diff --git a/advisories/unreviewed/2022/01/GHSA-qgr2-xgqv-24x8/GHSA-qgr2-xgqv-24x8.json b/advisories/unreviewed/2022/01/GHSA-qgr2-xgqv-24x8/GHSA-qgr2-xgqv-24x8.json index acbb91ae0dc..3c296eb62fb 100644 --- a/advisories/unreviewed/2022/01/GHSA-qgr2-xgqv-24x8/GHSA-qgr2-xgqv-24x8.json +++ b/advisories/unreviewed/2022/01/GHSA-qgr2-xgqv-24x8/GHSA-qgr2-xgqv-24x8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qgr2-xgqv-24x8", - "modified": "2024-11-04T18:31:16Z", + "modified": "2025-04-03T21:32:46Z", "published": "2022-01-29T00:00:42Z", "aliases": [ "CVE-2021-4034" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-4034" }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/pwnkit-pkexec-lpe-cve-2021-4034" + }, { "type": "WEB", "url": "https://www.suse.com/support/kb/doc/?id=000020564" diff --git a/advisories/unreviewed/2022/05/GHSA-5c53-gj37-m7jp/GHSA-5c53-gj37-m7jp.json b/advisories/unreviewed/2022/05/GHSA-5c53-gj37-m7jp/GHSA-5c53-gj37-m7jp.json index 9fcb0a5cc35..4ce9a3c4c2c 100644 --- a/advisories/unreviewed/2022/05/GHSA-5c53-gj37-m7jp/GHSA-5c53-gj37-m7jp.json +++ b/advisories/unreviewed/2022/05/GHSA-5c53-gj37-m7jp/GHSA-5c53-gj37-m7jp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5c53-gj37-m7jp", - "modified": "2022-05-24T16:50:14Z", + "modified": "2025-04-03T21:32:38Z", "published": "2022-05-24T16:50:14Z", "aliases": [ "CVE-2019-0880" ], "details": "A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of Privilege Vulnerability'.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2023/01/GHSA-2cfq-hfxh-5h78/GHSA-2cfq-hfxh-5h78.json b/advisories/unreviewed/2023/01/GHSA-2cfq-hfxh-5h78/GHSA-2cfq-hfxh-5h78.json index 22761a7eb61..ae7aba84ea4 100644 --- a/advisories/unreviewed/2023/01/GHSA-2cfq-hfxh-5h78/GHSA-2cfq-hfxh-5h78.json +++ b/advisories/unreviewed/2023/01/GHSA-2cfq-hfxh-5h78/GHSA-2cfq-hfxh-5h78.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2cfq-hfxh-5h78", - "modified": "2023-01-30T15:30:36Z", + "modified": "2025-04-03T21:32:47Z", "published": "2023-01-19T00:30:30Z", "aliases": [ "CVE-2022-4235" diff --git a/advisories/unreviewed/2023/01/GHSA-6fhx-fm6h-hpxq/GHSA-6fhx-fm6h-hpxq.json b/advisories/unreviewed/2023/01/GHSA-6fhx-fm6h-hpxq/GHSA-6fhx-fm6h-hpxq.json index e0da6fee217..c43f85e6c9b 100644 --- a/advisories/unreviewed/2023/01/GHSA-6fhx-fm6h-hpxq/GHSA-6fhx-fm6h-hpxq.json +++ b/advisories/unreviewed/2023/01/GHSA-6fhx-fm6h-hpxq/GHSA-6fhx-fm6h-hpxq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6fhx-fm6h-hpxq", - "modified": "2023-02-02T15:30:37Z", + "modified": "2025-04-03T21:32:49Z", "published": "2023-01-20T21:30:30Z", "aliases": [ "CVE-2022-48279" @@ -43,6 +43,18 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/01/msg00023.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/52TGCZCOHYBDCVWJYNN2PS4QLOHCXWTQ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SYRTXTOQQI6SB2TLI5QXU76DURSLS4XI" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WCH6JM4I4MD4YABYFHSBDDOUFDGIFJKL" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/52TGCZCOHYBDCVWJYNN2PS4QLOHCXWTQ" @@ -58,7 +70,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-436" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-84gr-vfg9-783r/GHSA-84gr-vfg9-783r.json b/advisories/unreviewed/2023/01/GHSA-84gr-vfg9-783r/GHSA-84gr-vfg9-783r.json index ee8e0348990..d9f6502db84 100644 --- a/advisories/unreviewed/2023/01/GHSA-84gr-vfg9-783r/GHSA-84gr-vfg9-783r.json +++ b/advisories/unreviewed/2023/01/GHSA-84gr-vfg9-783r/GHSA-84gr-vfg9-783r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-84gr-vfg9-783r", - "modified": "2023-01-27T18:30:31Z", + "modified": "2025-04-03T21:32:46Z", "published": "2023-01-17T21:30:22Z", "aliases": [ "CVE-2023-23749" diff --git a/advisories/unreviewed/2023/01/GHSA-fg9c-fh23-jcmv/GHSA-fg9c-fh23-jcmv.json b/advisories/unreviewed/2023/01/GHSA-fg9c-fh23-jcmv/GHSA-fg9c-fh23-jcmv.json index bdde1bbcb2e..581cedf3d3c 100644 --- a/advisories/unreviewed/2023/01/GHSA-fg9c-fh23-jcmv/GHSA-fg9c-fh23-jcmv.json +++ b/advisories/unreviewed/2023/01/GHSA-fg9c-fh23-jcmv/GHSA-fg9c-fh23-jcmv.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-862" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-hwpw-gw93-83r7/GHSA-hwpw-gw93-83r7.json b/advisories/unreviewed/2023/01/GHSA-hwpw-gw93-83r7/GHSA-hwpw-gw93-83r7.json index 4be7b7110e9..d53b15da94a 100644 --- a/advisories/unreviewed/2023/01/GHSA-hwpw-gw93-83r7/GHSA-hwpw-gw93-83r7.json +++ b/advisories/unreviewed/2023/01/GHSA-hwpw-gw93-83r7/GHSA-hwpw-gw93-83r7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hwpw-gw93-83r7", - "modified": "2023-01-26T18:30:48Z", + "modified": "2025-04-03T21:32:48Z", "published": "2023-01-20T09:30:31Z", "aliases": [ "CVE-2022-48191" diff --git a/advisories/unreviewed/2023/01/GHSA-jc8x-vpwq-c9g5/GHSA-jc8x-vpwq-c9g5.json b/advisories/unreviewed/2023/01/GHSA-jc8x-vpwq-c9g5/GHSA-jc8x-vpwq-c9g5.json index e01d50a9538..3db086bb908 100644 --- a/advisories/unreviewed/2023/01/GHSA-jc8x-vpwq-c9g5/GHSA-jc8x-vpwq-c9g5.json +++ b/advisories/unreviewed/2023/01/GHSA-jc8x-vpwq-c9g5/GHSA-jc8x-vpwq-c9g5.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-qf97-64qx-gqhq/GHSA-qf97-64qx-gqhq.json b/advisories/unreviewed/2023/01/GHSA-qf97-64qx-gqhq/GHSA-qf97-64qx-gqhq.json index d1c7bbcf468..e5f74844efd 100644 --- a/advisories/unreviewed/2023/01/GHSA-qf97-64qx-gqhq/GHSA-qf97-64qx-gqhq.json +++ b/advisories/unreviewed/2023/01/GHSA-qf97-64qx-gqhq/GHSA-qf97-64qx-gqhq.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1284", "CWE-20" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/01/GHSA-qwfh-7v4c-5cqf/GHSA-qwfh-7v4c-5cqf.json b/advisories/unreviewed/2023/01/GHSA-qwfh-7v4c-5cqf/GHSA-qwfh-7v4c-5cqf.json index d64b6abf1fd..8c6d598aa54 100644 --- a/advisories/unreviewed/2023/01/GHSA-qwfh-7v4c-5cqf/GHSA-qwfh-7v4c-5cqf.json +++ b/advisories/unreviewed/2023/01/GHSA-qwfh-7v4c-5cqf/GHSA-qwfh-7v4c-5cqf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qwfh-7v4c-5cqf", - "modified": "2023-01-28T06:30:29Z", + "modified": "2025-04-03T21:32:47Z", "published": "2023-01-19T00:30:30Z", "aliases": [ "CVE-2023-0164" diff --git a/advisories/unreviewed/2023/01/GHSA-r659-h3gg-4vrp/GHSA-r659-h3gg-4vrp.json b/advisories/unreviewed/2023/01/GHSA-r659-h3gg-4vrp/GHSA-r659-h3gg-4vrp.json index 0a626975236..f83587f64ea 100644 --- a/advisories/unreviewed/2023/01/GHSA-r659-h3gg-4vrp/GHSA-r659-h3gg-4vrp.json +++ b/advisories/unreviewed/2023/01/GHSA-r659-h3gg-4vrp/GHSA-r659-h3gg-4vrp.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-v9hj-4wpj-hcq2/GHSA-v9hj-4wpj-hcq2.json b/advisories/unreviewed/2023/01/GHSA-v9hj-4wpj-hcq2/GHSA-v9hj-4wpj-hcq2.json index d1851e1d3ad..f5a519f554f 100644 --- a/advisories/unreviewed/2023/01/GHSA-v9hj-4wpj-hcq2/GHSA-v9hj-4wpj-hcq2.json +++ b/advisories/unreviewed/2023/01/GHSA-v9hj-4wpj-hcq2/GHSA-v9hj-4wpj-hcq2.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-494" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-xc32-mq6r-3364/GHSA-xc32-mq6r-3364.json b/advisories/unreviewed/2023/01/GHSA-xc32-mq6r-3364/GHSA-xc32-mq6r-3364.json index 8ef7a7b7be9..28ced8d152b 100644 --- a/advisories/unreviewed/2023/01/GHSA-xc32-mq6r-3364/GHSA-xc32-mq6r-3364.json +++ b/advisories/unreviewed/2023/01/GHSA-xc32-mq6r-3364/GHSA-xc32-mq6r-3364.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-jrmv-h6h9-gcm3/GHSA-jrmv-h6h9-gcm3.json b/advisories/unreviewed/2023/07/GHSA-jrmv-h6h9-gcm3/GHSA-jrmv-h6h9-gcm3.json index 338aa39caae..a781f693710 100644 --- a/advisories/unreviewed/2023/07/GHSA-jrmv-h6h9-gcm3/GHSA-jrmv-h6h9-gcm3.json +++ b/advisories/unreviewed/2023/07/GHSA-jrmv-h6h9-gcm3/GHSA-jrmv-h6h9-gcm3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jrmv-h6h9-gcm3", - "modified": "2024-04-04T05:31:40Z", + "modified": "2025-04-03T21:32:47Z", "published": "2023-07-06T19:24:07Z", "aliases": [ "CVE-2021-4314" diff --git a/advisories/unreviewed/2025/03/GHSA-qmc4-wjcr-2569/GHSA-qmc4-wjcr-2569.json b/advisories/unreviewed/2025/03/GHSA-qmc4-wjcr-2569/GHSA-qmc4-wjcr-2569.json index 770cc318159..232c9b3543f 100644 --- a/advisories/unreviewed/2025/03/GHSA-qmc4-wjcr-2569/GHSA-qmc4-wjcr-2569.json +++ b/advisories/unreviewed/2025/03/GHSA-qmc4-wjcr-2569/GHSA-qmc4-wjcr-2569.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qmc4-wjcr-2569", - "modified": "2025-03-05T18:32:03Z", + "modified": "2025-04-03T21:32:54Z", "published": "2025-03-01T00:31:55Z", "aliases": [ "CVE-2025-25723" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://github.com/gpac/gpac/issues/3089" + }, + { + "type": "WEB", + "url": "https://github.com/gpac/gpac/commit/74e26b8dfeb0ab8c7317603b80a18306d0698473" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/04/GHSA-2h82-w6j2-mfx6/GHSA-2h82-w6j2-mfx6.json b/advisories/unreviewed/2025/04/GHSA-2h82-w6j2-mfx6/GHSA-2h82-w6j2-mfx6.json index 5f9312b92d2..09e016adc9d 100644 --- a/advisories/unreviewed/2025/04/GHSA-2h82-w6j2-mfx6/GHSA-2h82-w6j2-mfx6.json +++ b/advisories/unreviewed/2025/04/GHSA-2h82-w6j2-mfx6/GHSA-2h82-w6j2-mfx6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2h82-w6j2-mfx6", - "modified": "2025-04-01T00:30:35Z", + "modified": "2025-04-03T21:32:57Z", "published": "2025-04-01T00:30:35Z", "aliases": [ "CVE-2025-24095" ], "details": "This issue was addressed with additional entitlement checks. This issue is fixed in visionOS 2.4, iOS 18.4 and iPadOS 18.4. An app may be able to bypass Privacy preferences.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-288" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:16Z" diff --git a/advisories/unreviewed/2025/04/GHSA-2hgm-xvx6-w372/GHSA-2hgm-xvx6-w372.json b/advisories/unreviewed/2025/04/GHSA-2hgm-xvx6-w372/GHSA-2hgm-xvx6-w372.json new file mode 100644 index 00000000000..8a9981f7e82 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2hgm-xvx6-w372/GHSA-2hgm-xvx6-w372.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2hgm-xvx6-w372", + "modified": "2025-04-03T21:32:59Z", + "published": "2025-04-03T21:32:59Z", + "aliases": [ + "CVE-2025-26818" + ], + "details": "Netwrix Password Secure through 9.2 allows command injection.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26818" + }, + { + "type": "WEB", + "url": "https://helpcenter.netwrix.com/bundle/PasswordSecure_9.2_ReleaseNotes/resource/Netwrix_PasswordSecure_9.2_BugFixList.pdf" + }, + { + "type": "WEB", + "url": "https://security.netwrix.com/advisories/adv-2025-009" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-03T20:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2wf7-238m-g5qh/GHSA-2wf7-238m-g5qh.json b/advisories/unreviewed/2025/04/GHSA-2wf7-238m-g5qh/GHSA-2wf7-238m-g5qh.json new file mode 100644 index 00000000000..34f7898173b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2wf7-238m-g5qh/GHSA-2wf7-238m-g5qh.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2wf7-238m-g5qh", + "modified": "2025-04-03T21:33:00Z", + "published": "2025-04-03T21:33:00Z", + "aliases": [ + "CVE-2025-3179" + ], + "details": "A vulnerability classified as critical has been found in projectworlds Online Doctor Appointment Booking System 1.0. Affected is an unknown function of the file /doctor/deletepatient.php. The manipulation of the argument ic leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3179" + }, + { + "type": "WEB", + "url": "https://github.com/p1026/CVE/issues/13" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303138" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303138" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.543839" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-03T21:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2x46-9926-54cg/GHSA-2x46-9926-54cg.json b/advisories/unreviewed/2025/04/GHSA-2x46-9926-54cg/GHSA-2x46-9926-54cg.json new file mode 100644 index 00000000000..f230dc665fd --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2x46-9926-54cg/GHSA-2x46-9926-54cg.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2x46-9926-54cg", + "modified": "2025-04-03T21:33:00Z", + "published": "2025-04-03T21:33:00Z", + "aliases": [ + "CVE-2025-3176" + ], + "details": "A vulnerability was found in Project Worlds Online Lawyer Management System 1.0. It has been classified as critical. This affects an unknown part of the file /single_lawyer.php. The manipulation of the argument u_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3176" + }, + { + "type": "WEB", + "url": "https://github.com/p1026/CVE/issues/10" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303135" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303135" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.543278" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-03T20:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-33qf-6xj8-p2pq/GHSA-33qf-6xj8-p2pq.json b/advisories/unreviewed/2025/04/GHSA-33qf-6xj8-p2pq/GHSA-33qf-6xj8-p2pq.json new file mode 100644 index 00000000000..2e5dcb2e788 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-33qf-6xj8-p2pq/GHSA-33qf-6xj8-p2pq.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-33qf-6xj8-p2pq", + "modified": "2025-04-03T21:33:00Z", + "published": "2025-04-03T21:33:00Z", + "aliases": [ + "CVE-2025-3178" + ], + "details": "A vulnerability was found in projectworlds Online Doctor Appointment Booking System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /doctor/deleteappointment.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3178" + }, + { + "type": "WEB", + "url": "https://github.com/p1026/CVE/issues/12" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303137" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303137" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.543838" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-03T21:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-38v2-f365-h79h/GHSA-38v2-f365-h79h.json b/advisories/unreviewed/2025/04/GHSA-38v2-f365-h79h/GHSA-38v2-f365-h79h.json new file mode 100644 index 00000000000..286fbcabd12 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-38v2-f365-h79h/GHSA-38v2-f365-h79h.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-38v2-f365-h79h", + "modified": "2025-04-03T21:32:59Z", + "published": "2025-04-03T21:32:59Z", + "aliases": [ + "CVE-2025-29504" + ], + "details": "Insecure Permission vulnerability in student-manage 1 allows a local attacker to escalate privileges via the Unsafe permission verification.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29504" + }, + { + "type": "WEB", + "url": "https://gitee.com/huang-yk/student-manage/issues/IBQ14H" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-03T20:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3wrm-64r6-6q6c/GHSA-3wrm-64r6-6q6c.json b/advisories/unreviewed/2025/04/GHSA-3wrm-64r6-6q6c/GHSA-3wrm-64r6-6q6c.json new file mode 100644 index 00000000000..335e8ac66d4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3wrm-64r6-6q6c/GHSA-3wrm-64r6-6q6c.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3wrm-64r6-6q6c", + "modified": "2025-04-03T21:33:00Z", + "published": "2025-04-03T21:33:00Z", + "aliases": [ + "CVE-2024-47215" + ], + "details": "An issue was discovered in Snowbridge setups sending data to Google Tag Manager Server Side. It involves attaching an invalid GTM SS preview header to events, causing them to be retried indefinitely. As a result, the performance of forwarding events to GTM SS overall can be affected (latency, throughput).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47215" + }, + { + "type": "WEB", + "url": "https://support.snowplow.io/hc/en-us/articles/26318139354909-Update-Critical-Snowplow-Security-Updates-Impact-on-Open-Source-Software-Users" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-03T21:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4hmf-3gjv-f764/GHSA-4hmf-3gjv-f764.json b/advisories/unreviewed/2025/04/GHSA-4hmf-3gjv-f764/GHSA-4hmf-3gjv-f764.json new file mode 100644 index 00000000000..f4a4de4bc64 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4hmf-3gjv-f764/GHSA-4hmf-3gjv-f764.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4hmf-3gjv-f764", + "modified": "2025-04-03T21:33:00Z", + "published": "2025-04-03T21:33:00Z", + "aliases": [ + "CVE-2025-3177" + ], + "details": "A vulnerability was found in FastCMS 0.1.5. It has been declared as critical. This vulnerability affects unknown code of the component JWT Handler. The manipulation leads to use of hard-coded cryptographic key\n . The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3177" + }, + { + "type": "WEB", + "url": "https://github.com/chujianxin0101/vuln/issues/2" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303136" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303136" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.543673" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-03T20:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-536r-2xvj-w9h5/GHSA-536r-2xvj-w9h5.json b/advisories/unreviewed/2025/04/GHSA-536r-2xvj-w9h5/GHSA-536r-2xvj-w9h5.json new file mode 100644 index 00000000000..f7d5b3bc38a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-536r-2xvj-w9h5/GHSA-536r-2xvj-w9h5.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-536r-2xvj-w9h5", + "modified": "2025-04-03T21:32:59Z", + "published": "2025-04-03T21:32:59Z", + "aliases": [ + "CVE-2025-26817" + ], + "details": "Netwrix Password Secure 9.2.0.32454 allows OS command injection.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26817" + }, + { + "type": "WEB", + "url": "https://helpcenter.netwrix.com/bundle/PasswordSecure_9.2_ReleaseNotes/resource/Netwrix_PasswordSecure_9.2_BugFixList.pdf" + }, + { + "type": "WEB", + "url": "https://security.netwrix.com/advisories/adv-2025-009" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-03T20:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6j75-9vmv-439p/GHSA-6j75-9vmv-439p.json b/advisories/unreviewed/2025/04/GHSA-6j75-9vmv-439p/GHSA-6j75-9vmv-439p.json new file mode 100644 index 00000000000..3d444070be0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6j75-9vmv-439p/GHSA-6j75-9vmv-439p.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6j75-9vmv-439p", + "modified": "2025-04-03T21:32:58Z", + "published": "2025-04-03T21:32:58Z", + "aliases": [ + "CVE-2025-3171" + ], + "details": "A vulnerability classified as critical was found in Project Worlds Online Lawyer Management System 1.0. This vulnerability affects unknown code of the file /approve_lawyer.php. The manipulation of the argument unblock_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3171" + }, + { + "type": "WEB", + "url": "https://github.com/p1026/CVE/issues/5" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303130" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303130" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.543273" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-03T18:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-777h-hpfj-x7hv/GHSA-777h-hpfj-x7hv.json b/advisories/unreviewed/2025/04/GHSA-777h-hpfj-x7hv/GHSA-777h-hpfj-x7hv.json index b126f51fd77..fc243a7e1a4 100644 --- a/advisories/unreviewed/2025/04/GHSA-777h-hpfj-x7hv/GHSA-777h-hpfj-x7hv.json +++ b/advisories/unreviewed/2025/04/GHSA-777h-hpfj-x7hv/GHSA-777h-hpfj-x7hv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-777h-hpfj-x7hv", - "modified": "2025-04-01T00:30:44Z", + "modified": "2025-04-03T21:32:57Z", "published": "2025-04-01T00:30:44Z", "aliases": [ "CVE-2025-31192" ], "details": "The issue was addressed with improved checks. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. A website may be able to access sensor information without user consent.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-305" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:29Z" diff --git a/advisories/unreviewed/2025/04/GHSA-8hhf-mvxr-j339/GHSA-8hhf-mvxr-j339.json b/advisories/unreviewed/2025/04/GHSA-8hhf-mvxr-j339/GHSA-8hhf-mvxr-j339.json new file mode 100644 index 00000000000..5dfaac1a87d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8hhf-mvxr-j339/GHSA-8hhf-mvxr-j339.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8hhf-mvxr-j339", + "modified": "2025-04-03T21:32:59Z", + "published": "2025-04-03T21:32:59Z", + "aliases": [ + "CVE-2025-3173" + ], + "details": "A vulnerability, which was classified as critical, was found in Project Worlds Online Lawyer Management System 1.0. Affected is an unknown function of the file /save_booking.php. The manipulation of the argument lawyer_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3173" + }, + { + "type": "WEB", + "url": "https://github.com/p1026/CVE/issues/7" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303132" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303132" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.543275" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-03T19:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8m52-qhhm-24hg/GHSA-8m52-qhhm-24hg.json b/advisories/unreviewed/2025/04/GHSA-8m52-qhhm-24hg/GHSA-8m52-qhhm-24hg.json new file mode 100644 index 00000000000..556606c153d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8m52-qhhm-24hg/GHSA-8m52-qhhm-24hg.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8m52-qhhm-24hg", + "modified": "2025-04-03T21:33:00Z", + "published": "2025-04-03T21:33:00Z", + "aliases": [ + "CVE-2024-45199" + ], + "details": "insightsoftware Hive JDBC through 2.6.13 has a remote code execution vulnerability. Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process when the JDBC Driver uses this URL to connect to the database. This can further lead to remote code execution.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45199" + }, + { + "type": "WEB", + "url": "https://gist.github.com/azraelxuemo/d019ad079d540ef28870dbd9552a7c62" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-03T21:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8mq7-j2hp-g76j/GHSA-8mq7-j2hp-g76j.json b/advisories/unreviewed/2025/04/GHSA-8mq7-j2hp-g76j/GHSA-8mq7-j2hp-g76j.json index 513edada533..64b5b4241fd 100644 --- a/advisories/unreviewed/2025/04/GHSA-8mq7-j2hp-g76j/GHSA-8mq7-j2hp-g76j.json +++ b/advisories/unreviewed/2025/04/GHSA-8mq7-j2hp-g76j/GHSA-8mq7-j2hp-g76j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8mq7-j2hp-g76j", - "modified": "2025-04-01T00:30:38Z", + "modified": "2025-04-03T21:32:57Z", "published": "2025-04-01T00:30:38Z", "aliases": [ "CVE-2025-24216" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in visionOS 2.4, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, Safari 18.4. Processing maliciously crafted web content may lead to an unexpected Safari crash.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:19Z" diff --git a/advisories/unreviewed/2025/04/GHSA-8xhv-fwf3-q27f/GHSA-8xhv-fwf3-q27f.json b/advisories/unreviewed/2025/04/GHSA-8xhv-fwf3-q27f/GHSA-8xhv-fwf3-q27f.json new file mode 100644 index 00000000000..7dc41c88725 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8xhv-fwf3-q27f/GHSA-8xhv-fwf3-q27f.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8xhv-fwf3-q27f", + "modified": "2025-04-03T21:32:58Z", + "published": "2025-04-03T21:32:58Z", + "aliases": [ + "CVE-2025-3170" + ], + "details": "A vulnerability classified as critical has been found in Project Worlds Online Lawyer Management System 1.0. This affects an unknown part of the file /admin_user.php. The manipulation of the argument block_id/unblock_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3170" + }, + { + "type": "WEB", + "url": "https://github.com/p1026/CVE/issues/3" + }, + { + "type": "WEB", + "url": "https://github.com/p1026/CVE/issues/4" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303129" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303129" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.543271" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-03T18:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9grg-pp2p-gqf6/GHSA-9grg-pp2p-gqf6.json b/advisories/unreviewed/2025/04/GHSA-9grg-pp2p-gqf6/GHSA-9grg-pp2p-gqf6.json new file mode 100644 index 00000000000..a1b93ebf6c4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9grg-pp2p-gqf6/GHSA-9grg-pp2p-gqf6.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9grg-pp2p-gqf6", + "modified": "2025-04-03T21:32:58Z", + "published": "2025-04-03T21:32:58Z", + "aliases": [ + "CVE-2025-29647" + ], + "details": "SeaCMS v13.3 has a SQL injection vulnerability in the component admin_tempvideo.php.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29647" + }, + { + "type": "WEB", + "url": "https://gitee.com/B00W_NSD/poc/blob/master/seacms13.3-sql/poc.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-03T19:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c57f-m24w-hf5p/GHSA-c57f-m24w-hf5p.json b/advisories/unreviewed/2025/04/GHSA-c57f-m24w-hf5p/GHSA-c57f-m24w-hf5p.json new file mode 100644 index 00000000000..e3abb76531d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c57f-m24w-hf5p/GHSA-c57f-m24w-hf5p.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c57f-m24w-hf5p", + "modified": "2025-04-03T21:33:00Z", + "published": "2025-04-03T21:33:00Z", + "aliases": [ + "CVE-2025-3180" + ], + "details": "A vulnerability classified as critical was found in projectworlds Online Doctor Appointment Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file /doctor/deleteschedule.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3180" + }, + { + "type": "WEB", + "url": "https://github.com/p1026/CVE/issues/14" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303139" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303139" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.543840" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-03T21:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c57h-rx24-vf52/GHSA-c57h-rx24-vf52.json b/advisories/unreviewed/2025/04/GHSA-c57h-rx24-vf52/GHSA-c57h-rx24-vf52.json new file mode 100644 index 00000000000..d941967113b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c57h-rx24-vf52/GHSA-c57h-rx24-vf52.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c57h-rx24-vf52", + "modified": "2025-04-03T21:32:59Z", + "published": "2025-04-03T21:32:59Z", + "aliases": [ + "CVE-2025-31161" + ], + "details": "CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unless a DMZ proxy instance is used), as exploited in the wild in March and April 2025, aka \"Unauthenticated HTTP(S) port access.\" A race condition exists in the AWS4-HMAC (compatible with S3) authorization method of the HTTP component of the FTP server. The server first verifies the existence of the user by performing a call to login_user_pass() with no password requirement. This will authenticate the session through the HMAC verification process and up until the server checks for user verification once more. The vulnerability can be further stabilized, eliminating the need for successfully triggering a race condition, by sending a mangled AWS4-HMAC header. By providing only the username and a following slash (/), the server will successfully find a username, which triggers the successful anypass authentication process, but the server will fail to find the expected SignedHeaders entry, resulting in an index-out-of-bounds error that stops the code from reaching the session cleanup. Together, these issues make it trivial to authenticate as any known or guessable user (e.g., crushadmin), and can lead to a full compromise of the system by obtaining an administrative account.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31161" + }, + { + "type": "WEB", + "url": "https://crushftp.com/crush11wiki/Wiki.jsp?page=Update#section-Update-VulnerabilityInfo" + }, + { + "type": "WEB", + "url": "https://outpost24.com/blog/crushftp-auth-bypass-vulnerability" + }, + { + "type": "WEB", + "url": "https://projectdiscovery.io/blog/crushftp-authentication-bypass" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-305" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-03T20:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cc4w-4629-8rc3/GHSA-cc4w-4629-8rc3.json b/advisories/unreviewed/2025/04/GHSA-cc4w-4629-8rc3/GHSA-cc4w-4629-8rc3.json index 31dad031ba8..44fff35337c 100644 --- a/advisories/unreviewed/2025/04/GHSA-cc4w-4629-8rc3/GHSA-cc4w-4629-8rc3.json +++ b/advisories/unreviewed/2025/04/GHSA-cc4w-4629-8rc3/GHSA-cc4w-4629-8rc3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cc4w-4629-8rc3", - "modified": "2025-04-02T15:31:36Z", + "modified": "2025-04-03T21:32:57Z", "published": "2025-04-02T15:31:36Z", "aliases": [ "CVE-2025-1805" ], "details": "Crypt::Salt for Perl version 0.01 uses insecure rand() function when generating salts for cryptographic purposes.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], "affected": [], "references": [ { @@ -31,7 +36,7 @@ "cwe_ids": [ "CWE-338" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-02T13:15:40Z" diff --git a/advisories/unreviewed/2025/04/GHSA-chv8-32cq-8ghq/GHSA-chv8-32cq-8ghq.json b/advisories/unreviewed/2025/04/GHSA-chv8-32cq-8ghq/GHSA-chv8-32cq-8ghq.json new file mode 100644 index 00000000000..69488a410ec --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-chv8-32cq-8ghq/GHSA-chv8-32cq-8ghq.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-chv8-32cq-8ghq", + "modified": "2025-04-03T21:32:59Z", + "published": "2025-04-03T21:32:59Z", + "aliases": [ + "CVE-2025-29462" + ], + "details": "A buffer overflow vulnerability has been discovered in Tenda Ac15 V15.13.07.13. The vulnerability occurs when the webCgiGetUploadFile function calls the socketRead function to process HTTP request messages, resulting in the overwriting of a buffer on the stack.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29462" + }, + { + "type": "WEB", + "url": "https://hackmd.io/@7QWW9EKUSNGgPWZNOHkL2w/Sk4xbvejyx" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-03T20:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cjw6-jvpm-42v2/GHSA-cjw6-jvpm-42v2.json b/advisories/unreviewed/2025/04/GHSA-cjw6-jvpm-42v2/GHSA-cjw6-jvpm-42v2.json new file mode 100644 index 00000000000..ea325df39ed --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cjw6-jvpm-42v2/GHSA-cjw6-jvpm-42v2.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cjw6-jvpm-42v2", + "modified": "2025-04-03T21:32:59Z", + "published": "2025-04-03T21:32:59Z", + "aliases": [ + "CVE-2025-3175" + ], + "details": "A vulnerability was found in Project Worlds Online Lawyer Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /save_user_edit_profile.php. The manipulation of the argument first_Name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3175" + }, + { + "type": "WEB", + "url": "https://github.com/p1026/CVE/issues/9" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303134" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303134" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.543277" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-03T19:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fphf-v8m4-xjvx/GHSA-fphf-v8m4-xjvx.json b/advisories/unreviewed/2025/04/GHSA-fphf-v8m4-xjvx/GHSA-fphf-v8m4-xjvx.json new file mode 100644 index 00000000000..bb428928b52 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fphf-v8m4-xjvx/GHSA-fphf-v8m4-xjvx.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fphf-v8m4-xjvx", + "modified": "2025-04-03T21:33:00Z", + "published": "2025-04-03T21:33:00Z", + "aliases": [ + "CVE-2024-47217" + ], + "details": "An issue was discovered in Iglu Server 0.13.0 and below. It is similar to CVE-2024-47214, but involves an authenticated endpoint. It can render Iglu Server completely unresponsive. If the operation of Iglu Server is not restored, event processing in the pipeline would eventually halt.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47217" + }, + { + "type": "WEB", + "url": "https://support.snowplow.io/hc/en-us/articles/26318139354909-Update-Critical-Snowplow-Security-Updates-Impact-on-Open-Source-Software-Users" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-03T21:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fv89-7wfw-xmjg/GHSA-fv89-7wfw-xmjg.json b/advisories/unreviewed/2025/04/GHSA-fv89-7wfw-xmjg/GHSA-fv89-7wfw-xmjg.json new file mode 100644 index 00000000000..966eb45b9bc --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fv89-7wfw-xmjg/GHSA-fv89-7wfw-xmjg.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fv89-7wfw-xmjg", + "modified": "2025-04-03T21:33:00Z", + "published": "2025-04-03T21:33:00Z", + "aliases": [ + "CVE-2024-47213" + ], + "details": "An issue was discovered affecting Enrich 5.1.0 and below. It involves sending a maliciously crafted Snowplow event to the pipeline. Upon receiving this event and trying to validate it, Enrich crashes and attempts to restart indefinitely. As a result, event processing would be halted.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47213" + }, + { + "type": "WEB", + "url": "https://support.snowplow.io/hc/en-us/articles/26318139354909-Update-Critical-Snowplow-Security-Updates-Impact-on-Open-Source-Software-Users" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-03T21:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hgp9-3v5v-223j/GHSA-hgp9-3v5v-223j.json b/advisories/unreviewed/2025/04/GHSA-hgp9-3v5v-223j/GHSA-hgp9-3v5v-223j.json new file mode 100644 index 00000000000..6e5998b8640 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hgp9-3v5v-223j/GHSA-hgp9-3v5v-223j.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hgp9-3v5v-223j", + "modified": "2025-04-03T21:32:59Z", + "published": "2025-04-03T21:32:59Z", + "aliases": [ + "CVE-2025-30406" + ], + "details": "Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal's hardcoded machineKey use, which enables threat actors (who know the machineKey) to serialize a payload for server-side deserialization to achieve remote code execution. NOTE: the CentreStack admin can manually delete the machineKey defined in portal\\web.config.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30406" + }, + { + "type": "WEB", + "url": "https://gladinetsupport.s3.us-east-1.amazonaws.com/gladinet/securityadvisory-cve-2005.pdf" + }, + { + "type": "WEB", + "url": "https://www.centrestack.com/p/gce_latest_release.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-03T20:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j2xc-53c4-c8p4/GHSA-j2xc-53c4-c8p4.json b/advisories/unreviewed/2025/04/GHSA-j2xc-53c4-c8p4/GHSA-j2xc-53c4-c8p4.json new file mode 100644 index 00000000000..8116cc023f5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j2xc-53c4-c8p4/GHSA-j2xc-53c4-c8p4.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j2xc-53c4-c8p4", + "modified": "2025-04-03T21:32:59Z", + "published": "2025-04-03T21:32:59Z", + "aliases": [ + "CVE-2025-3174" + ], + "details": "A vulnerability has been found in Project Worlds Online Lawyer Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /searchLawyer.php. The manipulation of the argument experience leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3174" + }, + { + "type": "WEB", + "url": "https://github.com/p1026/CVE/issues/8" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303133" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303133" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.543276" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-03T19:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j739-g4jp-g7r6/GHSA-j739-g4jp-g7r6.json b/advisories/unreviewed/2025/04/GHSA-j739-g4jp-g7r6/GHSA-j739-g4jp-g7r6.json new file mode 100644 index 00000000000..68f303c04ab --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j739-g4jp-g7r6/GHSA-j739-g4jp-g7r6.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j739-g4jp-g7r6", + "modified": "2025-04-03T21:32:59Z", + "published": "2025-04-03T21:32:59Z", + "aliases": [ + "CVE-2024-45198" + ], + "details": "insightsoftware Spark JDBC 2.6.21 has a remote code execution vulnerability. Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process when the JDBC Driver uses this URL to connect to the database. This can further lead to remote code execution.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45198" + }, + { + "type": "WEB", + "url": "https://gist.github.com/azraelxuemo/ef11311ae0633cbd3d794f73c64e3877" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-03T20:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qcwf-jj36-gr7m/GHSA-qcwf-jj36-gr7m.json b/advisories/unreviewed/2025/04/GHSA-qcwf-jj36-gr7m/GHSA-qcwf-jj36-gr7m.json new file mode 100644 index 00000000000..6a4dde09a5b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qcwf-jj36-gr7m/GHSA-qcwf-jj36-gr7m.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qcwf-jj36-gr7m", + "modified": "2025-04-03T21:33:00Z", + "published": "2025-04-03T21:33:00Z", + "aliases": [ + "CVE-2024-47214" + ], + "details": "An issue was discovered in Iglu Server 0.13.0 and below. It is similar to CVE-2024-47212, but involves a different kind of malicious payload. As above, it can render Iglu Server completely unresponsive. If the operation of Iglu Server is not restored, event processing in the pipeline would eventually halt.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47214" + }, + { + "type": "WEB", + "url": "https://support.snowplow.io/hc/en-us/articles/26318139354909-Update-Critical-Snowplow-Security-Updates-Impact-on-Open-Source-Software-Users" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-03T21:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qg7f-449v-85xg/GHSA-qg7f-449v-85xg.json b/advisories/unreviewed/2025/04/GHSA-qg7f-449v-85xg/GHSA-qg7f-449v-85xg.json new file mode 100644 index 00000000000..ffcb4de4ca5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qg7f-449v-85xg/GHSA-qg7f-449v-85xg.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qg7f-449v-85xg", + "modified": "2025-04-03T21:33:00Z", + "published": "2025-04-03T21:33:00Z", + "aliases": [ + "CVE-2024-56528" + ], + "details": "This vulnerability affects Snowplow Collector 3.x before 3.3.0 (unless it’s set up behind a reverse proxy that establishes payload limits). It involves sending very large payloads to the Collector and can render it unresponsive to the rest of the requests. As a result, data would not enter the pipeline and would be potentially lost.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56528" + }, + { + "type": "WEB", + "url": "https://support.snowplow.io/hc/en-us/articles/26318139354909-Update-Critical-Snowplow-Security-Updates-Impact-on-Open-Source-Software-Users" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-03T21:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-r6wp-29qw-vxr5/GHSA-r6wp-29qw-vxr5.json b/advisories/unreviewed/2025/04/GHSA-r6wp-29qw-vxr5/GHSA-r6wp-29qw-vxr5.json index f53318e4968..b5e68e2bff3 100644 --- a/advisories/unreviewed/2025/04/GHSA-r6wp-29qw-vxr5/GHSA-r6wp-29qw-vxr5.json +++ b/advisories/unreviewed/2025/04/GHSA-r6wp-29qw-vxr5/GHSA-r6wp-29qw-vxr5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r6wp-29qw-vxr5", - "modified": "2025-04-01T00:30:41Z", + "modified": "2025-04-03T21:32:57Z", "published": "2025-04-01T00:30:41Z", "aliases": [ "CVE-2025-30432" ], "details": "A logic issue was addressed with improved state management. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sonoma 14.7.5. A malicious app may be able to attempt passcode entries on a locked device and thereby cause escalating time delays after 4 failures.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:25Z" diff --git a/advisories/unreviewed/2025/04/GHSA-rmr8-rg92-5f98/GHSA-rmr8-rg92-5f98.json b/advisories/unreviewed/2025/04/GHSA-rmr8-rg92-5f98/GHSA-rmr8-rg92-5f98.json new file mode 100644 index 00000000000..0403a558902 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rmr8-rg92-5f98/GHSA-rmr8-rg92-5f98.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rmr8-rg92-5f98", + "modified": "2025-04-03T21:32:59Z", + "published": "2025-04-03T21:32:59Z", + "aliases": [ + "CVE-2025-29064" + ], + "details": "An issue in TOTOLINK x18 v.9.1.0cu.2024_B20220329 allows a remote attacker to execute arbitrary code via the sub_410E54 function of the cstecgi.cgi.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29064" + }, + { + "type": "WEB", + "url": "https://github.com/kn0sky/cve/blob/main/TOTOLINK%20X18/OS%20Command%20Injection%20setLanguageCfg_lang.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-03T20:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rwxg-r4cq-frp9/GHSA-rwxg-r4cq-frp9.json b/advisories/unreviewed/2025/04/GHSA-rwxg-r4cq-frp9/GHSA-rwxg-r4cq-frp9.json new file mode 100644 index 00000000000..cd5e17f33bd --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rwxg-r4cq-frp9/GHSA-rwxg-r4cq-frp9.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rwxg-r4cq-frp9", + "modified": "2025-04-03T21:33:00Z", + "published": "2025-04-03T21:33:00Z", + "aliases": [ + "CVE-2024-47212" + ], + "details": "An issue was discovered in Iglu Server 0.13.0 and below. It involves sending very large payloads to a particular API endpoint of Iglu Server and can render it completely unresponsive. If the operation of Iglu Server is not restored, event processing in the pipeline would eventually halt.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47212" + }, + { + "type": "WEB", + "url": "https://support.snowplow.io/hc/en-us/articles/26318139354909-Update-Critical-Snowplow-Security-Updates-Impact-on-Open-Source-Software-Users" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-03T21:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vhf9-v5pf-qmcg/GHSA-vhf9-v5pf-qmcg.json b/advisories/unreviewed/2025/04/GHSA-vhf9-v5pf-qmcg/GHSA-vhf9-v5pf-qmcg.json index d1e860bfdc8..942e9e11766 100644 --- a/advisories/unreviewed/2025/04/GHSA-vhf9-v5pf-qmcg/GHSA-vhf9-v5pf-qmcg.json +++ b/advisories/unreviewed/2025/04/GHSA-vhf9-v5pf-qmcg/GHSA-vhf9-v5pf-qmcg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vhf9-v5pf-qmcg", - "modified": "2025-04-01T00:30:41Z", + "modified": "2025-04-03T21:32:57Z", "published": "2025-04-01T00:30:41Z", "aliases": [ "CVE-2025-30428" ], "details": "This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6. Photos in the Hidden Photos Album may be viewed without authentication.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-305" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:25Z" diff --git a/advisories/unreviewed/2025/04/GHSA-w9qw-39gf-jp7r/GHSA-w9qw-39gf-jp7r.json b/advisories/unreviewed/2025/04/GHSA-w9qw-39gf-jp7r/GHSA-w9qw-39gf-jp7r.json index 99a3be69859..2507ee82e64 100644 --- a/advisories/unreviewed/2025/04/GHSA-w9qw-39gf-jp7r/GHSA-w9qw-39gf-jp7r.json +++ b/advisories/unreviewed/2025/04/GHSA-w9qw-39gf-jp7r/GHSA-w9qw-39gf-jp7r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w9qw-39gf-jp7r", - "modified": "2025-04-02T15:31:23Z", + "modified": "2025-04-03T21:32:57Z", "published": "2025-04-01T21:31:29Z", "aliases": [ "CVE-2025-29069" @@ -21,6 +21,10 @@ { "type": "WEB", "url": "https://github.com/mm2/Little-CMS/issues/476#issuecomment-2696670843" + }, + { + "type": "WEB", + "url": "https://github.com/mm2/Little-CMS/issues/476#issuecomment-2770644813" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/04/GHSA-x9f6-hx4w-vq6q/GHSA-x9f6-hx4w-vq6q.json b/advisories/unreviewed/2025/04/GHSA-x9f6-hx4w-vq6q/GHSA-x9f6-hx4w-vq6q.json new file mode 100644 index 00000000000..0548ed183e9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-x9f6-hx4w-vq6q/GHSA-x9f6-hx4w-vq6q.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x9f6-hx4w-vq6q", + "modified": "2025-04-03T21:32:59Z", + "published": "2025-04-03T21:32:59Z", + "aliases": [ + "CVE-2025-29570" + ], + "details": "An issue in Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v3.2 allows a local attacker to escalate privileges via the function tftp_image_check of a binary named rc.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29570" + }, + { + "type": "WEB", + "url": "https://github.com/IOTRes/IOT_Firmware_Update/blob/main/firmwareupdate.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-03T20:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xmgg-6wgj-628j/GHSA-xmgg-6wgj-628j.json b/advisories/unreviewed/2025/04/GHSA-xmgg-6wgj-628j/GHSA-xmgg-6wgj-628j.json new file mode 100644 index 00000000000..25a5001ca18 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xmgg-6wgj-628j/GHSA-xmgg-6wgj-628j.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xmgg-6wgj-628j", + "modified": "2025-04-03T21:32:58Z", + "published": "2025-04-03T21:32:58Z", + "aliases": [ + "CVE-2024-22611" + ], + "details": "OpenEMR 7.0.2 is vulnerable to SQL Injection via \\openemr\\library\\classes\\Pharmacy.class.php, \\controllers\\C_Pharmacy.class.php and \\openemr\\controller.php.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22611" + }, + { + "type": "WEB", + "url": "https://github.com/baolqinfosec/CVE-Reseach/blob/main/OpenERM_CVE-2024-22611.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-03T19:15:39Z" + } +} \ No newline at end of file