba3a9309b 100644 --- a/advisories/unreviewed/2022/12/GHSA-5hrv-4r6h-jgxc/GHSA-5hrv-4r6h-jgxc.json +++ b/advisories/unreviewed/2022/12/GHSA-5hrv-4r6h-jgxc/GHSA-5hrv-4r6h-jgxc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5hrv-4r6h-jgxc", - "modified": "2022-12-29T18:30:25Z", + "modified": "2025-04-16T18:31:36Z", "published": "2022-12-22T21:30:30Z", "aliases": [ "CVE-2022-22740" diff --git a/advisories/unreviewed/2022/12/GHSA-62m5-vcjm-vvp5/GHSA-62m5-vcjm-vvp5.json b/advisories/unreviewed/2022/12/GHSA-62m5-vcjm-vvp5/GHSA-62m5-vcjm-vvp5.json index 69b4cde1962..f894b0c9e02 100644 --- a/advisories/unreviewed/2022/12/GHSA-62m5-vcjm-vvp5/GHSA-62m5-vcjm-vvp5.json +++ b/advisories/unreviewed/2022/12/GHSA-62m5-vcjm-vvp5/GHSA-62m5-vcjm-vvp5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-62m5-vcjm-vvp5", - "modified": "2022-12-28T18:30:21Z", + "modified": "2025-04-16T18:31:30Z", "published": "2022-12-20T21:30:19Z", "aliases": [ "CVE-2022-46914" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46914" }, + { + "type": "WEB", + "url": "https://hackmd.io/%40slASVrz_SrW7NQCsunofeA/BJ4czlpwi" + }, { "type": "WEB", "url": "https://hackmd.io/@slASVrz_SrW7NQCsunofeA/BJ4czlpwi" diff --git a/advisories/unreviewed/2022/12/GHSA-6pmm-vfgm-49r7/GHSA-6pmm-vfgm-49r7.json b/advisories/unreviewed/2022/12/GHSA-6pmm-vfgm-49r7/GHSA-6pmm-vfgm-49r7.json index 23f60aa7389..83f320e6563 100644 --- a/advisories/unreviewed/2022/12/GHSA-6pmm-vfgm-49r7/GHSA-6pmm-vfgm-49r7.json +++ b/advisories/unreviewed/2022/12/GHSA-6pmm-vfgm-49r7/GHSA-6pmm-vfgm-49r7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6pmm-vfgm-49r7", - "modified": "2022-12-29T21:30:30Z", + "modified": "2025-04-16T18:31:32Z", "published": "2022-12-22T21:30:31Z", "aliases": [ "CVE-2020-15679" diff --git a/advisories/unreviewed/2022/12/GHSA-7h6j-6653-fx8c/GHSA-7h6j-6653-fx8c.json b/advisories/unreviewed/2022/12/GHSA-7h6j-6653-fx8c/GHSA-7h6j-6653-fx8c.json index 6ea492ffdd0..12ea5d133e8 100644 --- a/advisories/unreviewed/2022/12/GHSA-7h6j-6653-fx8c/GHSA-7h6j-6653-fx8c.json +++ b/advisories/unreviewed/2022/12/GHSA-7h6j-6653-fx8c/GHSA-7h6j-6653-fx8c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7h6j-6653-fx8c", - "modified": "2022-12-30T00:30:42Z", + "modified": "2025-04-16T18:31:36Z", "published": "2022-12-22T21:30:30Z", "aliases": [ "CVE-2022-22747" diff --git a/advisories/unreviewed/2022/12/GHSA-7rf2-x8gr-rv3r/GHSA-7rf2-x8gr-rv3r.json b/advisories/unreviewed/2022/12/GHSA-7rf2-x8gr-rv3r/GHSA-7rf2-x8gr-rv3r.json index 3a97d87b6cf..86d6c9cd1ee 100644 --- a/advisories/unreviewed/2022/12/GHSA-7rf2-x8gr-rv3r/GHSA-7rf2-x8gr-rv3r.json +++ b/advisories/unreviewed/2022/12/GHSA-7rf2-x8gr-rv3r/GHSA-7rf2-x8gr-rv3r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7rf2-x8gr-rv3r", - "modified": "2022-12-31T00:30:24Z", + "modified": "2025-04-16T18:31:30Z", "published": "2022-12-21T09:30:25Z", "aliases": [ "CVE-2022-44449" diff --git a/advisories/unreviewed/2022/12/GHSA-7wp9-fj5q-c4jc/GHSA-7wp9-fj5q-c4jc.json b/advisories/unreviewed/2022/12/GHSA-7wp9-fj5q-c4jc/GHSA-7wp9-fj5q-c4jc.json index 62f4c489704..301f9050cfa 100644 --- a/advisories/unreviewed/2022/12/GHSA-7wp9-fj5q-c4jc/GHSA-7wp9-fj5q-c4jc.json +++ b/advisories/unreviewed/2022/12/GHSA-7wp9-fj5q-c4jc/GHSA-7wp9-fj5q-c4jc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7wp9-fj5q-c4jc", - "modified": "2023-01-04T15:30:20Z", + "modified": "2025-04-16T18:31:32Z", "published": "2022-12-22T21:30:31Z", "aliases": [ "CVE-2021-4127" diff --git a/advisories/unreviewed/2022/12/GHSA-cpxq-p6pr-9jf6/GHSA-cpxq-p6pr-9jf6.json b/advisories/unreviewed/2022/12/GHSA-cpxq-p6pr-9jf6/GHSA-cpxq-p6pr-9jf6.json index 7a305f70ffb..071c91318d3 100644 --- a/advisories/unreviewed/2022/12/GHSA-cpxq-p6pr-9jf6/GHSA-cpxq-p6pr-9jf6.json +++ b/advisories/unreviewed/2022/12/GHSA-cpxq-p6pr-9jf6/GHSA-cpxq-p6pr-9jf6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cpxq-p6pr-9jf6", - "modified": "2022-12-30T00:30:42Z", + "modified": "2025-04-16T18:31:36Z", "published": "2022-12-22T21:30:30Z", "aliases": [ "CVE-2022-22750" diff --git a/advisories/unreviewed/2022/12/GHSA-grr5-5v7v-g4c4/GHSA-grr5-5v7v-g4c4.json b/advisories/unreviewed/2022/12/GHSA-grr5-5v7v-g4c4/GHSA-grr5-5v7v-g4c4.json index f08ee17c7ed..c0be8cb3a54 100644 --- a/advisories/unreviewed/2022/12/GHSA-grr5-5v7v-g4c4/GHSA-grr5-5v7v-g4c4.json +++ b/advisories/unreviewed/2022/12/GHSA-grr5-5v7v-g4c4/GHSA-grr5-5v7v-g4c4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-grr5-5v7v-g4c4", - "modified": "2022-12-29T18:30:24Z", + "modified": "2025-04-16T18:31:35Z", "published": "2022-12-22T21:30:30Z", "aliases": [ "CVE-2022-1529" diff --git a/advisories/unreviewed/2022/12/GHSA-h5mr-xp97-c4p5/GHSA-h5mr-xp97-c4p5.json b/advisories/unreviewed/2022/12/GHSA-h5mr-xp97-c4p5/GHSA-h5mr-xp97-c4p5.json index 4a050cac493..e53e41dd547 100644 --- a/advisories/unreviewed/2022/12/GHSA-h5mr-xp97-c4p5/GHSA-h5mr-xp97-c4p5.json +++ b/advisories/unreviewed/2022/12/GHSA-h5mr-xp97-c4p5/GHSA-h5mr-xp97-c4p5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h5mr-xp97-c4p5", - "modified": "2023-01-03T21:30:20Z", + "modified": "2025-04-16T18:31:33Z", "published": "2022-12-22T21:30:31Z", "aliases": [ "CVE-2021-4140" diff --git a/advisories/unreviewed/2022/12/GHSA-h922-mv7w-mhm4/GHSA-h922-mv7w-mhm4.json b/advisories/unreviewed/2022/12/GHSA-h922-mv7w-mhm4/GHSA-h922-mv7w-mhm4.json index 5b9170ce3fb..d54d59d6c8d 100644 --- a/advisories/unreviewed/2022/12/GHSA-h922-mv7w-mhm4/GHSA-h922-mv7w-mhm4.json +++ b/advisories/unreviewed/2022/12/GHSA-h922-mv7w-mhm4/GHSA-h922-mv7w-mhm4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h922-mv7w-mhm4", - "modified": "2022-12-29T18:30:24Z", + "modified": "2025-04-16T18:31:35Z", "published": "2022-12-22T21:30:31Z", "aliases": [ "CVE-2022-1197" diff --git a/advisories/unreviewed/2022/12/GHSA-j4m3-g4pc-cph8/GHSA-j4m3-g4pc-cph8.json b/advisories/unreviewed/2022/12/GHSA-j4m3-g4pc-cph8/GHSA-j4m3-g4pc-cph8.json index a871405ca63..c45882c54f6 100644 --- a/advisories/unreviewed/2022/12/GHSA-j4m3-g4pc-cph8/GHSA-j4m3-g4pc-cph8.json +++ b/advisories/unreviewed/2022/12/GHSA-j4m3-g4pc-cph8/GHSA-j4m3-g4pc-cph8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j4m3-g4pc-cph8", - "modified": "2023-01-03T15:30:16Z", + "modified": "2025-04-16T18:31:30Z", "published": "2022-12-21T00:30:28Z", "aliases": [ "CVE-2022-47629" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://dev.gnupg.org/T6284" }, + { + "type": "WEB", + "url": "https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libksba.git%3Ba=commit%3Bh=f61a5ea4e0f6a80fd4b28ef0174bee77793cf070" + }, { "type": "WEB", "url": "https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libksba.git;a=commit;h=f61a5ea4e0f6a80fd4b28ef0174bee77793cf070" diff --git a/advisories/unreviewed/2022/12/GHSA-jxxq-8qw2-56g4/GHSA-jxxq-8qw2-56g4.json b/advisories/unreviewed/2022/12/GHSA-jxxq-8qw2-56g4/GHSA-jxxq-8qw2-56g4.json index 50f5772c00a..b048296c817 100644 --- a/advisories/unreviewed/2022/12/GHSA-jxxq-8qw2-56g4/GHSA-jxxq-8qw2-56g4.json +++ b/advisories/unreviewed/2022/12/GHSA-jxxq-8qw2-56g4/GHSA-jxxq-8qw2-56g4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jxxq-8qw2-56g4", - "modified": "2023-01-04T21:30:19Z", + "modified": "2025-04-16T18:31:30Z", "published": "2022-12-21T09:30:25Z", "aliases": [ "CVE-2022-43543" @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-116" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-p859-wprc-3cjx/GHSA-p859-wprc-3cjx.json b/advisories/unreviewed/2022/12/GHSA-p859-wprc-3cjx/GHSA-p859-wprc-3cjx.json index e331cf61b8f..36a03a13821 100644 --- a/advisories/unreviewed/2022/12/GHSA-p859-wprc-3cjx/GHSA-p859-wprc-3cjx.json +++ b/advisories/unreviewed/2022/12/GHSA-p859-wprc-3cjx/GHSA-p859-wprc-3cjx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p859-wprc-3cjx", - "modified": "2022-12-29T18:30:24Z", + "modified": "2025-04-16T18:31:35Z", "published": "2022-12-22T21:30:30Z", "aliases": [ "CVE-2022-1802" diff --git a/advisories/unreviewed/2022/12/GHSA-pr8r-56vp-3rp2/GHSA-pr8r-56vp-3rp2.json b/advisories/unreviewed/2022/12/GHSA-pr8r-56vp-3rp2/GHSA-pr8r-56vp-3rp2.json index 8b86fc522d3..e3e9713a6a4 100644 --- a/advisories/unreviewed/2022/12/GHSA-pr8r-56vp-3rp2/GHSA-pr8r-56vp-3rp2.json +++ b/advisories/unreviewed/2022/12/GHSA-pr8r-56vp-3rp2/GHSA-pr8r-56vp-3rp2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pr8r-56vp-3rp2", - "modified": "2022-12-28T18:30:21Z", + "modified": "2025-04-16T18:31:29Z", "published": "2022-12-20T21:30:19Z", "aliases": [ "CVE-2022-46435" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46435" }, + { + "type": "WEB", + "url": "https://hackmd.io/%40slASVrz_SrW7NQCsunofeA/SyvnlO9Pi" + }, { "type": "WEB", "url": "https://hackmd.io/@slASVrz_SrW7NQCsunofeA/SyvnlO9Pi" diff --git a/advisories/unreviewed/2022/12/GHSA-qh42-r75f-c8h4/GHSA-qh42-r75f-c8h4.json b/advisories/unreviewed/2022/12/GHSA-qh42-r75f-c8h4/GHSA-qh42-r75f-c8h4.json index dc930ebf273..45498365afe 100644 --- a/advisories/unreviewed/2022/12/GHSA-qh42-r75f-c8h4/GHSA-qh42-r75f-c8h4.json +++ b/advisories/unreviewed/2022/12/GHSA-qh42-r75f-c8h4/GHSA-qh42-r75f-c8h4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qh42-r75f-c8h4", - "modified": "2022-12-28T18:30:21Z", + "modified": "2025-04-16T18:31:30Z", "published": "2022-12-20T21:30:19Z", "aliases": [ "CVE-2022-46910" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46910" }, + { + "type": "WEB", + "url": "https://hackmd.io/%40slASVrz_SrW7NQCsunofeA/BkwzORiDo" + }, { "type": "WEB", "url": "https://hackmd.io/@slASVrz_SrW7NQCsunofeA/BkwzORiDo" diff --git a/advisories/unreviewed/2022/12/GHSA-qq6h-hx9q-4fxv/GHSA-qq6h-hx9q-4fxv.json b/advisories/unreviewed/2022/12/GHSA-qq6h-hx9q-4fxv/GHSA-qq6h-hx9q-4fxv.json index 9e2c1acd612..35cb220309e 100644 --- a/advisories/unreviewed/2022/12/GHSA-qq6h-hx9q-4fxv/GHSA-qq6h-hx9q-4fxv.json +++ b/advisories/unreviewed/2022/12/GHSA-qq6h-hx9q-4fxv/GHSA-qq6h-hx9q-4fxv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qq6h-hx9q-4fxv", - "modified": "2022-12-29T18:30:25Z", + "modified": "2025-04-16T18:31:35Z", "published": "2022-12-22T21:30:30Z", "aliases": [ "CVE-2022-1834" diff --git a/advisories/unreviewed/2022/12/GHSA-qx74-qh3q-h8rj/GHSA-qx74-qh3q-h8rj.json b/advisories/unreviewed/2022/12/GHSA-qx74-qh3q-h8rj/GHSA-qx74-qh3q-h8rj.json index 06164008983..2df8f7acdb7 100644 --- a/advisories/unreviewed/2022/12/GHSA-qx74-qh3q-h8rj/GHSA-qx74-qh3q-h8rj.json +++ b/advisories/unreviewed/2022/12/GHSA-qx74-qh3q-h8rj/GHSA-qx74-qh3q-h8rj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qx74-qh3q-h8rj", - "modified": "2023-01-03T21:30:20Z", + "modified": "2025-04-16T18:31:33Z", "published": "2022-12-22T21:30:31Z", "aliases": [ "CVE-2021-4128" diff --git a/advisories/unreviewed/2022/12/GHSA-qx9j-6hf5-hxjp/GHSA-qx9j-6hf5-hxjp.json b/advisories/unreviewed/2022/12/GHSA-qx9j-6hf5-hxjp/GHSA-qx9j-6hf5-hxjp.json index cdca87f6415..a1f00aebfc7 100644 --- a/advisories/unreviewed/2022/12/GHSA-qx9j-6hf5-hxjp/GHSA-qx9j-6hf5-hxjp.json +++ b/advisories/unreviewed/2022/12/GHSA-qx9j-6hf5-hxjp/GHSA-qx9j-6hf5-hxjp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qx9j-6hf5-hxjp", - "modified": "2022-12-28T21:30:22Z", + "modified": "2025-04-16T18:31:29Z", "published": "2022-12-20T21:30:19Z", "aliases": [ "CVE-2022-46432" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46432" }, + { + "type": "WEB", + "url": "https://hackmd.io/%40slASVrz_SrW7NQCsunofeA/B1Vgv1uwo" + }, { "type": "WEB", "url": "https://hackmd.io/@slASVrz_SrW7NQCsunofeA/B1Vgv1uwo" diff --git a/advisories/unreviewed/2022/12/GHSA-v25r-h4v7-62rr/GHSA-v25r-h4v7-62rr.json b/advisories/unreviewed/2022/12/GHSA-v25r-h4v7-62rr/GHSA-v25r-h4v7-62rr.json index 93739bcc0f2..1e2d247be9d 100644 --- a/advisories/unreviewed/2022/12/GHSA-v25r-h4v7-62rr/GHSA-v25r-h4v7-62rr.json +++ b/advisories/unreviewed/2022/12/GHSA-v25r-h4v7-62rr/GHSA-v25r-h4v7-62rr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v25r-h4v7-62rr", - "modified": "2023-01-03T21:30:20Z", + "modified": "2025-04-16T18:31:33Z", "published": "2022-12-22T21:30:31Z", "aliases": [ "CVE-2021-4129" @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-v2cr-gvw4-g56p/GHSA-v2cr-gvw4-g56p.json b/advisories/unreviewed/2022/12/GHSA-v2cr-gvw4-g56p/GHSA-v2cr-gvw4-g56p.json index 846eaa5fc0a..c4338f58767 100644 --- a/advisories/unreviewed/2022/12/GHSA-v2cr-gvw4-g56p/GHSA-v2cr-gvw4-g56p.json +++ b/advisories/unreviewed/2022/12/GHSA-v2cr-gvw4-g56p/GHSA-v2cr-gvw4-g56p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v2cr-gvw4-g56p", - "modified": "2023-01-04T15:30:20Z", + "modified": "2025-04-16T18:31:32Z", "published": "2022-12-22T21:30:31Z", "aliases": [ "CVE-2021-4126" diff --git a/advisories/unreviewed/2022/12/GHSA-vpvf-2qgj-mm25/GHSA-vpvf-2qgj-mm25.json b/advisories/unreviewed/2022/12/GHSA-vpvf-2qgj-mm25/GHSA-vpvf-2qgj-mm25.json index 30a014b7aef..6b28fa37097 100644 --- a/advisories/unreviewed/2022/12/GHSA-vpvf-2qgj-mm25/GHSA-vpvf-2qgj-mm25.json +++ b/advisories/unreviewed/2022/12/GHSA-vpvf-2qgj-mm25/GHSA-vpvf-2qgj-mm25.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vpvf-2qgj-mm25", - "modified": "2022-12-29T18:30:25Z", + "modified": "2025-04-16T18:31:36Z", "published": "2022-12-22T21:30:30Z", "aliases": [ "CVE-2022-22739" diff --git a/advisories/unreviewed/2022/12/GHSA-wmph-fgw4-55rj/GHSA-wmph-fgw4-55rj.json b/advisories/unreviewed/2022/12/GHSA-wmph-fgw4-55rj/GHSA-wmph-fgw4-55rj.json index 411dba1ca55..1a8c4ba8eaf 100644 --- a/advisories/unreviewed/2022/12/GHSA-wmph-fgw4-55rj/GHSA-wmph-fgw4-55rj.json +++ b/advisories/unreviewed/2022/12/GHSA-wmph-fgw4-55rj/GHSA-wmph-fgw4-55rj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wmph-fgw4-55rj", - "modified": "2022-12-24T06:30:24Z", + "modified": "2025-04-16T18:31:34Z", "published": "2022-12-22T21:30:31Z", "aliases": [ "CVE-2021-4221" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-1007" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-59xm-w7f6-pq99/GHSA-59xm-w7f6-pq99.json b/advisories/unreviewed/2024/03/GHSA-59xm-w7f6-pq99/GHSA-59xm-w7f6-pq99.json index 00cb0fcdee7..ede2b0f269b 100644 --- a/advisories/unreviewed/2024/03/GHSA-59xm-w7f6-pq99/GHSA-59xm-w7f6-pq99.json +++ b/advisories/unreviewed/2024/03/GHSA-59xm-w7f6-pq99/GHSA-59xm-w7f6-pq99.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-59xm-w7f6-pq99", - "modified": "2024-03-18T15:30:50Z", + "modified": "2025-04-16T18:31:38Z", "published": "2024-03-18T15:30:50Z", "aliases": [ "CVE-2024-2587" diff --git a/advisories/unreviewed/2024/03/GHSA-7hrp-6pgm-w8r3/GHSA-7hrp-6pgm-w8r3.json b/advisories/unreviewed/2024/03/GHSA-7hrp-6pgm-w8r3/GHSA-7hrp-6pgm-w8r3.json index 014a67a194a..4b14ad11ff3 100644 --- a/advisories/unreviewed/2024/03/GHSA-7hrp-6pgm-w8r3/GHSA-7hrp-6pgm-w8r3.json +++ b/advisories/unreviewed/2024/03/GHSA-7hrp-6pgm-w8r3/GHSA-7hrp-6pgm-w8r3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7hrp-6pgm-w8r3", - "modified": "2024-03-18T15:30:50Z", + "modified": "2025-04-16T18:31:39Z", "published": "2024-03-18T15:30:50Z", "aliases": [ "CVE-2024-2588" diff --git a/advisories/unreviewed/2024/03/GHSA-mfrg-mc7h-8xrw/GHSA-mfrg-mc7h-8xrw.json b/advisories/unreviewed/2024/03/GHSA-mfrg-mc7h-8xrw/GHSA-mfrg-mc7h-8xrw.json index 02eb4113365..e7a9b3bd107 100644 --- a/advisories/unreviewed/2024/03/GHSA-mfrg-mc7h-8xrw/GHSA-mfrg-mc7h-8xrw.json +++ b/advisories/unreviewed/2024/03/GHSA-mfrg-mc7h-8xrw/GHSA-mfrg-mc7h-8xrw.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-mfrg-mc7h-8xrw", - "modified": "2025-02-10T21:31:27Z", + "modified": "2025-04-16T18:31:38Z", "published": "2024-03-18T00:30:44Z", "aliases": [ "CVE-2024-23139" ], - "details": "An Out-Of-Bounds Write Vulnerability in Autodesk FBX Review version 1.5.3.0 and prior may lead to code execution or information disclosure through maliciously crafted ActionScript Byte Code “ABC” files. ABC files are created by the Flash compiler and contain executable code. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.\n", + "details": "An Out-Of-Bounds Write Vulnerability in Autodesk FBX Review version 1.5.3.0 and prior may lead to code execution or information disclosure through maliciously crafted ActionScript Byte Code “ABC” files. ABC files are created by the Flash compiler and contain executable code. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-prfm-p99w-7gm2/GHSA-prfm-p99w-7gm2.json b/advisories/unreviewed/2024/03/GHSA-prfm-p99w-7gm2/GHSA-prfm-p99w-7gm2.json index 667e3b076e2..2190137c8e6 100644 --- a/advisories/unreviewed/2024/03/GHSA-prfm-p99w-7gm2/GHSA-prfm-p99w-7gm2.json +++ b/advisories/unreviewed/2024/03/GHSA-prfm-p99w-7gm2/GHSA-prfm-p99w-7gm2.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-798" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-4wxr-6xmc-853x/GHSA-4wxr-6xmc-853x.json b/advisories/unreviewed/2024/05/GHSA-4wxr-6xmc-853x/GHSA-4wxr-6xmc-853x.json index 6b30795a9b6..50eb58dbe20 100644 --- a/advisories/unreviewed/2024/05/GHSA-4wxr-6xmc-853x/GHSA-4wxr-6xmc-853x.json +++ b/advisories/unreviewed/2024/05/GHSA-4wxr-6xmc-853x/GHSA-4wxr-6xmc-853x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4wxr-6xmc-853x", - "modified": "2024-05-07T18:30:34Z", + "modified": "2025-04-16T18:31:42Z", "published": "2024-05-07T18:30:34Z", "aliases": [ "CVE-2024-33148" ], "details": "J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the list function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T17:15:08Z" diff --git a/advisories/unreviewed/2024/08/GHSA-gw56-mg6j-26qj/GHSA-gw56-mg6j-26qj.json b/advisories/unreviewed/2024/08/GHSA-gw56-mg6j-26qj/GHSA-gw56-mg6j-26qj.json index 80ee04485ed..4989ba55e0a 100644 --- a/advisories/unreviewed/2024/08/GHSA-gw56-mg6j-26qj/GHSA-gw56-mg6j-26qj.json +++ b/advisories/unreviewed/2024/08/GHSA-gw56-mg6j-26qj/GHSA-gw56-mg6j-26qj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gw56-mg6j-26qj", - "modified": "2025-01-01T00:30:26Z", + "modified": "2025-04-16T18:31:42Z", "published": "2024-08-08T03:30:49Z", "aliases": [ "CVE-2024-38202" @@ -22,6 +22,14 @@ { "type": "WEB", "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38202" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/cve-2024-38202-potential-elevation-of-privilege-vulnerability-in-windows-backup-detection-script" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/cve-2024-38202-potential-elevation-of-privilege-vulnerability-in-windows-backup-mitigation-script" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-jfhf-w467-c85w/GHSA-jfhf-w467-c85w.json b/advisories/unreviewed/2025/01/GHSA-jfhf-w467-c85w/GHSA-jfhf-w467-c85w.json index 4a71255e752..851d17d647d 100644 --- a/advisories/unreviewed/2025/01/GHSA-jfhf-w467-c85w/GHSA-jfhf-w467-c85w.json +++ b/advisories/unreviewed/2025/01/GHSA-jfhf-w467-c85w/GHSA-jfhf-w467-c85w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jfhf-w467-c85w", - "modified": "2025-01-13T21:30:52Z", + "modified": "2025-04-16T18:31:42Z", "published": "2025-01-10T18:31:41Z", "aliases": [ "CVE-2024-50807" @@ -22,6 +22,14 @@ { "type": "WEB", "url": "https://gist.github.com/HackShiv/4254db89214913867aa8dd5c1ec09b7e" + }, + { + "type": "WEB", + "url": "https://gist.github.com/SecShiv/4254db89214913867aa8dd5c1ec09b7e" + }, + { + "type": "WEB", + "url": "https://github.com/SecShiv/CVE/blob/main/CVE-2024-50807.md" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-8xfh-434c-qfv7/GHSA-8xfh-434c-qfv7.json b/advisories/unreviewed/2025/03/GHSA-8xfh-434c-qfv7/GHSA-8xfh-434c-qfv7.json index 71e654a45db..b4c21b276b0 100644 --- a/advisories/unreviewed/2025/03/GHSA-8xfh-434c-qfv7/GHSA-8xfh-434c-qfv7.json +++ b/advisories/unreviewed/2025/03/GHSA-8xfh-434c-qfv7/GHSA-8xfh-434c-qfv7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8xfh-434c-qfv7", - "modified": "2025-03-11T18:32:19Z", + "modified": "2025-04-16T18:31:47Z", "published": "2025-03-11T18:32:19Z", "aliases": [ "CVE-2025-26633" @@ -22,6 +22,14 @@ { "type": "WEB", "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26633" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/cve-2025-26633-security-feature-bypass-in-microsoft-management-console-detection-script" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/cve-2025-26633-security-feature-bypass-in-microsoft-management-console-mitigation-script" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-mppc-8qxh-4wjw/GHSA-mppc-8qxh-4wjw.json b/advisories/unreviewed/2025/03/GHSA-mppc-8qxh-4wjw/GHSA-mppc-8qxh-4wjw.json index 9e75925ac58..198aca760e1 100644 --- a/advisories/unreviewed/2025/03/GHSA-mppc-8qxh-4wjw/GHSA-mppc-8qxh-4wjw.json +++ b/advisories/unreviewed/2025/03/GHSA-mppc-8qxh-4wjw/GHSA-mppc-8qxh-4wjw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mppc-8qxh-4wjw", - "modified": "2025-03-11T18:32:17Z", + "modified": "2025-04-16T18:31:47Z", "published": "2025-03-11T18:32:17Z", "aliases": [ "CVE-2025-24071" @@ -22,6 +22,14 @@ { "type": "WEB", "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24071" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/cve-2025-24071-spoofing-vulnerability-in-microsoft-windows-file-explorer-detection-scrip" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/cve-2025-24071-spoofing-vulnerability-in-microsoft-windows-file-explorer-mitigation-script" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/04/GHSA-2689-cw26-6cpj/GHSA-2689-cw26-6cpj.json b/advisories/unreviewed/2025/04/GHSA-2689-cw26-6cpj/GHSA-2689-cw26-6cpj.json new file mode 100644 index 00000000000..054feb26463 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2689-cw26-6cpj/GHSA-2689-cw26-6cpj.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2689-cw26-6cpj", + "modified": "2025-04-16T18:31:54Z", + "published": "2025-04-16T18:31:54Z", + "aliases": [ + "CVE-2024-53305" + ], + "details": "An issue in the component /models/config.py of Whoogle search v0.9.0 allows attackers to execute arbitrary code via supplying a crafted search query.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53305" + }, + { + "type": "WEB", + "url": "https://github.com/benbusby/whoogle-search/commit/223f00c3c0533423114f99b30c561278bc0b42ba" + }, + { + "type": "WEB", + "url": "https://gist.github.com/fern89/ca5fe76ad81b4bc363e7341e523a1651" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2cqp-v7m3-p6hm/GHSA-2cqp-v7m3-p6hm.json b/advisories/unreviewed/2025/04/GHSA-2cqp-v7m3-p6hm/GHSA-2cqp-v7m3-p6hm.json index 3a6c4383236..45dca1225bb 100644 --- a/advisories/unreviewed/2025/04/GHSA-2cqp-v7m3-p6hm/GHSA-2cqp-v7m3-p6hm.json +++ b/advisories/unreviewed/2025/04/GHSA-2cqp-v7m3-p6hm/GHSA-2cqp-v7m3-p6hm.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-2f64-9486-5qm3/GHSA-2f64-9486-5qm3.json b/advisories/unreviewed/2025/04/GHSA-2f64-9486-5qm3/GHSA-2f64-9486-5qm3.json new file mode 100644 index 00000000000..7696d076f3e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2f64-9486-5qm3/GHSA-2f64-9486-5qm3.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2f64-9486-5qm3", + "modified": "2025-04-16T18:31:55Z", + "published": "2025-04-16T18:31:55Z", + "aliases": [ + "CVE-2025-32831" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateProjectUserRights' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32831" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2fxf-g7gx-j9pr/GHSA-2fxf-g7gx-j9pr.json b/advisories/unreviewed/2025/04/GHSA-2fxf-g7gx-j9pr/GHSA-2fxf-g7gx-j9pr.json index d89198b30c6..7a2aafa7493 100644 --- a/advisories/unreviewed/2025/04/GHSA-2fxf-g7gx-j9pr/GHSA-2fxf-g7gx-j9pr.json +++ b/advisories/unreviewed/2025/04/GHSA-2fxf-g7gx-j9pr/GHSA-2fxf-g7gx-j9pr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-2r37-q3rp-gh53/GHSA-2r37-q3rp-gh53.json b/advisories/unreviewed/2025/04/GHSA-2r37-q3rp-gh53/GHSA-2r37-q3rp-gh53.json new file mode 100644 index 00000000000..252106d40ef --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2r37-q3rp-gh53/GHSA-2r37-q3rp-gh53.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2r37-q3rp-gh53", + "modified": "2025-04-16T18:31:56Z", + "published": "2025-04-16T18:31:56Z", + "aliases": [ + "CVE-2025-32845" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateGeneralSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32845" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2r3c-qw88-pfgq/GHSA-2r3c-qw88-pfgq.json b/advisories/unreviewed/2025/04/GHSA-2r3c-qw88-pfgq/GHSA-2r3c-qw88-pfgq.json new file mode 100644 index 00000000000..7c2c0766ff3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2r3c-qw88-pfgq/GHSA-2r3c-qw88-pfgq.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2r3c-qw88-pfgq", + "modified": "2025-04-16T18:31:57Z", + "published": "2025-04-16T18:31:57Z", + "aliases": [ + "CVE-2025-32853" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UnlockDatabaseSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32853" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2vpw-mvv7-vfx4/GHSA-2vpw-mvv7-vfx4.json b/advisories/unreviewed/2025/04/GHSA-2vpw-mvv7-vfx4/GHSA-2vpw-mvv7-vfx4.json new file mode 100644 index 00000000000..266ac9c4e8e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2vpw-mvv7-vfx4/GHSA-2vpw-mvv7-vfx4.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2vpw-mvv7-vfx4", + "modified": "2025-04-16T18:31:53Z", + "published": "2025-04-16T18:31:53Z", + "aliases": [ + "CVE-2024-40071" + ], + "details": "Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_generator/classes/SystemSettings.php?f=update_settings. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40071" + }, + { + "type": "WEB", + "url": "https://github.com/DiliLearngent/BugReport/blob/main/php/Online-ID-Generator-System/bug2-File-upload-img.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T17:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-332x-qjv9-28mf/GHSA-332x-qjv9-28mf.json b/advisories/unreviewed/2025/04/GHSA-332x-qjv9-28mf/GHSA-332x-qjv9-28mf.json new file mode 100644 index 00000000000..3d505a603d7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-332x-qjv9-28mf/GHSA-332x-qjv9-28mf.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-332x-qjv9-28mf", + "modified": "2025-04-16T18:31:56Z", + "published": "2025-04-16T18:31:56Z", + "aliases": [ + "CVE-2025-32850" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'LockTcmSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32850" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-39cf-f784-9gfv/GHSA-39cf-f784-9gfv.json b/advisories/unreviewed/2025/04/GHSA-39cf-f784-9gfv/GHSA-39cf-f784-9gfv.json new file mode 100644 index 00000000000..2a505860dad --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-39cf-f784-9gfv/GHSA-39cf-f784-9gfv.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-39cf-f784-9gfv", + "modified": "2025-04-16T18:31:55Z", + "published": "2025-04-16T18:31:55Z", + "aliases": [ + "CVE-2025-32829" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'LockProjectCrossCommunications' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32829" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3fvx-r9r8-xq97/GHSA-3fvx-r9r8-xq97.json b/advisories/unreviewed/2025/04/GHSA-3fvx-r9r8-xq97/GHSA-3fvx-r9r8-xq97.json index 3a6cf34d131..092fa736f19 100644 --- a/advisories/unreviewed/2025/04/GHSA-3fvx-r9r8-xq97/GHSA-3fvx-r9r8-xq97.json +++ b/advisories/unreviewed/2025/04/GHSA-3fvx-r9r8-xq97/GHSA-3fvx-r9r8-xq97.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-3mxx-c2rp-35q6/GHSA-3mxx-c2rp-35q6.json b/advisories/unreviewed/2025/04/GHSA-3mxx-c2rp-35q6/GHSA-3mxx-c2rp-35q6.json new file mode 100644 index 00000000000..f975225a6d9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3mxx-c2rp-35q6/GHSA-3mxx-c2rp-35q6.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3mxx-c2rp-35q6", + "modified": "2025-04-16T18:31:58Z", + "published": "2025-04-16T18:31:58Z", + "aliases": [ + "CVE-2025-32869" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'ImportCertificate' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32869" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3rmg-5jwh-4537/GHSA-3rmg-5jwh-4537.json b/advisories/unreviewed/2025/04/GHSA-3rmg-5jwh-4537/GHSA-3rmg-5jwh-4537.json new file mode 100644 index 00000000000..06c9094685e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3rmg-5jwh-4537/GHSA-3rmg-5jwh-4537.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3rmg-5jwh-4537", + "modified": "2025-04-16T18:31:56Z", + "published": "2025-04-16T18:31:56Z", + "aliases": [ + "CVE-2025-32839" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'GetGateways' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32839" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4574-jv92-whqq/GHSA-4574-jv92-whqq.json b/advisories/unreviewed/2025/04/GHSA-4574-jv92-whqq/GHSA-4574-jv92-whqq.json new file mode 100644 index 00000000000..f6c163fbc69 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4574-jv92-whqq/GHSA-4574-jv92-whqq.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4574-jv92-whqq", + "modified": "2025-04-16T18:31:56Z", + "published": "2025-04-16T18:31:55Z", + "aliases": [ + "CVE-2025-32836" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'GetConnectionVariables' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32836" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-484q-pw9g-43jp/GHSA-484q-pw9g-43jp.json b/advisories/unreviewed/2025/04/GHSA-484q-pw9g-43jp/GHSA-484q-pw9g-43jp.json new file mode 100644 index 00000000000..6ddc71795a4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-484q-pw9g-43jp/GHSA-484q-pw9g-43jp.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-484q-pw9g-43jp", + "modified": "2025-04-16T18:31:58Z", + "published": "2025-04-16T18:31:58Z", + "aliases": [ + "CVE-2025-32871" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'MigrateDatabase' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32871" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-48p8-54rv-5v4r/GHSA-48p8-54rv-5v4r.json b/advisories/unreviewed/2025/04/GHSA-48p8-54rv-5v4r/GHSA-48p8-54rv-5v4r.json index 9528d449f95..2cadbd1d8ee 100644 --- a/advisories/unreviewed/2025/04/GHSA-48p8-54rv-5v4r/GHSA-48p8-54rv-5v4r.json +++ b/advisories/unreviewed/2025/04/GHSA-48p8-54rv-5v4r/GHSA-48p8-54rv-5v4r.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-4x2m-9cgv-ww5m/GHSA-4x2m-9cgv-ww5m.json b/advisories/unreviewed/2025/04/GHSA-4x2m-9cgv-ww5m/GHSA-4x2m-9cgv-ww5m.json new file mode 100644 index 00000000000..fcecdfb0b54 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4x2m-9cgv-ww5m/GHSA-4x2m-9cgv-ww5m.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4x2m-9cgv-ww5m", + "modified": "2025-04-16T18:31:55Z", + "published": "2025-04-16T18:31:55Z", + "aliases": [ + "CVE-2025-32826" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'GetActiveProjects' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32826" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-52j6-97cf-wwf9/GHSA-52j6-97cf-wwf9.json b/advisories/unreviewed/2025/04/GHSA-52j6-97cf-wwf9/GHSA-52j6-97cf-wwf9.json new file mode 100644 index 00000000000..cb04bb0cdfa --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-52j6-97cf-wwf9/GHSA-52j6-97cf-wwf9.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-52j6-97cf-wwf9", + "modified": "2025-04-16T18:31:54Z", + "published": "2025-04-16T18:31:54Z", + "aliases": [ + "CVE-2025-30031" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateUsers' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on. (ZDI-CAN-25922)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30031" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5f2v-m5mv-jjvw/GHSA-5f2v-m5mv-jjvw.json b/advisories/unreviewed/2025/04/GHSA-5f2v-m5mv-jjvw/GHSA-5f2v-m5mv-jjvw.json new file mode 100644 index 00000000000..16d89c33a8f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5f2v-m5mv-jjvw/GHSA-5f2v-m5mv-jjvw.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5f2v-m5mv-jjvw", + "modified": "2025-04-16T18:31:55Z", + "published": "2025-04-16T18:31:54Z", + "aliases": [ + "CVE-2025-31351" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'CreateProject' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on. (ZDI-CAN-25917)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31351" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5xv7-xrgm-g78v/GHSA-5xv7-xrgm-g78v.json b/advisories/unreviewed/2025/04/GHSA-5xv7-xrgm-g78v/GHSA-5xv7-xrgm-g78v.json index 2e914a2a50a..14f64692355 100644 --- a/advisories/unreviewed/2025/04/GHSA-5xv7-xrgm-g78v/GHSA-5xv7-xrgm-g78v.json +++ b/advisories/unreviewed/2025/04/GHSA-5xv7-xrgm-g78v/GHSA-5xv7-xrgm-g78v.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-643m-q4f3-rfc2/GHSA-643m-q4f3-rfc2.json b/advisories/unreviewed/2025/04/GHSA-643m-q4f3-rfc2/GHSA-643m-q4f3-rfc2.json new file mode 100644 index 00000000000..9dd69683c8f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-643m-q4f3-rfc2/GHSA-643m-q4f3-rfc2.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-643m-q4f3-rfc2", + "modified": "2025-04-16T18:31:50Z", + "published": "2025-04-16T18:31:50Z", + "aliases": [ + "CVE-2024-58249" + ], + "details": "In wxWidgets before 3.2.7, a crash can be triggered in wxWidgets apps when connections are refused in wxWebRequestCURL.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-58249" + }, + { + "type": "WEB", + "url": "https://github.com/wxWidgets/wxWidgets/issues/24885" + }, + { + "type": "WEB", + "url": "https://github.com/wxWidgets/wxWidgets/commit/f2918a9ac823074901ce27de939baa57788beb3d" + }, + { + "type": "WEB", + "url": "https://github.com/wxWidgets/wxWidgets/compare/v3.2.6...v3.2.7" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-826" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T16:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-66m6-88fv-h8x7/GHSA-66m6-88fv-h8x7.json b/advisories/unreviewed/2025/04/GHSA-66m6-88fv-h8x7/GHSA-66m6-88fv-h8x7.json index b7b423ebbcb..8a01a3f4234 100644 --- a/advisories/unreviewed/2025/04/GHSA-66m6-88fv-h8x7/GHSA-66m6-88fv-h8x7.json +++ b/advisories/unreviewed/2025/04/GHSA-66m6-88fv-h8x7/GHSA-66m6-88fv-h8x7.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-66qf-7h58-9q6q/GHSA-66qf-7h58-9q6q.json b/advisories/unreviewed/2025/04/GHSA-66qf-7h58-9q6q/GHSA-66qf-7h58-9q6q.json new file mode 100644 index 00000000000..6703225bf7f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-66qf-7h58-9q6q/GHSA-66qf-7h58-9q6q.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-66qf-7h58-9q6q", + "modified": "2025-04-16T18:31:54Z", + "published": "2025-04-16T18:31:54Z", + "aliases": [ + "CVE-2024-53303" + ], + "details": "A remote code execution (RCE) vulnerability in the upload_file function of LRQA Nettitude PoshC2 after commit 123db87 allows authenticated attackers to execute arbitrary code via a crafted POST request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53303" + }, + { + "type": "WEB", + "url": "https://gist.github.com/fern89/3464e8428d7675e4f0f390a6b2b2842e" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-67pg-3555-mjqm/GHSA-67pg-3555-mjqm.json b/advisories/unreviewed/2025/04/GHSA-67pg-3555-mjqm/GHSA-67pg-3555-mjqm.json new file mode 100644 index 00000000000..3ee96c8a33c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-67pg-3555-mjqm/GHSA-67pg-3555-mjqm.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67pg-3555-mjqm", + "modified": "2025-04-16T18:31:58Z", + "published": "2025-04-16T18:31:58Z", + "aliases": [ + "CVE-2025-32868" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'ExportCertificate' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32868" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6938-r83g-5rjp/GHSA-6938-r83g-5rjp.json b/advisories/unreviewed/2025/04/GHSA-6938-r83g-5rjp/GHSA-6938-r83g-5rjp.json new file mode 100644 index 00000000000..d1bbc315a8c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6938-r83g-5rjp/GHSA-6938-r83g-5rjp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6938-r83g-5rjp", + "modified": "2025-04-16T18:31:50Z", + "published": "2025-04-16T18:31:50Z", + "aliases": [ + "CVE-2025-20150" + ], + "details": "A vulnerability in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to enumerate LDAP user accounts.\n\nThis vulnerability is due to the improper handling of LDAP authentication requests. An attacker could exploit this vulnerability by sending authentication requests to an affected system. A successful exploit could allow an attacker to determine which usernames are valid LDAP user accounts.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20150" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nd-unenum-2xFFh472" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-209" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T16:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6c5j-8m58-46gp/GHSA-6c5j-8m58-46gp.json b/advisories/unreviewed/2025/04/GHSA-6c5j-8m58-46gp/GHSA-6c5j-8m58-46gp.json new file mode 100644 index 00000000000..9ff2d9c6afa --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6c5j-8m58-46gp/GHSA-6c5j-8m58-46gp.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6c5j-8m58-46gp", + "modified": "2025-04-16T18:31:56Z", + "published": "2025-04-16T18:31:56Z", + "aliases": [ + "CVE-2025-32844" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UnlockUser' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32844" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6jfj-vjhh-47gp/GHSA-6jfj-vjhh-47gp.json b/advisories/unreviewed/2025/04/GHSA-6jfj-vjhh-47gp/GHSA-6jfj-vjhh-47gp.json new file mode 100644 index 00000000000..1f28bb74ba5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6jfj-vjhh-47gp/GHSA-6jfj-vjhh-47gp.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6jfj-vjhh-47gp", + "modified": "2025-04-16T18:31:54Z", + "published": "2025-04-16T18:31:54Z", + "aliases": [ + "CVE-2025-30030" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'ImportDatabase' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on. (ZDI-CAN-25924)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30030" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6mqv-8gqr-vv4v/GHSA-6mqv-8gqr-vv4v.json b/advisories/unreviewed/2025/04/GHSA-6mqv-8gqr-vv4v/GHSA-6mqv-8gqr-vv4v.json new file mode 100644 index 00000000000..cbe60b9d86a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6mqv-8gqr-vv4v/GHSA-6mqv-8gqr-vv4v.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6mqv-8gqr-vv4v", + "modified": "2025-04-16T18:31:56Z", + "published": "2025-04-16T18:31:56Z", + "aliases": [ + "CVE-2025-32851" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UnlockTcmSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32851" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6mr2-mm2m-3hfq/GHSA-6mr2-mm2m-3hfq.json b/advisories/unreviewed/2025/04/GHSA-6mr2-mm2m-3hfq/GHSA-6mr2-mm2m-3hfq.json new file mode 100644 index 00000000000..82c5d252f42 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6mr2-mm2m-3hfq/GHSA-6mr2-mm2m-3hfq.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6mr2-mm2m-3hfq", + "modified": "2025-04-16T18:31:54Z", + "published": "2025-04-16T18:31:54Z", + "aliases": [ + "CVE-2025-29905" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'RestoreFromBackup' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on. (ZDI-CAN-25923)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29905" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6p94-34xm-5x7f/GHSA-6p94-34xm-5x7f.json b/advisories/unreviewed/2025/04/GHSA-6p94-34xm-5x7f/GHSA-6p94-34xm-5x7f.json new file mode 100644 index 00000000000..3ad69ce4fce --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6p94-34xm-5x7f/GHSA-6p94-34xm-5x7f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6p94-34xm-5x7f", + "modified": "2025-04-16T18:31:53Z", + "published": "2025-04-16T18:31:53Z", + "aliases": [ + "CVE-2025-3734" + ], + "details": "Allocation of Resources Without Limits or Throttling vulnerability in Drupal Stage File Proxy allows Flooding.This issue affects Stage File Proxy: from 0.0.0 before 3.1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3734" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-035" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T17:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6xwm-pqmf-hpfc/GHSA-6xwm-pqmf-hpfc.json b/advisories/unreviewed/2025/04/GHSA-6xwm-pqmf-hpfc/GHSA-6xwm-pqmf-hpfc.json new file mode 100644 index 00000000000..578e9b24ce4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6xwm-pqmf-hpfc/GHSA-6xwm-pqmf-hpfc.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6xwm-pqmf-hpfc", + "modified": "2025-04-16T18:31:57Z", + "published": "2025-04-16T18:31:57Z", + "aliases": [ + "CVE-2025-32856" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'LockBufferingSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32856" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-724x-fw2m-fpwp/GHSA-724x-fw2m-fpwp.json b/advisories/unreviewed/2025/04/GHSA-724x-fw2m-fpwp/GHSA-724x-fw2m-fpwp.json new file mode 100644 index 00000000000..db940280bd9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-724x-fw2m-fpwp/GHSA-724x-fw2m-fpwp.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-724x-fw2m-fpwp", + "modified": "2025-04-16T18:31:55Z", + "published": "2025-04-16T18:31:55Z", + "aliases": [ + "CVE-2025-32823" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'LockProject' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32823" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-73ch-cpx9-cfrm/GHSA-73ch-cpx9-cfrm.json b/advisories/unreviewed/2025/04/GHSA-73ch-cpx9-cfrm/GHSA-73ch-cpx9-cfrm.json index 8cc9f6ad4ea..23aae234c6a 100644 --- a/advisories/unreviewed/2025/04/GHSA-73ch-cpx9-cfrm/GHSA-73ch-cpx9-cfrm.json +++ b/advisories/unreviewed/2025/04/GHSA-73ch-cpx9-cfrm/GHSA-73ch-cpx9-cfrm.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-497" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-74mq-6c57-fxpx/GHSA-74mq-6c57-fxpx.json b/advisories/unreviewed/2025/04/GHSA-74mq-6c57-fxpx/GHSA-74mq-6c57-fxpx.json index 246ad29aff8..5b64083a394 100644 --- a/advisories/unreviewed/2025/04/GHSA-74mq-6c57-fxpx/GHSA-74mq-6c57-fxpx.json +++ b/advisories/unreviewed/2025/04/GHSA-74mq-6c57-fxpx/GHSA-74mq-6c57-fxpx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-74mq-6c57-fxpx", - "modified": "2025-04-08T18:34:57Z", + "modified": "2025-04-16T18:31:47Z", "published": "2025-04-08T18:34:57Z", "aliases": [ "CVE-2025-29824" @@ -22,6 +22,14 @@ { "type": "WEB", "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29824" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/cve-2025-29824-windows-common-log-file-system-driver-elevation-of-privilege-vulnerability-detection-script" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/cve-2025-29824-windows-common-log-file-system-driver-elevation-of-privilege-vulnerability-mitigation-script" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/04/GHSA-7537-v29c-77qh/GHSA-7537-v29c-77qh.json b/advisories/unreviewed/2025/04/GHSA-7537-v29c-77qh/GHSA-7537-v29c-77qh.json new file mode 100644 index 00000000000..43c98e65cc8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7537-v29c-77qh/GHSA-7537-v29c-77qh.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7537-v29c-77qh", + "modified": "2025-04-16T18:31:56Z", + "published": "2025-04-16T18:31:56Z", + "aliases": [ + "CVE-2025-32843" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'LockUser' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32843" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-78x4-9v34-rvc7/GHSA-78x4-9v34-rvc7.json b/advisories/unreviewed/2025/04/GHSA-78x4-9v34-rvc7/GHSA-78x4-9v34-rvc7.json new file mode 100644 index 00000000000..e593779a623 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-78x4-9v34-rvc7/GHSA-78x4-9v34-rvc7.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-78x4-9v34-rvc7", + "modified": "2025-04-16T18:31:54Z", + "published": "2025-04-16T18:31:54Z", + "aliases": [ + "CVE-2025-31350" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateBufferingSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on. (ZDI-CAN-25918)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31350" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7f6c-8chx-2vm5/GHSA-7f6c-8chx-2vm5.json b/advisories/unreviewed/2025/04/GHSA-7f6c-8chx-2vm5/GHSA-7f6c-8chx-2vm5.json index f924ebdc27b..9c876339619 100644 --- a/advisories/unreviewed/2025/04/GHSA-7f6c-8chx-2vm5/GHSA-7f6c-8chx-2vm5.json +++ b/advisories/unreviewed/2025/04/GHSA-7f6c-8chx-2vm5/GHSA-7f6c-8chx-2vm5.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-7pgr-547g-q4qv/GHSA-7pgr-547g-q4qv.json b/advisories/unreviewed/2025/04/GHSA-7pgr-547g-q4qv/GHSA-7pgr-547g-q4qv.json new file mode 100644 index 00000000000..0f0dffb64c3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7pgr-547g-q4qv/GHSA-7pgr-547g-q4qv.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7pgr-547g-q4qv", + "modified": "2025-04-16T18:31:57Z", + "published": "2025-04-16T18:31:56Z", + "aliases": [ + "CVE-2025-32847" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UnlockGeneralSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32847" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7whc-q564-cpc4/GHSA-7whc-q564-cpc4.json b/advisories/unreviewed/2025/04/GHSA-7whc-q564-cpc4/GHSA-7whc-q564-cpc4.json index d19b67d5b16..fd528957e30 100644 --- a/advisories/unreviewed/2025/04/GHSA-7whc-q564-cpc4/GHSA-7whc-q564-cpc4.json +++ b/advisories/unreviewed/2025/04/GHSA-7whc-q564-cpc4/GHSA-7whc-q564-cpc4.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-732" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-7xcg-8h7r-rgfx/GHSA-7xcg-8h7r-rgfx.json b/advisories/unreviewed/2025/04/GHSA-7xcg-8h7r-rgfx/GHSA-7xcg-8h7r-rgfx.json index 5dc19649805..4e2a05fa7b7 100644 --- a/advisories/unreviewed/2025/04/GHSA-7xcg-8h7r-rgfx/GHSA-7xcg-8h7r-rgfx.json +++ b/advisories/unreviewed/2025/04/GHSA-7xcg-8h7r-rgfx/GHSA-7xcg-8h7r-rgfx.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-83r7-48f6-rrw5/GHSA-83r7-48f6-rrw5.json b/advisories/unreviewed/2025/04/GHSA-83r7-48f6-rrw5/GHSA-83r7-48f6-rrw5.json new file mode 100644 index 00000000000..a723c7d0bc2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-83r7-48f6-rrw5/GHSA-83r7-48f6-rrw5.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-83r7-48f6-rrw5", + "modified": "2025-04-16T18:31:57Z", + "published": "2025-04-16T18:31:57Z", + "aliases": [ + "CVE-2025-32864" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'GetSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32864" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8477-pj67-v6wm/GHSA-8477-pj67-v6wm.json b/advisories/unreviewed/2025/04/GHSA-8477-pj67-v6wm/GHSA-8477-pj67-v6wm.json new file mode 100644 index 00000000000..660f117f5f6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8477-pj67-v6wm/GHSA-8477-pj67-v6wm.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8477-pj67-v6wm", + "modified": "2025-04-16T18:31:57Z", + "published": "2025-04-16T18:31:57Z", + "aliases": [ + "CVE-2025-32861" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateTraceLevelSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32861" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-86hf-m877-h67j/GHSA-86hf-m877-h67j.json b/advisories/unreviewed/2025/04/GHSA-86hf-m877-h67j/GHSA-86hf-m877-h67j.json new file mode 100644 index 00000000000..f607570cb1f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-86hf-m877-h67j/GHSA-86hf-m877-h67j.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-86hf-m877-h67j", + "modified": "2025-04-16T18:31:54Z", + "published": "2025-04-16T18:31:54Z", + "aliases": [ + "CVE-2025-31349" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateSmtpSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on. (ZDI-CAN-25919)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31349" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-88mw-6w32-cx68/GHSA-88mw-6w32-cx68.json b/advisories/unreviewed/2025/04/GHSA-88mw-6w32-cx68/GHSA-88mw-6w32-cx68.json new file mode 100644 index 00000000000..f8eb311cac6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-88mw-6w32-cx68/GHSA-88mw-6w32-cx68.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-88mw-6w32-cx68", + "modified": "2025-04-16T18:31:55Z", + "published": "2025-04-16T18:31:55Z", + "aliases": [ + "CVE-2025-32827" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'ActivateProject' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32827" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8mf4-r4mv-hgq9/GHSA-8mf4-r4mv-hgq9.json b/advisories/unreviewed/2025/04/GHSA-8mf4-r4mv-hgq9/GHSA-8mf4-r4mv-hgq9.json new file mode 100644 index 00000000000..725d9cdc15e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8mf4-r4mv-hgq9/GHSA-8mf4-r4mv-hgq9.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8mf4-r4mv-hgq9", + "modified": "2025-04-16T18:31:55Z", + "published": "2025-04-16T18:31:55Z", + "aliases": [ + "CVE-2025-32824" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UnlockProject' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32824" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8p48-rwh9-r9c4/GHSA-8p48-rwh9-r9c4.json b/advisories/unreviewed/2025/04/GHSA-8p48-rwh9-r9c4/GHSA-8p48-rwh9-r9c4.json new file mode 100644 index 00000000000..1fcfdf955bd --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8p48-rwh9-r9c4/GHSA-8p48-rwh9-r9c4.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8p48-rwh9-r9c4", + "modified": "2025-04-16T18:31:54Z", + "published": "2025-04-16T18:31:54Z", + "aliases": [ + "CVE-2025-27540" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'Authenticate' method. This could allow an unauthenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on. (ZDI-CAN-25913)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27540" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8rv9-x4xj-49jq/GHSA-8rv9-x4xj-49jq.json b/advisories/unreviewed/2025/04/GHSA-8rv9-x4xj-49jq/GHSA-8rv9-x4xj-49jq.json new file mode 100644 index 00000000000..2b0aac04dd6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8rv9-x4xj-49jq/GHSA-8rv9-x4xj-49jq.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8rv9-x4xj-49jq", + "modified": "2025-04-16T18:31:57Z", + "published": "2025-04-16T18:31:57Z", + "aliases": [ + "CVE-2025-32860" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UnlockWebServerGatewaySettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32860" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8wxq-8qgg-75mj/GHSA-8wxq-8qgg-75mj.json b/advisories/unreviewed/2025/04/GHSA-8wxq-8qgg-75mj/GHSA-8wxq-8qgg-75mj.json new file mode 100644 index 00000000000..d62788254cb --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8wxq-8qgg-75mj/GHSA-8wxq-8qgg-75mj.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8wxq-8qgg-75mj", + "modified": "2025-04-16T18:31:57Z", + "published": "2025-04-16T18:31:57Z", + "aliases": [ + "CVE-2025-32855" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UnlockOpcSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32855" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-92m6-2vg7-62p6/GHSA-92m6-2vg7-62p6.json b/advisories/unreviewed/2025/04/GHSA-92m6-2vg7-62p6/GHSA-92m6-2vg7-62p6.json new file mode 100644 index 00000000000..bcb7f0213fa --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-92m6-2vg7-62p6/GHSA-92m6-2vg7-62p6.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-92m6-2vg7-62p6", + "modified": "2025-04-16T18:31:56Z", + "published": "2025-04-16T18:31:55Z", + "aliases": [ + "CVE-2025-32835" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateConnectionVariableArchivingBuffering' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32835" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-932r-mjp5-94jg/GHSA-932r-mjp5-94jg.json b/advisories/unreviewed/2025/04/GHSA-932r-mjp5-94jg/GHSA-932r-mjp5-94jg.json new file mode 100644 index 00000000000..fe1013cff22 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-932r-mjp5-94jg/GHSA-932r-mjp5-94jg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-932r-mjp5-94jg", + "modified": "2025-04-16T18:31:51Z", + "published": "2025-04-16T18:31:51Z", + "aliases": [ + "CVE-2024-22314" + ], + "details": "IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.12 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22314" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7229903" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-327" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T17:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-94jj-v7wj-fvfc/GHSA-94jj-v7wj-fvfc.json b/advisories/unreviewed/2025/04/GHSA-94jj-v7wj-fvfc/GHSA-94jj-v7wj-fvfc.json new file mode 100644 index 00000000000..59e485aea8e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-94jj-v7wj-fvfc/GHSA-94jj-v7wj-fvfc.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-94jj-v7wj-fvfc", + "modified": "2025-04-16T18:31:57Z", + "published": "2025-04-16T18:31:56Z", + "aliases": [ + "CVE-2025-32852" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'LockDatabaseSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32852" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9799-8fpv-535m/GHSA-9799-8fpv-535m.json b/advisories/unreviewed/2025/04/GHSA-9799-8fpv-535m/GHSA-9799-8fpv-535m.json new file mode 100644 index 00000000000..b8e1ea28d08 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9799-8fpv-535m/GHSA-9799-8fpv-535m.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9799-8fpv-535m", + "modified": "2025-04-16T18:31:53Z", + "published": "2025-04-16T18:31:53Z", + "aliases": [ + "CVE-2025-3739" + ], + "details": "Vulnerability in Drupal Drupal 8 Google Optimize Hide Page.This issue affects Drupal 8 Google Optimize Hide Page: *.*.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3739" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-040" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9f5x-9jj2-7f3w/GHSA-9f5x-9jj2-7f3w.json b/advisories/unreviewed/2025/04/GHSA-9f5x-9jj2-7f3w/GHSA-9f5x-9jj2-7f3w.json new file mode 100644 index 00000000000..f54966b2bfd --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9f5x-9jj2-7f3w/GHSA-9f5x-9jj2-7f3w.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9f5x-9jj2-7f3w", + "modified": "2025-04-16T18:31:51Z", + "published": "2025-04-16T18:31:51Z", + "aliases": [ + "CVE-2024-40068" + ], + "details": "Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at id_generator/admin/?page=templates/manage_template&id=1.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40068" + }, + { + "type": "WEB", + "url": "https://github.com/DiliLearngent/BugReport/blob/main/php/Online-ID-Generator-System/bug5-SQL-Injection-id2.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T17:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9p9m-q7jc-4hqp/GHSA-9p9m-q7jc-4hqp.json b/advisories/unreviewed/2025/04/GHSA-9p9m-q7jc-4hqp/GHSA-9p9m-q7jc-4hqp.json new file mode 100644 index 00000000000..373d93086f9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9p9m-q7jc-4hqp/GHSA-9p9m-q7jc-4hqp.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9p9m-q7jc-4hqp", + "modified": "2025-04-16T18:31:56Z", + "published": "2025-04-16T18:31:55Z", + "aliases": [ + "CVE-2025-32833" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UnlockProjectUserRights' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32833" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9x4w-phf4-v7cf/GHSA-9x4w-phf4-v7cf.json b/advisories/unreviewed/2025/04/GHSA-9x4w-phf4-v7cf/GHSA-9x4w-phf4-v7cf.json new file mode 100644 index 00000000000..8ee8cd9be12 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9x4w-phf4-v7cf/GHSA-9x4w-phf4-v7cf.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9x4w-phf4-v7cf", + "modified": "2025-04-16T18:31:55Z", + "published": "2025-04-16T18:31:55Z", + "aliases": [ + "CVE-2025-31352" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateGateways' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on. (ZDI-CAN-25915)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31352" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c52r-j8mc-82cv/GHSA-c52r-j8mc-82cv.json b/advisories/unreviewed/2025/04/GHSA-c52r-j8mc-82cv/GHSA-c52r-j8mc-82cv.json new file mode 100644 index 00000000000..28cb4d42c97 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c52r-j8mc-82cv/GHSA-c52r-j8mc-82cv.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c52r-j8mc-82cv", + "modified": "2025-04-16T18:31:57Z", + "published": "2025-04-16T18:31:57Z", + "aliases": [ + "CVE-2025-32854" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'LockOpcSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32854" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c839-wqcr-r3p3/GHSA-c839-wqcr-r3p3.json b/advisories/unreviewed/2025/04/GHSA-c839-wqcr-r3p3/GHSA-c839-wqcr-r3p3.json new file mode 100644 index 00000000000..0997c48bb3b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c839-wqcr-r3p3/GHSA-c839-wqcr-r3p3.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c839-wqcr-r3p3", + "modified": "2025-04-16T18:31:53Z", + "published": "2025-04-16T18:31:53Z", + "aliases": [ + "CVE-2024-40072" + ], + "details": "Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at id_generator/admin/?page=generate/index&id=1.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40072" + }, + { + "type": "WEB", + "url": "https://github.com/DiliLearngent/BugReport/blob/main/php/Online-ID-Generator-System/bug3-SQL-Injection-id1.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T17:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cgxr-gppg-w5v2/GHSA-cgxr-gppg-w5v2.json b/advisories/unreviewed/2025/04/GHSA-cgxr-gppg-w5v2/GHSA-cgxr-gppg-w5v2.json new file mode 100644 index 00000000000..f5b5fbc557e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cgxr-gppg-w5v2/GHSA-cgxr-gppg-w5v2.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cgxr-gppg-w5v2", + "modified": "2025-04-16T18:31:54Z", + "published": "2025-04-16T18:31:54Z", + "aliases": [ + "CVE-2025-30032" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateDatabaseSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on. (ZDI-CAN-25921)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30032" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cj26-58c8-7wq6/GHSA-cj26-58c8-7wq6.json b/advisories/unreviewed/2025/04/GHSA-cj26-58c8-7wq6/GHSA-cj26-58c8-7wq6.json new file mode 100644 index 00000000000..28dafb7d2e5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cj26-58c8-7wq6/GHSA-cj26-58c8-7wq6.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cj26-58c8-7wq6", + "modified": "2025-04-16T18:31:53Z", + "published": "2025-04-16T18:31:53Z", + "aliases": [ + "CVE-2025-3736" + ], + "details": "Vulnerability in Drupal Simple GTM.This issue affects Simple GTM: *.*.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3736" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-037" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f6pm-2f84-c3x3/GHSA-f6pm-2f84-c3x3.json b/advisories/unreviewed/2025/04/GHSA-f6pm-2f84-c3x3/GHSA-f6pm-2f84-c3x3.json new file mode 100644 index 00000000000..9e15e968146 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f6pm-2f84-c3x3/GHSA-f6pm-2f84-c3x3.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f6pm-2f84-c3x3", + "modified": "2025-04-16T18:31:56Z", + "published": "2025-04-16T18:31:56Z", + "aliases": [ + "CVE-2025-32838" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'ImportConnectionVariables' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32838" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f79v-x23w-9hr4/GHSA-f79v-x23w-9hr4.json b/advisories/unreviewed/2025/04/GHSA-f79v-x23w-9hr4/GHSA-f79v-x23w-9hr4.json new file mode 100644 index 00000000000..93c3ba38927 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f79v-x23w-9hr4/GHSA-f79v-x23w-9hr4.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f79v-x23w-9hr4", + "modified": "2025-04-16T18:31:58Z", + "published": "2025-04-16T18:31:58Z", + "aliases": [ + "CVE-2025-32870" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'GetTraces' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32870" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f9px-2356-59h7/GHSA-f9px-2356-59h7.json b/advisories/unreviewed/2025/04/GHSA-f9px-2356-59h7/GHSA-f9px-2356-59h7.json new file mode 100644 index 00000000000..763020a6a2d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f9px-2356-59h7/GHSA-f9px-2356-59h7.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f9px-2356-59h7", + "modified": "2025-04-16T18:31:53Z", + "published": "2025-04-16T18:31:53Z", + "aliases": [ + "CVE-2025-3733" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal baguetteBox.Js allows Cross-Site Scripting (XSS).This issue affects baguetteBox.Js: from 0.0.0 before 2.0.4, from 3.0.0 before 3.0.1.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3733" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-034" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T17:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fmhf-c37c-7cvc/GHSA-fmhf-c37c-7cvc.json b/advisories/unreviewed/2025/04/GHSA-fmhf-c37c-7cvc/GHSA-fmhf-c37c-7cvc.json index 5a4823ac51d..0d6d0cadca2 100644 --- a/advisories/unreviewed/2025/04/GHSA-fmhf-c37c-7cvc/GHSA-fmhf-c37c-7cvc.json +++ b/advisories/unreviewed/2025/04/GHSA-fmhf-c37c-7cvc/GHSA-fmhf-c37c-7cvc.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-fp5v-pr7j-hxj9/GHSA-fp5v-pr7j-hxj9.json b/advisories/unreviewed/2025/04/GHSA-fp5v-pr7j-hxj9/GHSA-fp5v-pr7j-hxj9.json new file mode 100644 index 00000000000..bb9783a49b9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fp5v-pr7j-hxj9/GHSA-fp5v-pr7j-hxj9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fp5v-pr7j-hxj9", + "modified": "2025-04-16T18:31:58Z", + "published": "2025-04-16T18:31:58Z", + "aliases": [ + "CVE-2025-39472" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WPWeb WooCommerce Social Login allows Cross Site Request Forgery.This issue affects WooCommerce Social Login: from n/a through 2.8.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39472" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woo-social-login/vulnerability/wordpress-woocommerce-social-login-plugin-2-8-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fqhh-gmfw-8v68/GHSA-fqhh-gmfw-8v68.json b/advisories/unreviewed/2025/04/GHSA-fqhh-gmfw-8v68/GHSA-fqhh-gmfw-8v68.json new file mode 100644 index 00000000000..b453d9e4fbb --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fqhh-gmfw-8v68/GHSA-fqhh-gmfw-8v68.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fqhh-gmfw-8v68", + "modified": "2025-04-16T18:31:58Z", + "published": "2025-04-16T18:31:58Z", + "aliases": [ + "CVE-2025-32872" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'GetOverview' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32872" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fr9q-xchw-895x/GHSA-fr9q-xchw-895x.json b/advisories/unreviewed/2025/04/GHSA-fr9q-xchw-895x/GHSA-fr9q-xchw-895x.json new file mode 100644 index 00000000000..f30abf09092 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fr9q-xchw-895x/GHSA-fr9q-xchw-895x.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fr9q-xchw-895x", + "modified": "2025-04-16T18:31:54Z", + "published": "2025-04-16T18:31:54Z", + "aliases": [ + "CVE-2025-30003" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateProjectConnections' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on. (ZDI-CAN-25910)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30003" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fvqg-wm9j-4gc4/GHSA-fvqg-wm9j-4gc4.json b/advisories/unreviewed/2025/04/GHSA-fvqg-wm9j-4gc4/GHSA-fvqg-wm9j-4gc4.json new file mode 100644 index 00000000000..217e5e6f7e7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fvqg-wm9j-4gc4/GHSA-fvqg-wm9j-4gc4.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fvqg-wm9j-4gc4", + "modified": "2025-04-16T18:31:51Z", + "published": "2025-04-16T18:31:51Z", + "aliases": [ + "CVE-2024-40069" + ], + "details": "Sourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via id_generator/classes/Users.php?f=save, and the point of vulnerability is in the POST parameter 'firstname' and 'lastname'.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40069" + }, + { + "type": "WEB", + "url": "https://github.com/DiliLearngent/BugReport/blob/main/php/Online-ID-Generator-System/bug7-XSS-firstname-lastname.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T17:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g5cv-cw8w-2mp7/GHSA-g5cv-cw8w-2mp7.json b/advisories/unreviewed/2025/04/GHSA-g5cv-cw8w-2mp7/GHSA-g5cv-cw8w-2mp7.json new file mode 100644 index 00000000000..6c04cf562a8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g5cv-cw8w-2mp7/GHSA-g5cv-cw8w-2mp7.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g5cv-cw8w-2mp7", + "modified": "2025-04-16T18:31:58Z", + "published": "2025-04-16T18:31:57Z", + "aliases": [ + "CVE-2025-32867" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'CreateBackup' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32867" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g6fh-mr9f-jrcx/GHSA-g6fh-mr9f-jrcx.json b/advisories/unreviewed/2025/04/GHSA-g6fh-mr9f-jrcx/GHSA-g6fh-mr9f-jrcx.json index 4c7e19f4cfe..5015eed5822 100644 --- a/advisories/unreviewed/2025/04/GHSA-g6fh-mr9f-jrcx/GHSA-g6fh-mr9f-jrcx.json +++ b/advisories/unreviewed/2025/04/GHSA-g6fh-mr9f-jrcx/GHSA-g6fh-mr9f-jrcx.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-g6r6-p92w-p2qw/GHSA-g6r6-p92w-p2qw.json b/advisories/unreviewed/2025/04/GHSA-g6r6-p92w-p2qw/GHSA-g6r6-p92w-p2qw.json new file mode 100644 index 00000000000..bef8b4ee751 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g6r6-p92w-p2qw/GHSA-g6r6-p92w-p2qw.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g6r6-p92w-p2qw", + "modified": "2025-04-16T18:31:54Z", + "published": "2025-04-16T18:31:54Z", + "aliases": [ + "CVE-2025-27495" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'CreateTrace' method. This could allow an unauthenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on. (ZDI-CAN-25911)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27495" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g7w5-3c3r-2w69/GHSA-g7w5-3c3r-2w69.json b/advisories/unreviewed/2025/04/GHSA-g7w5-3c3r-2w69/GHSA-g7w5-3c3r-2w69.json new file mode 100644 index 00000000000..99413cb7e40 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g7w5-3c3r-2w69/GHSA-g7w5-3c3r-2w69.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g7w5-3c3r-2w69", + "modified": "2025-04-16T18:31:55Z", + "published": "2025-04-16T18:31:55Z", + "aliases": [ + "CVE-2025-32834" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateConnectionVariablesWithImport' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32834" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-ggqf-578v-v9gm/GHSA-ggqf-578v-v9gm.json b/advisories/unreviewed/2025/04/GHSA-ggqf-578v-v9gm/GHSA-ggqf-578v-v9gm.json new file mode 100644 index 00000000000..c5209aaf681 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-ggqf-578v-v9gm/GHSA-ggqf-578v-v9gm.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ggqf-578v-v9gm", + "modified": "2025-04-16T18:31:56Z", + "published": "2025-04-16T18:31:56Z", + "aliases": [ + "CVE-2025-32841" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UnlockGateway' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32841" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gj7g-7f7f-wjr5/GHSA-gj7g-7f7f-wjr5.json b/advisories/unreviewed/2025/04/GHSA-gj7g-7f7f-wjr5/GHSA-gj7g-7f7f-wjr5.json new file mode 100644 index 00000000000..7f7fb2a67ac --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gj7g-7f7f-wjr5/GHSA-gj7g-7f7f-wjr5.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gj7g-7f7f-wjr5", + "modified": "2025-04-16T18:31:49Z", + "published": "2025-04-16T18:31:49Z", + "aliases": [ + "CVE-2024-56736" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in Apache HertzBeat.\n\nThis issue affects Apache HertzBeat (incubating): before 1.7.0.\n\nUsers are recommended to upgrade to version 1.7.0, which fixes the issue.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56736" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/kdzg36h9yxp0q0n4lhcfppxntjy8rj1x" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/lwfhsllos1rx9v8k0yhl252cbpqpn0sv" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/04/16/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-grgq-p9q4-xvmm/GHSA-grgq-p9q4-xvmm.json b/advisories/unreviewed/2025/04/GHSA-grgq-p9q4-xvmm/GHSA-grgq-p9q4-xvmm.json index 7221b59e375..86e36219ace 100644 --- a/advisories/unreviewed/2025/04/GHSA-grgq-p9q4-xvmm/GHSA-grgq-p9q4-xvmm.json +++ b/advisories/unreviewed/2025/04/GHSA-grgq-p9q4-xvmm/GHSA-grgq-p9q4-xvmm.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-h4p7-4v4q-3q54/GHSA-h4p7-4v4q-3q54.json b/advisories/unreviewed/2025/04/GHSA-h4p7-4v4q-3q54/GHSA-h4p7-4v4q-3q54.json new file mode 100644 index 00000000000..42dc1483795 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-h4p7-4v4q-3q54/GHSA-h4p7-4v4q-3q54.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h4p7-4v4q-3q54", + "modified": "2025-04-16T18:31:56Z", + "published": "2025-04-16T18:31:56Z", + "aliases": [ + "CVE-2025-32840" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'LockGateway' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32840" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h6wq-rhmx-rv6x/GHSA-h6wq-rhmx-rv6x.json b/advisories/unreviewed/2025/04/GHSA-h6wq-rhmx-rv6x/GHSA-h6wq-rhmx-rv6x.json new file mode 100644 index 00000000000..da71bd7541e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-h6wq-rhmx-rv6x/GHSA-h6wq-rhmx-rv6x.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h6wq-rhmx-rv6x", + "modified": "2025-04-16T18:31:55Z", + "published": "2025-04-16T18:31:55Z", + "aliases": [ + "CVE-2025-32830" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UnlockProject' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32830" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h8rc-25rp-vw97/GHSA-h8rc-25rp-vw97.json b/advisories/unreviewed/2025/04/GHSA-h8rc-25rp-vw97/GHSA-h8rc-25rp-vw97.json index 3d7f329d35c..36eab521eed 100644 --- a/advisories/unreviewed/2025/04/GHSA-h8rc-25rp-vw97/GHSA-h8rc-25rp-vw97.json +++ b/advisories/unreviewed/2025/04/GHSA-h8rc-25rp-vw97/GHSA-h8rc-25rp-vw97.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-732", "CWE-770" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/04/GHSA-hc75-5r67-9j7v/GHSA-hc75-5r67-9j7v.json b/advisories/unreviewed/2025/04/GHSA-hc75-5r67-9j7v/GHSA-hc75-5r67-9j7v.json new file mode 100644 index 00000000000..155100287af --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hc75-5r67-9j7v/GHSA-hc75-5r67-9j7v.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hc75-5r67-9j7v", + "modified": "2025-04-16T18:31:57Z", + "published": "2025-04-16T18:31:57Z", + "aliases": [ + "CVE-2025-32865" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'CreateLog' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32865" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hcw4-c8qw-p53q/GHSA-hcw4-c8qw-p53q.json b/advisories/unreviewed/2025/04/GHSA-hcw4-c8qw-p53q/GHSA-hcw4-c8qw-p53q.json new file mode 100644 index 00000000000..c5ba70a48e5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hcw4-c8qw-p53q/GHSA-hcw4-c8qw-p53q.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hcw4-c8qw-p53q", + "modified": "2025-04-16T18:31:54Z", + "published": "2025-04-16T18:31:54Z", + "aliases": [ + "CVE-2024-53304" + ], + "details": "An issue in LRQA Nettitude PoshC2 after commit 09ee2cf allows unauthenticated attackers to connect to the C2 server and execute arbitrary commands via posing as an infected machine.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53304" + }, + { + "type": "WEB", + "url": "https://gist.github.com/fern89/3464e8428d7675e4f0f390a6b2b2842e" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hj8j-5hmm-p35x/GHSA-hj8j-5hmm-p35x.json b/advisories/unreviewed/2025/04/GHSA-hj8j-5hmm-p35x/GHSA-hj8j-5hmm-p35x.json new file mode 100644 index 00000000000..f02a153e0f7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hj8j-5hmm-p35x/GHSA-hj8j-5hmm-p35x.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hj8j-5hmm-p35x", + "modified": "2025-04-16T18:31:57Z", + "published": "2025-04-16T18:31:57Z", + "aliases": [ + "CVE-2025-32866" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'GetLogs' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32866" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hrx7-7gcr-7fmm/GHSA-hrx7-7gcr-7fmm.json b/advisories/unreviewed/2025/04/GHSA-hrx7-7gcr-7fmm/GHSA-hrx7-7gcr-7fmm.json new file mode 100644 index 00000000000..16c876ca0ce --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hrx7-7gcr-7fmm/GHSA-hrx7-7gcr-7fmm.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hrx7-7gcr-7fmm", + "modified": "2025-04-16T18:31:54Z", + "published": "2025-04-16T18:31:54Z", + "aliases": [ + "CVE-2025-27539" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'VerifyUser' method. This could allow an unauthenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on. (ZDI-CAN-25914)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27539" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j5ch-9qw6-2374/GHSA-j5ch-9qw6-2374.json b/advisories/unreviewed/2025/04/GHSA-j5ch-9qw6-2374/GHSA-j5ch-9qw6-2374.json new file mode 100644 index 00000000000..e95ec3c6af1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j5ch-9qw6-2374/GHSA-j5ch-9qw6-2374.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j5ch-9qw6-2374", + "modified": "2025-04-16T18:31:56Z", + "published": "2025-04-16T18:31:56Z", + "aliases": [ + "CVE-2025-32848" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'LockSmtpSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32848" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j6vg-xxfm-6g75/GHSA-j6vg-xxfm-6g75.json b/advisories/unreviewed/2025/04/GHSA-j6vg-xxfm-6g75/GHSA-j6vg-xxfm-6g75.json new file mode 100644 index 00000000000..812a4b5d709 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j6vg-xxfm-6g75/GHSA-j6vg-xxfm-6g75.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6vg-xxfm-6g75", + "modified": "2025-04-16T18:31:54Z", + "published": "2025-04-16T18:31:54Z", + "aliases": [ + "CVE-2025-30002" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateConnectionVariables' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on. (ZDI-CAN-25909)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30002" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jfph-3485-2gcv/GHSA-jfph-3485-2gcv.json b/advisories/unreviewed/2025/04/GHSA-jfph-3485-2gcv/GHSA-jfph-3485-2gcv.json new file mode 100644 index 00000000000..d333b24a8a0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jfph-3485-2gcv/GHSA-jfph-3485-2gcv.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jfph-3485-2gcv", + "modified": "2025-04-16T18:31:53Z", + "published": "2025-04-16T18:31:53Z", + "aliases": [ + "CVE-2025-3735" + ], + "details": "Vulnerability in Drupal Panelizer (obsolete).This issue affects Panelizer (obsolete): *.*.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3735" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-036" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m5h7-3m3h-qm4q/GHSA-m5h7-3m3h-qm4q.json b/advisories/unreviewed/2025/04/GHSA-m5h7-3m3h-qm4q/GHSA-m5h7-3m3h-qm4q.json index 8a74ef27367..c3bafe07e89 100644 --- a/advisories/unreviewed/2025/04/GHSA-m5h7-3m3h-qm4q/GHSA-m5h7-3m3h-qm4q.json +++ b/advisories/unreviewed/2025/04/GHSA-m5h7-3m3h-qm4q/GHSA-m5h7-3m3h-qm4q.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-m8pj-qq8w-cf26/GHSA-m8pj-qq8w-cf26.json b/advisories/unreviewed/2025/04/GHSA-m8pj-qq8w-cf26/GHSA-m8pj-qq8w-cf26.json index 8a6e535dba2..d9bb4633dc7 100644 --- a/advisories/unreviewed/2025/04/GHSA-m8pj-qq8w-cf26/GHSA-m8pj-qq8w-cf26.json +++ b/advisories/unreviewed/2025/04/GHSA-m8pj-qq8w-cf26/GHSA-m8pj-qq8w-cf26.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-732" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-mg6v-4575-j2gc/GHSA-mg6v-4575-j2gc.json b/advisories/unreviewed/2025/04/GHSA-mg6v-4575-j2gc/GHSA-mg6v-4575-j2gc.json index 8d304888223..0e03b3caf2d 100644 --- a/advisories/unreviewed/2025/04/GHSA-mg6v-4575-j2gc/GHSA-mg6v-4575-j2gc.json +++ b/advisories/unreviewed/2025/04/GHSA-mg6v-4575-j2gc/GHSA-mg6v-4575-j2gc.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-mgxr-xp39-whw3/GHSA-mgxr-xp39-whw3.json b/advisories/unreviewed/2025/04/GHSA-mgxr-xp39-whw3/GHSA-mgxr-xp39-whw3.json index ef4b02e3be3..44427b4052e 100644 --- a/advisories/unreviewed/2025/04/GHSA-mgxr-xp39-whw3/GHSA-mgxr-xp39-whw3.json +++ b/advisories/unreviewed/2025/04/GHSA-mgxr-xp39-whw3/GHSA-mgxr-xp39-whw3.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-732" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-mh6h-m5cw-m257/GHSA-mh6h-m5cw-m257.json b/advisories/unreviewed/2025/04/GHSA-mh6h-m5cw-m257/GHSA-mh6h-m5cw-m257.json index e3f5f70548b..c36701bc682 100644 --- a/advisories/unreviewed/2025/04/GHSA-mh6h-m5cw-m257/GHSA-mh6h-m5cw-m257.json +++ b/advisories/unreviewed/2025/04/GHSA-mh6h-m5cw-m257/GHSA-mh6h-m5cw-m257.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-mj2p-v2c2-vh4v/GHSA-mj2p-v2c2-vh4v.json b/advisories/unreviewed/2025/04/GHSA-mj2p-v2c2-vh4v/GHSA-mj2p-v2c2-vh4v.json new file mode 100644 index 00000000000..b4ee9568d63 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mj2p-v2c2-vh4v/GHSA-mj2p-v2c2-vh4v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mj2p-v2c2-vh4v", + "modified": "2025-04-16T18:31:53Z", + "published": "2025-04-16T18:31:53Z", + "aliases": [ + "CVE-2025-2564" + ], + "details": "Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to properly enforce the 'Allow users to view/update archived channels' System Console setting, which allows authenticated users to view members and member information of archived channels even when this setting is disabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2564" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T17:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mm9j-jhm4-xw9g/GHSA-mm9j-jhm4-xw9g.json b/advisories/unreviewed/2025/04/GHSA-mm9j-jhm4-xw9g/GHSA-mm9j-jhm4-xw9g.json new file mode 100644 index 00000000000..c32ef1c98db --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mm9j-jhm4-xw9g/GHSA-mm9j-jhm4-xw9g.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mm9j-jhm4-xw9g", + "modified": "2025-04-16T18:31:55Z", + "published": "2025-04-16T18:31:55Z", + "aliases": [ + "CVE-2025-32822" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'DeleteProject' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32822" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mqgj-2736-57g4/GHSA-mqgj-2736-57g4.json b/advisories/unreviewed/2025/04/GHSA-mqgj-2736-57g4/GHSA-mqgj-2736-57g4.json new file mode 100644 index 00000000000..be74fc44521 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mqgj-2736-57g4/GHSA-mqgj-2736-57g4.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mqgj-2736-57g4", + "modified": "2025-04-16T18:31:56Z", + "published": "2025-04-16T18:31:56Z", + "aliases": [ + "CVE-2025-32846" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'LockGeneralSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32846" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p349-27r5-4p76/GHSA-p349-27r5-4p76.json b/advisories/unreviewed/2025/04/GHSA-p349-27r5-4p76/GHSA-p349-27r5-4p76.json new file mode 100644 index 00000000000..73278b6ddac --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p349-27r5-4p76/GHSA-p349-27r5-4p76.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p349-27r5-4p76", + "modified": "2025-04-16T18:31:52Z", + "published": "2025-04-16T18:31:52Z", + "aliases": [ + "CVE-2024-40070" + ], + "details": "Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_generator/classes/Users.php?f=save. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40070" + }, + { + "type": "WEB", + "url": "https://github.com/DiliLearngent/BugReport/blob/main/php/Online-ID-Generator-System/bug6-File-upload-img2.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T17:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p4p6-jr54-56fc/GHSA-p4p6-jr54-56fc.json b/advisories/unreviewed/2025/04/GHSA-p4p6-jr54-56fc/GHSA-p4p6-jr54-56fc.json new file mode 100644 index 00000000000..bf7a3733579 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p4p6-jr54-56fc/GHSA-p4p6-jr54-56fc.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p4p6-jr54-56fc", + "modified": "2025-04-16T18:31:55Z", + "published": "2025-04-16T18:31:55Z", + "aliases": [ + "CVE-2025-32832" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'LockProjectUserRights' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32832" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pc48-gfjf-qv7q/GHSA-pc48-gfjf-qv7q.json b/advisories/unreviewed/2025/04/GHSA-pc48-gfjf-qv7q/GHSA-pc48-gfjf-qv7q.json new file mode 100644 index 00000000000..36b82024eb4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pc48-gfjf-qv7q/GHSA-pc48-gfjf-qv7q.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pc48-gfjf-qv7q", + "modified": "2025-04-16T18:31:53Z", + "published": "2025-04-16T18:31:53Z", + "aliases": [ + "CVE-2024-40074" + ], + "details": "Sourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via id_generator/classes/SystemSettings.php?f=update_settings, and the point of vulnerability is in the POST parameter 'short_name'.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40074" + }, + { + "type": "WEB", + "url": "https://github.com/DiliLearngent/BugReport/blob/main/php/Online-ID-Generator-System/bug1-XSS-short_name.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T17:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pc82-mp87-j8ch/GHSA-pc82-mp87-j8ch.json b/advisories/unreviewed/2025/04/GHSA-pc82-mp87-j8ch/GHSA-pc82-mp87-j8ch.json new file mode 100644 index 00000000000..174cf3a3bfc --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pc82-mp87-j8ch/GHSA-pc82-mp87-j8ch.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pc82-mp87-j8ch", + "modified": "2025-04-16T18:31:56Z", + "published": "2025-04-16T18:31:56Z", + "aliases": [ + "CVE-2025-32837" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'GetActiveConnectionVariables' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32837" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pfpp-vwh2-g27w/GHSA-pfpp-vwh2-g27w.json b/advisories/unreviewed/2025/04/GHSA-pfpp-vwh2-g27w/GHSA-pfpp-vwh2-g27w.json new file mode 100644 index 00000000000..4fb258ddd94 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pfpp-vwh2-g27w/GHSA-pfpp-vwh2-g27w.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pfpp-vwh2-g27w", + "modified": "2025-04-16T18:31:53Z", + "published": "2025-04-16T18:31:53Z", + "aliases": [ + "CVE-2024-40073" + ], + "details": "Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the template parameter at id_generator/admin/?page=generate&template=4.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40073" + }, + { + "type": "WEB", + "url": "https://github.com/DiliLearngent/BugReport/blob/main/php/Online-ID-Generator-System/bug4-SQL-Injection-template.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T17:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qc76-h4qh-8242/GHSA-qc76-h4qh-8242.json b/advisories/unreviewed/2025/04/GHSA-qc76-h4qh-8242/GHSA-qc76-h4qh-8242.json index 3d29c7c4682..bfd63ea1442 100644 --- a/advisories/unreviewed/2025/04/GHSA-qc76-h4qh-8242/GHSA-qc76-h4qh-8242.json +++ b/advisories/unreviewed/2025/04/GHSA-qc76-h4qh-8242/GHSA-qc76-h4qh-8242.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-qh4r-w9x4-6fq2/GHSA-qh4r-w9x4-6fq2.json b/advisories/unreviewed/2025/04/GHSA-qh4r-w9x4-6fq2/GHSA-qh4r-w9x4-6fq2.json index ec9d18a8058..97403b99a42 100644 --- a/advisories/unreviewed/2025/04/GHSA-qh4r-w9x4-6fq2/GHSA-qh4r-w9x4-6fq2.json +++ b/advisories/unreviewed/2025/04/GHSA-qh4r-w9x4-6fq2/GHSA-qh4r-w9x4-6fq2.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-qj9w-64mv-p2fw/GHSA-qj9w-64mv-p2fw.json b/advisories/unreviewed/2025/04/GHSA-qj9w-64mv-p2fw/GHSA-qj9w-64mv-p2fw.json new file mode 100644 index 00000000000..c92f4ccea39 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qj9w-64mv-p2fw/GHSA-qj9w-64mv-p2fw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qj9w-64mv-p2fw", + "modified": "2025-04-16T18:31:54Z", + "published": "2025-04-16T18:31:54Z", + "aliases": [ + "CVE-2025-2291" + ], + "details": "Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, which allows an attacker to log in with an already expired password", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2291" + }, + { + "type": "WEB", + "url": "https://www.pgbouncer.org/changelog.html#pgbouncer-124x" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-324" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qpwm-gxq3-4244/GHSA-qpwm-gxq3-4244.json b/advisories/unreviewed/2025/04/GHSA-qpwm-gxq3-4244/GHSA-qpwm-gxq3-4244.json new file mode 100644 index 00000000000..a926b6048ae --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qpwm-gxq3-4244/GHSA-qpwm-gxq3-4244.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qpwm-gxq3-4244", + "modified": "2025-04-16T18:31:55Z", + "published": "2025-04-16T18:31:55Z", + "aliases": [ + "CVE-2025-32475" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateProject' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on. (ZDI-CAN-25912)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32475" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-r4rw-9xj5-3mcv/GHSA-r4rw-9xj5-3mcv.json b/advisories/unreviewed/2025/04/GHSA-r4rw-9xj5-3mcv/GHSA-r4rw-9xj5-3mcv.json new file mode 100644 index 00000000000..1005f4ca6c4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-r4rw-9xj5-3mcv/GHSA-r4rw-9xj5-3mcv.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r4rw-9xj5-3mcv", + "modified": "2025-04-16T18:31:55Z", + "published": "2025-04-16T18:31:55Z", + "aliases": [ + "CVE-2025-31353" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateOpcSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on. (ZDI-CAN-25916)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31353" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-r6wc-34gj-m284/GHSA-r6wc-34gj-m284.json b/advisories/unreviewed/2025/04/GHSA-r6wc-34gj-m284/GHSA-r6wc-34gj-m284.json new file mode 100644 index 00000000000..c0b0ab618a1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-r6wc-34gj-m284/GHSA-r6wc-34gj-m284.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r6wc-34gj-m284", + "modified": "2025-04-16T18:31:54Z", + "published": "2025-04-16T18:31:54Z", + "aliases": [ + "CVE-2025-31343" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateTcmSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on. (ZDI-CAN-25920)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31343" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rhjm-r2rh-2g5q/GHSA-rhjm-r2rh-2g5q.json b/advisories/unreviewed/2025/04/GHSA-rhjm-r2rh-2g5q/GHSA-rhjm-r2rh-2g5q.json new file mode 100644 index 00000000000..c9024d2b27e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rhjm-r2rh-2g5q/GHSA-rhjm-r2rh-2g5q.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rhjm-r2rh-2g5q", + "modified": "2025-04-16T18:31:56Z", + "published": "2025-04-16T18:31:56Z", + "aliases": [ + "CVE-2025-32842" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'GetUsers' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32842" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rmxj-f9rm-4c5q/GHSA-rmxj-f9rm-4c5q.json b/advisories/unreviewed/2025/04/GHSA-rmxj-f9rm-4c5q/GHSA-rmxj-f9rm-4c5q.json new file mode 100644 index 00000000000..a0d1fed8ae6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rmxj-f9rm-4c5q/GHSA-rmxj-f9rm-4c5q.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rmxj-f9rm-4c5q", + "modified": "2025-04-16T18:31:55Z", + "published": "2025-04-16T18:31:55Z", + "aliases": [ + "CVE-2025-32825" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'GetProjects' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32825" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rv87-h47c-m27v/GHSA-rv87-h47c-m27v.json b/advisories/unreviewed/2025/04/GHSA-rv87-h47c-m27v/GHSA-rv87-h47c-m27v.json new file mode 100644 index 00000000000..76120635084 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rv87-h47c-m27v/GHSA-rv87-h47c-m27v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rv87-h47c-m27v", + "modified": "2025-04-16T18:31:53Z", + "published": "2025-04-16T18:31:53Z", + "aliases": [ + "CVE-2025-20236" + ], + "details": "A vulnerability in the custom URL parser of Cisco Webex App could allow an unauthenticated, remote attacker to persuade a user to download arbitrary files, which could allow the attacker to execute arbitrary commands on the host of the targeted user.\n\nThis vulnerability is due to insufficient input validation when Cisco Webex App processes a meeting invite link. An attacker could exploit this vulnerability by persuading a user to click a crafted meeting invite link and download arbitrary files. A successful exploit could allow the attacker to execute arbitrary commands with the privileges of the targeted user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20236" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-app-client-rce-ufyMMYLC" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-829" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T17:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-v32m-vc38-632r/GHSA-v32m-vc38-632r.json b/advisories/unreviewed/2025/04/GHSA-v32m-vc38-632r/GHSA-v32m-vc38-632r.json new file mode 100644 index 00000000000..dfda5c39968 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v32m-vc38-632r/GHSA-v32m-vc38-632r.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v32m-vc38-632r", + "modified": "2025-04-16T18:31:57Z", + "published": "2025-04-16T18:31:57Z", + "aliases": [ + "CVE-2025-32857" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UnlockBufferingSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32857" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-v3r6-268x-w57p/GHSA-v3r6-268x-w57p.json b/advisories/unreviewed/2025/04/GHSA-v3r6-268x-w57p/GHSA-v3r6-268x-w57p.json new file mode 100644 index 00000000000..ee426780e49 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v3r6-268x-w57p/GHSA-v3r6-268x-w57p.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v3r6-268x-w57p", + "modified": "2025-04-16T18:31:53Z", + "published": "2025-04-16T18:31:53Z", + "aliases": [ + "CVE-2025-3737" + ], + "details": "Vulnerability in Drupal Google Maps: Store Locator.This issue affects Google Maps: Store Locator: *.*.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3737" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-038" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-v664-v4vw-9f75/GHSA-v664-v4vw-9f75.json b/advisories/unreviewed/2025/04/GHSA-v664-v4vw-9f75/GHSA-v664-v4vw-9f75.json new file mode 100644 index 00000000000..6586575a9ba --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v664-v4vw-9f75/GHSA-v664-v4vw-9f75.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v664-v4vw-9f75", + "modified": "2025-04-16T18:31:57Z", + "published": "2025-04-16T18:31:57Z", + "aliases": [ + "CVE-2025-32859" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'LockWebServerGatewaySettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32859" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-v9jg-x75g-m949/GHSA-v9jg-x75g-m949.json b/advisories/unreviewed/2025/04/GHSA-v9jg-x75g-m949/GHSA-v9jg-x75g-m949.json new file mode 100644 index 00000000000..697a4cc2726 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v9jg-x75g-m949/GHSA-v9jg-x75g-m949.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v9jg-x75g-m949", + "modified": "2025-04-16T18:31:57Z", + "published": "2025-04-16T18:31:57Z", + "aliases": [ + "CVE-2025-32862" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'LockTraceLevelSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32862" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vr9w-fp6c-vj58/GHSA-vr9w-fp6c-vj58.json b/advisories/unreviewed/2025/04/GHSA-vr9w-fp6c-vj58/GHSA-vr9w-fp6c-vj58.json new file mode 100644 index 00000000000..db5cbccf6a7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vr9w-fp6c-vj58/GHSA-vr9w-fp6c-vj58.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vr9w-fp6c-vj58", + "modified": "2025-04-16T18:31:50Z", + "published": "2025-04-16T18:31:50Z", + "aliases": [ + "CVE-2025-20178" + ], + "details": "A vulnerability in the web-based management interface of Cisco Secure Network Analytics could allow an authenticated, remote attacker with valid administrative credentials to execute arbitrary commands as root on the underlying operating system.\n\n\nThis vulnerability is due to insufficient integrity checks within device backup files. An attacker with valid administrative credentials could exploit this vulnerability by crafting a malicious backup file and restoring it to an affected device. A successful exploit could allow the attacker to obtain shell access on the underlying operating system with the privileges of root.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20178" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sna-prvesc-4BQmK33Z" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-347" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T16:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-w22f-9vp5-hh8q/GHSA-w22f-9vp5-hh8q.json b/advisories/unreviewed/2025/04/GHSA-w22f-9vp5-hh8q/GHSA-w22f-9vp5-hh8q.json new file mode 100644 index 00000000000..976f78943fc --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-w22f-9vp5-hh8q/GHSA-w22f-9vp5-hh8q.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w22f-9vp5-hh8q", + "modified": "2025-04-16T18:31:53Z", + "published": "2025-04-16T18:31:53Z", + "aliases": [ + "CVE-2025-3738" + ], + "details": "Vulnerability in Drupal Google Optimize.This issue affects Google Optimize: *.*.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3738" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-039" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wgx2-mpwq-qfr4/GHSA-wgx2-mpwq-qfr4.json b/advisories/unreviewed/2025/04/GHSA-wgx2-mpwq-qfr4/GHSA-wgx2-mpwq-qfr4.json index 4396c95aa26..a595e357e57 100644 --- a/advisories/unreviewed/2025/04/GHSA-wgx2-mpwq-qfr4/GHSA-wgx2-mpwq-qfr4.json +++ b/advisories/unreviewed/2025/04/GHSA-wgx2-mpwq-qfr4/GHSA-wgx2-mpwq-qfr4.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-x2qh-cxvc-xrj7/GHSA-x2qh-cxvc-xrj7.json b/advisories/unreviewed/2025/04/GHSA-x2qh-cxvc-xrj7/GHSA-x2qh-cxvc-xrj7.json new file mode 100644 index 00000000000..48f7f7da2b0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-x2qh-cxvc-xrj7/GHSA-x2qh-cxvc-xrj7.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x2qh-cxvc-xrj7", + "modified": "2025-04-16T18:31:57Z", + "published": "2025-04-16T18:31:57Z", + "aliases": [ + "CVE-2025-32858" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateWebServerGatewaySettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32858" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-x367-5ghr-p4wq/GHSA-x367-5ghr-p4wq.json b/advisories/unreviewed/2025/04/GHSA-x367-5ghr-p4wq/GHSA-x367-5ghr-p4wq.json new file mode 100644 index 00000000000..6bff6d75d03 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-x367-5ghr-p4wq/GHSA-x367-5ghr-p4wq.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x367-5ghr-p4wq", + "modified": "2025-04-16T18:31:55Z", + "published": "2025-04-16T18:31:55Z", + "aliases": [ + "CVE-2025-32828" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateProjectCrossCommunications' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32828" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xjgf-c9ph-cxh2/GHSA-xjgf-c9ph-cxh2.json b/advisories/unreviewed/2025/04/GHSA-xjgf-c9ph-cxh2/GHSA-xjgf-c9ph-cxh2.json new file mode 100644 index 00000000000..97998f5a1bc --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xjgf-c9ph-cxh2/GHSA-xjgf-c9ph-cxh2.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xjgf-c9ph-cxh2", + "modified": "2025-04-16T18:31:56Z", + "published": "2025-04-16T18:31:56Z", + "aliases": [ + "CVE-2025-32849" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UnlockSmtpSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32849" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xpfx-g9x8-6hx6/GHSA-xpfx-g9x8-6hx6.json b/advisories/unreviewed/2025/04/GHSA-xpfx-g9x8-6hx6/GHSA-xpfx-g9x8-6hx6.json new file mode 100644 index 00000000000..e3eeda2b6f5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xpfx-g9x8-6hx6/GHSA-xpfx-g9x8-6hx6.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xpfx-g9x8-6hx6", + "modified": "2025-04-16T18:31:57Z", + "published": "2025-04-16T18:31:57Z", + "aliases": [ + "CVE-2025-32863" + ], + "details": "A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UnlockTraceLevelSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with \"NT AUTHORITY\\NetworkService\" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32863" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-443402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T18:16:17Z" + } +} \ No newline at end of file