From 385ec93ff01a6645f6e549364f8aa63108f81eca Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 5 Jun 2025 00:32:53 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-76p7-773f-r4q5.json | 6 +- .../GHSA-2pr9-w7jf-v4v7.json | 14 ++++- .../GHSA-779w-7mcf-pvxf.json | 17 +++++- .../GHSA-865m-f7p5-xc5c.json | 21 ++++++- .../GHSA-c39v-2g86-xrr6.json | 17 +++++- .../GHSA-m2mx-5gcx-j288.json | 6 +- .../GHSA-p4jj-wjcf-vhhr.json | 14 ++++- .../GHSA-r4mh-c83r-pv4f.json | 17 +++++- .../GHSA-r5f2-9rjc-r66m.json | 17 +++++- .../GHSA-rhr8-h74g-4f3h.json | 17 +++++- .../GHSA-vq75-425f-vq6r.json | 17 +++++- .../GHSA-45qr-r98p-f6qx.json | 2 +- .../GHSA-2q5m-vpfx-7jxh.json | 2 +- .../GHSA-8388-vmf2-8gm7.json | 2 +- .../GHSA-97h8-p95j-8mhw.json | 2 +- .../GHSA-j7r8-r87g-9m3j.json | 2 +- .../GHSA-mcp3-v9r2-v7vp.json | 2 +- .../GHSA-pq56-qw5r-672m.json | 2 +- .../GHSA-766x-w9p6-xvv5.json | 56 +++++++++++++++++++ .../GHSA-cp34-r5vc-7cw6.json | 56 +++++++++++++++++++ .../GHSA-f87m-rhgw-vj35.json | 36 ++++++++++++ .../GHSA-ghrm-9c9c-3r5v.json | 56 +++++++++++++++++++ .../GHSA-h882-r4xj-2hcq.json | 56 +++++++++++++++++++ .../GHSA-j6wp-hqmg-gx4g.json | 56 +++++++++++++++++++ .../GHSA-pjv5-ghj3-79pm.json | 56 +++++++++++++++++++ .../GHSA-q445-fpwx-qv82.json | 56 +++++++++++++++++++ .../GHSA-rvhr-6hhp-7p92.json | 56 +++++++++++++++++++ .../GHSA-v8p3-7jrm-c3rr.json | 56 +++++++++++++++++++ .../GHSA-w864-966p-qw8j.json | 56 +++++++++++++++++++ .../GHSA-x38m-jw59-wx9h.json | 56 +++++++++++++++++++ 30 files changed, 794 insertions(+), 35 deletions(-) create mode 100644 advisories/unreviewed/2025/06/GHSA-766x-w9p6-xvv5/GHSA-766x-w9p6-xvv5.json create mode 100644 advisories/unreviewed/2025/06/GHSA-cp34-r5vc-7cw6/GHSA-cp34-r5vc-7cw6.json create mode 100644 advisories/unreviewed/2025/06/GHSA-f87m-rhgw-vj35/GHSA-f87m-rhgw-vj35.json create mode 100644 advisories/unreviewed/2025/06/GHSA-ghrm-9c9c-3r5v/GHSA-ghrm-9c9c-3r5v.json create mode 100644 advisories/unreviewed/2025/06/GHSA-h882-r4xj-2hcq/GHSA-h882-r4xj-2hcq.json create mode 100644 advisories/unreviewed/2025/06/GHSA-j6wp-hqmg-gx4g/GHSA-j6wp-hqmg-gx4g.json create mode 100644 advisories/unreviewed/2025/06/GHSA-pjv5-ghj3-79pm/GHSA-pjv5-ghj3-79pm.json create mode 100644 advisories/unreviewed/2025/06/GHSA-q445-fpwx-qv82/GHSA-q445-fpwx-qv82.json create mode 100644 advisories/unreviewed/2025/06/GHSA-rvhr-6hhp-7p92/GHSA-rvhr-6hhp-7p92.json create mode 100644 advisories/unreviewed/2025/06/GHSA-v8p3-7jrm-c3rr/GHSA-v8p3-7jrm-c3rr.json create mode 100644 advisories/unreviewed/2025/06/GHSA-w864-966p-qw8j/GHSA-w864-966p-qw8j.json create mode 100644 advisories/unreviewed/2025/06/GHSA-x38m-jw59-wx9h/GHSA-x38m-jw59-wx9h.json diff --git a/advisories/github-reviewed/2025/02/GHSA-76p7-773f-r4q5/GHSA-76p7-773f-r4q5.json b/advisories/github-reviewed/2025/02/GHSA-76p7-773f-r4q5/GHSA-76p7-773f-r4q5.json index f720dcbd6e3..ee38d395d77 100644 --- a/advisories/github-reviewed/2025/02/GHSA-76p7-773f-r4q5/GHSA-76p7-773f-r4q5.json +++ b/advisories/github-reviewed/2025/02/GHSA-76p7-773f-r4q5/GHSA-76p7-773f-r4q5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-76p7-773f-r4q5", - "modified": "2025-06-04T21:31:03Z", + "modified": "2025-06-05T00:31:18Z", "published": "2025-02-10T18:30:47Z", "aliases": [ "CVE-2024-11831" @@ -80,6 +80,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:8544" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:8551" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-11831" diff --git a/advisories/unreviewed/2022/05/GHSA-2pr9-w7jf-v4v7/GHSA-2pr9-w7jf-v4v7.json b/advisories/unreviewed/2022/05/GHSA-2pr9-w7jf-v4v7/GHSA-2pr9-w7jf-v4v7.json index 98693bce0f9..db29cc76612 100644 --- a/advisories/unreviewed/2022/05/GHSA-2pr9-w7jf-v4v7/GHSA-2pr9-w7jf-v4v7.json +++ b/advisories/unreviewed/2022/05/GHSA-2pr9-w7jf-v4v7/GHSA-2pr9-w7jf-v4v7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2pr9-w7jf-v4v7", - "modified": "2022-05-24T17:26:19Z", + "modified": "2025-06-05T00:31:18Z", "published": "2022-05-24T17:26:19Z", "aliases": [ "CVE-2020-16241" ], "details": "Philips SureSigns VS4, A.07.107 and prior. The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], "affected": [], "references": [ { @@ -17,10 +22,15 @@ { "type": "WEB", "url": "https://us-cert.cisa.gov/ics/advisories/icsma-20-233-01" + }, + { + "type": "WEB", + "url": "https://www.philips.com/a-w/security/security-advisories/product-security-2020.html#2020_archive" } ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-863" ], "severity": "LOW", diff --git a/advisories/unreviewed/2022/05/GHSA-779w-7mcf-pvxf/GHSA-779w-7mcf-pvxf.json b/advisories/unreviewed/2022/05/GHSA-779w-7mcf-pvxf/GHSA-779w-7mcf-pvxf.json index a30e0b13206..d4e944bfc4b 100644 --- a/advisories/unreviewed/2022/05/GHSA-779w-7mcf-pvxf/GHSA-779w-7mcf-pvxf.json +++ b/advisories/unreviewed/2022/05/GHSA-779w-7mcf-pvxf/GHSA-779w-7mcf-pvxf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-779w-7mcf-pvxf", - "modified": "2022-05-24T17:28:54Z", + "modified": "2025-06-05T00:31:18Z", "published": "2022-05-24T17:28:54Z", "aliases": [ "CVE-2020-14525" ], "details": "Philips Clinical Collaboration Platform, Versions 12.2.1 and prior. The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output used as a webpage that is served to other users.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -17,10 +22,16 @@ { "type": "WEB", "url": "https://us-cert.cisa.gov/ics/advisories/icsma-20-261-01" + }, + { + "type": "WEB", + "url": "https://www.philips.com/a-w/security/security-advisories/product-security-2020.html#2020_archive" } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-83" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-865m-f7p5-xc5c/GHSA-865m-f7p5-xc5c.json b/advisories/unreviewed/2022/05/GHSA-865m-f7p5-xc5c/GHSA-865m-f7p5-xc5c.json index eecb3abf7ad..4fbc513984c 100644 --- a/advisories/unreviewed/2022/05/GHSA-865m-f7p5-xc5c/GHSA-865m-f7p5-xc5c.json +++ b/advisories/unreviewed/2022/05/GHSA-865m-f7p5-xc5c/GHSA-865m-f7p5-xc5c.json @@ -1,26 +1,41 @@ { "schema_version": "1.4.0", "id": "GHSA-865m-f7p5-xc5c", - "modified": "2022-05-24T17:20:19Z", + "modified": "2025-06-05T00:31:18Z", "published": "2022-05-24T17:20:19Z", "aliases": [ "CVE-2020-12023" ], "details": "Philips IntelliBridge Enterprise (IBE), Versions B.12 and prior, IntelliBridge Enterprise system integration with SureSigns (VS4), EarlyVue (VS30) and IntelliVue Guardian (IGS). Unencrypted user credentials received in the IntelliBridge Enterprise (IBE) are logged within the transaction logs, which are secured behind the login based administrative web portal. The unencrypted user credentials sent from the affected products listed above, for the purpose of handshake or authentication with the Enterprise Systems, are logged as the payload in IntelliBridge Enterprise (IBE) within the transaction logs. An attacker with administrative privileges could exploit this vulnerability to read plain text credentials from log files.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-12023" }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-20-163-01" + }, + { + "type": "WEB", + "url": "https://www.philips.com/a-w/security/security-advisories/product-security-2020.html#2020_archive" + }, { "type": "WEB", "url": "https://www.us-cert.gov/ics/advisories/icsma-20-163-01" } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-532" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c39v-2g86-xrr6/GHSA-c39v-2g86-xrr6.json b/advisories/unreviewed/2022/05/GHSA-c39v-2g86-xrr6/GHSA-c39v-2g86-xrr6.json index 6e89bb3565f..92d648b51de 100644 --- a/advisories/unreviewed/2022/05/GHSA-c39v-2g86-xrr6/GHSA-c39v-2g86-xrr6.json +++ b/advisories/unreviewed/2022/05/GHSA-c39v-2g86-xrr6/GHSA-c39v-2g86-xrr6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c39v-2g86-xrr6", - "modified": "2022-05-24T17:26:18Z", + "modified": "2025-06-05T00:31:17Z", "published": "2022-05-24T17:26:18Z", "aliases": [ "CVE-2020-16237" ], "details": "Philips SureSigns VS4, A.07.107 and prior. The product receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data safely and correctly.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], "affected": [], "references": [ { @@ -17,10 +22,16 @@ { "type": "WEB", "url": "https://us-cert.cisa.gov/ics/advisories/icsma-20-233-01" + }, + { + "type": "WEB", + "url": "https://www.philips.com/a-w/security/security-advisories/product-security-2020.html#2020_archive" } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-20" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m2mx-5gcx-j288/GHSA-m2mx-5gcx-j288.json b/advisories/unreviewed/2022/05/GHSA-m2mx-5gcx-j288/GHSA-m2mx-5gcx-j288.json index 66b37e2576e..5c3ce5838b9 100644 --- a/advisories/unreviewed/2022/05/GHSA-m2mx-5gcx-j288/GHSA-m2mx-5gcx-j288.json +++ b/advisories/unreviewed/2022/05/GHSA-m2mx-5gcx-j288/GHSA-m2mx-5gcx-j288.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m2mx-5gcx-j288", - "modified": "2022-05-24T17:28:58Z", + "modified": "2025-06-05T00:31:18Z", "published": "2022-05-24T17:28:58Z", "aliases": [ "CVE-2020-16247" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://us-cert.cisa.gov/ics/advisories/icsma-20-261-01" + }, + { + "type": "WEB", + "url": "https://www.philips.com/a-w/security/security-advisories/product-security-2020.html#2020_archive" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/05/GHSA-p4jj-wjcf-vhhr/GHSA-p4jj-wjcf-vhhr.json b/advisories/unreviewed/2022/05/GHSA-p4jj-wjcf-vhhr/GHSA-p4jj-wjcf-vhhr.json index 8c315e954af..6973122f77e 100644 --- a/advisories/unreviewed/2022/05/GHSA-p4jj-wjcf-vhhr/GHSA-p4jj-wjcf-vhhr.json +++ b/advisories/unreviewed/2022/05/GHSA-p4jj-wjcf-vhhr/GHSA-p4jj-wjcf-vhhr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p4jj-wjcf-vhhr", - "modified": "2022-05-24T17:21:43Z", + "modified": "2025-06-05T00:31:18Z", "published": "2022-05-24T17:21:43Z", "aliases": [ "CVE-2020-14477" ], "details": "In Philips Ultrasound ClearVue Versions 3.2 and prior, Ultrasound CX Versions 5.0.2 and prior, Ultrasound EPIQ/Affiniti Versions VM5.0 and prior, Ultrasound Sparq Version 3.0.2 and prior and Ultrasound Xperius all versions, an attacker may use an alternate path or channel that does not require authentication of the alternate service login to view or modify information.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,7 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-287", + "CWE-288" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r4mh-c83r-pv4f/GHSA-r4mh-c83r-pv4f.json b/advisories/unreviewed/2022/05/GHSA-r4mh-c83r-pv4f/GHSA-r4mh-c83r-pv4f.json index 29ac0eb3e69..fac76b53750 100644 --- a/advisories/unreviewed/2022/05/GHSA-r4mh-c83r-pv4f/GHSA-r4mh-c83r-pv4f.json +++ b/advisories/unreviewed/2022/05/GHSA-r4mh-c83r-pv4f/GHSA-r4mh-c83r-pv4f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r4mh-c83r-pv4f", - "modified": "2022-05-24T17:28:58Z", + "modified": "2025-06-05T00:31:18Z", "published": "2022-05-24T17:28:58Z", "aliases": [ "CVE-2020-16198" ], "details": "Philips Clinical Collaboration Platform, Versions 12.2.1 and prior. When an attacker claims to have a given identity, the software does not prove or insufficiently proves the claim is correct.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -17,10 +22,16 @@ { "type": "WEB", "url": "https://us-cert.cisa.gov/ics/advisories/icsma-20-261-01" + }, + { + "type": "WEB", + "url": "https://www.philips.com/a-w/security/security-advisories/product-security-2020.html#2020_archive" } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-693" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r5f2-9rjc-r66m/GHSA-r5f2-9rjc-r66m.json b/advisories/unreviewed/2022/05/GHSA-r5f2-9rjc-r66m/GHSA-r5f2-9rjc-r66m.json index d0df1e7deab..b1d2d5d3161 100644 --- a/advisories/unreviewed/2022/05/GHSA-r5f2-9rjc-r66m/GHSA-r5f2-9rjc-r66m.json +++ b/advisories/unreviewed/2022/05/GHSA-r5f2-9rjc-r66m/GHSA-r5f2-9rjc-r66m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r5f2-9rjc-r66m", - "modified": "2022-05-24T17:26:19Z", + "modified": "2025-06-05T00:31:18Z", "published": "2022-05-24T17:26:19Z", "aliases": [ "CVE-2020-16239" ], "details": "Philips SureSigns VS4, A.07.107 and prior. When an actor claims to have a given identity, the software does not prove or insufficiently proves the claim is correct.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -17,10 +22,16 @@ { "type": "WEB", "url": "https://us-cert.cisa.gov/ics/advisories/icsma-20-233-01" + }, + { + "type": "WEB", + "url": "https://www.philips.com/a-w/security/security-advisories/product-security-2020.html#2020_archive" } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-287" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rhr8-h74g-4f3h/GHSA-rhr8-h74g-4f3h.json b/advisories/unreviewed/2022/05/GHSA-rhr8-h74g-4f3h/GHSA-rhr8-h74g-4f3h.json index e64f0b8053b..1c8634f9ffa 100644 --- a/advisories/unreviewed/2022/05/GHSA-rhr8-h74g-4f3h/GHSA-rhr8-h74g-4f3h.json +++ b/advisories/unreviewed/2022/05/GHSA-rhr8-h74g-4f3h/GHSA-rhr8-h74g-4f3h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rhr8-h74g-4f3h", - "modified": "2022-05-24T17:26:18Z", + "modified": "2025-06-05T00:31:17Z", "published": "2022-05-24T17:26:18Z", "aliases": [ "CVE-2020-14518" ], "details": "Philips DreamMapper, Version 2.24 and prior. Information written to log files can give guidance to a potential attacker.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -17,10 +22,16 @@ { "type": "WEB", "url": "https://us-cert.cisa.gov/ics/advisories/icsma-20-212-01" + }, + { + "type": "WEB", + "url": "https://www.philips.com/a-w/security/security-advisories/product-security-2020.html#2020_archive" } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-532" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vq75-425f-vq6r/GHSA-vq75-425f-vq6r.json b/advisories/unreviewed/2022/05/GHSA-vq75-425f-vq6r/GHSA-vq75-425f-vq6r.json index 3e978a92a9b..efb761fee99 100644 --- a/advisories/unreviewed/2022/05/GHSA-vq75-425f-vq6r/GHSA-vq75-425f-vq6r.json +++ b/advisories/unreviewed/2022/05/GHSA-vq75-425f-vq6r/GHSA-vq75-425f-vq6r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vq75-425f-vq6r", - "modified": "2022-05-24T17:28:58Z", + "modified": "2025-06-05T00:31:18Z", "published": "2022-05-24T17:28:58Z", "aliases": [ "CVE-2020-16200" ], "details": "Philips Clinical Collaboration Platform, Versions 12.2.1 and prior. The software does not properly control the allocation and maintenance of a limited resource, thereby enabling an attacker to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -17,10 +22,16 @@ { "type": "WEB", "url": "https://us-cert.cisa.gov/ics/advisories/icsma-20-261-01" + }, + { + "type": "WEB", + "url": "https://www.philips.com/a-w/security/security-advisories/product-security-2020.html#2020_archive" } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-757" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-45qr-r98p-f6qx/GHSA-45qr-r98p-f6qx.json b/advisories/unreviewed/2024/02/GHSA-45qr-r98p-f6qx/GHSA-45qr-r98p-f6qx.json index a5680d1a217..ab281a4e0ab 100644 --- a/advisories/unreviewed/2024/02/GHSA-45qr-r98p-f6qx/GHSA-45qr-r98p-f6qx.json +++ b/advisories/unreviewed/2024/02/GHSA-45qr-r98p-f6qx/GHSA-45qr-r98p-f6qx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-45qr-r98p-f6qx", - "modified": "2024-02-07T18:30:27Z", + "modified": "2025-06-05T00:31:18Z", "published": "2024-02-02T03:30:32Z", "aliases": [ "CVE-2024-22903" diff --git a/advisories/unreviewed/2025/04/GHSA-2q5m-vpfx-7jxh/GHSA-2q5m-vpfx-7jxh.json b/advisories/unreviewed/2025/04/GHSA-2q5m-vpfx-7jxh/GHSA-2q5m-vpfx-7jxh.json index 4c71f2189fb..61870c23bcb 100644 --- a/advisories/unreviewed/2025/04/GHSA-2q5m-vpfx-7jxh/GHSA-2q5m-vpfx-7jxh.json +++ b/advisories/unreviewed/2025/04/GHSA-2q5m-vpfx-7jxh/GHSA-2q5m-vpfx-7jxh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2q5m-vpfx-7jxh", - "modified": "2025-04-05T06:30:21Z", + "modified": "2025-06-05T00:31:18Z", "published": "2025-04-05T06:30:21Z", "aliases": [ "CVE-2025-2789" diff --git a/advisories/unreviewed/2025/04/GHSA-8388-vmf2-8gm7/GHSA-8388-vmf2-8gm7.json b/advisories/unreviewed/2025/04/GHSA-8388-vmf2-8gm7/GHSA-8388-vmf2-8gm7.json index ffe32630ab5..9c5ad74e26e 100644 --- a/advisories/unreviewed/2025/04/GHSA-8388-vmf2-8gm7/GHSA-8388-vmf2-8gm7.json +++ b/advisories/unreviewed/2025/04/GHSA-8388-vmf2-8gm7/GHSA-8388-vmf2-8gm7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8388-vmf2-8gm7", - "modified": "2025-04-12T09:30:30Z", + "modified": "2025-06-05T00:31:19Z", "published": "2025-04-12T09:30:30Z", "aliases": [ "CVE-2025-3276" diff --git a/advisories/unreviewed/2025/05/GHSA-97h8-p95j-8mhw/GHSA-97h8-p95j-8mhw.json b/advisories/unreviewed/2025/05/GHSA-97h8-p95j-8mhw/GHSA-97h8-p95j-8mhw.json index 58a84675b24..e48065f9949 100644 --- a/advisories/unreviewed/2025/05/GHSA-97h8-p95j-8mhw/GHSA-97h8-p95j-8mhw.json +++ b/advisories/unreviewed/2025/05/GHSA-97h8-p95j-8mhw/GHSA-97h8-p95j-8mhw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-97h8-p95j-8mhw", - "modified": "2025-05-08T12:34:30Z", + "modified": "2025-06-05T00:31:20Z", "published": "2025-05-08T12:34:30Z", "aliases": [ "CVE-2025-3862" diff --git a/advisories/unreviewed/2025/05/GHSA-j7r8-r87g-9m3j/GHSA-j7r8-r87g-9m3j.json b/advisories/unreviewed/2025/05/GHSA-j7r8-r87g-9m3j/GHSA-j7r8-r87g-9m3j.json index 2581206eadd..4791144c823 100644 --- a/advisories/unreviewed/2025/05/GHSA-j7r8-r87g-9m3j/GHSA-j7r8-r87g-9m3j.json +++ b/advisories/unreviewed/2025/05/GHSA-j7r8-r87g-9m3j/GHSA-j7r8-r87g-9m3j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j7r8-r87g-9m3j", - "modified": "2025-05-08T09:30:25Z", + "modified": "2025-06-05T00:31:19Z", "published": "2025-05-08T09:30:25Z", "aliases": [ "CVE-2025-4127" diff --git a/advisories/unreviewed/2025/05/GHSA-mcp3-v9r2-v7vp/GHSA-mcp3-v9r2-v7vp.json b/advisories/unreviewed/2025/05/GHSA-mcp3-v9r2-v7vp/GHSA-mcp3-v9r2-v7vp.json index 14a0236ce09..0d0aab11074 100644 --- a/advisories/unreviewed/2025/05/GHSA-mcp3-v9r2-v7vp/GHSA-mcp3-v9r2-v7vp.json +++ b/advisories/unreviewed/2025/05/GHSA-mcp3-v9r2-v7vp/GHSA-mcp3-v9r2-v7vp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mcp3-v9r2-v7vp", - "modified": "2025-05-19T06:30:35Z", + "modified": "2025-06-05T00:31:20Z", "published": "2025-05-19T06:30:35Z", "aliases": [ "CVE-2025-2892" diff --git a/advisories/unreviewed/2025/05/GHSA-pq56-qw5r-672m/GHSA-pq56-qw5r-672m.json b/advisories/unreviewed/2025/05/GHSA-pq56-qw5r-672m/GHSA-pq56-qw5r-672m.json index 188980e914f..40c8f678394 100644 --- a/advisories/unreviewed/2025/05/GHSA-pq56-qw5r-672m/GHSA-pq56-qw5r-672m.json +++ b/advisories/unreviewed/2025/05/GHSA-pq56-qw5r-672m/GHSA-pq56-qw5r-672m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pq56-qw5r-672m", - "modified": "2025-05-08T12:34:29Z", + "modified": "2025-06-05T00:31:19Z", "published": "2025-05-08T12:34:29Z", "aliases": [ "CVE-2025-3468" diff --git a/advisories/unreviewed/2025/06/GHSA-766x-w9p6-xvv5/GHSA-766x-w9p6-xvv5.json b/advisories/unreviewed/2025/06/GHSA-766x-w9p6-xvv5/GHSA-766x-w9p6-xvv5.json new file mode 100644 index 00000000000..0c6e772b170 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-766x-w9p6-xvv5/GHSA-766x-w9p6-xvv5.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-766x-w9p6-xvv5", + "modified": "2025-06-05T00:31:20Z", + "published": "2025-06-05T00:31:20Z", + "aliases": [ + "CVE-2025-5617" + ], + "details": "A vulnerability classified as critical has been found in PHPGurukul Online Fire Reporting System 1.2. This affects an unknown part of the file /admin/manage-teams.php. The manipulation of the argument teamid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5617" + }, + { + "type": "WEB", + "url": "https://github.com/YZS17/CVE/blob/main/Online_Fire_Reporting_System/sqli_admin_manage-teams.php_teamid.md" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311103" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311103" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.589113" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-04T23:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-cp34-r5vc-7cw6/GHSA-cp34-r5vc-7cw6.json b/advisories/unreviewed/2025/06/GHSA-cp34-r5vc-7cw6/GHSA-cp34-r5vc-7cw6.json new file mode 100644 index 00000000000..db3068fbfa7 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-cp34-r5vc-7cw6/GHSA-cp34-r5vc-7cw6.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cp34-r5vc-7cw6", + "modified": "2025-06-05T00:31:21Z", + "published": "2025-06-05T00:31:21Z", + "aliases": [ + "CVE-2025-5619" + ], + "details": "A vulnerability, which was classified as critical, has been found in Tenda CH22 1.0.0.1. This issue affects the function formaddUserName of the file /goform/addUserName. The manipulation of the argument Password leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5619" + }, + { + "type": "WEB", + "url": "https://github.com/xubeining/Cve_report/blob/main/A%20remote%20code%20execution%20vulnerability%20in%20the%20router%20CH22%20V1.0.0.1%20manufactured%20by%20Shenzhen%20Jixiangtengda%20Technology%20Co.%2C%20Ltd.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311105" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311105" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.589179" + }, + { + "type": "WEB", + "url": "https://www.tenda.com.cn" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-04T23:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-f87m-rhgw-vj35/GHSA-f87m-rhgw-vj35.json b/advisories/unreviewed/2025/06/GHSA-f87m-rhgw-vj35/GHSA-f87m-rhgw-vj35.json new file mode 100644 index 00000000000..724d5db883a --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-f87m-rhgw-vj35/GHSA-f87m-rhgw-vj35.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f87m-rhgw-vj35", + "modified": "2025-06-05T00:31:20Z", + "published": "2025-06-05T00:31:20Z", + "aliases": [ + "CVE-2025-5690" + ], + "details": "PostgreSQL Anonymizer v2.0 and v2.1 contain a vulnerability that allows a masked user to bypass the masking rules defined on a table and read the original data using a database cursor or the --insert option of pg_dump. This problem occurs only when dynamic masking is enabled, which is not the default setting. The problem is resolved in version 2.2.1", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5690" + }, + { + "type": "WEB", + "url": "https://gitlab.com/dalibo/postgresql_anonymizer/-/issues/531" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-04T22:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-ghrm-9c9c-3r5v/GHSA-ghrm-9c9c-3r5v.json b/advisories/unreviewed/2025/06/GHSA-ghrm-9c9c-3r5v/GHSA-ghrm-9c9c-3r5v.json new file mode 100644 index 00000000000..321b5a2beb2 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-ghrm-9c9c-3r5v/GHSA-ghrm-9c9c-3r5v.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ghrm-9c9c-3r5v", + "modified": "2025-06-05T00:31:20Z", + "published": "2025-06-05T00:31:20Z", + "aliases": [ + "CVE-2025-5618" + ], + "details": "A vulnerability classified as critical was found in PHPGurukul Online Fire Reporting System 1.2. This vulnerability affects unknown code of the file /admin/edit-team.php. The manipulation of the argument teamid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5618" + }, + { + "type": "WEB", + "url": "https://github.com/YZS17/CVE/blob/main/Online_Fire_Reporting_System/sqli_admin_edit-team.php_teamid.md" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311104" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311104" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.589117" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-04T23:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-h882-r4xj-2hcq/GHSA-h882-r4xj-2hcq.json b/advisories/unreviewed/2025/06/GHSA-h882-r4xj-2hcq/GHSA-h882-r4xj-2hcq.json new file mode 100644 index 00000000000..e661aee4d1a --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-h882-r4xj-2hcq/GHSA-h882-r4xj-2hcq.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h882-r4xj-2hcq", + "modified": "2025-06-05T00:31:21Z", + "published": "2025-06-05T00:31:21Z", + "aliases": [ + "CVE-2025-5622" + ], + "details": "A vulnerability was found in D-Link DIR-816 1.10CNB05 and classified as critical. Affected by this issue is the function wirelessApcli_5g of the file /goform/wirelessApcli_5g. The manipulation of the argument apcli_mode_5g/apcli_enc_5g/apcli_default_key_5g leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5622" + }, + { + "type": "WEB", + "url": "https://github.com/wudipjq/my_vuln/blob/main/D-Link5/vuln_50/50.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311108" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311108" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.589222" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-05T00:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-j6wp-hqmg-gx4g/GHSA-j6wp-hqmg-gx4g.json b/advisories/unreviewed/2025/06/GHSA-j6wp-hqmg-gx4g/GHSA-j6wp-hqmg-gx4g.json new file mode 100644 index 00000000000..c3bd45774d0 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-j6wp-hqmg-gx4g/GHSA-j6wp-hqmg-gx4g.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6wp-hqmg-gx4g", + "modified": "2025-06-05T00:31:21Z", + "published": "2025-06-05T00:31:21Z", + "aliases": [ + "CVE-2025-5621" + ], + "details": "A vulnerability has been found in D-Link DIR-816 1.10CNB05 and classified as critical. Affected by this vulnerability is the function qosClassifier of the file /goform/qosClassifier. The manipulation of the argument dip_address/sip_address leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5621" + }, + { + "type": "WEB", + "url": "https://github.com/wudipjq/my_vuln/blob/main/D-Link5/vuln_49/49.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311107" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311107" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.589221" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-05T00:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-pjv5-ghj3-79pm/GHSA-pjv5-ghj3-79pm.json b/advisories/unreviewed/2025/06/GHSA-pjv5-ghj3-79pm/GHSA-pjv5-ghj3-79pm.json new file mode 100644 index 00000000000..dae5441b6b8 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-pjv5-ghj3-79pm/GHSA-pjv5-ghj3-79pm.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pjv5-ghj3-79pm", + "modified": "2025-06-05T00:31:20Z", + "published": "2025-06-05T00:31:20Z", + "aliases": [ + "CVE-2025-5615" + ], + "details": "A vulnerability was found in PHPGurukul Online Fire Reporting System 1.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /details.php. The manipulation of the argument requestid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5615" + }, + { + "type": "WEB", + "url": "https://github.com/YZS17/CVE/blob/main/Online_Fire_Reporting_System/sqli_details.php_requestid.md" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311101" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311101" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.589108" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-04T22:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-q445-fpwx-qv82/GHSA-q445-fpwx-qv82.json b/advisories/unreviewed/2025/06/GHSA-q445-fpwx-qv82/GHSA-q445-fpwx-qv82.json new file mode 100644 index 00000000000..17264d71908 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-q445-fpwx-qv82/GHSA-q445-fpwx-qv82.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q445-fpwx-qv82", + "modified": "2025-06-05T00:31:21Z", + "published": "2025-06-05T00:31:21Z", + "aliases": [ + "CVE-2025-5620" + ], + "details": "A vulnerability, which was classified as critical, was found in D-Link DIR-816 1.10CNB05. Affected is the function setipsec_config of the file /goform/setipsec_config. The manipulation of the argument localIP/remoteIP leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5620" + }, + { + "type": "WEB", + "url": "https://github.com/wudipjq/my_vuln/blob/main/D-Link5/vuln_48/48.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311106" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311106" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.589220" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-05T00:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-rvhr-6hhp-7p92/GHSA-rvhr-6hhp-7p92.json b/advisories/unreviewed/2025/06/GHSA-rvhr-6hhp-7p92/GHSA-rvhr-6hhp-7p92.json new file mode 100644 index 00000000000..4b3c963c537 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-rvhr-6hhp-7p92/GHSA-rvhr-6hhp-7p92.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rvhr-6hhp-7p92", + "modified": "2025-06-05T00:31:20Z", + "published": "2025-06-05T00:31:20Z", + "aliases": [ + "CVE-2025-5613" + ], + "details": "A vulnerability was found in PHPGurukul Online Fire Reporting System 1.2 and classified as critical. This issue affects some unknown processing of the file /request-details.php. The manipulation of the argument requestid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5613" + }, + { + "type": "WEB", + "url": "https://github.com/YZS17/CVE/blob/main/Online_Fire_Reporting_System/sqli_request-details.php_requestid.md" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311099" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311099" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.589106" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-04T22:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-v8p3-7jrm-c3rr/GHSA-v8p3-7jrm-c3rr.json b/advisories/unreviewed/2025/06/GHSA-v8p3-7jrm-c3rr/GHSA-v8p3-7jrm-c3rr.json new file mode 100644 index 00000000000..98d77378812 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-v8p3-7jrm-c3rr/GHSA-v8p3-7jrm-c3rr.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v8p3-7jrm-c3rr", + "modified": "2025-06-05T00:31:21Z", + "published": "2025-06-05T00:31:21Z", + "aliases": [ + "CVE-2025-5623" + ], + "details": "A vulnerability was found in D-Link DIR-816 1.10CNB05. It has been classified as critical. This affects the function qosClassifier of the file /goform/qosClassifier. The manipulation of the argument dip_address/sip_address leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5623" + }, + { + "type": "WEB", + "url": "https://github.com/wudipjq/my_vuln/blob/main/D-Link5/vuln_51/51.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311109" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311109" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.589224" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-05T00:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-w864-966p-qw8j/GHSA-w864-966p-qw8j.json b/advisories/unreviewed/2025/06/GHSA-w864-966p-qw8j/GHSA-w864-966p-qw8j.json new file mode 100644 index 00000000000..6c81bd92b8c --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-w864-966p-qw8j/GHSA-w864-966p-qw8j.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w864-966p-qw8j", + "modified": "2025-06-05T00:31:20Z", + "published": "2025-06-05T00:31:20Z", + "aliases": [ + "CVE-2025-5616" + ], + "details": "A vulnerability was found in PHPGurukul Online Fire Reporting System 1.2. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/profile.php. The manipulation of the argument mobilenumber leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5616" + }, + { + "type": "WEB", + "url": "https://github.com/YZS17/CVE/blob/main/Online_Fire_Reporting_System/sqli_admin_profile.php_mobilenumber.md" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311102" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311102" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.589109" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-04T23:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-x38m-jw59-wx9h/GHSA-x38m-jw59-wx9h.json b/advisories/unreviewed/2025/06/GHSA-x38m-jw59-wx9h/GHSA-x38m-jw59-wx9h.json new file mode 100644 index 00000000000..2842cc2739e --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-x38m-jw59-wx9h/GHSA-x38m-jw59-wx9h.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x38m-jw59-wx9h", + "modified": "2025-06-05T00:31:20Z", + "published": "2025-06-05T00:31:20Z", + "aliases": [ + "CVE-2025-5614" + ], + "details": "A vulnerability was found in PHPGurukul Online Fire Reporting System 1.2. It has been classified as critical. Affected is an unknown function of the file /search-report-result.php. The manipulation of the argument serachdata leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5614" + }, + { + "type": "WEB", + "url": "https://github.com/YZS17/CVE/blob/main/Online_Fire_Reporting_System/sqli_search-report-result.php_searchdata.md" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311100" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311100" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.589107" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-04T22:15:26Z" + } +} \ No newline at end of file