diff --git a/advisories/unreviewed/2022/12/GHSA-2rqg-qj27-3wj5/GHSA-2rqg-qj27-3wj5.json b/advisories/unreviewed/2022/12/GHSA-2rqg-qj27-3wj5/GHSA-2rqg-qj27-3wj5.json index e45ccd0b123..9fe1b05b641 100644 --- a/advisories/unreviewed/2022/12/GHSA-2rqg-qj27-3wj5/GHSA-2rqg-qj27-3wj5.json +++ b/advisories/unreviewed/2022/12/GHSA-2rqg-qj27-3wj5/GHSA-2rqg-qj27-3wj5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2rqg-qj27-3wj5", - "modified": "2022-12-15T18:30:16Z", + "modified": "2025-04-22T21:30:38Z", "published": "2022-12-13T00:30:43Z", "aliases": [ "CVE-2021-41943" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-41943" }, + { + "type": "WEB", + "url": "https://medium.com/%40idema16/how-i-found-a-cve-in-logrhythm-cve-2021-41943-61cef1797cb" + }, { "type": "WEB", "url": "https://medium.com/@idema16/how-i-found-a-cve-in-logrhythm-cve-2021-41943-61cef1797cb" diff --git a/advisories/unreviewed/2022/12/GHSA-44x9-g356-qcmm/GHSA-44x9-g356-qcmm.json b/advisories/unreviewed/2022/12/GHSA-44x9-g356-qcmm/GHSA-44x9-g356-qcmm.json index 852bf1d2c53..0b6d669226f 100644 --- a/advisories/unreviewed/2022/12/GHSA-44x9-g356-qcmm/GHSA-44x9-g356-qcmm.json +++ b/advisories/unreviewed/2022/12/GHSA-44x9-g356-qcmm/GHSA-44x9-g356-qcmm.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-770" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-4pmx-vh95-832r/GHSA-4pmx-vh95-832r.json b/advisories/unreviewed/2022/12/GHSA-4pmx-vh95-832r/GHSA-4pmx-vh95-832r.json index 9383c506255..b635059c99e 100644 --- a/advisories/unreviewed/2022/12/GHSA-4pmx-vh95-832r/GHSA-4pmx-vh95-832r.json +++ b/advisories/unreviewed/2022/12/GHSA-4pmx-vh95-832r/GHSA-4pmx-vh95-832r.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-5xmr-4hp2-hm52/GHSA-5xmr-4hp2-hm52.json b/advisories/unreviewed/2022/12/GHSA-5xmr-4hp2-hm52/GHSA-5xmr-4hp2-hm52.json index 3a202336483..7081851f36d 100644 --- a/advisories/unreviewed/2022/12/GHSA-5xmr-4hp2-hm52/GHSA-5xmr-4hp2-hm52.json +++ b/advisories/unreviewed/2022/12/GHSA-5xmr-4hp2-hm52/GHSA-5xmr-4hp2-hm52.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-770" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-cpcw-3j2g-7q8g/GHSA-cpcw-3j2g-7q8g.json b/advisories/unreviewed/2022/12/GHSA-cpcw-3j2g-7q8g/GHSA-cpcw-3j2g-7q8g.json index de6de70354b..f9f30fdac67 100644 --- a/advisories/unreviewed/2022/12/GHSA-cpcw-3j2g-7q8g/GHSA-cpcw-3j2g-7q8g.json +++ b/advisories/unreviewed/2022/12/GHSA-cpcw-3j2g-7q8g/GHSA-cpcw-3j2g-7q8g.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-276" + "CWE-276", + "CWE-862" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-gfwq-rc4c-9m52/GHSA-gfwq-rc4c-9m52.json b/advisories/unreviewed/2022/12/GHSA-gfwq-rc4c-9m52/GHSA-gfwq-rc4c-9m52.json index 7976875f002..b4f5e86cf26 100644 --- a/advisories/unreviewed/2022/12/GHSA-gfwq-rc4c-9m52/GHSA-gfwq-rc4c-9m52.json +++ b/advisories/unreviewed/2022/12/GHSA-gfwq-rc4c-9m52/GHSA-gfwq-rc4c-9m52.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-r5m2-pqwj-6px8/GHSA-r5m2-pqwj-6px8.json b/advisories/unreviewed/2022/12/GHSA-r5m2-pqwj-6px8/GHSA-r5m2-pqwj-6px8.json index e6919e6fcaf..124f90af81d 100644 --- a/advisories/unreviewed/2022/12/GHSA-r5m2-pqwj-6px8/GHSA-r5m2-pqwj-6px8.json +++ b/advisories/unreviewed/2022/12/GHSA-r5m2-pqwj-6px8/GHSA-r5m2-pqwj-6px8.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-190" + "CWE-190", + "CWE-191" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-r62h-65cq-7gqr/GHSA-r62h-65cq-7gqr.json b/advisories/unreviewed/2022/12/GHSA-r62h-65cq-7gqr/GHSA-r62h-65cq-7gqr.json index 4753618bc37..d1cfe1ac0f4 100644 --- a/advisories/unreviewed/2022/12/GHSA-r62h-65cq-7gqr/GHSA-r62h-65cq-7gqr.json +++ b/advisories/unreviewed/2022/12/GHSA-r62h-65cq-7gqr/GHSA-r62h-65cq-7gqr.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-rg83-6m8j-p698/GHSA-rg83-6m8j-p698.json b/advisories/unreviewed/2022/12/GHSA-rg83-6m8j-p698/GHSA-rg83-6m8j-p698.json index c61aa3e8332..04a8fd5a604 100644 --- a/advisories/unreviewed/2022/12/GHSA-rg83-6m8j-p698/GHSA-rg83-6m8j-p698.json +++ b/advisories/unreviewed/2022/12/GHSA-rg83-6m8j-p698/GHSA-rg83-6m8j-p698.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-770" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-399c-6449-xhh6/GHSA-399c-6449-xhh6.json b/advisories/unreviewed/2023/07/GHSA-399c-6449-xhh6/GHSA-399c-6449-xhh6.json index 6182e7054fd..cc1ebb681cd 100644 --- a/advisories/unreviewed/2023/07/GHSA-399c-6449-xhh6/GHSA-399c-6449-xhh6.json +++ b/advisories/unreviewed/2023/07/GHSA-399c-6449-xhh6/GHSA-399c-6449-xhh6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-399c-6449-xhh6", - "modified": "2024-04-04T05:30:52Z", + "modified": "2025-04-22T21:30:37Z", "published": "2023-07-06T19:24:05Z", "aliases": [ "CVE-2022-25836" diff --git a/advisories/unreviewed/2023/07/GHSA-gcxw-4wrx-xhw5/GHSA-gcxw-4wrx-xhw5.json b/advisories/unreviewed/2023/07/GHSA-gcxw-4wrx-xhw5/GHSA-gcxw-4wrx-xhw5.json index cd1893cb201..17064e1db0c 100644 --- a/advisories/unreviewed/2023/07/GHSA-gcxw-4wrx-xhw5/GHSA-gcxw-4wrx-xhw5.json +++ b/advisories/unreviewed/2023/07/GHSA-gcxw-4wrx-xhw5/GHSA-gcxw-4wrx-xhw5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gcxw-4wrx-xhw5", - "modified": "2024-04-04T05:30:51Z", + "modified": "2025-04-22T21:30:37Z", "published": "2023-07-06T19:24:05Z", "aliases": [ "CVE-2022-25837" diff --git a/advisories/unreviewed/2025/01/GHSA-3vxc-4v34-7cvc/GHSA-3vxc-4v34-7cvc.json b/advisories/unreviewed/2025/01/GHSA-3vxc-4v34-7cvc/GHSA-3vxc-4v34-7cvc.json index 2d08a1bcac1..aef7842f86a 100644 --- a/advisories/unreviewed/2025/01/GHSA-3vxc-4v34-7cvc/GHSA-3vxc-4v34-7cvc.json +++ b/advisories/unreviewed/2025/01/GHSA-3vxc-4v34-7cvc/GHSA-3vxc-4v34-7cvc.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-jh6q-j2jh-mp6g/GHSA-jh6q-j2jh-mp6g.json b/advisories/unreviewed/2025/01/GHSA-jh6q-j2jh-mp6g/GHSA-jh6q-j2jh-mp6g.json index f901dbeacbb..d9932694343 100644 --- a/advisories/unreviewed/2025/01/GHSA-jh6q-j2jh-mp6g/GHSA-jh6q-j2jh-mp6g.json +++ b/advisories/unreviewed/2025/01/GHSA-jh6q-j2jh-mp6g/GHSA-jh6q-j2jh-mp6g.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-v5j2-wgv7-q2cg/GHSA-v5j2-wgv7-q2cg.json b/advisories/unreviewed/2025/01/GHSA-v5j2-wgv7-q2cg/GHSA-v5j2-wgv7-q2cg.json index 6cc6ab29ace..ab479549100 100644 --- a/advisories/unreviewed/2025/01/GHSA-v5j2-wgv7-q2cg/GHSA-v5j2-wgv7-q2cg.json +++ b/advisories/unreviewed/2025/01/GHSA-v5j2-wgv7-q2cg/GHSA-v5j2-wgv7-q2cg.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-25f3-5qr3-55jw/GHSA-25f3-5qr3-55jw.json b/advisories/unreviewed/2025/04/GHSA-25f3-5qr3-55jw/GHSA-25f3-5qr3-55jw.json new file mode 100644 index 00000000000..e5a041d2b6e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-25f3-5qr3-55jw/GHSA-25f3-5qr3-55jw.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-25f3-5qr3-55jw", + "modified": "2025-04-22T21:30:44Z", + "published": "2025-04-22T21:30:44Z", + "aliases": [ + "CVE-2025-29621" + ], + "details": "Francois Jacquet RosarioSIS v12.0.0 was discovered to contain a content spoofing vulnerability in the Theme configuration under the My Preferences module. This vulnerability allows attackers to manipulate application settings.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29621" + }, + { + "type": "WEB", + "url": "https://medium.com/@rudranshsinghrajpurohit/content-spoofing-vulnerability-in-rosariosis-student-information-system-f6101e1ff84d" + }, + { + "type": "WEB", + "url": "https://www.getastra.com/blog/vulnerability/content-spoofing-vulnerability-in-rosariosis-student-information-system" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-290" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T19:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4gmr-f766-822g/GHSA-4gmr-f766-822g.json b/advisories/unreviewed/2025/04/GHSA-4gmr-f766-822g/GHSA-4gmr-f766-822g.json index f97397251ad..224d4710289 100644 --- a/advisories/unreviewed/2025/04/GHSA-4gmr-f766-822g/GHSA-4gmr-f766-822g.json +++ b/advisories/unreviewed/2025/04/GHSA-4gmr-f766-822g/GHSA-4gmr-f766-822g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4gmr-f766-822g", - "modified": "2025-04-22T18:32:13Z", + "modified": "2025-04-22T21:30:44Z", "published": "2025-04-22T18:32:13Z", "aliases": [ "CVE-2025-43952" ], "details": "A cross-site scripting (reflected XSS) vulnerability was found in Mettler Toledo FreeWeight.Net Web Reports Viewer 8.4.0 (440). It allows an attacker to inject malicious scripts via the IW_SessionID_ parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-22T18:16:01Z" diff --git a/advisories/unreviewed/2025/04/GHSA-4qhj-jmx7-8mr8/GHSA-4qhj-jmx7-8mr8.json b/advisories/unreviewed/2025/04/GHSA-4qhj-jmx7-8mr8/GHSA-4qhj-jmx7-8mr8.json index c563afcfe37..e73c2aa17f5 100644 --- a/advisories/unreviewed/2025/04/GHSA-4qhj-jmx7-8mr8/GHSA-4qhj-jmx7-8mr8.json +++ b/advisories/unreviewed/2025/04/GHSA-4qhj-jmx7-8mr8/GHSA-4qhj-jmx7-8mr8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4qhj-jmx7-8mr8", - "modified": "2025-04-22T15:30:52Z", + "modified": "2025-04-22T21:30:43Z", "published": "2025-04-22T15:30:52Z", "aliases": [ "CVE-2024-40445" ], "details": "Directory Traversal vulnerability in forkosh Mime Tex before v.1.77 allows an attacker to execute arbitrary code via a crafted file upload", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-22T14:15:24Z" diff --git a/advisories/unreviewed/2025/04/GHSA-6qxc-wcv9-954v/GHSA-6qxc-wcv9-954v.json b/advisories/unreviewed/2025/04/GHSA-6qxc-wcv9-954v/GHSA-6qxc-wcv9-954v.json new file mode 100644 index 00000000000..95e881ee334 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6qxc-wcv9-954v/GHSA-6qxc-wcv9-954v.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6qxc-wcv9-954v", + "modified": "2025-04-22T21:30:44Z", + "published": "2025-04-22T21:30:44Z", + "aliases": [ + "CVE-2024-53568" + ], + "details": "A stored cross-site scripting (XSS) vulnerability in the Image Upload section of Volmarg Personal Management System v1.4.65 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the tag parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53568" + }, + { + "type": "WEB", + "url": "https://medium.com/@rudranshsinghrajpurohit/cve-2024-53568-stored-cross-site-scripting-xss-vulnerability-in-volmarg-personal-management-cfbaec55046f" + }, + { + "type": "WEB", + "url": "https://www.getastra.com/blog/vulnerability/cve-2024-53568stored-cross-site-scripting-xss-vulnerability-in-volmarg-personal-management-system" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T19:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7g6v-qm5p-vjvg/GHSA-7g6v-qm5p-vjvg.json b/advisories/unreviewed/2025/04/GHSA-7g6v-qm5p-vjvg/GHSA-7g6v-qm5p-vjvg.json new file mode 100644 index 00000000000..3022a90d4e7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7g6v-qm5p-vjvg/GHSA-7g6v-qm5p-vjvg.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7g6v-qm5p-vjvg", + "modified": "2025-04-22T21:30:44Z", + "published": "2025-04-22T21:30:44Z", + "aliases": [ + "CVE-2025-31327" + ], + "details": "SAP Field Logistics Manage Logistics application OData meta-data property is vulnerable to data tampering, due to which certain fields could be externally modified by an attacker causing low impact on integrity of the application. Confidentiality and availability are not impacted.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31327" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3359825" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-472" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T19:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9262-x7f9-6hfc/GHSA-9262-x7f9-6hfc.json b/advisories/unreviewed/2025/04/GHSA-9262-x7f9-6hfc/GHSA-9262-x7f9-6hfc.json index 1ddd14211c2..f3fbeb690d4 100644 --- a/advisories/unreviewed/2025/04/GHSA-9262-x7f9-6hfc/GHSA-9262-x7f9-6hfc.json +++ b/advisories/unreviewed/2025/04/GHSA-9262-x7f9-6hfc/GHSA-9262-x7f9-6hfc.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-434" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-c785-qf3f-59ww/GHSA-c785-qf3f-59ww.json b/advisories/unreviewed/2025/04/GHSA-c785-qf3f-59ww/GHSA-c785-qf3f-59ww.json index 67b28007f72..73d0b9d054d 100644 --- a/advisories/unreviewed/2025/04/GHSA-c785-qf3f-59ww/GHSA-c785-qf3f-59ww.json +++ b/advisories/unreviewed/2025/04/GHSA-c785-qf3f-59ww/GHSA-c785-qf3f-59ww.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c785-qf3f-59ww", - "modified": "2025-04-22T15:30:53Z", + "modified": "2025-04-22T21:30:43Z", "published": "2025-04-22T15:30:53Z", "aliases": [ "CVE-2025-29547" ], "details": "In Rollback Rx Professional 12.8.0.0, the driver file shieldm.sys allows local users to cause a denial of service because of a null pointer dereference from IOCtl 0x96202000.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-22T15:16:12Z" diff --git a/advisories/unreviewed/2025/04/GHSA-fpx3-h2pc-88vf/GHSA-fpx3-h2pc-88vf.json b/advisories/unreviewed/2025/04/GHSA-fpx3-h2pc-88vf/GHSA-fpx3-h2pc-88vf.json new file mode 100644 index 00000000000..6bf450d0a73 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fpx3-h2pc-88vf/GHSA-fpx3-h2pc-88vf.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fpx3-h2pc-88vf", + "modified": "2025-04-22T21:30:44Z", + "published": "2025-04-22T21:30:44Z", + "aliases": [ + "CVE-2025-26159" + ], + "details": "Laravel Starter 11.11.0 is vulnerable to Cross Site Scripting (XSS) in the tags feature. Any user with the ability of create or modify tags can inject malicious JavaScript code in the name field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26159" + }, + { + "type": "WEB", + "url": "https://github.com/nasirkhan/laravel-starter" + }, + { + "type": "WEB", + "url": "https://godbadtry.github.io/posts/CVE-2025-26159" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T20:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g3rf-4jv4-r299/GHSA-g3rf-4jv4-r299.json b/advisories/unreviewed/2025/04/GHSA-g3rf-4jv4-r299/GHSA-g3rf-4jv4-r299.json index 2e4f607425c..9a5e5d6d3c1 100644 --- a/advisories/unreviewed/2025/04/GHSA-g3rf-4jv4-r299/GHSA-g3rf-4jv4-r299.json +++ b/advisories/unreviewed/2025/04/GHSA-g3rf-4jv4-r299/GHSA-g3rf-4jv4-r299.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-g4pf-cgvj-hjjw/GHSA-g4pf-cgvj-hjjw.json b/advisories/unreviewed/2025/04/GHSA-g4pf-cgvj-hjjw/GHSA-g4pf-cgvj-hjjw.json new file mode 100644 index 00000000000..664492f4919 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g4pf-cgvj-hjjw/GHSA-g4pf-cgvj-hjjw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g4pf-cgvj-hjjw", + "modified": "2025-04-22T21:30:44Z", + "published": "2025-04-22T21:30:44Z", + "aliases": [ + "CVE-2025-23253" + ], + "details": "NVIDIA NvContainer service for Windows contains a vulnerability in its usage of OpenSSL, where an attacker could exploit a hard-coded constant issue by copying a malicious DLL in a hard-coded path. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23253" + }, + { + "type": "WEB", + "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5644" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-547" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T19:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gwvg-5xhp-rp5q/GHSA-gwvg-5xhp-rp5q.json b/advisories/unreviewed/2025/04/GHSA-gwvg-5xhp-rp5q/GHSA-gwvg-5xhp-rp5q.json new file mode 100644 index 00000000000..cbce62ebc56 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gwvg-5xhp-rp5q/GHSA-gwvg-5xhp-rp5q.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gwvg-5xhp-rp5q", + "modified": "2025-04-22T21:30:44Z", + "published": "2025-04-22T21:30:44Z", + "aliases": [ + "CVE-2025-37087" + ], + "details": "A vulnerability in the cmdb service of the HPE Performance Cluster Manager (HPCM) could allow an attacker to gain access to an arbitrary file on the server host.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37087" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/docDisplay?docLocale=en_US&docId=a00146087en_us" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T21:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m9hc-8hvg-f4hc/GHSA-m9hc-8hvg-f4hc.json b/advisories/unreviewed/2025/04/GHSA-m9hc-8hvg-f4hc/GHSA-m9hc-8hvg-f4hc.json index 0e0ebcc2ac5..74351b166d3 100644 --- a/advisories/unreviewed/2025/04/GHSA-m9hc-8hvg-f4hc/GHSA-m9hc-8hvg-f4hc.json +++ b/advisories/unreviewed/2025/04/GHSA-m9hc-8hvg-f4hc/GHSA-m9hc-8hvg-f4hc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m9hc-8hvg-f4hc", - "modified": "2025-04-22T18:32:11Z", + "modified": "2025-04-22T21:30:43Z", "published": "2025-04-22T18:32:11Z", "aliases": [ "CVE-2025-28031" ], "details": "TOTOLINK A810R V4.1.2cu.5182_B20201026 was discovered to contain a hardcoded password for the telnet service in product.ini.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-259" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-22T16:15:45Z" diff --git a/advisories/unreviewed/2025/04/GHSA-mfh8-744x-7fgf/GHSA-mfh8-744x-7fgf.json b/advisories/unreviewed/2025/04/GHSA-mfh8-744x-7fgf/GHSA-mfh8-744x-7fgf.json new file mode 100644 index 00000000000..dd4ab28b53d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mfh8-744x-7fgf/GHSA-mfh8-744x-7fgf.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mfh8-744x-7fgf", + "modified": "2025-04-22T21:30:44Z", + "published": "2025-04-22T21:30:44Z", + "aliases": [ + "CVE-2024-53569" + ], + "details": "A stored cross-site scripting (XSS) vulnerability in the New Goal Creation section of Volmarg Personal Management System v1.4.65 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the description parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53569" + }, + { + "type": "WEB", + "url": "https://medium.com/@rudranshsinghrajpurohit/cve-2024-53569-stored-cross-site-scripting-xss-in-volmarg-personal-management-system-6cb0b9d6fe88" + }, + { + "type": "WEB", + "url": "https://www.getastra.com/blog/vulnerability/cve-2024-53569stored-cross-site-scripting-xss-in-volmarg-personal-management-system" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T19:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pv6x-3vgc-wphq/GHSA-pv6x-3vgc-wphq.json b/advisories/unreviewed/2025/04/GHSA-pv6x-3vgc-wphq/GHSA-pv6x-3vgc-wphq.json index 900b866b700..c57dbe1d189 100644 --- a/advisories/unreviewed/2025/04/GHSA-pv6x-3vgc-wphq/GHSA-pv6x-3vgc-wphq.json +++ b/advisories/unreviewed/2025/04/GHSA-pv6x-3vgc-wphq/GHSA-pv6x-3vgc-wphq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pv6x-3vgc-wphq", - "modified": "2025-04-22T18:32:13Z", + "modified": "2025-04-22T21:30:44Z", "published": "2025-04-22T18:32:13Z", "aliases": [ "CVE-2025-43947" ], "details": "Codemers KLIMS 1.6.DEV lacks a proper access control mechanism, allowing a normal KLIMS user to perform all the actions that an admin can perform, such as modifying the configuration, creating a user, uploading files, etc.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-22T18:16:01Z" diff --git a/advisories/unreviewed/2025/04/GHSA-q6v5-58gv-cxgm/GHSA-q6v5-58gv-cxgm.json b/advisories/unreviewed/2025/04/GHSA-q6v5-58gv-cxgm/GHSA-q6v5-58gv-cxgm.json index f563bbb9ee3..b1047a12ee7 100644 --- a/advisories/unreviewed/2025/04/GHSA-q6v5-58gv-cxgm/GHSA-q6v5-58gv-cxgm.json +++ b/advisories/unreviewed/2025/04/GHSA-q6v5-58gv-cxgm/GHSA-q6v5-58gv-cxgm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q6v5-58gv-cxgm", - "modified": "2025-04-22T18:32:13Z", + "modified": "2025-04-22T21:30:44Z", "published": "2025-04-22T18:32:13Z", "aliases": [ "CVE-2025-43948" ], "details": "Codemers KLIMS 1.6.DEV allows Python code injection. A user can provide Python code as an input value for a parameter or qualifier (such as for sorting), which will get executed on the server side.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-22T18:16:01Z" diff --git a/advisories/unreviewed/2025/04/GHSA-q7h8-385m-x32m/GHSA-q7h8-385m-x32m.json b/advisories/unreviewed/2025/04/GHSA-q7h8-385m-x32m/GHSA-q7h8-385m-x32m.json new file mode 100644 index 00000000000..36cf6c3be17 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-q7h8-385m-x32m/GHSA-q7h8-385m-x32m.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q7h8-385m-x32m", + "modified": "2025-04-22T21:30:44Z", + "published": "2025-04-22T21:30:44Z", + "aliases": [ + "CVE-2025-31328" + ], + "details": "SAP Learning Solution is vulnerable to Cross-Site Request Forgery (CSRF), allowing an attacker to trick authenticated user into sending unintended requests to the server. GET-based OData function is named in a way that it violates the expected behaviour. This issue could impact both the confidentiality and integrity of the application without affecting the availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31328" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3446649" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T19:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qm42-2jf7-gc6x/GHSA-qm42-2jf7-gc6x.json b/advisories/unreviewed/2025/04/GHSA-qm42-2jf7-gc6x/GHSA-qm42-2jf7-gc6x.json index 2cadb9e662c..09dc94dfa0e 100644 --- a/advisories/unreviewed/2025/04/GHSA-qm42-2jf7-gc6x/GHSA-qm42-2jf7-gc6x.json +++ b/advisories/unreviewed/2025/04/GHSA-qm42-2jf7-gc6x/GHSA-qm42-2jf7-gc6x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qm42-2jf7-gc6x", - "modified": "2025-04-22T18:32:11Z", + "modified": "2025-04-22T21:30:43Z", "published": "2025-04-22T18:32:11Z", "aliases": [ "CVE-2024-33452" ], "details": "An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling via a crafted HEAD request.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-444" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-22T16:15:44Z" diff --git a/advisories/unreviewed/2025/04/GHSA-rg4f-867h-7x6w/GHSA-rg4f-867h-7x6w.json b/advisories/unreviewed/2025/04/GHSA-rg4f-867h-7x6w/GHSA-rg4f-867h-7x6w.json new file mode 100644 index 00000000000..c05d6c2ebc0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rg4f-867h-7x6w/GHSA-rg4f-867h-7x6w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rg4f-867h-7x6w", + "modified": "2025-04-22T21:30:44Z", + "published": "2025-04-22T21:30:44Z", + "aliases": [ + "CVE-2025-29743" + ], + "details": "D-Link DIR-816 A2V1.1.0B05 was found to contain a command injection in /goform/delRouting.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29743" + }, + { + "type": "WEB", + "url": "https://github.com/n0wstr/IOTVuln/blob/main/DIR-816/DelRouting/readme.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T20:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xpqm-g5q7-2r7x/GHSA-xpqm-g5q7-2r7x.json b/advisories/unreviewed/2025/04/GHSA-xpqm-g5q7-2r7x/GHSA-xpqm-g5q7-2r7x.json index 258b065b0f7..6734b588317 100644 --- a/advisories/unreviewed/2025/04/GHSA-xpqm-g5q7-2r7x/GHSA-xpqm-g5q7-2r7x.json +++ b/advisories/unreviewed/2025/04/GHSA-xpqm-g5q7-2r7x/GHSA-xpqm-g5q7-2r7x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xpqm-g5q7-2r7x", - "modified": "2025-04-22T18:32:12Z", + "modified": "2025-04-22T21:30:43Z", "published": "2025-04-22T18:32:12Z", "aliases": [ "CVE-2025-28038" ], "details": "TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setWebWlanIdx function through the webWlanIdx parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-22T18:15:59Z" diff --git a/advisories/unreviewed/2025/04/GHSA-xv7x-v825-68c4/GHSA-xv7x-v825-68c4.json b/advisories/unreviewed/2025/04/GHSA-xv7x-v825-68c4/GHSA-xv7x-v825-68c4.json index 14ccffd019e..758dc67a024 100644 --- a/advisories/unreviewed/2025/04/GHSA-xv7x-v825-68c4/GHSA-xv7x-v825-68c4.json +++ b/advisories/unreviewed/2025/04/GHSA-xv7x-v825-68c4/GHSA-xv7x-v825-68c4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xv7x-v825-68c4", - "modified": "2025-04-22T18:32:12Z", + "modified": "2025-04-22T21:30:43Z", "published": "2025-04-22T18:32:12Z", "aliases": [ "CVE-2025-28039" ], "details": "TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setUpgradeFW function through the FileName parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-22T18:15:59Z"