diff --git a/advisories/unreviewed/2022/11/GHSA-39cv-33wr-fgxh/GHSA-39cv-33wr-fgxh.json b/advisories/unreviewed/2022/11/GHSA-39cv-33wr-fgxh/GHSA-39cv-33wr-fgxh.json index bbfc7e3ec4d..f9a6549e8e1 100644 --- a/advisories/unreviewed/2022/11/GHSA-39cv-33wr-fgxh/GHSA-39cv-33wr-fgxh.json +++ b/advisories/unreviewed/2022/11/GHSA-39cv-33wr-fgxh/GHSA-39cv-33wr-fgxh.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-4cwv-p4c3-xrh9/GHSA-4cwv-p4c3-xrh9.json b/advisories/unreviewed/2022/11/GHSA-4cwv-p4c3-xrh9/GHSA-4cwv-p4c3-xrh9.json index c0f7261e678..ac24231cdb4 100644 --- a/advisories/unreviewed/2022/11/GHSA-4cwv-p4c3-xrh9/GHSA-4cwv-p4c3-xrh9.json +++ b/advisories/unreviewed/2022/11/GHSA-4cwv-p4c3-xrh9/GHSA-4cwv-p4c3-xrh9.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-fvf3-rpfr-xqw3/GHSA-fvf3-rpfr-xqw3.json b/advisories/unreviewed/2022/11/GHSA-fvf3-rpfr-xqw3/GHSA-fvf3-rpfr-xqw3.json index 1cd1dad5213..e04f4a1972c 100644 --- a/advisories/unreviewed/2022/11/GHSA-fvf3-rpfr-xqw3/GHSA-fvf3-rpfr-xqw3.json +++ b/advisories/unreviewed/2022/11/GHSA-fvf3-rpfr-xqw3/GHSA-fvf3-rpfr-xqw3.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-347" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/11/GHSA-hppc-7rjj-h77r/GHSA-hppc-7rjj-h77r.json b/advisories/unreviewed/2022/11/GHSA-hppc-7rjj-h77r/GHSA-hppc-7rjj-h77r.json index 4f54fd14bf6..89a82db3cec 100644 --- a/advisories/unreviewed/2022/11/GHSA-hppc-7rjj-h77r/GHSA-hppc-7rjj-h77r.json +++ b/advisories/unreviewed/2022/11/GHSA-hppc-7rjj-h77r/GHSA-hppc-7rjj-h77r.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-mvp8-3j6q-qffq/GHSA-mvp8-3j6q-qffq.json b/advisories/unreviewed/2022/11/GHSA-mvp8-3j6q-qffq/GHSA-mvp8-3j6q-qffq.json index ae953fa92f1..4ae56092bf7 100644 --- a/advisories/unreviewed/2022/11/GHSA-mvp8-3j6q-qffq/GHSA-mvp8-3j6q-qffq.json +++ b/advisories/unreviewed/2022/11/GHSA-mvp8-3j6q-qffq/GHSA-mvp8-3j6q-qffq.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-1284" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-2pw8-phr9-8fj4/GHSA-2pw8-phr9-8fj4.json b/advisories/unreviewed/2022/12/GHSA-2pw8-phr9-8fj4/GHSA-2pw8-phr9-8fj4.json index 892003fbf0c..d580cb4030e 100644 --- a/advisories/unreviewed/2022/12/GHSA-2pw8-phr9-8fj4/GHSA-2pw8-phr9-8fj4.json +++ b/advisories/unreviewed/2022/12/GHSA-2pw8-phr9-8fj4/GHSA-2pw8-phr9-8fj4.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-783" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-46qx-xf9f-62gx/GHSA-46qx-xf9f-62gx.json b/advisories/unreviewed/2022/12/GHSA-46qx-xf9f-62gx/GHSA-46qx-xf9f-62gx.json index 6d0906c7667..a41d3d9a81f 100644 --- a/advisories/unreviewed/2022/12/GHSA-46qx-xf9f-62gx/GHSA-46qx-xf9f-62gx.json +++ b/advisories/unreviewed/2022/12/GHSA-46qx-xf9f-62gx/GHSA-46qx-xf9f-62gx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-46qx-xf9f-62gx", - "modified": "2022-12-16T21:30:44Z", + "modified": "2025-04-22T18:31:59Z", "published": "2022-12-14T18:30:23Z", "aliases": [ "CVE-2022-46256" @@ -19,6 +19,26 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46256" }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server%403.3/admin/release-notes#3.3.17" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server%403.4/admin/release-notes#3.4.12" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server%403.5/admin/release-notes#3.5.9" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server%403.6/admin/release-notes#3.6.5" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server%403.7/admin/release-notes#3.7.2" + }, { "type": "WEB", "url": "https://docs.github.com/en/enterprise-server@3.3/admin/release-notes#3.3.17" diff --git a/advisories/unreviewed/2022/12/GHSA-5hp7-2mv5-p69r/GHSA-5hp7-2mv5-p69r.json b/advisories/unreviewed/2022/12/GHSA-5hp7-2mv5-p69r/GHSA-5hp7-2mv5-p69r.json index deea149c1ec..84dba79f065 100644 --- a/advisories/unreviewed/2022/12/GHSA-5hp7-2mv5-p69r/GHSA-5hp7-2mv5-p69r.json +++ b/advisories/unreviewed/2022/12/GHSA-5hp7-2mv5-p69r/GHSA-5hp7-2mv5-p69r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5hp7-2mv5-p69r", - "modified": "2022-12-19T21:30:27Z", + "modified": "2025-04-22T18:32:00Z", "published": "2022-12-14T21:30:16Z", "aliases": [ "CVE-2022-46342" diff --git a/advisories/unreviewed/2022/12/GHSA-7c7w-25xj-4mp8/GHSA-7c7w-25xj-4mp8.json b/advisories/unreviewed/2022/12/GHSA-7c7w-25xj-4mp8/GHSA-7c7w-25xj-4mp8.json index 83bf4163195..ab4b2bf12ff 100644 --- a/advisories/unreviewed/2022/12/GHSA-7c7w-25xj-4mp8/GHSA-7c7w-25xj-4mp8.json +++ b/advisories/unreviewed/2022/12/GHSA-7c7w-25xj-4mp8/GHSA-7c7w-25xj-4mp8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7c7w-25xj-4mp8", - "modified": "2023-01-26T21:30:24Z", + "modified": "2025-04-22T18:31:58Z", "published": "2022-12-14T00:30:23Z", "aliases": [ "CVE-2022-37155" @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-7g4x-mgr6-m9g9/GHSA-7g4x-mgr6-m9g9.json b/advisories/unreviewed/2022/12/GHSA-7g4x-mgr6-m9g9/GHSA-7g4x-mgr6-m9g9.json index 31094993336..693008db850 100644 --- a/advisories/unreviewed/2022/12/GHSA-7g4x-mgr6-m9g9/GHSA-7g4x-mgr6-m9g9.json +++ b/advisories/unreviewed/2022/12/GHSA-7g4x-mgr6-m9g9/GHSA-7g4x-mgr6-m9g9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7g4x-mgr6-m9g9", - "modified": "2022-12-16T21:30:43Z", + "modified": "2025-04-22T18:31:59Z", "published": "2022-12-14T18:30:23Z", "aliases": [ "CVE-2022-46255" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46255" }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server%403.7/admin/release-notes#3.7.1" + }, { "type": "WEB", "url": "https://docs.github.com/en/enterprise-server@3.7/admin/release-notes#3.7.1" diff --git a/advisories/unreviewed/2022/12/GHSA-7vvx-67x5-5jw2/GHSA-7vvx-67x5-5jw2.json b/advisories/unreviewed/2022/12/GHSA-7vvx-67x5-5jw2/GHSA-7vvx-67x5-5jw2.json index 7cb03630bb3..1a97148ea89 100644 --- a/advisories/unreviewed/2022/12/GHSA-7vvx-67x5-5jw2/GHSA-7vvx-67x5-5jw2.json +++ b/advisories/unreviewed/2022/12/GHSA-7vvx-67x5-5jw2/GHSA-7vvx-67x5-5jw2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7vvx-67x5-5jw2", - "modified": "2022-12-16T21:30:44Z", + "modified": "2025-04-22T18:31:59Z", "published": "2022-12-14T21:30:17Z", "aliases": [ "CVE-2022-23741" @@ -19,6 +19,22 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-23741" }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server%403.3/admin/release-notes#3.3.17" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server%403.4/admin/release-notes#3.4.12" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server%403.5/admin/release-notes#3.5.9" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server%403.6/admin/release-notes#3.6.5" + }, { "type": "WEB", "url": "https://docs.github.com/en/enterprise-server@3.3/admin/release-notes#3.3.17" diff --git a/advisories/unreviewed/2022/12/GHSA-8vgr-hc2x-gh7h/GHSA-8vgr-hc2x-gh7h.json b/advisories/unreviewed/2022/12/GHSA-8vgr-hc2x-gh7h/GHSA-8vgr-hc2x-gh7h.json index 5ce2dc57feb..d64cfa0d40d 100644 --- a/advisories/unreviewed/2022/12/GHSA-8vgr-hc2x-gh7h/GHSA-8vgr-hc2x-gh7h.json +++ b/advisories/unreviewed/2022/12/GHSA-8vgr-hc2x-gh7h/GHSA-8vgr-hc2x-gh7h.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-770" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-cfjv-73gp-92j6/GHSA-cfjv-73gp-92j6.json b/advisories/unreviewed/2022/12/GHSA-cfjv-73gp-92j6/GHSA-cfjv-73gp-92j6.json index 37fb91ca031..1dac1b2b14a 100644 --- a/advisories/unreviewed/2022/12/GHSA-cfjv-73gp-92j6/GHSA-cfjv-73gp-92j6.json +++ b/advisories/unreviewed/2022/12/GHSA-cfjv-73gp-92j6/GHSA-cfjv-73gp-92j6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cfjv-73gp-92j6", - "modified": "2022-12-19T21:30:26Z", + "modified": "2025-04-22T18:32:00Z", "published": "2022-12-14T21:30:16Z", "aliases": [ "CVE-2022-46343" diff --git a/advisories/unreviewed/2022/12/GHSA-cj4x-645f-6pwx/GHSA-cj4x-645f-6pwx.json b/advisories/unreviewed/2022/12/GHSA-cj4x-645f-6pwx/GHSA-cj4x-645f-6pwx.json index 85090578772..e2d311f33f6 100644 --- a/advisories/unreviewed/2022/12/GHSA-cj4x-645f-6pwx/GHSA-cj4x-645f-6pwx.json +++ b/advisories/unreviewed/2022/12/GHSA-cj4x-645f-6pwx/GHSA-cj4x-645f-6pwx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cj4x-645f-6pwx", - "modified": "2022-12-20T03:30:28Z", + "modified": "2025-04-22T18:32:00Z", "published": "2022-12-14T21:30:16Z", "aliases": [ "CVE-2022-46341" diff --git a/advisories/unreviewed/2022/12/GHSA-cj7x-83xx-p9jq/GHSA-cj7x-83xx-p9jq.json b/advisories/unreviewed/2022/12/GHSA-cj7x-83xx-p9jq/GHSA-cj7x-83xx-p9jq.json index bef41b49980..54969382b14 100644 --- a/advisories/unreviewed/2022/12/GHSA-cj7x-83xx-p9jq/GHSA-cj7x-83xx-p9jq.json +++ b/advisories/unreviewed/2022/12/GHSA-cj7x-83xx-p9jq/GHSA-cj7x-83xx-p9jq.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-fv9q-xh4m-8hx9/GHSA-fv9q-xh4m-8hx9.json b/advisories/unreviewed/2022/12/GHSA-fv9q-xh4m-8hx9/GHSA-fv9q-xh4m-8hx9.json index e605cbe2c43..d3c4ab45a03 100644 --- a/advisories/unreviewed/2022/12/GHSA-fv9q-xh4m-8hx9/GHSA-fv9q-xh4m-8hx9.json +++ b/advisories/unreviewed/2022/12/GHSA-fv9q-xh4m-8hx9/GHSA-fv9q-xh4m-8hx9.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-hvwj-m4ph-92v4/GHSA-hvwj-m4ph-92v4.json b/advisories/unreviewed/2022/12/GHSA-hvwj-m4ph-92v4/GHSA-hvwj-m4ph-92v4.json index 601864610e4..f96401c75db 100644 --- a/advisories/unreviewed/2022/12/GHSA-hvwj-m4ph-92v4/GHSA-hvwj-m4ph-92v4.json +++ b/advisories/unreviewed/2022/12/GHSA-hvwj-m4ph-92v4/GHSA-hvwj-m4ph-92v4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hvwj-m4ph-92v4", - "modified": "2022-12-19T18:30:25Z", + "modified": "2025-04-22T18:32:00Z", "published": "2022-12-14T21:30:16Z", "aliases": [ "CVE-2022-46340" diff --git a/advisories/unreviewed/2022/12/GHSA-j8g9-rvg7-2x7w/GHSA-j8g9-rvg7-2x7w.json b/advisories/unreviewed/2022/12/GHSA-j8g9-rvg7-2x7w/GHSA-j8g9-rvg7-2x7w.json index 046cd0f0c56..a8405ce7fc2 100644 --- a/advisories/unreviewed/2022/12/GHSA-j8g9-rvg7-2x7w/GHSA-j8g9-rvg7-2x7w.json +++ b/advisories/unreviewed/2022/12/GHSA-j8g9-rvg7-2x7w/GHSA-j8g9-rvg7-2x7w.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-770" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-jp99-g9qj-38pv/GHSA-jp99-g9qj-38pv.json b/advisories/unreviewed/2022/12/GHSA-jp99-g9qj-38pv/GHSA-jp99-g9qj-38pv.json index 3008b11e326..558ebb110b9 100644 --- a/advisories/unreviewed/2022/12/GHSA-jp99-g9qj-38pv/GHSA-jp99-g9qj-38pv.json +++ b/advisories/unreviewed/2022/12/GHSA-jp99-g9qj-38pv/GHSA-jp99-g9qj-38pv.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-306" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-mph7-2393-pmmf/GHSA-mph7-2393-pmmf.json b/advisories/unreviewed/2022/12/GHSA-mph7-2393-pmmf/GHSA-mph7-2393-pmmf.json index a5c7f8449b7..b0202e143c4 100644 --- a/advisories/unreviewed/2022/12/GHSA-mph7-2393-pmmf/GHSA-mph7-2393-pmmf.json +++ b/advisories/unreviewed/2022/12/GHSA-mph7-2393-pmmf/GHSA-mph7-2393-pmmf.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-119" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-rxvq-gr74-jvpj/GHSA-rxvq-gr74-jvpj.json b/advisories/unreviewed/2022/12/GHSA-rxvq-gr74-jvpj/GHSA-rxvq-gr74-jvpj.json index 877e18f76c6..577976e0f42 100644 --- a/advisories/unreviewed/2022/12/GHSA-rxvq-gr74-jvpj/GHSA-rxvq-gr74-jvpj.json +++ b/advisories/unreviewed/2022/12/GHSA-rxvq-gr74-jvpj/GHSA-rxvq-gr74-jvpj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rxvq-gr74-jvpj", - "modified": "2022-12-16T21:30:44Z", + "modified": "2025-04-22T18:31:59Z", "published": "2022-12-14T15:30:16Z", "aliases": [ "CVE-2022-31358" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-31358" }, + { + "type": "WEB", + "url": "https://git.proxmox.com/?p=pve-http-server.git%3Ba=commitdiff%3Bh=00661f1223b7c0afffa64e1d91f5e018b985f762" + }, { "type": "WEB", "url": "https://git.proxmox.com/?p=pve-http-server.git;a=commitdiff;h=00661f1223b7c0afffa64e1d91f5e018b985f762" diff --git a/advisories/unreviewed/2022/12/GHSA-vf24-whv8-r4jj/GHSA-vf24-whv8-r4jj.json b/advisories/unreviewed/2022/12/GHSA-vf24-whv8-r4jj/GHSA-vf24-whv8-r4jj.json index 5bde5578136..47101fbe67b 100644 --- a/advisories/unreviewed/2022/12/GHSA-vf24-whv8-r4jj/GHSA-vf24-whv8-r4jj.json +++ b/advisories/unreviewed/2022/12/GHSA-vf24-whv8-r4jj/GHSA-vf24-whv8-r4jj.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-287", "CWE-863" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/12/GHSA-vv25-wjrq-fcv6/GHSA-vv25-wjrq-fcv6.json b/advisories/unreviewed/2022/12/GHSA-vv25-wjrq-fcv6/GHSA-vv25-wjrq-fcv6.json index ecaf4c44bd2..7e2e9bd464b 100644 --- a/advisories/unreviewed/2022/12/GHSA-vv25-wjrq-fcv6/GHSA-vv25-wjrq-fcv6.json +++ b/advisories/unreviewed/2022/12/GHSA-vv25-wjrq-fcv6/GHSA-vv25-wjrq-fcv6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vv25-wjrq-fcv6", - "modified": "2022-12-19T18:30:25Z", + "modified": "2025-04-22T18:31:59Z", "published": "2022-12-14T21:30:17Z", "aliases": [ "CVE-2022-38488" diff --git a/advisories/unreviewed/2024/02/GHSA-3mgm-628r-4cx7/GHSA-3mgm-628r-4cx7.json b/advisories/unreviewed/2024/02/GHSA-3mgm-628r-4cx7/GHSA-3mgm-628r-4cx7.json index f3488df53c4..e847a4f785c 100644 --- a/advisories/unreviewed/2024/02/GHSA-3mgm-628r-4cx7/GHSA-3mgm-628r-4cx7.json +++ b/advisories/unreviewed/2024/02/GHSA-3mgm-628r-4cx7/GHSA-3mgm-628r-4cx7.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-3mgm-628r-4cx7", - "modified": "2024-02-29T15:32:25Z", + "modified": "2025-04-22T18:32:01Z", "published": "2024-02-29T06:30:32Z", "aliases": [ "CVE-2023-51696" ], - "details": "Cross-Site Request Forgery (CSRF) vulnerability in СleanTalk - Anti-Spam Protection Spam protection, Anti-Spam, FireWall by CleanTalk.This issue affects Spam protection, Anti-Spam, FireWall by CleanTalk: from n/a through 6.20.\n\n", + "details": "Cross-Site Request Forgery (CSRF) vulnerability in СleanTalk - Anti-Spam Protection Spam protection, Anti-Spam, FireWall by CleanTalk.This issue affects Spam protection, Anti-Spam, FireWall by CleanTalk: from n/a through 6.20.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/02/GHSA-8h6j-vxpr-4ff5/GHSA-8h6j-vxpr-4ff5.json b/advisories/unreviewed/2024/02/GHSA-8h6j-vxpr-4ff5/GHSA-8h6j-vxpr-4ff5.json index 6e4051936b2..c0f0c864d25 100644 --- a/advisories/unreviewed/2024/02/GHSA-8h6j-vxpr-4ff5/GHSA-8h6j-vxpr-4ff5.json +++ b/advisories/unreviewed/2024/02/GHSA-8h6j-vxpr-4ff5/GHSA-8h6j-vxpr-4ff5.json @@ -58,6 +58,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-400", "CWE-662" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/02/GHSA-w6v7-mjp2-pwcf/GHSA-w6v7-mjp2-pwcf.json b/advisories/unreviewed/2024/02/GHSA-w6v7-mjp2-pwcf/GHSA-w6v7-mjp2-pwcf.json index 744676864ab..8ab614cafb7 100644 --- a/advisories/unreviewed/2024/02/GHSA-w6v7-mjp2-pwcf/GHSA-w6v7-mjp2-pwcf.json +++ b/advisories/unreviewed/2024/02/GHSA-w6v7-mjp2-pwcf/GHSA-w6v7-mjp2-pwcf.json @@ -54,7 +54,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-416" + "CWE-416", + "CWE-476" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-286f-m35x-h7r5/GHSA-286f-m35x-h7r5.json b/advisories/unreviewed/2025/04/GHSA-286f-m35x-h7r5/GHSA-286f-m35x-h7r5.json new file mode 100644 index 00000000000..8738e43f721 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-286f-m35x-h7r5/GHSA-286f-m35x-h7r5.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-286f-m35x-h7r5", + "modified": "2025-04-22T18:32:12Z", + "published": "2025-04-22T18:32:12Z", + "aliases": [ + "CVE-2025-28029" + ], + "details": "TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a buffer overflow vulnerability in cstecgi.cgi", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28029" + }, + { + "type": "WEB", + "url": "https://locrian-lightning-dc7.notion.site/BufferOverflow5-1978e5e2b1a28043af78e5ccfc0203a0" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T18:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2m4j-5h27-9q77/GHSA-2m4j-5h27-9q77.json b/advisories/unreviewed/2025/04/GHSA-2m4j-5h27-9q77/GHSA-2m4j-5h27-9q77.json new file mode 100644 index 00000000000..c8a053a9cc2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2m4j-5h27-9q77/GHSA-2m4j-5h27-9q77.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2m4j-5h27-9q77", + "modified": "2025-04-22T18:32:12Z", + "published": "2025-04-22T18:32:12Z", + "aliases": [ + "CVE-2025-28027" + ], + "details": "TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 was found to contain a buffer overflow vulnerability in downloadFile.cgi.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28027" + }, + { + "type": "WEB", + "url": "https://locrian-lightning-dc7.notion.site/BufferOverflow2-19e8e5e2b1a2806db38bea19abb4630a?pvs=73" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T18:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4gmr-f766-822g/GHSA-4gmr-f766-822g.json b/advisories/unreviewed/2025/04/GHSA-4gmr-f766-822g/GHSA-4gmr-f766-822g.json new file mode 100644 index 00000000000..f97397251ad --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4gmr-f766-822g/GHSA-4gmr-f766-822g.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4gmr-f766-822g", + "modified": "2025-04-22T18:32:13Z", + "published": "2025-04-22T18:32:13Z", + "aliases": [ + "CVE-2025-43952" + ], + "details": "A cross-site scripting (reflected XSS) vulnerability was found in Mettler Toledo FreeWeight.Net Web Reports Viewer 8.4.0 (440). It allows an attacker to inject malicious scripts via the IW_SessionID_ parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43952" + }, + { + "type": "WEB", + "url": "https://github.com/Henkel-CyberVM/CVEs/tree/main/CVE-2025-43952" + }, + { + "type": "WEB", + "url": "https://www.mt.com/FreeWeighNet" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T18:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4gxx-54gw-qwch/GHSA-4gxx-54gw-qwch.json b/advisories/unreviewed/2025/04/GHSA-4gxx-54gw-qwch/GHSA-4gxx-54gw-qwch.json index 65a715f9d5a..2342fb77bdb 100644 --- a/advisories/unreviewed/2025/04/GHSA-4gxx-54gw-qwch/GHSA-4gxx-54gw-qwch.json +++ b/advisories/unreviewed/2025/04/GHSA-4gxx-54gw-qwch/GHSA-4gxx-54gw-qwch.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4gxx-54gw-qwch", - "modified": "2025-04-09T18:30:57Z", + "modified": "2025-04-22T18:32:09Z", "published": "2025-04-09T18:30:57Z", "aliases": [ "CVE-2025-3115" ], "details": "Injection Vulnerabilities: Attackers can inject malicious code, potentially gaining control over the system executing these functions.\nAdditionally, insufficient validation of filenames during file uploads can enable attackers to upload and execute malicious files, leading to arbitrary code execution", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2025/04/GHSA-4vvf-q5vq-fm6w/GHSA-4vvf-q5vq-fm6w.json b/advisories/unreviewed/2025/04/GHSA-4vvf-q5vq-fm6w/GHSA-4vvf-q5vq-fm6w.json new file mode 100644 index 00000000000..ad6d0a27908 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4vvf-q5vq-fm6w/GHSA-4vvf-q5vq-fm6w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4vvf-q5vq-fm6w", + "modified": "2025-04-22T18:32:11Z", + "published": "2025-04-22T18:32:11Z", + "aliases": [ + "CVE-2025-23251" + ], + "details": "NVIDIA NeMo Framework contains a vulnerability where a user could cause an improper control of generation of code by remote code execution. A successful exploit of this vulnerability might lead to code execution and data tampering.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23251" + }, + { + "type": "WEB", + "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5641" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T16:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-623j-76jx-rrxr/GHSA-623j-76jx-rrxr.json b/advisories/unreviewed/2025/04/GHSA-623j-76jx-rrxr/GHSA-623j-76jx-rrxr.json new file mode 100644 index 00000000000..7e31bf7222f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-623j-76jx-rrxr/GHSA-623j-76jx-rrxr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-623j-76jx-rrxr", + "modified": "2025-04-22T18:32:11Z", + "published": "2025-04-22T18:32:11Z", + "aliases": [ + "CVE-2025-23249" + ], + "details": "NVIDIA NeMo Framework contains a vulnerability where a user could cause a deserialization of untrusted data by remote code execution. A successful exploit of this vulnerability might lead to code execution and data tampering.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23249" + }, + { + "type": "WEB", + "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5641" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T16:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-68p2-2v8j-wr5h/GHSA-68p2-2v8j-wr5h.json b/advisories/unreviewed/2025/04/GHSA-68p2-2v8j-wr5h/GHSA-68p2-2v8j-wr5h.json index e1c45bd8b2d..a598551e434 100644 --- a/advisories/unreviewed/2025/04/GHSA-68p2-2v8j-wr5h/GHSA-68p2-2v8j-wr5h.json +++ b/advisories/unreviewed/2025/04/GHSA-68p2-2v8j-wr5h/GHSA-68p2-2v8j-wr5h.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-6pxq-w9rr-772v/GHSA-6pxq-w9rr-772v.json b/advisories/unreviewed/2025/04/GHSA-6pxq-w9rr-772v/GHSA-6pxq-w9rr-772v.json new file mode 100644 index 00000000000..d45322bb39b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6pxq-w9rr-772v/GHSA-6pxq-w9rr-772v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6pxq-w9rr-772v", + "modified": "2025-04-22T18:32:11Z", + "published": "2025-04-22T18:32:11Z", + "aliases": [ + "CVE-2025-27907" + ], + "details": "IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27907" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7231514" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T17:16:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6q9c-pjw5-5rjm/GHSA-6q9c-pjw5-5rjm.json b/advisories/unreviewed/2025/04/GHSA-6q9c-pjw5-5rjm/GHSA-6q9c-pjw5-5rjm.json new file mode 100644 index 00000000000..f547fd6ca32 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6q9c-pjw5-5rjm/GHSA-6q9c-pjw5-5rjm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6q9c-pjw5-5rjm", + "modified": "2025-04-22T18:32:12Z", + "published": "2025-04-22T18:32:12Z", + "aliases": [ + "CVE-2025-34028" + ], + "details": "A path traversal vulnerability in Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files, which, when expanded by the target server, result in Remote Code Execution.\n\n\n\n\n\nThis issue affects Command Center Innovation Release: 11.38.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-34028" + }, + { + "type": "WEB", + "url": "https://documentation.commvault.com/securityadvisories/CV_2025_04_1.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T17:16:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-743m-763q-grgv/GHSA-743m-763q-grgv.json b/advisories/unreviewed/2025/04/GHSA-743m-763q-grgv/GHSA-743m-763q-grgv.json new file mode 100644 index 00000000000..8492dfff03c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-743m-763q-grgv/GHSA-743m-763q-grgv.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-743m-763q-grgv", + "modified": "2025-04-22T18:32:13Z", + "published": "2025-04-22T18:32:13Z", + "aliases": [ + "CVE-2025-43951" + ], + "details": "LabVantage before LV 8.8.0.13 HF6 allows local file inclusion. Authenticated users can retrieve arbitrary files from the environment via the objectname request parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43951" + }, + { + "type": "WEB", + "url": "https://github.com/Henkel-CyberVM/CVEs/tree/main/CVE-2025-43951" + }, + { + "type": "WEB", + "url": "https://www.labvantage.com/informatics/lims" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T18:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7gr5-w4q5-hvw3/GHSA-7gr5-w4q5-hvw3.json b/advisories/unreviewed/2025/04/GHSA-7gr5-w4q5-hvw3/GHSA-7gr5-w4q5-hvw3.json new file mode 100644 index 00000000000..e54613efaee --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7gr5-w4q5-hvw3/GHSA-7gr5-w4q5-hvw3.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7gr5-w4q5-hvw3", + "modified": "2025-04-22T18:32:12Z", + "published": "2025-04-22T18:32:12Z", + "aliases": [ + "CVE-2023-44753" + ], + "details": "A stored cross-site scripting (XSS) vulnerability fin Student Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email parameter on the profile.php page.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-44753" + }, + { + "type": "WEB", + "url": "https://flashy-lemonade-192.notion.site/Multiple-Cross-site-scripting-in-Edu-Authorities-Student-Management-System-f55752a1027f43eb91a5a489785e6d45" + }, + { + "type": "WEB", + "url": "https://flashy-lemonade-192.notion.site/Multiple-Cross-site-scripting-in-Edu-Authorities-Student-Management-System-f55752a1027f43eb91a5a489785e6d45?pvs=4" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T18:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-869x-7923-5x6q/GHSA-869x-7923-5x6q.json b/advisories/unreviewed/2025/04/GHSA-869x-7923-5x6q/GHSA-869x-7923-5x6q.json new file mode 100644 index 00000000000..ef7afccab3f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-869x-7923-5x6q/GHSA-869x-7923-5x6q.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-869x-7923-5x6q", + "modified": "2025-04-22T18:32:13Z", + "published": "2025-04-22T18:32:13Z", + "aliases": [ + "CVE-2025-43946" + ], + "details": "TCPWave DDI 11.34P1C2 allows Remote Code Execution via Unrestricted File Upload (combined with Path Traversal).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43946" + }, + { + "type": "WEB", + "url": "https://github.com/Henkel-CyberVM/CVEs/tree/main/CVE-2025-43946" + }, + { + "type": "WEB", + "url": "https://tcpwave.com/ddi-dns-dhcp-ipam" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T18:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-92w5-fx6f-j3pw/GHSA-92w5-fx6f-j3pw.json b/advisories/unreviewed/2025/04/GHSA-92w5-fx6f-j3pw/GHSA-92w5-fx6f-j3pw.json new file mode 100644 index 00000000000..a88321736df --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-92w5-fx6f-j3pw/GHSA-92w5-fx6f-j3pw.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-92w5-fx6f-j3pw", + "modified": "2025-04-22T18:32:13Z", + "published": "2025-04-22T18:32:13Z", + "aliases": [ + "CVE-2025-43949" + ], + "details": "MuM (aka Mensch und Maschine) MapEdit (aka mapedit-web) 24.2.3 is vulnerable to SQL Injection that allows an attacker to execute malicious SQL statements that control a web application's database server.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43949" + }, + { + "type": "WEB", + "url": "https://github.com/Henkel-CyberVM/CVEs/tree/main/CVE-2025-43949" + }, + { + "type": "WEB", + "url": "https://www.mum.de/produkte/mum-mapedit" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T18:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9cjm-fv5h-54p6/GHSA-9cjm-fv5h-54p6.json b/advisories/unreviewed/2025/04/GHSA-9cjm-fv5h-54p6/GHSA-9cjm-fv5h-54p6.json index 26fb42c3b45..3703c7918d4 100644 --- a/advisories/unreviewed/2025/04/GHSA-9cjm-fv5h-54p6/GHSA-9cjm-fv5h-54p6.json +++ b/advisories/unreviewed/2025/04/GHSA-9cjm-fv5h-54p6/GHSA-9cjm-fv5h-54p6.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-c846-2c33-mpmm/GHSA-c846-2c33-mpmm.json b/advisories/unreviewed/2025/04/GHSA-c846-2c33-mpmm/GHSA-c846-2c33-mpmm.json index 9124fd9f013..6aa4b451a64 100644 --- a/advisories/unreviewed/2025/04/GHSA-c846-2c33-mpmm/GHSA-c846-2c33-mpmm.json +++ b/advisories/unreviewed/2025/04/GHSA-c846-2c33-mpmm/GHSA-c846-2c33-mpmm.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-cm5r-mjj2-pxp4/GHSA-cm5r-mjj2-pxp4.json b/advisories/unreviewed/2025/04/GHSA-cm5r-mjj2-pxp4/GHSA-cm5r-mjj2-pxp4.json new file mode 100644 index 00000000000..0492a75551c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cm5r-mjj2-pxp4/GHSA-cm5r-mjj2-pxp4.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cm5r-mjj2-pxp4", + "modified": "2025-04-22T18:32:12Z", + "published": "2025-04-22T18:32:12Z", + "aliases": [ + "CVE-2025-28036" + ], + "details": "TOTOLINK A950RG V4.1.2cu.5161_B20200903 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28036" + }, + { + "type": "WEB", + "url": "https://locrian-lightning-dc7.notion.site/RCE1-1a98e5e2b1a28081880dd817104b3af4" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T18:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cqc2-rc24-647j/GHSA-cqc2-rc24-647j.json b/advisories/unreviewed/2025/04/GHSA-cqc2-rc24-647j/GHSA-cqc2-rc24-647j.json index 0ce0f809aae..cbf8f896278 100644 --- a/advisories/unreviewed/2025/04/GHSA-cqc2-rc24-647j/GHSA-cqc2-rc24-647j.json +++ b/advisories/unreviewed/2025/04/GHSA-cqc2-rc24-647j/GHSA-cqc2-rc24-647j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cqc2-rc24-647j", - "modified": "2025-04-17T18:31:23Z", + "modified": "2025-04-22T18:32:10Z", "published": "2025-04-17T18:31:23Z", "aliases": [ "CVE-2025-26269" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://github.com/dragonflydb/dragonfly/commit/4612aec9a78e3f604e6fb19bee51acde89723308" + }, + { + "type": "WEB", + "url": "https://gist.github.com/ankki-zsyang/d8215cf6e868d07546eaa5346a884ebd" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/04/GHSA-fg9r-f95c-6rgw/GHSA-fg9r-f95c-6rgw.json b/advisories/unreviewed/2025/04/GHSA-fg9r-f95c-6rgw/GHSA-fg9r-f95c-6rgw.json new file mode 100644 index 00000000000..b97134a8aca --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fg9r-f95c-6rgw/GHSA-fg9r-f95c-6rgw.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fg9r-f95c-6rgw", + "modified": "2025-04-22T18:32:12Z", + "published": "2025-04-22T18:32:12Z", + "aliases": [ + "CVE-2025-28035" + ], + "details": "TOTOLINK A830R V4.1.2cu.5182_B20201102 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28035" + }, + { + "type": "WEB", + "url": "https://locrian-lightning-dc7.notion.site/RCE1-1a98e5e2b1a28081880dd817104b3af4?pvs=73" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T18:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fjxj-774q-fh4q/GHSA-fjxj-774q-fh4q.json b/advisories/unreviewed/2025/04/GHSA-fjxj-774q-fh4q/GHSA-fjxj-774q-fh4q.json new file mode 100644 index 00000000000..5e50014f7bc --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fjxj-774q-fh4q/GHSA-fjxj-774q-fh4q.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fjxj-774q-fh4q", + "modified": "2025-04-22T18:32:12Z", + "published": "2025-04-22T18:32:12Z", + "aliases": [ + "CVE-2023-44755" + ], + "details": "Sacco Management system v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /sacco/ajax.php.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-44755" + }, + { + "type": "WEB", + "url": "https://flashy-lemonade-192.notion.site/SQL-injection-in-Sacco-Management-system-via-password-and-id-parameter-1d85fc432de24db896446002f91acfd1" + }, + { + "type": "WEB", + "url": "https://flashy-lemonade-192.notion.site/SQL-injection-in-Sacco-Management-system-via-password-and-id-parameter-1d85fc432de24db896446002f91acfd1?pvs=4" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T18:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gg8q-wm6m-x7w3/GHSA-gg8q-wm6m-x7w3.json b/advisories/unreviewed/2025/04/GHSA-gg8q-wm6m-x7w3/GHSA-gg8q-wm6m-x7w3.json new file mode 100644 index 00000000000..09b0cdb4ed7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gg8q-wm6m-x7w3/GHSA-gg8q-wm6m-x7w3.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gg8q-wm6m-x7w3", + "modified": "2025-04-22T18:32:12Z", + "published": "2025-04-22T18:32:12Z", + "aliases": [ + "CVE-2025-28026" + ], + "details": "TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a buffer overflow vulnerability in downloadFile.cgi.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28026" + }, + { + "type": "WEB", + "url": "https://locrian-lightning-dc7.notion.site/BufferOverflow3-19e8e5e2b1a28048b8ddd4afdbe18d55" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T18:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gxj5-h4j6-fmfx/GHSA-gxj5-h4j6-fmfx.json b/advisories/unreviewed/2025/04/GHSA-gxj5-h4j6-fmfx/GHSA-gxj5-h4j6-fmfx.json new file mode 100644 index 00000000000..addd95115ec --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gxj5-h4j6-fmfx/GHSA-gxj5-h4j6-fmfx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gxj5-h4j6-fmfx", + "modified": "2025-04-22T18:32:11Z", + "published": "2025-04-22T18:32:11Z", + "aliases": [ + "CVE-2025-23250" + ], + "details": "NVIDIA NeMo Framework contains a vulnerability where an attacker could cause an improper limitation of a pathname to a restricted directory by an arbitrary file write. A successful exploit of this vulnerability might lead to code execution and data tampering.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23250" + }, + { + "type": "WEB", + "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5641" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T16:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h65q-2g3v-qm4r/GHSA-h65q-2g3v-qm4r.json b/advisories/unreviewed/2025/04/GHSA-h65q-2g3v-qm4r/GHSA-h65q-2g3v-qm4r.json new file mode 100644 index 00000000000..cc80b6653e3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-h65q-2g3v-qm4r/GHSA-h65q-2g3v-qm4r.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h65q-2g3v-qm4r", + "modified": "2025-04-22T18:32:12Z", + "published": "2025-04-22T18:32:12Z", + "aliases": [ + "CVE-2023-43958" + ], + "details": "An arbitrary file upload vulnerability in the component /jquery-file-upload/server/php/index.php of Hospital Management System v4.0 allows an unauthenticated attacker to upload any file to the server and execute arbitrary code.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43958" + }, + { + "type": "WEB", + "url": "https://flashy-lemonade-192.notion.site/Unauthenticated-arbitrary-file-upload-via-jQuery-File-Upload-in-Hospital-Management-System-3c02c1e8ef65432686321fcbad78bb1e" + }, + { + "type": "WEB", + "url": "https://flashy-lemonade-192.notion.site/Unauthenticated-arbitrary-file-upload-via-jQuery-File-Upload-in-Hospital-Management-System-3c02c1e8ef65432686321fcbad78bb1e?pvs=4" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T18:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m9hc-8hvg-f4hc/GHSA-m9hc-8hvg-f4hc.json b/advisories/unreviewed/2025/04/GHSA-m9hc-8hvg-f4hc/GHSA-m9hc-8hvg-f4hc.json new file mode 100644 index 00000000000..0e0ebcc2ac5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m9hc-8hvg-f4hc/GHSA-m9hc-8hvg-f4hc.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m9hc-8hvg-f4hc", + "modified": "2025-04-22T18:32:11Z", + "published": "2025-04-22T18:32:11Z", + "aliases": [ + "CVE-2025-28031" + ], + "details": "TOTOLINK A810R V4.1.2cu.5182_B20201026 was discovered to contain a hardcoded password for the telnet service in product.ini.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28031" + }, + { + "type": "WEB", + "url": "https://locrian-lightning-dc7.notion.site/Hard-code-Password-19f8e5e2b1a2803f864afbbc4262152e?pvs=73" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T16:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pv6x-3vgc-wphq/GHSA-pv6x-3vgc-wphq.json b/advisories/unreviewed/2025/04/GHSA-pv6x-3vgc-wphq/GHSA-pv6x-3vgc-wphq.json new file mode 100644 index 00000000000..900b866b700 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pv6x-3vgc-wphq/GHSA-pv6x-3vgc-wphq.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pv6x-3vgc-wphq", + "modified": "2025-04-22T18:32:13Z", + "published": "2025-04-22T18:32:13Z", + "aliases": [ + "CVE-2025-43947" + ], + "details": "Codemers KLIMS 1.6.DEV lacks a proper access control mechanism, allowing a normal KLIMS user to perform all the actions that an admin can perform, such as modifying the configuration, creating a user, uploading files, etc.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43947" + }, + { + "type": "WEB", + "url": "https://de.linkedin.com/company/codemers" + }, + { + "type": "WEB", + "url": "https://github.com/Henkel-CyberVM/CVEs/tree/main/CVE-2025-43947" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T18:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-q6v5-58gv-cxgm/GHSA-q6v5-58gv-cxgm.json b/advisories/unreviewed/2025/04/GHSA-q6v5-58gv-cxgm/GHSA-q6v5-58gv-cxgm.json new file mode 100644 index 00000000000..f563bbb9ee3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-q6v5-58gv-cxgm/GHSA-q6v5-58gv-cxgm.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q6v5-58gv-cxgm", + "modified": "2025-04-22T18:32:13Z", + "published": "2025-04-22T18:32:13Z", + "aliases": [ + "CVE-2025-43948" + ], + "details": "Codemers KLIMS 1.6.DEV allows Python code injection. A user can provide Python code as an input value for a parameter or qualifier (such as for sorting), which will get executed on the server side.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43948" + }, + { + "type": "WEB", + "url": "https://de.linkedin.com/company/codemers" + }, + { + "type": "WEB", + "url": "https://github.com/Henkel-CyberVM/CVEs/tree/main/CVE-2025-43948" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T18:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qgc3-2f6v-85jf/GHSA-qgc3-2f6v-85jf.json b/advisories/unreviewed/2025/04/GHSA-qgc3-2f6v-85jf/GHSA-qgc3-2f6v-85jf.json index 3a3a30a45e8..ec8d7a96a85 100644 --- a/advisories/unreviewed/2025/04/GHSA-qgc3-2f6v-85jf/GHSA-qgc3-2f6v-85jf.json +++ b/advisories/unreviewed/2025/04/GHSA-qgc3-2f6v-85jf/GHSA-qgc3-2f6v-85jf.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-qm42-2jf7-gc6x/GHSA-qm42-2jf7-gc6x.json b/advisories/unreviewed/2025/04/GHSA-qm42-2jf7-gc6x/GHSA-qm42-2jf7-gc6x.json new file mode 100644 index 00000000000..2cadb9e662c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qm42-2jf7-gc6x/GHSA-qm42-2jf7-gc6x.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qm42-2jf7-gc6x", + "modified": "2025-04-22T18:32:11Z", + "published": "2025-04-22T18:32:11Z", + "aliases": [ + "CVE-2024-33452" + ], + "details": "An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling via a crafted HEAD request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33452" + }, + { + "type": "WEB", + "url": "https://portswigger.net/research/http-desync-attacks-request-smuggling-reborn" + }, + { + "type": "WEB", + "url": "https://www.benasin.space/2025/03/18/OpenResty-lua-nginx-module-v0-10-26-HTTP-Request-Smuggling-in-HEAD-requests" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T16:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qrqw-4g4q-63h8/GHSA-qrqw-4g4q-63h8.json b/advisories/unreviewed/2025/04/GHSA-qrqw-4g4q-63h8/GHSA-qrqw-4g4q-63h8.json new file mode 100644 index 00000000000..be9fb1e0e11 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qrqw-4g4q-63h8/GHSA-qrqw-4g4q-63h8.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qrqw-4g4q-63h8", + "modified": "2025-04-22T18:32:12Z", + "published": "2025-04-22T18:32:12Z", + "aliases": [ + "CVE-2023-43378" + ], + "details": "A cross-site scripting (XSS) vulnerability in Hoteldruid v3.0.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the commento1_1 parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43378" + }, + { + "type": "WEB", + "url": "https://flashy-lemonade-192.notion.site/Cross-site-scripting-in-hoteldruid-version-3-0-5-via-commento1_1-post-parameter-44ff18cb61cd4a80bbba75d5e4360ee4" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T18:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-r24q-j79w-9jww/GHSA-r24q-j79w-9jww.json b/advisories/unreviewed/2025/04/GHSA-r24q-j79w-9jww/GHSA-r24q-j79w-9jww.json new file mode 100644 index 00000000000..998b56469b6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-r24q-j79w-9jww/GHSA-r24q-j79w-9jww.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r24q-j79w-9jww", + "modified": "2025-04-22T18:32:13Z", + "published": "2025-04-22T18:32:13Z", + "aliases": [ + "CVE-2025-43950" + ], + "details": "DPMAdirektPro 4.1.5 is vulnerable to DLL Hijacking. It happens by placing a malicious DLL in a directory (in the absence of a legitimate DLL), which is then loaded by the application instead of the legitimate DLL. This causes the malicious DLL to load with the same privileges as the application, thus causing a privilege escalation.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43950" + }, + { + "type": "WEB", + "url": "https://github.com/Henkel-CyberVM/CVEs/tree/main/CVE-2025-43950" + }, + { + "type": "WEB", + "url": "https://www.dpma.de/english/services/efiling/dpmadirekt/downloads/index.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T18:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rgcr-wg7p-29p2/GHSA-rgcr-wg7p-29p2.json b/advisories/unreviewed/2025/04/GHSA-rgcr-wg7p-29p2/GHSA-rgcr-wg7p-29p2.json new file mode 100644 index 00000000000..bcdfe620213 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rgcr-wg7p-29p2/GHSA-rgcr-wg7p-29p2.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rgcr-wg7p-29p2", + "modified": "2025-04-22T18:32:11Z", + "published": "2025-04-22T18:32:11Z", + "aliases": [ + "CVE-2025-28030" + ], + "details": "TOTOLINK A810R V4.1.2cu.5182_B20201026 was discovered to contain a stack overflow via the startTime and endTime parameters in setParentalRules function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28030" + }, + { + "type": "WEB", + "url": "https://locrian-lightning-dc7.notion.site/BufferOverflow6-19f8e5e2b1a2803db1d9ce7b4d06e2e0?pvs=73" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T16:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rpcc-c8w6-wwj6/GHSA-rpcc-c8w6-wwj6.json b/advisories/unreviewed/2025/04/GHSA-rpcc-c8w6-wwj6/GHSA-rpcc-c8w6-wwj6.json new file mode 100644 index 00000000000..c004d751899 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rpcc-c8w6-wwj6/GHSA-rpcc-c8w6-wwj6.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rpcc-c8w6-wwj6", + "modified": "2025-04-22T18:32:12Z", + "published": "2025-04-22T18:32:12Z", + "aliases": [ + "CVE-2023-44752" + ], + "details": "An issue in Student Study Center Desk Management System v1.0 allows attackers to bypass authentication via a crafted GET request to /php-sscdms/admin/login.php.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-44752" + }, + { + "type": "WEB", + "url": "https://flashy-lemonade-192.notion.site/Login-Bypass-in-Student-Study-Center-Desk-Management-System-v1-0-fe410cff4fc3441ea4c5aa663225e445" + }, + { + "type": "WEB", + "url": "https://flashy-lemonade-192.notion.site/Login-Bypass-in-Student-Study-Center-Desk-Management-System-v1-0-fe410cff4fc3441ea4c5aa663225e445?pvs=4" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T18:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-v7m9-pm9f-frqg/GHSA-v7m9-pm9f-frqg.json b/advisories/unreviewed/2025/04/GHSA-v7m9-pm9f-frqg/GHSA-v7m9-pm9f-frqg.json new file mode 100644 index 00000000000..0b15bdcd8d5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v7m9-pm9f-frqg/GHSA-v7m9-pm9f-frqg.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v7m9-pm9f-frqg", + "modified": "2025-04-22T18:32:11Z", + "published": "2025-04-22T18:32:11Z", + "aliases": [ + "CVE-2025-29339" + ], + "details": "An issue in UPF in Open5GS UPF versions up to v2.7.2 results an assertion failure vulnerability in PFCP session parameter validation. When processing a PFCP Session Establishment Request with PDN Type=0, the UPF fails to handle the invalid value propagated from SMF (or via direct attack), triggering a fatal assertion check and causing a daemon crash.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29339" + }, + { + "type": "WEB", + "url": "https://github.com/open5gs/open5gs/issues/3727" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T17:16:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vg6j-x3v7-mwq9/GHSA-vg6j-x3v7-mwq9.json b/advisories/unreviewed/2025/04/GHSA-vg6j-x3v7-mwq9/GHSA-vg6j-x3v7-mwq9.json index e8822a41e8f..4143dcd50a4 100644 --- a/advisories/unreviewed/2025/04/GHSA-vg6j-x3v7-mwq9/GHSA-vg6j-x3v7-mwq9.json +++ b/advisories/unreviewed/2025/04/GHSA-vg6j-x3v7-mwq9/GHSA-vg6j-x3v7-mwq9.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-829", "CWE-830" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/04/GHSA-vwgx-54x2-gc6m/GHSA-vwgx-54x2-gc6m.json b/advisories/unreviewed/2025/04/GHSA-vwgx-54x2-gc6m/GHSA-vwgx-54x2-gc6m.json new file mode 100644 index 00000000000..a41fb54e621 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vwgx-54x2-gc6m/GHSA-vwgx-54x2-gc6m.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vwgx-54x2-gc6m", + "modified": "2025-04-22T18:32:11Z", + "published": "2025-04-22T18:32:11Z", + "aliases": [ + "CVE-2025-28024" + ], + "details": "TOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in the cstecgi.cgi", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28024" + }, + { + "type": "WEB", + "url": "https://locrian-lightning-dc7.notion.site/BufferOverflow5-1978e5e2b1a2800caaced7ae3fb4783c" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T16:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-x7cp-g8mq-6p3p/GHSA-x7cp-g8mq-6p3p.json b/advisories/unreviewed/2025/04/GHSA-x7cp-g8mq-6p3p/GHSA-x7cp-g8mq-6p3p.json new file mode 100644 index 00000000000..fdcde1f67d2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-x7cp-g8mq-6p3p/GHSA-x7cp-g8mq-6p3p.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x7cp-g8mq-6p3p", + "modified": "2025-04-22T18:32:11Z", + "published": "2025-04-22T18:32:11Z", + "aliases": [ + "CVE-2025-28037" + ], + "details": "TOTOLINK A810R V4.1.2cu.5182_B20201026 and A950RG V4.1.2cu.5161_B20200903 were found to contain a pre-auth remote command execution vulnerability in the setDiagnosisCfg function through the ipDomain parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28037" + }, + { + "type": "WEB", + "url": "https://locrian-lightning-dc7.notion.site/RCE3-1ad8e5e2b1a280e192e8cff9fef896cc" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T16:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xmr8-xw2g-rqh3/GHSA-xmr8-xw2g-rqh3.json b/advisories/unreviewed/2025/04/GHSA-xmr8-xw2g-rqh3/GHSA-xmr8-xw2g-rqh3.json new file mode 100644 index 00000000000..665125ed793 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xmr8-xw2g-rqh3/GHSA-xmr8-xw2g-rqh3.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xmr8-xw2g-rqh3", + "modified": "2025-04-22T18:32:11Z", + "published": "2025-04-22T18:32:11Z", + "aliases": [ + "CVE-2025-3767" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon BAM (Boolean KPi Listing modules) allows SQL Injection.\n\n\nThis page is only accessible to authenticated users with high privileges.\n\nThis issue affects Centreon BAM: from 24.10 before 24.10.1, from 24.04 before 24.04.5, from 23.10 before 23.10.10, from 23.04 before 23.04.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3767" + }, + { + "type": "WEB", + "url": "https://github.com/centreon/centreon/releases" + }, + { + "type": "WEB", + "url": "https://thewatch.centreon.com/latest-security-bulletins-64/cve-2024-46924-cve-2025-3767-centreon-bam-high-severity-4459" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T16:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xpqm-g5q7-2r7x/GHSA-xpqm-g5q7-2r7x.json b/advisories/unreviewed/2025/04/GHSA-xpqm-g5q7-2r7x/GHSA-xpqm-g5q7-2r7x.json new file mode 100644 index 00000000000..258b065b0f7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xpqm-g5q7-2r7x/GHSA-xpqm-g5q7-2r7x.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xpqm-g5q7-2r7x", + "modified": "2025-04-22T18:32:12Z", + "published": "2025-04-22T18:32:12Z", + "aliases": [ + "CVE-2025-28038" + ], + "details": "TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setWebWlanIdx function through the webWlanIdx parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28038" + }, + { + "type": "WEB", + "url": "https://locrian-lightning-dc7.notion.site/RCE1-1ad8e5e2b1a28030a1c8febac89935a0" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T18:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xv7x-v825-68c4/GHSA-xv7x-v825-68c4.json b/advisories/unreviewed/2025/04/GHSA-xv7x-v825-68c4/GHSA-xv7x-v825-68c4.json new file mode 100644 index 00000000000..14ccffd019e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xv7x-v825-68c4/GHSA-xv7x-v825-68c4.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xv7x-v825-68c4", + "modified": "2025-04-22T18:32:12Z", + "published": "2025-04-22T18:32:12Z", + "aliases": [ + "CVE-2025-28039" + ], + "details": "TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setUpgradeFW function through the FileName parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28039" + }, + { + "type": "WEB", + "url": "https://locrian-lightning-dc7.notion.site/RCE2-1ad8e5e2b1a280fbb0cacc7e758e7299" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T18:15:59Z" + } +} \ No newline at end of file