diff --git a/advisories/unreviewed/2022/10/GHSA-73xq-c68f-h599/GHSA-73xq-c68f-h599.json b/advisories/unreviewed/2022/10/GHSA-73xq-c68f-h599/GHSA-73xq-c68f-h599.json index 0bdc75a3c5f..f1330eab5fa 100644 --- a/advisories/unreviewed/2022/10/GHSA-73xq-c68f-h599/GHSA-73xq-c68f-h599.json +++ b/advisories/unreviewed/2022/10/GHSA-73xq-c68f-h599/GHSA-73xq-c68f-h599.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-73xq-c68f-h599", - "modified": "2022-10-28T12:00:34Z", + "modified": "2025-05-09T18:30:35Z", "published": "2022-10-26T12:00:30Z", "aliases": [ "CVE-2022-28170" diff --git a/advisories/unreviewed/2022/10/GHSA-c4gp-696g-43xv/GHSA-c4gp-696g-43xv.json b/advisories/unreviewed/2022/10/GHSA-c4gp-696g-43xv/GHSA-c4gp-696g-43xv.json index 0d6e2de81bc..0468ad3f342 100644 --- a/advisories/unreviewed/2022/10/GHSA-c4gp-696g-43xv/GHSA-c4gp-696g-43xv.json +++ b/advisories/unreviewed/2022/10/GHSA-c4gp-696g-43xv/GHSA-c4gp-696g-43xv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c4gp-696g-43xv", - "modified": "2022-10-28T19:00:42Z", + "modified": "2025-05-09T18:30:35Z", "published": "2022-10-26T12:00:30Z", "aliases": [ "CVE-2022-28169" diff --git a/advisories/unreviewed/2024/01/GHSA-8mgx-wgjw-q32g/GHSA-8mgx-wgjw-q32g.json b/advisories/unreviewed/2024/01/GHSA-8mgx-wgjw-q32g/GHSA-8mgx-wgjw-q32g.json index 6edfb483c3c..93f142c6d47 100644 --- a/advisories/unreviewed/2024/01/GHSA-8mgx-wgjw-q32g/GHSA-8mgx-wgjw-q32g.json +++ b/advisories/unreviewed/2024/01/GHSA-8mgx-wgjw-q32g/GHSA-8mgx-wgjw-q32g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8mgx-wgjw-q32g", - "modified": "2024-01-23T18:31:11Z", + "modified": "2025-05-09T18:30:35Z", "published": "2024-01-16T18:31:10Z", "aliases": [ "CVE-2024-0239" diff --git a/advisories/unreviewed/2024/01/GHSA-h9pp-v4f3-fp7x/GHSA-h9pp-v4f3-fp7x.json b/advisories/unreviewed/2024/01/GHSA-h9pp-v4f3-fp7x/GHSA-h9pp-v4f3-fp7x.json index 279265a2f27..398808157f4 100644 --- a/advisories/unreviewed/2024/01/GHSA-h9pp-v4f3-fp7x/GHSA-h9pp-v4f3-fp7x.json +++ b/advisories/unreviewed/2024/01/GHSA-h9pp-v4f3-fp7x/GHSA-h9pp-v4f3-fp7x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h9pp-v4f3-fp7x", - "modified": "2024-01-23T21:30:20Z", + "modified": "2025-05-09T18:30:35Z", "published": "2024-01-16T18:31:09Z", "aliases": [ "CVE-2022-23179" diff --git a/advisories/unreviewed/2024/04/GHSA-gvqq-xg2j-r2p6/GHSA-gvqq-xg2j-r2p6.json b/advisories/unreviewed/2024/04/GHSA-gvqq-xg2j-r2p6/GHSA-gvqq-xg2j-r2p6.json index 646017ab0dd..399850cd99d 100644 --- a/advisories/unreviewed/2024/04/GHSA-gvqq-xg2j-r2p6/GHSA-gvqq-xg2j-r2p6.json +++ b/advisories/unreviewed/2024/04/GHSA-gvqq-xg2j-r2p6/GHSA-gvqq-xg2j-r2p6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gvqq-xg2j-r2p6", - "modified": "2024-04-17T00:30:57Z", + "modified": "2025-05-09T18:30:36Z", "published": "2024-04-17T00:30:57Z", "aliases": [ "CVE-2024-21111" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21111" }, + { + "type": "WEB", + "url": "https://www.exploit-db.com/exploits/52287" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2024.html" diff --git a/advisories/unreviewed/2024/05/GHSA-p5j5-mxj7-f5fg/GHSA-p5j5-mxj7-f5fg.json b/advisories/unreviewed/2024/05/GHSA-p5j5-mxj7-f5fg/GHSA-p5j5-mxj7-f5fg.json index 86e3875a03d..2671b56e3dc 100644 --- a/advisories/unreviewed/2024/05/GHSA-p5j5-mxj7-f5fg/GHSA-p5j5-mxj7-f5fg.json +++ b/advisories/unreviewed/2024/05/GHSA-p5j5-mxj7-f5fg/GHSA-p5j5-mxj7-f5fg.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/08/GHSA-82w9-g9wm-675r/GHSA-82w9-g9wm-675r.json b/advisories/unreviewed/2024/08/GHSA-82w9-g9wm-675r/GHSA-82w9-g9wm-675r.json index b08e26b47cd..19835322935 100644 --- a/advisories/unreviewed/2024/08/GHSA-82w9-g9wm-675r/GHSA-82w9-g9wm-675r.json +++ b/advisories/unreviewed/2024/08/GHSA-82w9-g9wm-675r/GHSA-82w9-g9wm-675r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-82w9-g9wm-675r", - "modified": "2024-08-13T18:31:17Z", + "modified": "2025-05-09T18:30:36Z", "published": "2024-08-13T18:31:17Z", "aliases": [ "CVE-2024-38193" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38193" + }, + { + "type": "WEB", + "url": "https://www.exploit-db.com/exploits/52284" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/05/GHSA-3m4v-8v7m-fjqh/GHSA-3m4v-8v7m-fjqh.json b/advisories/unreviewed/2025/05/GHSA-3m4v-8v7m-fjqh/GHSA-3m4v-8v7m-fjqh.json new file mode 100644 index 00000000000..0edc5bebeea --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3m4v-8v7m-fjqh/GHSA-3m4v-8v7m-fjqh.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3m4v-8v7m-fjqh", + "modified": "2025-05-09T18:30:37Z", + "published": "2025-05-09T18:30:37Z", + "aliases": [ + "CVE-2025-28203" + ], + "details": "Victure RX1800 EN_V1.0.0_r12_110933 was discovered to contain a command injection vulnerability.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28203" + }, + { + "type": "WEB", + "url": "https://pwnit.io/2025/02/13/finding-vulnerabilities-in-wi-fi-router" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-09T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3qjj-xgvq-44qh/GHSA-3qjj-xgvq-44qh.json b/advisories/unreviewed/2025/05/GHSA-3qjj-xgvq-44qh/GHSA-3qjj-xgvq-44qh.json index ee6af796df8..e64b4e6a298 100644 --- a/advisories/unreviewed/2025/05/GHSA-3qjj-xgvq-44qh/GHSA-3qjj-xgvq-44qh.json +++ b/advisories/unreviewed/2025/05/GHSA-3qjj-xgvq-44qh/GHSA-3qjj-xgvq-44qh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3qjj-xgvq-44qh", - "modified": "2025-05-06T15:31:00Z", + "modified": "2025-05-09T18:30:36Z", "published": "2025-05-02T09:30:35Z", "aliases": [ "CVE-2024-13860" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://www.buddyboss.com/platform" }, + { + "type": "WEB", + "url": "https://www.buddyboss.com/resources/buddyboss-platform-releases/2-8-51" + }, { "type": "WEB", "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a0ac8a41-553e-473b-82a7-226de17e472d?source=cve" diff --git a/advisories/unreviewed/2025/05/GHSA-3qvh-wj74-grpw/GHSA-3qvh-wj74-grpw.json b/advisories/unreviewed/2025/05/GHSA-3qvh-wj74-grpw/GHSA-3qvh-wj74-grpw.json new file mode 100644 index 00000000000..9f6abb82ae6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3qvh-wj74-grpw/GHSA-3qvh-wj74-grpw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qvh-wj74-grpw", + "modified": "2025-05-09T18:30:36Z", + "published": "2025-05-09T18:30:36Z", + "aliases": [ + "CVE-2024-13759" + ], + "details": "Local Privilege Escalation in Avira.Spotlight.Service.exe in Avira Prime 1.1.96.2 on Windows 10 x64  allows local attackers to gain system-level privileges via arbitrary file deletion", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13759" + }, + { + "type": "WEB", + "url": "https://www.gendigital.com/us/en/contact-us/security-advisories/)" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-09T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3vr2-w427-fcqp/GHSA-3vr2-w427-fcqp.json b/advisories/unreviewed/2025/05/GHSA-3vr2-w427-fcqp/GHSA-3vr2-w427-fcqp.json new file mode 100644 index 00000000000..fe78e2a4235 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3vr2-w427-fcqp/GHSA-3vr2-w427-fcqp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3vr2-w427-fcqp", + "modified": "2025-05-09T18:30:36Z", + "published": "2025-05-09T18:30:36Z", + "aliases": [ + "CVE-2024-13959" + ], + "details": "Link Following Local Privilege Escalation Vulnerability in TuneupSvc.exe in AVG TuneUp 24.2.16593.9844 on Windows allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via creating a symbolic link and leveraging the service to delete a directory", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13959" + }, + { + "type": "WEB", + "url": "https://www.gendigital.com/us/en/contact-us/security-advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-09T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4hrx-7c6v-v9v5/GHSA-4hrx-7c6v-v9v5.json b/advisories/unreviewed/2025/05/GHSA-4hrx-7c6v-v9v5/GHSA-4hrx-7c6v-v9v5.json new file mode 100644 index 00000000000..4cf1c23f5a7 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4hrx-7c6v-v9v5/GHSA-4hrx-7c6v-v9v5.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4hrx-7c6v-v9v5", + "modified": "2025-05-09T18:30:37Z", + "published": "2025-05-09T18:30:37Z", + "aliases": [ + "CVE-2025-28201" + ], + "details": "An issue in Victure RX1800 EN_V1.0.0_r12_110933 allows physically proximate attackers to execute arbitrary code or gain root access.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28201" + }, + { + "type": "WEB", + "url": "https://pwnit.io/2025/02/13/finding-vulnerabilities-in-wi-fi-router" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-09T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-57f7-wfqr-87r7/GHSA-57f7-wfqr-87r7.json b/advisories/unreviewed/2025/05/GHSA-57f7-wfqr-87r7/GHSA-57f7-wfqr-87r7.json new file mode 100644 index 00000000000..abf151e9f63 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-57f7-wfqr-87r7/GHSA-57f7-wfqr-87r7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-57f7-wfqr-87r7", + "modified": "2025-05-09T18:30:36Z", + "published": "2025-05-09T18:30:36Z", + "aliases": [ + "CVE-2024-13944" + ], + "details": "Link Following Local Privilege Escalation Vulnerability in NortonUtilitiesSvc in Norton Utilities Ultimate Version 24.2.16862.6344 on Windows 10 Pro x64 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via the creation of a symbolic link and leveraging a TOCTTOU (time-of-check to time-of-use) attack.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13944" + }, + { + "type": "WEB", + "url": "https://www.gendigital.com/us/en/contact-us/security-advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-09T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5g2m-h52j-gj53/GHSA-5g2m-h52j-gj53.json b/advisories/unreviewed/2025/05/GHSA-5g2m-h52j-gj53/GHSA-5g2m-h52j-gj53.json new file mode 100644 index 00000000000..6a4e90d45bc --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5g2m-h52j-gj53/GHSA-5g2m-h52j-gj53.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5g2m-h52j-gj53", + "modified": "2025-05-09T18:30:37Z", + "published": "2025-05-09T18:30:37Z", + "aliases": [ + "CVE-2025-45513" + ], + "details": "Tenda FH451 V1.0.0.9 has a stack overflow vulnerability in the function.P2pListFilter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45513" + }, + { + "type": "WEB", + "url": "https://github.com/Eu21ka/cve_report/blob/master/The%20router%20Tenda%20FH451%20V1.0.0.9%20of%20Shenzhen%20Jixiang%20Tenda%20Technology%20Co.%2C%20Ltd.%20has%20a%20stack%20overflow%20vulnerability.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-09T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6wp9-fhmq-qf9x/GHSA-6wp9-fhmq-qf9x.json b/advisories/unreviewed/2025/05/GHSA-6wp9-fhmq-qf9x/GHSA-6wp9-fhmq-qf9x.json new file mode 100644 index 00000000000..d50fe6f1413 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6wp9-fhmq-qf9x/GHSA-6wp9-fhmq-qf9x.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6wp9-fhmq-qf9x", + "modified": "2025-05-09T18:30:38Z", + "published": "2025-05-09T18:30:38Z", + "aliases": [ + "CVE-2025-46188" + ], + "details": "SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in superadmin_phpmyadmin.php.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46188" + }, + { + "type": "WEB", + "url": "https://github.com/x6vrn/mitre/blob/main/CVE-2025-46188.md" + }, + { + "type": "WEB", + "url": "https://medium.com/@bijay.kumar1857/sql-injection-to-rce-exploitation-0a5048e592be" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-09T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6x46-2273-xjjf/GHSA-6x46-2273-xjjf.json b/advisories/unreviewed/2025/05/GHSA-6x46-2273-xjjf/GHSA-6x46-2273-xjjf.json index 54615c1a1f4..9f2f7ee90f8 100644 --- a/advisories/unreviewed/2025/05/GHSA-6x46-2273-xjjf/GHSA-6x46-2273-xjjf.json +++ b/advisories/unreviewed/2025/05/GHSA-6x46-2273-xjjf/GHSA-6x46-2273-xjjf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6x46-2273-xjjf", - "modified": "2025-05-08T15:31:13Z", + "modified": "2025-05-09T18:30:36Z", "published": "2025-05-08T15:31:13Z", "aliases": [ "CVE-2025-4207" @@ -19,9 +19,17 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4207" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00011.html" + }, { "type": "WEB", "url": "https://www.postgresql.org/support/security/CVE-2025-4207" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/05/09/3" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/05/GHSA-99vm-2jmg-q6cj/GHSA-99vm-2jmg-q6cj.json b/advisories/unreviewed/2025/05/GHSA-99vm-2jmg-q6cj/GHSA-99vm-2jmg-q6cj.json new file mode 100644 index 00000000000..6145e429481 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-99vm-2jmg-q6cj/GHSA-99vm-2jmg-q6cj.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-99vm-2jmg-q6cj", + "modified": "2025-05-09T18:30:39Z", + "published": "2025-05-09T18:30:39Z", + "aliases": [ + "CVE-2025-29509" + ], + "details": "Jan v0.5.14 and before is vulnerable to remote code execution (RCE) when the user clicks on a rendered link in the conversation, due to opening external website in the app and the exposure of electronAPI, with a lack of filtering of URL when calling shell.openExternal().", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29509" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1qDztNtn2merSjYgPRLWFFXqlXM9tcrjD/view?usp=sharing" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Suuuuuzy/b8fa2fa083793c460e3686c182f8c4d1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-09T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c86p-w88r-qvqr/GHSA-c86p-w88r-qvqr.json b/advisories/unreviewed/2025/05/GHSA-c86p-w88r-qvqr/GHSA-c86p-w88r-qvqr.json new file mode 100644 index 00000000000..1455e9c10cd --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c86p-w88r-qvqr/GHSA-c86p-w88r-qvqr.json @@ -0,0 +1,60 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c86p-w88r-qvqr", + "modified": "2025-05-09T18:30:39Z", + "published": "2025-05-09T18:30:38Z", + "aliases": [ + "CVE-2025-4432" + ], + "details": "A flaw was found in Rust's Ring package. A panic may be triggered when overflow checking is enabled. In the QUIC protocol, this flaw allows an attacker to induce this panic by sending a specially crafted packet. It will likely occur unintentionally in 1 out of every 2**32 packets sent or received.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4432" + }, + { + "type": "WEB", + "url": "https://github.com/briansmith/ring/pull/2447" + }, + { + "type": "WEB", + "url": "https://github.com/briansmith/ring/commit/ec2d3cf1d91f148c84e4806b4f0b3c98f6df3b38" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-4432" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2350655" + }, + { + "type": "WEB", + "url": "https://github.com/briansmith/ring" + }, + { + "type": "WEB", + "url": "https://github.com/briansmith/ring/blob/main/RELEASES.md#version-01712-2025-03-05" + }, + { + "type": "WEB", + "url": "https://rustsec.org/advisories/RUSTSEC-2025-0009.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-09T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-cgmh-59mf-xh4r/GHSA-cgmh-59mf-xh4r.json b/advisories/unreviewed/2025/05/GHSA-cgmh-59mf-xh4r/GHSA-cgmh-59mf-xh4r.json new file mode 100644 index 00000000000..282e0f2494b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-cgmh-59mf-xh4r/GHSA-cgmh-59mf-xh4r.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cgmh-59mf-xh4r", + "modified": "2025-05-09T18:30:39Z", + "published": "2025-05-09T18:30:39Z", + "aliases": [ + "CVE-2025-4481" + ], + "details": "A vulnerability was found in SourceCodester Apartment Visitor Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /search-result.php. The manipulation of the argument searchdata leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4481" + }, + { + "type": "WEB", + "url": "https://github.com/hackerzhuo/CVE/issues/1" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.308195" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.308195" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.566671" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-09T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-crgq-r5hp-5v47/GHSA-crgq-r5hp-5v47.json b/advisories/unreviewed/2025/05/GHSA-crgq-r5hp-5v47/GHSA-crgq-r5hp-5v47.json new file mode 100644 index 00000000000..c13ac34b7a7 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-crgq-r5hp-5v47/GHSA-crgq-r5hp-5v47.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crgq-r5hp-5v47", + "modified": "2025-05-09T18:30:37Z", + "published": "2025-05-09T18:30:37Z", + "aliases": [ + "CVE-2025-28202" + ], + "details": "Incorrect access control in Victure RX1800 EN_V1.0.0_r12_110933 allows attackers to enable SSH and Telnet services without authentication.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28202" + }, + { + "type": "WEB", + "url": "https://pwnit.io/2025/02/13/finding-vulnerabilities-in-wi-fi-router" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-09T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fxh7-543f-qcr8/GHSA-fxh7-543f-qcr8.json b/advisories/unreviewed/2025/05/GHSA-fxh7-543f-qcr8/GHSA-fxh7-543f-qcr8.json new file mode 100644 index 00000000000..83fc73f10e4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fxh7-543f-qcr8/GHSA-fxh7-543f-qcr8.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fxh7-543f-qcr8", + "modified": "2025-05-09T18:30:38Z", + "published": "2025-05-09T18:30:38Z", + "aliases": [ + "CVE-2025-46189" + ], + "details": "SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_order_customer_update.php via the order_id POST parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46189" + }, + { + "type": "WEB", + "url": "https://github.com/x6vrn/mitre/blob/main/CVE-2025-46189.md" + }, + { + "type": "WEB", + "url": "https://medium.com/@YousefAlotaibi/disclaimer-1699f46cb1a0" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-09T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g29r-vm3j-h4pj/GHSA-g29r-vm3j-h4pj.json b/advisories/unreviewed/2025/05/GHSA-g29r-vm3j-h4pj/GHSA-g29r-vm3j-h4pj.json new file mode 100644 index 00000000000..6059bd74ae6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g29r-vm3j-h4pj/GHSA-g29r-vm3j-h4pj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g29r-vm3j-h4pj", + "modified": "2025-05-09T18:30:37Z", + "published": "2025-05-09T18:30:37Z", + "aliases": [ + "CVE-2024-13962" + ], + "details": "Link Following Local Privilege Escalation Vulnerability in TuneupSvc in Gen Digital Inc. Avast Cleanup Premium Version 24.2.16593.17810 on Windows 10 Pro x64 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via creating a symbolic link and leveraging a TOCTTOU (time-of-check to time-of-use) attack.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13962" + }, + { + "type": "WEB", + "url": "https://www.gendigital.com/us/en/contact-us/security-advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-09T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g475-6rmv-x646/GHSA-g475-6rmv-x646.json b/advisories/unreviewed/2025/05/GHSA-g475-6rmv-x646/GHSA-g475-6rmv-x646.json new file mode 100644 index 00000000000..c34d41cb920 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g475-6rmv-x646/GHSA-g475-6rmv-x646.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g475-6rmv-x646", + "modified": "2025-05-09T18:30:39Z", + "published": "2025-05-09T18:30:39Z", + "aliases": [ + "CVE-2025-1993" + ], + "details": "IBM App Connect Enterprise Certified Container 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, 12.3, 12.4, 12.5, 12.6, 12.7, 12.8, 12.9, and 12.10 DesignerAuthoring instances store their flows in a database that is protected by weaker than expected cryptographic algorithms that could be decrypted by a local user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1993" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7233054" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-521" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-09T18:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g6x2-86jw-7c7w/GHSA-g6x2-86jw-7c7w.json b/advisories/unreviewed/2025/05/GHSA-g6x2-86jw-7c7w/GHSA-g6x2-86jw-7c7w.json new file mode 100644 index 00000000000..2760c86c16f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g6x2-86jw-7c7w/GHSA-g6x2-86jw-7c7w.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g6x2-86jw-7c7w", + "modified": "2025-05-09T18:30:39Z", + "published": "2025-05-09T18:30:39Z", + "aliases": [ + "CVE-2025-4480" + ], + "details": "A vulnerability was found in code-projects Simple College Management System 1.0. It has been declared as critical. This vulnerability affects the function input of the component Add New Student. The manipulation of the argument name/branch leads to stack-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4480" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/zzzxc643/cve/blob/main/SIMPLE_COLLEGE_MANAGEMENT_SYSTEM.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.308194" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.308194" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.566525" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-09T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hxm6-cc9v-9f63/GHSA-hxm6-cc9v-9f63.json b/advisories/unreviewed/2025/05/GHSA-hxm6-cc9v-9f63/GHSA-hxm6-cc9v-9f63.json new file mode 100644 index 00000000000..d5470fc8a8d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hxm6-cc9v-9f63/GHSA-hxm6-cc9v-9f63.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hxm6-cc9v-9f63", + "modified": "2025-05-09T18:30:39Z", + "published": "2025-05-09T18:30:39Z", + "aliases": [ + "CVE-2025-46191" + ], + "details": "Arbitrary File Upload in user_payment_update.php in SourceCodester Client Database Management System 1.0 allows unauthenticated users to upload arbitrary files via the uploaded_file_cancelled field. Due to the absence of proper file extension checks, MIME type validation, and authentication, attackers can upload executable PHP files to a web-accessible directory (/files/). This allows them to execute arbitrary commands remotely by accessing the uploaded script, resulting in full Remote Code Execution (RCE) without authentication.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46191" + }, + { + "type": "WEB", + "url": "https://github.com/x6vrn/mitre/blob/main/CVE-2025-46191.md" + }, + { + "type": "WEB", + "url": "https://portswigger.net/web-security/file-upload" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-09T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jwhw-fx3f-p3m6/GHSA-jwhw-fx3f-p3m6.json b/advisories/unreviewed/2025/05/GHSA-jwhw-fx3f-p3m6/GHSA-jwhw-fx3f-p3m6.json index fd617fc0dc7..cd217882250 100644 --- a/advisories/unreviewed/2025/05/GHSA-jwhw-fx3f-p3m6/GHSA-jwhw-fx3f-p3m6.json +++ b/advisories/unreviewed/2025/05/GHSA-jwhw-fx3f-p3m6/GHSA-jwhw-fx3f-p3m6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jwhw-fx3f-p3m6", - "modified": "2025-05-06T15:31:00Z", + "modified": "2025-05-09T18:30:36Z", "published": "2025-05-02T09:30:35Z", "aliases": [ "CVE-2024-13859" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://www.buddyboss.com/platform" }, + { + "type": "WEB", + "url": "https://www.buddyboss.com/resources/buddyboss-platform-releases/2-8-51" + }, { "type": "WEB", "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d77c8096-40b1-4ac7-881f-6aed98da6752?source=cve" diff --git a/advisories/unreviewed/2025/05/GHSA-m245-6qxg-35cj/GHSA-m245-6qxg-35cj.json b/advisories/unreviewed/2025/05/GHSA-m245-6qxg-35cj/GHSA-m245-6qxg-35cj.json new file mode 100644 index 00000000000..398ae1a2408 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-m245-6qxg-35cj/GHSA-m245-6qxg-35cj.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m245-6qxg-35cj", + "modified": "2025-05-09T18:30:39Z", + "published": "2025-05-09T18:30:39Z", + "aliases": [ + "CVE-2025-4483" + ], + "details": "A vulnerability, which was classified as critical, has been found in itsourcecode Gym Management System 1.0. Affected by this issue is some unknown functionality of the file /view_pdetails.php. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4483" + }, + { + "type": "WEB", + "url": "https://github.com/wyl091256/CVE/issues/3" + }, + { + "type": "WEB", + "url": "https://itsourcecode.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.308198" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.308198" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.566778" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-09T18:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mr2x-vhgx-59m3/GHSA-mr2x-vhgx-59m3.json b/advisories/unreviewed/2025/05/GHSA-mr2x-vhgx-59m3/GHSA-mr2x-vhgx-59m3.json new file mode 100644 index 00000000000..d66eecdcf87 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mr2x-vhgx-59m3/GHSA-mr2x-vhgx-59m3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mr2x-vhgx-59m3", + "modified": "2025-05-09T18:30:37Z", + "published": "2025-05-09T18:30:37Z", + "aliases": [ + "CVE-2024-9524" + ], + "details": "Link Following Local Privilege Escalation Vulnerability in System Speedup Service in Avira Operations GmbH Avira Prime Version 1.1.96.2 on Windows 10 x64 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via creating a symbolic link and leveraging a TOCTTOU (time-of-check to time-of-use) attack.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9524" + }, + { + "type": "WEB", + "url": "https://www.gendigital.com/us/en/contact-us/security-advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-09T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-pj3j-8874-c986/GHSA-pj3j-8874-c986.json b/advisories/unreviewed/2025/05/GHSA-pj3j-8874-c986/GHSA-pj3j-8874-c986.json new file mode 100644 index 00000000000..ca4f44716dd --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pj3j-8874-c986/GHSA-pj3j-8874-c986.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pj3j-8874-c986", + "modified": "2025-05-09T18:30:38Z", + "published": "2025-05-09T18:30:38Z", + "aliases": [ + "CVE-2025-46193" + ], + "details": "SourceCodester Client Database Management System 1.0 is vulnerable to Remote code execution via Arbitrary file upload in user_proposal_update_order.php.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46193" + }, + { + "type": "WEB", + "url": "https://github.com/x6vrn/mitre/blob/main/CVE-2025-46193.md" + }, + { + "type": "WEB", + "url": "https://portswigger.net/web-security/file-upload" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-09T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q656-cxxx-f8h7/GHSA-q656-cxxx-f8h7.json b/advisories/unreviewed/2025/05/GHSA-q656-cxxx-f8h7/GHSA-q656-cxxx-f8h7.json new file mode 100644 index 00000000000..4e5031879ef --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q656-cxxx-f8h7/GHSA-q656-cxxx-f8h7.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q656-cxxx-f8h7", + "modified": "2025-05-09T18:30:38Z", + "published": "2025-05-09T18:30:38Z", + "aliases": [ + "CVE-2024-8973" + ], + "details": "An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.9.8, from 17.10 prior to 17.10.6, and from 17.11 prior to 17.11.2. It was possible to cause a DoS condition via GitHub import requests using a malicious crafted payload.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8973" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2711684" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/491041" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-09T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q768-3m4h-qj2j/GHSA-q768-3m4h-qj2j.json b/advisories/unreviewed/2025/05/GHSA-q768-3m4h-qj2j/GHSA-q768-3m4h-qj2j.json new file mode 100644 index 00000000000..406cbb1d2e4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q768-3m4h-qj2j/GHSA-q768-3m4h-qj2j.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q768-3m4h-qj2j", + "modified": "2025-05-09T18:30:39Z", + "published": "2025-05-09T18:30:39Z", + "aliases": [ + "CVE-2025-1278" + ], + "details": "An issue has been discovered in GitLab CE/EE affecting all versions from 12.0 before 17.9.8, 17.10 before 17.10.6, and 17.11 before 17.11.2. Under certain conditions users could bypass IP access restrictions and view sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1278" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2977149" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/519580" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1220" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-09T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q8cg-g95p-qfr2/GHSA-q8cg-g95p-qfr2.json b/advisories/unreviewed/2025/05/GHSA-q8cg-g95p-qfr2/GHSA-q8cg-g95p-qfr2.json new file mode 100644 index 00000000000..6183da9a1da --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q8cg-g95p-qfr2/GHSA-q8cg-g95p-qfr2.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q8cg-g95p-qfr2", + "modified": "2025-05-09T18:30:39Z", + "published": "2025-05-09T18:30:38Z", + "aliases": [ + "CVE-2025-0549" + ], + "details": "An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.3 prior to 17.9.8, from 17.10 prior to 17.10.6, and from 17.11 prior to 17.11.2. A security vulnerability allows attackers to bypass Device OAuth flow protections, enabling authorization form submission through minimal user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0549" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2927555" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/513996" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-09T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qqrc-c2h6-m823/GHSA-qqrc-c2h6-m823.json b/advisories/unreviewed/2025/05/GHSA-qqrc-c2h6-m823/GHSA-qqrc-c2h6-m823.json index de5f4c1f55c..38b57b22447 100644 --- a/advisories/unreviewed/2025/05/GHSA-qqrc-c2h6-m823/GHSA-qqrc-c2h6-m823.json +++ b/advisories/unreviewed/2025/05/GHSA-qqrc-c2h6-m823/GHSA-qqrc-c2h6-m823.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qqrc-c2h6-m823", - "modified": "2025-05-06T15:31:00Z", + "modified": "2025-05-09T18:30:36Z", "published": "2025-05-02T09:30:35Z", "aliases": [ "CVE-2024-13858" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://www.buddyboss.com/platform" }, + { + "type": "WEB", + "url": "https://www.buddyboss.com/resources/buddyboss-platform-releases/2-8-51" + }, { "type": "WEB", "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5f50e293-aebd-44dd-a692-64dea8f6622f?source=cve" diff --git a/advisories/unreviewed/2025/05/GHSA-qr56-hpqq-mc7v/GHSA-qr56-hpqq-mc7v.json b/advisories/unreviewed/2025/05/GHSA-qr56-hpqq-mc7v/GHSA-qr56-hpqq-mc7v.json new file mode 100644 index 00000000000..1da03fcc6a0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qr56-hpqq-mc7v/GHSA-qr56-hpqq-mc7v.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qr56-hpqq-mc7v", + "modified": "2025-05-09T18:30:39Z", + "published": "2025-05-09T18:30:39Z", + "aliases": [ + "CVE-2025-46190" + ], + "details": "SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_delivery_update.php via the order_id POST parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46190" + }, + { + "type": "WEB", + "url": "https://github.com/x6vrn/mitre/blob/main/CVE-2025-46190.md" + }, + { + "type": "WEB", + "url": "https://www.invicti.com/learn/blind-sql-injection" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-09T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rvhv-2qpm-56c6/GHSA-rvhv-2qpm-56c6.json b/advisories/unreviewed/2025/05/GHSA-rvhv-2qpm-56c6/GHSA-rvhv-2qpm-56c6.json new file mode 100644 index 00000000000..9f1df0c89dc --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rvhv-2qpm-56c6/GHSA-rvhv-2qpm-56c6.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rvhv-2qpm-56c6", + "modified": "2025-05-09T18:30:39Z", + "published": "2025-05-09T18:30:39Z", + "aliases": [ + "CVE-2025-46192" + ], + "details": "SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_payment_update.php via the order_id POST parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46192" + }, + { + "type": "WEB", + "url": "https://github.com/x6vrn/mitre/blob/main/CVE-2025-46192.md" + }, + { + "type": "WEB", + "url": "https://www.invicti.com/learn/blind-sql-injection" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-09T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vcq3-w776-rvhp/GHSA-vcq3-w776-rvhp.json b/advisories/unreviewed/2025/05/GHSA-vcq3-w776-rvhp/GHSA-vcq3-w776-rvhp.json new file mode 100644 index 00000000000..17a7de27bce --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vcq3-w776-rvhp/GHSA-vcq3-w776-rvhp.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vcq3-w776-rvhp", + "modified": "2025-05-09T18:30:39Z", + "published": "2025-05-09T18:30:39Z", + "aliases": [ + "CVE-2025-4482" + ], + "details": "A vulnerability classified as critical was found in Project Worlds Student Project Allocation System 1.0. Affected by this vulnerability is an unknown functionality of the file /change_pass/forgot_password_sql.php. The manipulation of the argument Pat_BloodGroup1 leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4482" + }, + { + "type": "WEB", + "url": "https://github.com/hhhanxx/attack/issues/3" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.308197" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.308197" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.566719" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-09T18:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wm67-4pmx-xf72/GHSA-wm67-4pmx-xf72.json b/advisories/unreviewed/2025/05/GHSA-wm67-4pmx-xf72/GHSA-wm67-4pmx-xf72.json new file mode 100644 index 00000000000..f1a47cdd0d3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wm67-4pmx-xf72/GHSA-wm67-4pmx-xf72.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wm67-4pmx-xf72", + "modified": "2025-05-09T18:30:37Z", + "published": "2025-05-09T18:30:37Z", + "aliases": [ + "CVE-2024-13961" + ], + "details": "Link Following Local Privilege Escalation Vulnerability in TuneupSvc in Avast Cleanup Premium Version 24.2.16593.17810 on Windows 10 Pro x64 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via creating a symbolic link and leveraging a TOCTTOU (time-of-check to time-of-use) attack.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13961" + }, + { + "type": "WEB", + "url": "https://www.gendigital.com/us/en/contact-us/security-advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-09T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-x3g7-56f2-8w33/GHSA-x3g7-56f2-8w33.json b/advisories/unreviewed/2025/05/GHSA-x3g7-56f2-8w33/GHSA-x3g7-56f2-8w33.json new file mode 100644 index 00000000000..1f02b37b085 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-x3g7-56f2-8w33/GHSA-x3g7-56f2-8w33.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x3g7-56f2-8w33", + "modified": "2025-05-09T18:30:37Z", + "published": "2025-05-09T18:30:37Z", + "aliases": [ + "CVE-2025-28200" + ], + "details": "Victure RX1800 EN_V1.0.0_r12_110933 was discovered to utilize a weak default password which includes the last 8 digits of the Mac address.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28200" + }, + { + "type": "WEB", + "url": "https://pwnit.io/2025/02/13/finding-vulnerabilities-in-wi-fi-router" + }, + { + "type": "WEB", + "url": "http://rx1800.com" + }, + { + "type": "WEB", + "url": "http://victure.com" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-09T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-x6fj-h4wg-gc58/GHSA-x6fj-h4wg-gc58.json b/advisories/unreviewed/2025/05/GHSA-x6fj-h4wg-gc58/GHSA-x6fj-h4wg-gc58.json new file mode 100644 index 00000000000..5de7f55955b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-x6fj-h4wg-gc58/GHSA-x6fj-h4wg-gc58.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x6fj-h4wg-gc58", + "modified": "2025-05-09T18:30:37Z", + "published": "2025-05-09T18:30:37Z", + "aliases": [ + "CVE-2024-13960" + ], + "details": "Link Following Local Privilege Escalation Vulnerability in TuneUp Service in AVG TuneUp Version 23.4 (build 15592) on Windows 10 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via creating a symbolic link and leveraging a TOCTTOU (time-of-check to time-of-use) attack.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13960" + }, + { + "type": "WEB", + "url": "https://www.gendigital.com/us/en/contact-us/security-advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-09T16:15:23Z" + } +} \ No newline at end of file