diff --git a/advisories/unreviewed/2023/01/GHSA-8gg5-pvcf-9jwc/GHSA-8gg5-pvcf-9jwc.json b/advisories/unreviewed/2023/01/GHSA-8gg5-pvcf-9jwc/GHSA-8gg5-pvcf-9jwc.json index 320183364be..6b5efba68b5 100644 --- a/advisories/unreviewed/2023/01/GHSA-8gg5-pvcf-9jwc/GHSA-8gg5-pvcf-9jwc.json +++ b/advisories/unreviewed/2023/01/GHSA-8gg5-pvcf-9jwc/GHSA-8gg5-pvcf-9jwc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8gg5-pvcf-9jwc", - "modified": "2023-02-08T21:30:21Z", + "modified": "2025-03-31T21:32:40Z", "published": "2023-01-27T00:30:19Z", "aliases": [ "CVE-2022-45770" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://github.com/Marsel-marsel/CVE-2022-45770" }, + { + "type": "WEB", + "url": "https://hackmag.com/security/aguard-cve" + }, { "type": "WEB", "url": "https://xakep.ru/2023/01/27/aguard-cve" diff --git a/advisories/unreviewed/2024/11/GHSA-4g32-4h7x-954w/GHSA-4g32-4h7x-954w.json b/advisories/unreviewed/2024/11/GHSA-4g32-4h7x-954w/GHSA-4g32-4h7x-954w.json index 266ba9f65e2..25e9a7f4167 100644 --- a/advisories/unreviewed/2024/11/GHSA-4g32-4h7x-954w/GHSA-4g32-4h7x-954w.json +++ b/advisories/unreviewed/2024/11/GHSA-4g32-4h7x-954w/GHSA-4g32-4h7x-954w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4g32-4h7x-954w", - "modified": "2024-11-16T00:31:50Z", + "modified": "2025-03-31T21:32:44Z", "published": "2024-11-15T21:30:47Z", "aliases": [ "CVE-2024-24459" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://cellularsecurity.org/ransacked" }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04780en_us&docLocale=en_US" + }, { "type": "WEB", "url": "http://athonet.com" diff --git a/advisories/unreviewed/2024/11/GHSA-7pj9-85vv-hh5r/GHSA-7pj9-85vv-hh5r.json b/advisories/unreviewed/2024/11/GHSA-7pj9-85vv-hh5r/GHSA-7pj9-85vv-hh5r.json index 0689238efc1..7d8b1353b3e 100644 --- a/advisories/unreviewed/2024/11/GHSA-7pj9-85vv-hh5r/GHSA-7pj9-85vv-hh5r.json +++ b/advisories/unreviewed/2024/11/GHSA-7pj9-85vv-hh5r/GHSA-7pj9-85vv-hh5r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7pj9-85vv-hh5r", - "modified": "2024-11-16T00:31:50Z", + "modified": "2025-03-31T21:32:44Z", "published": "2024-11-15T21:30:47Z", "aliases": [ "CVE-2024-24454" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://cellularsecurity.org/ransacked" }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04780en_us&docLocale=en_US" + }, { "type": "WEB", "url": "http://athonet.com" diff --git a/advisories/unreviewed/2024/11/GHSA-8386-783g-q974/GHSA-8386-783g-q974.json b/advisories/unreviewed/2024/11/GHSA-8386-783g-q974/GHSA-8386-783g-q974.json index 42e6d32920e..c2ce6925da1 100644 --- a/advisories/unreviewed/2024/11/GHSA-8386-783g-q974/GHSA-8386-783g-q974.json +++ b/advisories/unreviewed/2024/11/GHSA-8386-783g-q974/GHSA-8386-783g-q974.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8386-783g-q974", - "modified": "2024-11-16T00:31:50Z", + "modified": "2025-03-31T21:32:42Z", "published": "2024-11-15T21:30:47Z", "aliases": [ "CVE-2024-24452" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://cellularsecurity.org/ransacked" }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04780en_us&docLocale=en_US" + }, { "type": "WEB", "url": "http://athonet.com" diff --git a/advisories/unreviewed/2024/11/GHSA-cvm8-v9rf-89jw/GHSA-cvm8-v9rf-89jw.json b/advisories/unreviewed/2024/11/GHSA-cvm8-v9rf-89jw/GHSA-cvm8-v9rf-89jw.json index 68037f7f280..b5cf5bf1eb7 100644 --- a/advisories/unreviewed/2024/11/GHSA-cvm8-v9rf-89jw/GHSA-cvm8-v9rf-89jw.json +++ b/advisories/unreviewed/2024/11/GHSA-cvm8-v9rf-89jw/GHSA-cvm8-v9rf-89jw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cvm8-v9rf-89jw", - "modified": "2024-11-16T00:31:50Z", + "modified": "2025-03-31T21:32:44Z", "published": "2024-11-15T21:30:47Z", "aliases": [ "CVE-2024-24455" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://cellularsecurity.org/ransacked" }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04780en_us&docLocale=en_US" + }, { "type": "WEB", "url": "http://athonet.com" diff --git a/advisories/unreviewed/2024/11/GHSA-mcxg-gq2f-3x39/GHSA-mcxg-gq2f-3x39.json b/advisories/unreviewed/2024/11/GHSA-mcxg-gq2f-3x39/GHSA-mcxg-gq2f-3x39.json index b5883ef3f00..ca3ed5936a0 100644 --- a/advisories/unreviewed/2024/11/GHSA-mcxg-gq2f-3x39/GHSA-mcxg-gq2f-3x39.json +++ b/advisories/unreviewed/2024/11/GHSA-mcxg-gq2f-3x39/GHSA-mcxg-gq2f-3x39.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mcxg-gq2f-3x39", - "modified": "2024-11-16T00:31:50Z", + "modified": "2025-03-31T21:32:44Z", "published": "2024-11-15T21:30:47Z", "aliases": [ "CVE-2024-24458" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://cellularsecurity.org/ransacked" }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04780en_us&docLocale=en_US" + }, { "type": "WEB", "url": "http://athonet.com" diff --git a/advisories/unreviewed/2024/11/GHSA-qf7p-2hmj-48mq/GHSA-qf7p-2hmj-48mq.json b/advisories/unreviewed/2024/11/GHSA-qf7p-2hmj-48mq/GHSA-qf7p-2hmj-48mq.json index 23f9063bdad..3034b89b458 100644 --- a/advisories/unreviewed/2024/11/GHSA-qf7p-2hmj-48mq/GHSA-qf7p-2hmj-48mq.json +++ b/advisories/unreviewed/2024/11/GHSA-qf7p-2hmj-48mq/GHSA-qf7p-2hmj-48mq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qf7p-2hmj-48mq", - "modified": "2024-11-16T00:31:50Z", + "modified": "2025-03-31T21:32:43Z", "published": "2024-11-15T21:30:47Z", "aliases": [ "CVE-2024-24453" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://cellularsecurity.org/ransacked" }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04780en_us&docLocale=en_US" + }, { "type": "WEB", "url": "http://athonet.com" diff --git a/advisories/unreviewed/2024/11/GHSA-qwhj-q28h-8hg6/GHSA-qwhj-q28h-8hg6.json b/advisories/unreviewed/2024/11/GHSA-qwhj-q28h-8hg6/GHSA-qwhj-q28h-8hg6.json index f9b63b3762a..9dac106028b 100644 --- a/advisories/unreviewed/2024/11/GHSA-qwhj-q28h-8hg6/GHSA-qwhj-q28h-8hg6.json +++ b/advisories/unreviewed/2024/11/GHSA-qwhj-q28h-8hg6/GHSA-qwhj-q28h-8hg6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qwhj-q28h-8hg6", - "modified": "2024-11-20T15:30:52Z", + "modified": "2025-03-31T21:32:45Z", "published": "2024-11-20T15:30:52Z", "aliases": [ "CVE-2024-51209" ], "details": "Cross-Site Scripting (XSS) vulnerabilities in Anuj Kumar's Client Management System Version 1.2 allow local attackers to inject arbitrary web script or HTML via the search input field parameter to admin search invoice page and client search invoice page.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-20T15:15:08Z" diff --git a/advisories/unreviewed/2024/11/GHSA-rf7m-w6xx-cv97/GHSA-rf7m-w6xx-cv97.json b/advisories/unreviewed/2024/11/GHSA-rf7m-w6xx-cv97/GHSA-rf7m-w6xx-cv97.json index 48870dc1121..08e75610559 100644 --- a/advisories/unreviewed/2024/11/GHSA-rf7m-w6xx-cv97/GHSA-rf7m-w6xx-cv97.json +++ b/advisories/unreviewed/2024/11/GHSA-rf7m-w6xx-cv97/GHSA-rf7m-w6xx-cv97.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-xmrx-pprf-648j/GHSA-xmrx-pprf-648j.json b/advisories/unreviewed/2024/11/GHSA-xmrx-pprf-648j/GHSA-xmrx-pprf-648j.json index 000ca2818d1..71fec204c23 100644 --- a/advisories/unreviewed/2024/11/GHSA-xmrx-pprf-648j/GHSA-xmrx-pprf-648j.json +++ b/advisories/unreviewed/2024/11/GHSA-xmrx-pprf-648j/GHSA-xmrx-pprf-648j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xmrx-pprf-648j", - "modified": "2024-11-16T00:31:50Z", + "modified": "2025-03-31T21:32:44Z", "published": "2024-11-15T21:30:47Z", "aliases": [ "CVE-2024-24457" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://cellularsecurity.org/ransacked" }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04780en_us&docLocale=en_US" + }, { "type": "WEB", "url": "http://athonet.com" diff --git a/advisories/unreviewed/2025/03/GHSA-27q4-qvjw-mjxw/GHSA-27q4-qvjw-mjxw.json b/advisories/unreviewed/2025/03/GHSA-27q4-qvjw-mjxw/GHSA-27q4-qvjw-mjxw.json new file mode 100644 index 00000000000..c1e1de9839d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-27q4-qvjw-mjxw/GHSA-27q4-qvjw-mjxw.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-27q4-qvjw-mjxw", + "modified": "2025-03-31T21:32:50Z", + "published": "2025-03-31T21:32:50Z", + "aliases": [ + "CVE-2024-54805" + ], + "details": "Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the nvram parameter get_email. After which, they can visit the send_log.cgi endpoint which uses the parameter in a system call to achieve command execution.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54805" + }, + { + "type": "WEB", + "url": "https://faultpoint.com/post/2025-03-25-8-cves-on-the-wnr854t-junkyard/#805" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T21:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2mf8-xmm6-qx35/GHSA-2mf8-xmm6-qx35.json b/advisories/unreviewed/2025/03/GHSA-2mf8-xmm6-qx35/GHSA-2mf8-xmm6-qx35.json new file mode 100644 index 00000000000..30e34ee0d16 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2mf8-xmm6-qx35/GHSA-2mf8-xmm6-qx35.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2mf8-xmm6-qx35", + "modified": "2025-03-31T21:32:50Z", + "published": "2025-03-31T21:32:50Z", + "aliases": [ + "CVE-2024-54809" + ], + "details": "Netgear Inc WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the parse_st_header function due to use of a request header parameter in a strncpy where size is determined based on the input specified. By sending a specially crafted packet, an attacker can take control of the program counter and hijack control flow of the program to execute arbitrary system commands.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54809" + }, + { + "type": "WEB", + "url": "https://faultpoint.com/post/2025-03-25-8-cves-on-the-wnr854t-junkyard/#809" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T21:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3gj4-2f6h-gghr/GHSA-3gj4-2f6h-gghr.json b/advisories/unreviewed/2025/03/GHSA-3gj4-2f6h-gghr/GHSA-3gj4-2f6h-gghr.json new file mode 100644 index 00000000000..c94b46af54a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3gj4-2f6h-gghr/GHSA-3gj4-2f6h-gghr.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3gj4-2f6h-gghr", + "modified": "2025-03-31T21:32:50Z", + "published": "2025-03-31T21:32:50Z", + "aliases": [ + "CVE-2024-54804" + ], + "details": "Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the nvram parameter wan_hostname and forcing a reboot. This will result in command injection.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54804" + }, + { + "type": "WEB", + "url": "https://faultpoint.com/post/2025-03-25-8-cves-on-the-wnr854t-junkyard/#804" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T21:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4m6w-jp94-34vc/GHSA-4m6w-jp94-34vc.json b/advisories/unreviewed/2025/03/GHSA-4m6w-jp94-34vc/GHSA-4m6w-jp94-34vc.json new file mode 100644 index 00000000000..b9d79c23a51 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4m6w-jp94-34vc/GHSA-4m6w-jp94-34vc.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4m6w-jp94-34vc", + "modified": "2025-03-31T21:32:49Z", + "published": "2025-03-31T21:32:49Z", + "aliases": [ + "CVE-2025-3010" + ], + "details": "A vulnerability, which was classified as problematic, has been found in Khronos Group glslang 15.1.0. Affected by this issue is the function glslang::TIntermediate::isConversionAllowed of the file glslang/MachineIndependent/Intermediate.cpp. The manipulation leads to null pointer dereference. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3010" + }, + { + "type": "WEB", + "url": "https://github.com/KhronosGroup/glslang/issues/3903" + }, + { + "type": "WEB", + "url": "https://github.com/KhronosGroup/glslang/issues/3903#issue-2927492534" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.302060" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.302060" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.524561" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-404" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T20:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6rmj-m2q8-5fvh/GHSA-6rmj-m2q8-5fvh.json b/advisories/unreviewed/2025/03/GHSA-6rmj-m2q8-5fvh/GHSA-6rmj-m2q8-5fvh.json new file mode 100644 index 00000000000..33ca900651a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6rmj-m2q8-5fvh/GHSA-6rmj-m2q8-5fvh.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6rmj-m2q8-5fvh", + "modified": "2025-03-31T21:32:49Z", + "published": "2025-03-31T21:32:49Z", + "aliases": [ + "CVE-2024-54802" + ], + "details": "In Netgear WNR854T 1.5.2 (North America), the UPNP service (/usr/sbin/upnp) is vulnerable to stack-based buffer overflow in the M-SEARCH Host header.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54802" + }, + { + "type": "WEB", + "url": "https://faultpoint.com/post/2025-03-25-8-cves-on-the-wnr854t-junkyard/#802" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T21:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7chq-xr5g-6crp/GHSA-7chq-xr5g-6crp.json b/advisories/unreviewed/2025/03/GHSA-7chq-xr5g-6crp/GHSA-7chq-xr5g-6crp.json new file mode 100644 index 00000000000..47f881b5363 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7chq-xr5g-6crp/GHSA-7chq-xr5g-6crp.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7chq-xr5g-6crp", + "modified": "2025-03-31T21:32:48Z", + "published": "2025-03-31T21:32:48Z", + "aliases": [ + "CVE-2025-3007" + ], + "details": "A vulnerability was found in Novastar CX40 up to 2.44.0. It has been rated as critical. This issue affects the function getopt of the file /usr/nova/bin/netconfig of the component NetFilter Utility. The manipulation of the argument cmd/netmask/pipeout/nettask leads to stack-based buffer overflow. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3007" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.302057" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.302057" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.524867" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T19:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7q69-vmcq-34w9/GHSA-7q69-vmcq-34w9.json b/advisories/unreviewed/2025/03/GHSA-7q69-vmcq-34w9/GHSA-7q69-vmcq-34w9.json index a6ffdcbf3f9..1055f53c2ca 100644 --- a/advisories/unreviewed/2025/03/GHSA-7q69-vmcq-34w9/GHSA-7q69-vmcq-34w9.json +++ b/advisories/unreviewed/2025/03/GHSA-7q69-vmcq-34w9/GHSA-7q69-vmcq-34w9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7q69-vmcq-34w9", - "modified": "2025-03-29T00:31:34Z", + "modified": "2025-03-31T21:32:45Z", "published": "2025-03-29T00:31:34Z", "aliases": [ "CVE-2025-28090" ], "details": "maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) in the Collection Custom Interface feature.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-918" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-28T22:15:17Z" diff --git a/advisories/unreviewed/2025/03/GHSA-7wj9-f5xc-vmq2/GHSA-7wj9-f5xc-vmq2.json b/advisories/unreviewed/2025/03/GHSA-7wj9-f5xc-vmq2/GHSA-7wj9-f5xc-vmq2.json new file mode 100644 index 00000000000..1af813f4bfd --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7wj9-f5xc-vmq2/GHSA-7wj9-f5xc-vmq2.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7wj9-f5xc-vmq2", + "modified": "2025-03-31T21:32:49Z", + "published": "2025-03-31T21:32:49Z", + "aliases": [ + "CVE-2024-24456" + ], + "details": "An E-RAB Release Command packet containing a malformed NAS PDU will cause the Athonet MME to immediately crash, potentially due to a buffer overflow.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24456" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04780en_us&docLocale=en_US" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T21:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8w2m-3cmp-47gw/GHSA-8w2m-3cmp-47gw.json b/advisories/unreviewed/2025/03/GHSA-8w2m-3cmp-47gw/GHSA-8w2m-3cmp-47gw.json new file mode 100644 index 00000000000..c0872684daf --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8w2m-3cmp-47gw/GHSA-8w2m-3cmp-47gw.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8w2m-3cmp-47gw", + "modified": "2025-03-31T21:32:50Z", + "published": "2025-03-31T21:32:50Z", + "aliases": [ + "CVE-2024-54807" + ], + "details": "In Netgear WNR854T 1.5.2 (North America), the UPNP service is vulnerable to command injection in the function addmap_exec which parses the NewInternalClient parameter of the AddPortMapping SOAPAction into a system call without sanitation. An attacker can send a specially crafted SOAPAction request for AddPortMapping via the router's WANIPConn1 service to achieve arbitrary command execution.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54807" + }, + { + "type": "WEB", + "url": "https://faultpoint.com/post/2025-03-25-8-cves-on-the-wnr854t-junkyard/#807" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T21:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9r2h-jf64-j5hc/GHSA-9r2h-jf64-j5hc.json b/advisories/unreviewed/2025/03/GHSA-9r2h-jf64-j5hc/GHSA-9r2h-jf64-j5hc.json new file mode 100644 index 00000000000..5ab7c27b1d0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9r2h-jf64-j5hc/GHSA-9r2h-jf64-j5hc.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9r2h-jf64-j5hc", + "modified": "2025-03-31T21:32:49Z", + "published": "2025-03-31T21:32:49Z", + "aliases": [ + "CVE-2025-3009" + ], + "details": "A vulnerability classified as critical was found in Jinher Network OA C6. Affected by this vulnerability is an unknown functionality of the file /C6/JHSoft.Web.NetDisk/NetDiskProperty.aspx. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3009" + }, + { + "type": "WEB", + "url": "https://github.com/Myoung-SA/cve/issues/1" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.302059" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.302059" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.524554" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T20:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-c928-5v6m-vm5h/GHSA-c928-5v6m-vm5h.json b/advisories/unreviewed/2025/03/GHSA-c928-5v6m-vm5h/GHSA-c928-5v6m-vm5h.json index 540e33a9bf9..e64db613ca4 100644 --- a/advisories/unreviewed/2025/03/GHSA-c928-5v6m-vm5h/GHSA-c928-5v6m-vm5h.json +++ b/advisories/unreviewed/2025/03/GHSA-c928-5v6m-vm5h/GHSA-c928-5v6m-vm5h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c928-5v6m-vm5h", - "modified": "2025-03-29T00:31:34Z", + "modified": "2025-03-31T21:32:45Z", "published": "2025-03-29T00:31:34Z", "aliases": [ "CVE-2025-28089" ], "details": "maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) via the Scheduled Task function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-918" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-28T22:15:17Z" diff --git a/advisories/unreviewed/2025/03/GHSA-fpgq-9jcf-446p/GHSA-fpgq-9jcf-446p.json b/advisories/unreviewed/2025/03/GHSA-fpgq-9jcf-446p/GHSA-fpgq-9jcf-446p.json new file mode 100644 index 00000000000..30f0a4fb3b0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fpgq-9jcf-446p/GHSA-fpgq-9jcf-446p.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fpgq-9jcf-446p", + "modified": "2025-03-31T21:32:50Z", + "published": "2025-03-31T21:32:50Z", + "aliases": [ + "CVE-2024-54806" + ], + "details": "Netgear WNR854T 1.5.2 (North America) is vulnerable to Arbitrary command execution in cmd.cgi which allows for the execution of system commands via the web interface.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54806" + }, + { + "type": "WEB", + "url": "https://faultpoint.com/post/2025-03-25-8-cves-on-the-wnr854t-junkyard/#806" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T21:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gfhv-5rqh-7qx3/GHSA-gfhv-5rqh-7qx3.json b/advisories/unreviewed/2025/03/GHSA-gfhv-5rqh-7qx3/GHSA-gfhv-5rqh-7qx3.json index 4908cc6490e..184c0f52c6e 100644 --- a/advisories/unreviewed/2025/03/GHSA-gfhv-5rqh-7qx3/GHSA-gfhv-5rqh-7qx3.json +++ b/advisories/unreviewed/2025/03/GHSA-gfhv-5rqh-7qx3/GHSA-gfhv-5rqh-7qx3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gfhv-5rqh-7qx3", - "modified": "2025-03-29T00:31:34Z", + "modified": "2025-03-31T21:32:46Z", "published": "2025-03-29T00:31:34Z", "aliases": [ "CVE-2025-28093" ], "details": "ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) in Email Settings.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-28T22:15:18Z" diff --git a/advisories/unreviewed/2025/03/GHSA-j456-qg26-rqx4/GHSA-j456-qg26-rqx4.json b/advisories/unreviewed/2025/03/GHSA-j456-qg26-rqx4/GHSA-j456-qg26-rqx4.json new file mode 100644 index 00000000000..6dafa40fb67 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-j456-qg26-rqx4/GHSA-j456-qg26-rqx4.json @@ -0,0 +1,64 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j456-qg26-rqx4", + "modified": "2025-03-31T21:32:50Z", + "published": "2025-03-31T21:32:50Z", + "aliases": [ + "CVE-2025-3015" + ], + "details": "A vulnerability classified as critical has been found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::ASEImporter::BuildUniqueRepresentation of the file code/AssetLib/ASE/ASELoader.cpp of the component ASE File Handler. The manipulation of the argument mIndices leads to out-of-bounds read. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 6.0 is able to address this issue. The patch is named 7c705fde418d68cca4e8eff56be01b2617b0d6fe. It is recommended to apply a patch to fix this issue.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3015" + }, + { + "type": "WEB", + "url": "https://github.com/assimp/assimp/issues/6021" + }, + { + "type": "WEB", + "url": "https://github.com/assimp/assimp/issues/6021#issue-2877378829" + }, + { + "type": "WEB", + "url": "https://github.com/assimp/assimp/pull/6045" + }, + { + "type": "WEB", + "url": "https://github.com/assimp/assimp/commit/7c705fde418d68cca4e8eff56be01b2617b0d6fe" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.302067" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.302067" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.524589" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T21:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mhwj-vqr2-3j7m/GHSA-mhwj-vqr2-3j7m.json b/advisories/unreviewed/2025/03/GHSA-mhwj-vqr2-3j7m/GHSA-mhwj-vqr2-3j7m.json index 2ac2be6dfc7..2eff8437759 100644 --- a/advisories/unreviewed/2025/03/GHSA-mhwj-vqr2-3j7m/GHSA-mhwj-vqr2-3j7m.json +++ b/advisories/unreviewed/2025/03/GHSA-mhwj-vqr2-3j7m/GHSA-mhwj-vqr2-3j7m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mhwj-vqr2-3j7m", - "modified": "2025-03-29T00:31:33Z", + "modified": "2025-03-31T21:32:45Z", "published": "2025-03-29T00:31:33Z", "aliases": [ "CVE-2025-28087" ], "details": "Sourcecodester Online Exam System 1.0 is vulnerable to SQL Injection via dash.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-28T22:15:17Z" diff --git a/advisories/unreviewed/2025/03/GHSA-mhxj-3vr2-vm4r/GHSA-mhxj-3vr2-vm4r.json b/advisories/unreviewed/2025/03/GHSA-mhxj-3vr2-vm4r/GHSA-mhxj-3vr2-vm4r.json new file mode 100644 index 00000000000..84dd7371522 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mhxj-3vr2-vm4r/GHSA-mhxj-3vr2-vm4r.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mhxj-3vr2-vm4r", + "modified": "2025-03-31T21:32:50Z", + "published": "2025-03-31T21:32:50Z", + "aliases": [ + "CVE-2024-54808" + ], + "details": "Netgear WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the SetDefaultConnectionService function due to an unconstrained use of sscanf. The vulnerability allows for control of the program counter and can be utilized to achieve arbitrary code execution.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54808" + }, + { + "type": "WEB", + "url": "https://faultpoint.com/post/2025-03-25-8-cves-on-the-wnr854t-junkyard/#808" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T21:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mpgp-fqh7-8mm2/GHSA-mpgp-fqh7-8mm2.json b/advisories/unreviewed/2025/03/GHSA-mpgp-fqh7-8mm2/GHSA-mpgp-fqh7-8mm2.json new file mode 100644 index 00000000000..fe7c591b1dc --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mpgp-fqh7-8mm2/GHSA-mpgp-fqh7-8mm2.json @@ -0,0 +1,60 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mpgp-fqh7-8mm2", + "modified": "2025-03-31T21:32:51Z", + "published": "2025-03-31T21:32:50Z", + "aliases": [ + "CVE-2025-3016" + ], + "details": "A vulnerability classified as problematic was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function Assimp::MDLImporter::ParseTextureColorData of the file code/AssetLib/MDL/MDLMaterialLoader.cpp of the component MDL File Handler. The manipulation of the argument mWidth/mHeight leads to resource consumption. The attack can be initiated remotely. Upgrading to version 6.0 is able to address this issue. The name of the patch is 5d2a7482312db2e866439a8c05a07ce1e718bed1. It is recommended to apply a patch to fix this issue.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3016" + }, + { + "type": "WEB", + "url": "https://github.com/assimp/assimp/issues/6022" + }, + { + "type": "WEB", + "url": "https://github.com/assimp/assimp/pull/6046" + }, + { + "type": "WEB", + "url": "https://github.com/assimp/assimp/commit/5d2a7482312db2e866439a8c05a07ce1e718bed1" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.302068" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.302068" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.524593" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T21:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-p736-g6pg-hjhw/GHSA-p736-g6pg-hjhw.json b/advisories/unreviewed/2025/03/GHSA-p736-g6pg-hjhw/GHSA-p736-g6pg-hjhw.json index f430e2db45d..44eec8decdf 100644 --- a/advisories/unreviewed/2025/03/GHSA-p736-g6pg-hjhw/GHSA-p736-g6pg-hjhw.json +++ b/advisories/unreviewed/2025/03/GHSA-p736-g6pg-hjhw/GHSA-p736-g6pg-hjhw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p736-g6pg-hjhw", - "modified": "2025-03-29T00:31:34Z", + "modified": "2025-03-31T21:32:46Z", "published": "2025-03-29T00:31:34Z", "aliases": [ "CVE-2025-28092" ], "details": "ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) via image upload function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-28T22:15:18Z" diff --git a/advisories/unreviewed/2025/03/GHSA-prxc-p2g7-m92v/GHSA-prxc-p2g7-m92v.json b/advisories/unreviewed/2025/03/GHSA-prxc-p2g7-m92v/GHSA-prxc-p2g7-m92v.json new file mode 100644 index 00000000000..19fca2f2c16 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-prxc-p2g7-m92v/GHSA-prxc-p2g7-m92v.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-prxc-p2g7-m92v", + "modified": "2025-03-31T21:32:48Z", + "published": "2025-03-31T21:32:48Z", + "aliases": [ + "CVE-2025-21893" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nkeys: Fix UAF in key_put()\n\nOnce a key's reference count has been reduced to 0, the garbage collector\nthread may destroy it at any time and so key_put() is not allowed to touch\nthe key after that point. The most key_put() is normally allowed to do is\nto touch key_gc_work as that's a static global variable.\n\nHowever, in an effort to speed up the reclamation of quota, this is now\ndone in key_put() once the key's usage is reduced to 0 - but now the code\nis looking at the key after the deadline, which is forbidden.\n\nFix this by using a flag to indicate that a key can be gc'd now rather than\nlooking at the key's refcount in the garbage collector.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21893" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6afe2ea2daec156bd94ad2c5a6f4f4c48240dcd3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/75845c6c1a64483e9985302793dbf0dfa5f71e32" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f6a3cf833188e897c97028cd7b926e3f2cb1a8c0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T20:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-q22h-369v-75m8/GHSA-q22h-369v-75m8.json b/advisories/unreviewed/2025/03/GHSA-q22h-369v-75m8/GHSA-q22h-369v-75m8.json new file mode 100644 index 00000000000..ada7c240814 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-q22h-369v-75m8/GHSA-q22h-369v-75m8.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q22h-369v-75m8", + "modified": "2025-03-31T21:32:48Z", + "published": "2025-03-31T21:32:48Z", + "aliases": [ + "CVE-2025-3008" + ], + "details": "A vulnerability classified as critical has been found in Novastar CX40 up to 2.44.0. Affected is the function system/popen of the file /usr/nova/bin/netconfig of the component NetFilter Utility. The manipulation leads to command injection. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3008" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.302058" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.302058" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.524869" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T19:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qp6q-xwww-8q6h/GHSA-qp6q-xwww-8q6h.json b/advisories/unreviewed/2025/03/GHSA-qp6q-xwww-8q6h/GHSA-qp6q-xwww-8q6h.json index a977aeb2537..c22d1de3a14 100644 --- a/advisories/unreviewed/2025/03/GHSA-qp6q-xwww-8q6h/GHSA-qp6q-xwww-8q6h.json +++ b/advisories/unreviewed/2025/03/GHSA-qp6q-xwww-8q6h/GHSA-qp6q-xwww-8q6h.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-rwcm-vvj8-qgg5/GHSA-rwcm-vvj8-qgg5.json b/advisories/unreviewed/2025/03/GHSA-rwcm-vvj8-qgg5/GHSA-rwcm-vvj8-qgg5.json index 388f70e951b..5d8329b3f91 100644 --- a/advisories/unreviewed/2025/03/GHSA-rwcm-vvj8-qgg5/GHSA-rwcm-vvj8-qgg5.json +++ b/advisories/unreviewed/2025/03/GHSA-rwcm-vvj8-qgg5/GHSA-rwcm-vvj8-qgg5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rwcm-vvj8-qgg5", - "modified": "2025-03-29T00:31:34Z", + "modified": "2025-03-31T21:32:46Z", "published": "2025-03-29T00:31:34Z", "aliases": [ "CVE-2025-28091" ], "details": "maccms10 v2025.1000.4047 has a Server-Side Request Forgery (SSRF) vulnerability via Add Article.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -17,11 +22,17 @@ { "type": "WEB", "url": "https://www.yuque.com/morysummer/vx41bz/ax55rxv4u3our1ic" + }, + { + "type": "WEB", + "url": "https://www.yuque.com/morysummer/vx41bz/xo5w1euakvtgenex" } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-918" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-28T22:15:18Z" diff --git a/advisories/unreviewed/2025/03/GHSA-vwg8-27rw-7g9v/GHSA-vwg8-27rw-7g9v.json b/advisories/unreviewed/2025/03/GHSA-vwg8-27rw-7g9v/GHSA-vwg8-27rw-7g9v.json new file mode 100644 index 00000000000..495431b83bf --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-vwg8-27rw-7g9v/GHSA-vwg8-27rw-7g9v.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vwg8-27rw-7g9v", + "modified": "2025-03-31T21:32:49Z", + "published": "2025-03-31T21:32:49Z", + "aliases": [ + "CVE-2024-54803" + ], + "details": "Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the nvram parameter pppoe_peer_mac and forcing a reboot. This will result in command injection.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54803" + }, + { + "type": "WEB", + "url": "https://faultpoint.com/post/2025-03-25-8-cves-on-the-wnr854t-junkyard/#803" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T21:15:47Z" + } +} \ No newline at end of file