diff --git a/advisories/unreviewed/2023/03/GHSA-5xvv-4r9w-mw22/GHSA-5xvv-4r9w-mw22.json b/advisories/unreviewed/2023/03/GHSA-5xvv-4r9w-mw22/GHSA-5xvv-4r9w-mw22.json index a46ec55dfa0..92a4ac31cbd 100644 --- a/advisories/unreviewed/2023/03/GHSA-5xvv-4r9w-mw22/GHSA-5xvv-4r9w-mw22.json +++ b/advisories/unreviewed/2023/03/GHSA-5xvv-4r9w-mw22/GHSA-5xvv-4r9w-mw22.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-20" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-89r7-5w6c-hqpp/GHSA-89r7-5w6c-hqpp.json b/advisories/unreviewed/2023/03/GHSA-89r7-5w6c-hqpp/GHSA-89r7-5w6c-hqpp.json index 7120c8a56ea..268e6bfcc59 100644 --- a/advisories/unreviewed/2023/03/GHSA-89r7-5w6c-hqpp/GHSA-89r7-5w6c-hqpp.json +++ b/advisories/unreviewed/2023/03/GHSA-89r7-5w6c-hqpp/GHSA-89r7-5w6c-hqpp.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-665" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-fh7h-m5x3-9v4g/GHSA-fh7h-m5x3-9v4g.json b/advisories/unreviewed/2023/03/GHSA-fh7h-m5x3-9v4g/GHSA-fh7h-m5x3-9v4g.json index fb467bc865d..c9e5da9f854 100644 --- a/advisories/unreviewed/2023/03/GHSA-fh7h-m5x3-9v4g/GHSA-fh7h-m5x3-9v4g.json +++ b/advisories/unreviewed/2023/03/GHSA-fh7h-m5x3-9v4g/GHSA-fh7h-m5x3-9v4g.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-hjmv-7x32-qx8w/GHSA-hjmv-7x32-qx8w.json b/advisories/unreviewed/2023/03/GHSA-hjmv-7x32-qx8w/GHSA-hjmv-7x32-qx8w.json index b0f85288f17..653d335bc0f 100644 --- a/advisories/unreviewed/2023/03/GHSA-hjmv-7x32-qx8w/GHSA-hjmv-7x32-qx8w.json +++ b/advisories/unreviewed/2023/03/GHSA-hjmv-7x32-qx8w/GHSA-hjmv-7x32-qx8w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hjmv-7x32-qx8w", - "modified": "2023-03-16T15:30:19Z", + "modified": "2025-02-28T18:30:52Z", "published": "2023-03-10T00:30:15Z", "aliases": [ "CVE-2021-34125" @@ -53,7 +53,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-w7j6-m5pm-5f26/GHSA-w7j6-m5pm-5f26.json b/advisories/unreviewed/2023/03/GHSA-w7j6-m5pm-5f26/GHSA-w7j6-m5pm-5f26.json index 182d779dda6..0ee7e057dad 100644 --- a/advisories/unreviewed/2023/03/GHSA-w7j6-m5pm-5f26/GHSA-w7j6-m5pm-5f26.json +++ b/advisories/unreviewed/2023/03/GHSA-w7j6-m5pm-5f26/GHSA-w7j6-m5pm-5f26.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-59" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-26gv-chv5-g7q6/GHSA-26gv-chv5-g7q6.json b/advisories/unreviewed/2025/02/GHSA-26gv-chv5-g7q6/GHSA-26gv-chv5-g7q6.json new file mode 100644 index 00000000000..219c5ba1d87 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-26gv-chv5-g7q6/GHSA-26gv-chv5-g7q6.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-26gv-chv5-g7q6", + "modified": "2025-02-28T18:31:04Z", + "published": "2025-02-28T18:31:04Z", + "aliases": [ + "CVE-2025-20060" + ], + "details": "An attacker could expose cross-user personal identifiable information (PII) and personal health information transmitted to the Android device via the Dario Health application database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20060" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-058-01" + }, + { + "type": "WEB", + "url": "https://www.dariohealth.com/contact" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-359" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-28T17:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-3346-684m-gqjw/GHSA-3346-684m-gqjw.json b/advisories/unreviewed/2025/02/GHSA-3346-684m-gqjw/GHSA-3346-684m-gqjw.json new file mode 100644 index 00000000000..b7fbac16070 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-3346-684m-gqjw/GHSA-3346-684m-gqjw.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3346-684m-gqjw", + "modified": "2025-02-28T18:31:04Z", + "published": "2025-02-28T18:31:04Z", + "aliases": [ + "CVE-2025-20049" + ], + "details": "The Dario Health portal service application is vulnerable to XSS, which could allow an attacker to obtain sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20049" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-058-01" + }, + { + "type": "WEB", + "url": "https://www.dariohealth.com/contact" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-28T17:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-3pmf-5hr9-r9r6/GHSA-3pmf-5hr9-r9r6.json b/advisories/unreviewed/2025/02/GHSA-3pmf-5hr9-r9r6/GHSA-3pmf-5hr9-r9r6.json index 6b2036f1a73..6dbe950dc72 100644 --- a/advisories/unreviewed/2025/02/GHSA-3pmf-5hr9-r9r6/GHSA-3pmf-5hr9-r9r6.json +++ b/advisories/unreviewed/2025/02/GHSA-3pmf-5hr9-r9r6/GHSA-3pmf-5hr9-r9r6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3pmf-5hr9-r9r6", - "modified": "2025-02-27T21:32:17Z", + "modified": "2025-02-28T18:31:01Z", "published": "2025-02-27T21:32:17Z", "aliases": [ "CVE-2024-41336" ], "details": "Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2133/2762/2832 prior to v3.9.8, Vigor 2135/2765/2766 prior to v4.4.5.1, Vigor 2865/2866/2927 prior to v4.4.5.3, Vigor 2962/3910 prior to v4.3.2.7, Vigor 3912 prior to v4.3.5.2, and Vigor 2925 up to v3.9.6 were discovered to store passwords in plaintext.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-256" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T21:15:36Z" diff --git a/advisories/unreviewed/2025/02/GHSA-3qf8-ww35-9vjg/GHSA-3qf8-ww35-9vjg.json b/advisories/unreviewed/2025/02/GHSA-3qf8-ww35-9vjg/GHSA-3qf8-ww35-9vjg.json index 88560b092a6..3f57c5d99a6 100644 --- a/advisories/unreviewed/2025/02/GHSA-3qf8-ww35-9vjg/GHSA-3qf8-ww35-9vjg.json +++ b/advisories/unreviewed/2025/02/GHSA-3qf8-ww35-9vjg/GHSA-3qf8-ww35-9vjg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3qf8-ww35-9vjg", - "modified": "2025-02-28T00:30:51Z", + "modified": "2025-02-28T18:31:02Z", "published": "2025-02-28T00:30:51Z", "aliases": [ "CVE-2025-26325" ], "details": "ShopXO 6.4.0 is vulnerable to File Upload in ThemeDataService.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T22:15:39Z" diff --git a/advisories/unreviewed/2025/02/GHSA-45qm-3p86-7499/GHSA-45qm-3p86-7499.json b/advisories/unreviewed/2025/02/GHSA-45qm-3p86-7499/GHSA-45qm-3p86-7499.json index 4572f54d1b3..302138ed3b5 100644 --- a/advisories/unreviewed/2025/02/GHSA-45qm-3p86-7499/GHSA-45qm-3p86-7499.json +++ b/advisories/unreviewed/2025/02/GHSA-45qm-3p86-7499/GHSA-45qm-3p86-7499.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-45qm-3p86-7499", - "modified": "2025-02-14T18:30:51Z", + "modified": "2025-02-28T18:30:58Z", "published": "2025-02-14T18:30:51Z", "aliases": [ "CVE-2024-56973" ], "details": "Insecure Permissions vulnerability in Alvaria, Inc Unified IP Unified Director before v.7.2SP2 allows a remote attacker to execute arbitrary code via the source and filename parameters to the ProcessUploadFromURL.jsp component.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-281" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-14T16:15:34Z" diff --git a/advisories/unreviewed/2025/02/GHSA-47m2-cqqx-crjc/GHSA-47m2-cqqx-crjc.json b/advisories/unreviewed/2025/02/GHSA-47m2-cqqx-crjc/GHSA-47m2-cqqx-crjc.json new file mode 100644 index 00000000000..8f1b40a7c50 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-47m2-cqqx-crjc/GHSA-47m2-cqqx-crjc.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-47m2-cqqx-crjc", + "modified": "2025-02-28T18:31:05Z", + "published": "2025-02-28T18:31:04Z", + "aliases": [ + "CVE-2025-24318" + ], + "details": "Cookie policy is observable via built-in browser tools. In the presence of XSS, this could lead to full session compromise.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24318" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-058-01" + }, + { + "type": "WEB", + "url": "https://www.dariohealth.com/contact" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1004" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-28T17:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-53j9-5hmj-8v9f/GHSA-53j9-5hmj-8v9f.json b/advisories/unreviewed/2025/02/GHSA-53j9-5hmj-8v9f/GHSA-53j9-5hmj-8v9f.json index 74829c9a131..9da14f685ae 100644 --- a/advisories/unreviewed/2025/02/GHSA-53j9-5hmj-8v9f/GHSA-53j9-5hmj-8v9f.json +++ b/advisories/unreviewed/2025/02/GHSA-53j9-5hmj-8v9f/GHSA-53j9-5hmj-8v9f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-53j9-5hmj-8v9f", - "modified": "2025-02-28T00:30:52Z", + "modified": "2025-02-28T18:31:03Z", "published": "2025-02-28T00:30:51Z", "aliases": [ "CVE-2024-37566" ], "details": "Infoblox NIOS through 8.6.4 has Improper Authentication for Grids.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T23:15:37Z" diff --git a/advisories/unreviewed/2025/02/GHSA-53x3-6ggr-2vp5/GHSA-53x3-6ggr-2vp5.json b/advisories/unreviewed/2025/02/GHSA-53x3-6ggr-2vp5/GHSA-53x3-6ggr-2vp5.json new file mode 100644 index 00000000000..4cef0848000 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-53x3-6ggr-2vp5/GHSA-53x3-6ggr-2vp5.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-53x3-6ggr-2vp5", + "modified": "2025-02-28T18:31:04Z", + "published": "2025-02-28T18:31:04Z", + "aliases": [ + "CVE-2025-26263" + ], + "details": "GeoVision ASManager Windows desktop application with the version 6.1.2.0 or less, is vulnerable to credentials disclosure due to improper memory handling in the ASManagerService.exe process.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26263" + }, + { + "type": "WEB", + "url": "https://github.com/DRAGOWN/CVE-2025-26263" + }, + { + "type": "WEB", + "url": "https://www.geovision.com.tw/download/product/GV-ASManager" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-28T16:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-5mwf-pvj7-8qj6/GHSA-5mwf-pvj7-8qj6.json b/advisories/unreviewed/2025/02/GHSA-5mwf-pvj7-8qj6/GHSA-5mwf-pvj7-8qj6.json index 737f3a98906..5ac43793988 100644 --- a/advisories/unreviewed/2025/02/GHSA-5mwf-pvj7-8qj6/GHSA-5mwf-pvj7-8qj6.json +++ b/advisories/unreviewed/2025/02/GHSA-5mwf-pvj7-8qj6/GHSA-5mwf-pvj7-8qj6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5mwf-pvj7-8qj6", - "modified": "2025-02-27T18:31:14Z", + "modified": "2025-02-28T18:31:00Z", "published": "2025-02-27T18:31:14Z", "aliases": [ "CVE-2025-25331" ], "details": "An issue in Beitatong Technology LianJia iOS 9.83.50 allows attackers to access sensitive user information via supplying a crafted link.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-84" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T16:15:40Z" diff --git a/advisories/unreviewed/2025/02/GHSA-62rc-944q-7vq6/GHSA-62rc-944q-7vq6.json b/advisories/unreviewed/2025/02/GHSA-62rc-944q-7vq6/GHSA-62rc-944q-7vq6.json new file mode 100644 index 00000000000..327fbf9663d --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-62rc-944q-7vq6/GHSA-62rc-944q-7vq6.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62rc-944q-7vq6", + "modified": "2025-02-28T18:31:05Z", + "published": "2025-02-28T18:31:04Z", + "aliases": [ + "CVE-2025-23405" + ], + "details": "Unauthenticated log effects metrics gathering incident response efforts and potentially exposes risk of injection attacks (ex log injection).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23405" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-058-01" + }, + { + "type": "WEB", + "url": "https://www.dariohealth.com/contact" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-117" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-28T17:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-65hc-mhvg-x697/GHSA-65hc-mhvg-x697.json b/advisories/unreviewed/2025/02/GHSA-65hc-mhvg-x697/GHSA-65hc-mhvg-x697.json index a5b31a1994e..fe5094c6dda 100644 --- a/advisories/unreviewed/2025/02/GHSA-65hc-mhvg-x697/GHSA-65hc-mhvg-x697.json +++ b/advisories/unreviewed/2025/02/GHSA-65hc-mhvg-x697/GHSA-65hc-mhvg-x697.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-65hc-mhvg-x697", - "modified": "2025-02-27T18:31:14Z", + "modified": "2025-02-28T18:31:00Z", "published": "2025-02-27T18:31:14Z", "aliases": [ "CVE-2025-25330" ], "details": "An issue in Boohee Technology Boohee Health iOS 13.0.13 allows attackers to access sensitive user information via supplying a crafted link.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-84" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T16:15:40Z" diff --git a/advisories/unreviewed/2025/02/GHSA-79wv-5cfm-5wm8/GHSA-79wv-5cfm-5wm8.json b/advisories/unreviewed/2025/02/GHSA-79wv-5cfm-5wm8/GHSA-79wv-5cfm-5wm8.json new file mode 100644 index 00000000000..406ee13d245 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-79wv-5cfm-5wm8/GHSA-79wv-5cfm-5wm8.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-79wv-5cfm-5wm8", + "modified": "2025-02-28T18:31:04Z", + "published": "2025-02-28T18:31:04Z", + "aliases": [ + "CVE-2024-44754" + ], + "details": "Cryptographic key extraction from internal flash in Minut M2 with firmware version #15142 allows physically proximate attackers to inject modified firmware into any other Minut M2 product via USB.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44754" + }, + { + "type": "WEB", + "url": "https://www.amlisoft.se/sec_20241114.html" + }, + { + "type": "WEB", + "url": "http://minut.com" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-28T16:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-85x2-vg3f-pxwm/GHSA-85x2-vg3f-pxwm.json b/advisories/unreviewed/2025/02/GHSA-85x2-vg3f-pxwm/GHSA-85x2-vg3f-pxwm.json new file mode 100644 index 00000000000..18b95e9c589 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-85x2-vg3f-pxwm/GHSA-85x2-vg3f-pxwm.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-85x2-vg3f-pxwm", + "modified": "2025-02-28T18:31:05Z", + "published": "2025-02-28T18:31:04Z", + "aliases": [ + "CVE-2025-24316" + ], + "details": "The Dario Health Internet-based server infrastructure is vulnerable due to exposure of development environment details, which could lead to unsafe functionality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24316" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-058-01" + }, + { + "type": "WEB", + "url": "https://www.dariohealth.com/contact" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-213" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-28T17:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-8qhp-xq5c-cg2r/GHSA-8qhp-xq5c-cg2r.json b/advisories/unreviewed/2025/02/GHSA-8qhp-xq5c-cg2r/GHSA-8qhp-xq5c-cg2r.json new file mode 100644 index 00000000000..3aa2dc52718 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-8qhp-xq5c-cg2r/GHSA-8qhp-xq5c-cg2r.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8qhp-xq5c-cg2r", + "modified": "2025-02-28T18:31:05Z", + "published": "2025-02-28T18:31:05Z", + "aliases": [ + "CVE-2025-24849" + ], + "details": "Lack of encryption in transit for cloud infrastructure facilitating potential for sensitive data manipulation or exposure.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24849" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-058-01" + }, + { + "type": "WEB", + "url": "https://www.dariohealth.com/contact" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-319" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-28T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-8vc4-8cgc-2m74/GHSA-8vc4-8cgc-2m74.json b/advisories/unreviewed/2025/02/GHSA-8vc4-8cgc-2m74/GHSA-8vc4-8cgc-2m74.json index 15ebb7b0241..486a5d0fb1e 100644 --- a/advisories/unreviewed/2025/02/GHSA-8vc4-8cgc-2m74/GHSA-8vc4-8cgc-2m74.json +++ b/advisories/unreviewed/2025/02/GHSA-8vc4-8cgc-2m74/GHSA-8vc4-8cgc-2m74.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8vc4-8cgc-2m74", - "modified": "2025-02-28T00:30:52Z", + "modified": "2025-02-28T18:31:03Z", "published": "2025-02-28T00:30:52Z", "aliases": [ "CVE-2025-25729" ], "details": "An information disclosure vulnerability in Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 allows attackers to obtain hardcoded cleartext credentials via the update or boot process.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-28T00:15:36Z" diff --git a/advisories/unreviewed/2025/02/GHSA-92hm-vx54-jg8m/GHSA-92hm-vx54-jg8m.json b/advisories/unreviewed/2025/02/GHSA-92hm-vx54-jg8m/GHSA-92hm-vx54-jg8m.json index 7307eceef44..0243d5a0199 100644 --- a/advisories/unreviewed/2025/02/GHSA-92hm-vx54-jg8m/GHSA-92hm-vx54-jg8m.json +++ b/advisories/unreviewed/2025/02/GHSA-92hm-vx54-jg8m/GHSA-92hm-vx54-jg8m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-92hm-vx54-jg8m", - "modified": "2025-02-27T21:32:17Z", + "modified": "2025-02-28T18:31:00Z", "published": "2025-02-27T21:32:17Z", "aliases": [ "CVE-2024-41334" ], "details": "Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2133/2762/2832 prior to v3.9.8, Vigor 2135/2765/2766 prior to v4.4.5.1, Vigor 2865/2866/2927 prior to v4.4.5.3, Vigor 2962/3910 prior to v4.3.2.7, Vigor 3912 prior to v4.3.5.2, and Vigor 2925 up to v3.9.6 were discovered to not utilize certificate verification, allowing attackers to upload crafted APPE modules from non-official servers, leading to arbitrary code execution.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T21:15:36Z" diff --git a/advisories/unreviewed/2025/02/GHSA-9c2w-rfmh-q65f/GHSA-9c2w-rfmh-q65f.json b/advisories/unreviewed/2025/02/GHSA-9c2w-rfmh-q65f/GHSA-9c2w-rfmh-q65f.json index 7f930e36ecd..a4e9ce66241 100644 --- a/advisories/unreviewed/2025/02/GHSA-9c2w-rfmh-q65f/GHSA-9c2w-rfmh-q65f.json +++ b/advisories/unreviewed/2025/02/GHSA-9c2w-rfmh-q65f/GHSA-9c2w-rfmh-q65f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9c2w-rfmh-q65f", - "modified": "2025-02-28T00:30:51Z", + "modified": "2025-02-28T18:31:02Z", "published": "2025-02-28T00:30:51Z", "aliases": [ "CVE-2025-26264" ], "details": "GeoVision GV-ASWeb with the version 6.1.2.0 or less, contains a Remote Code Execution (RCE) vulnerability within its Notification Settings feature. An authenticated attacker with \"System Settings\" privileges in ASWeb can exploit this flaw to execute arbitrary commands on the server, leading to a full system compromise.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T22:15:38Z" diff --git a/advisories/unreviewed/2025/02/GHSA-9h7g-r8hc-vrmp/GHSA-9h7g-r8hc-vrmp.json b/advisories/unreviewed/2025/02/GHSA-9h7g-r8hc-vrmp/GHSA-9h7g-r8hc-vrmp.json new file mode 100644 index 00000000000..fcd2df38b7f --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-9h7g-r8hc-vrmp/GHSA-9h7g-r8hc-vrmp.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9h7g-r8hc-vrmp", + "modified": "2025-02-28T18:31:05Z", + "published": "2025-02-28T18:31:05Z", + "aliases": [ + "CVE-2025-25431" + ], + "details": "Trendnet TEW-929DRU 1.0.0.10 contains a Stored Cross-site Scripting (XSS) vulnerability via the The ssid key of wifi_data parameter on the /captive_portal.htm page.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25431" + }, + { + "type": "WEB", + "url": "https://instinctive-acapella-fc7.notion.site/Trendnet-TEW-929DRU-XSS-17b15d9d4d26806a90f3d830a6143ebe" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-28T18:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-9w44-6hcw-v783/GHSA-9w44-6hcw-v783.json b/advisories/unreviewed/2025/02/GHSA-9w44-6hcw-v783/GHSA-9w44-6hcw-v783.json new file mode 100644 index 00000000000..aaba513e0eb --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-9w44-6hcw-v783/GHSA-9w44-6hcw-v783.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9w44-6hcw-v783", + "modified": "2025-02-28T18:31:05Z", + "published": "2025-02-28T18:31:04Z", + "aliases": [ + "CVE-2025-24843" + ], + "details": "Insecure file retrieval process that facilitates potential for file manipulation to affect product stability and confidentiality, integrity, authenticity, and attestation of stored data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24843" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-058-01" + }, + { + "type": "WEB", + "url": "https://www.dariohealth.com/contact" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-921" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-28T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-cpr3-4f88-q3jq/GHSA-cpr3-4f88-q3jq.json b/advisories/unreviewed/2025/02/GHSA-cpr3-4f88-q3jq/GHSA-cpr3-4f88-q3jq.json index d5cbaaabbe0..16e565ce15a 100644 --- a/advisories/unreviewed/2025/02/GHSA-cpr3-4f88-q3jq/GHSA-cpr3-4f88-q3jq.json +++ b/advisories/unreviewed/2025/02/GHSA-cpr3-4f88-q3jq/GHSA-cpr3-4f88-q3jq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cpr3-4f88-q3jq", - "modified": "2025-02-27T21:32:18Z", + "modified": "2025-02-28T18:31:01Z", "published": "2025-02-27T21:32:18Z", "aliases": [ "CVE-2024-41339" ], "details": "An issue in the CGI endpoint used to upload configurations in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2133/2762/2832 prior to v3.9.8, Vigor 2135/2765/2766 prior to v4.4.5.1, Vigor 2865/2866/2927 prior to v4.4.5.3, Vigor 2962/3910 prior to v4.3.2.7, Vigor 3912 prior to v4.3.5.2, and Vigor 2925 up to v3.9.6 allows attackers to upload a crafted kernel module, allowing for arbitrary code execution.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T21:15:36Z" diff --git a/advisories/unreviewed/2025/02/GHSA-g4r7-7j67-74ch/GHSA-g4r7-7j67-74ch.json b/advisories/unreviewed/2025/02/GHSA-g4r7-7j67-74ch/GHSA-g4r7-7j67-74ch.json index 8d0af0f3d82..8fbb5772188 100644 --- a/advisories/unreviewed/2025/02/GHSA-g4r7-7j67-74ch/GHSA-g4r7-7j67-74ch.json +++ b/advisories/unreviewed/2025/02/GHSA-g4r7-7j67-74ch/GHSA-g4r7-7j67-74ch.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g4r7-7j67-74ch", - "modified": "2025-02-24T18:32:42Z", + "modified": "2025-02-28T18:30:58Z", "published": "2025-02-24T18:32:42Z", "aliases": [ "CVE-2024-57026" ], "details": "TawkTo Widget Version <= 1.3.7 is vulnerable to Cross Site Scripting (XSS) due to processing user input in a way that allows JavaScript execution.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-24T18:15:19Z" diff --git a/advisories/unreviewed/2025/02/GHSA-g4v7-6h28-6phm/GHSA-g4v7-6h28-6phm.json b/advisories/unreviewed/2025/02/GHSA-g4v7-6h28-6phm/GHSA-g4v7-6h28-6phm.json index de4c30ec398..a975d872b93 100644 --- a/advisories/unreviewed/2025/02/GHSA-g4v7-6h28-6phm/GHSA-g4v7-6h28-6phm.json +++ b/advisories/unreviewed/2025/02/GHSA-g4v7-6h28-6phm/GHSA-g4v7-6h28-6phm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g4v7-6h28-6phm", - "modified": "2025-02-28T00:30:51Z", + "modified": "2025-02-28T18:31:01Z", "published": "2025-02-28T00:30:51Z", "aliases": [ "CVE-2024-38291" ], "details": "In XIQ-SE before 24.2.11, a low-privileged user may be able to access admin passwords, which could lead to privilege escalation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T22:15:38Z" diff --git a/advisories/unreviewed/2025/02/GHSA-gq6q-2ffm-3vc2/GHSA-gq6q-2ffm-3vc2.json b/advisories/unreviewed/2025/02/GHSA-gq6q-2ffm-3vc2/GHSA-gq6q-2ffm-3vc2.json index 76b3f09f62b..7757ccdcdd6 100644 --- a/advisories/unreviewed/2025/02/GHSA-gq6q-2ffm-3vc2/GHSA-gq6q-2ffm-3vc2.json +++ b/advisories/unreviewed/2025/02/GHSA-gq6q-2ffm-3vc2/GHSA-gq6q-2ffm-3vc2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gq6q-2ffm-3vc2", - "modified": "2025-02-27T18:31:13Z", + "modified": "2025-02-28T18:30:59Z", "published": "2025-02-27T18:31:13Z", "aliases": [ "CVE-2025-25323" ], "details": "An issue in Qianjin Network Information Technology (Shanghai) Co., Ltd 51Job iOS 14.22.0 allows attackers to access sensitive user information via supplying a crafted link.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-84" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T16:15:39Z" diff --git a/advisories/unreviewed/2025/02/GHSA-gr74-v59q-3p8g/GHSA-gr74-v59q-3p8g.json b/advisories/unreviewed/2025/02/GHSA-gr74-v59q-3p8g/GHSA-gr74-v59q-3p8g.json index d27523e48af..19c9bc46875 100644 --- a/advisories/unreviewed/2025/02/GHSA-gr74-v59q-3p8g/GHSA-gr74-v59q-3p8g.json +++ b/advisories/unreviewed/2025/02/GHSA-gr74-v59q-3p8g/GHSA-gr74-v59q-3p8g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gr74-v59q-3p8g", - "modified": "2025-02-27T18:31:13Z", + "modified": "2025-02-28T18:30:59Z", "published": "2025-02-27T18:31:13Z", "aliases": [ "CVE-2025-25324" ], "details": "An issue in Shandong Provincial Big Data Center AiShanDong iOS 5.0.0 allows attackers to access sensitive user information via supplying a crafted link.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-84" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T16:15:39Z" diff --git a/advisories/unreviewed/2025/02/GHSA-h33c-355w-g26q/GHSA-h33c-355w-g26q.json b/advisories/unreviewed/2025/02/GHSA-h33c-355w-g26q/GHSA-h33c-355w-g26q.json index 23c089a2568..22c8e3d53c4 100644 --- a/advisories/unreviewed/2025/02/GHSA-h33c-355w-g26q/GHSA-h33c-355w-g26q.json +++ b/advisories/unreviewed/2025/02/GHSA-h33c-355w-g26q/GHSA-h33c-355w-g26q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h33c-355w-g26q", - "modified": "2025-02-28T00:30:51Z", + "modified": "2025-02-28T18:31:02Z", "published": "2025-02-28T00:30:51Z", "aliases": [ "CVE-2025-25730" ], "details": "An issue in Motorola Mobility Droid Razr HD (Model XT926) System Version: 9.18.94.XT926.Verizon.en.US allows physically proximate unauthorized attackers to access USB debugging, leading to control of the host device itself.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T22:15:38Z" diff --git a/advisories/unreviewed/2025/02/GHSA-hcjx-v7fg-j456/GHSA-hcjx-v7fg-j456.json b/advisories/unreviewed/2025/02/GHSA-hcjx-v7fg-j456/GHSA-hcjx-v7fg-j456.json new file mode 100644 index 00000000000..478417db550 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-hcjx-v7fg-j456/GHSA-hcjx-v7fg-j456.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hcjx-v7fg-j456", + "modified": "2025-02-28T18:31:04Z", + "published": "2025-02-28T18:31:04Z", + "aliases": [ + "CVE-2025-25461" + ], + "details": "A Stored Cross-Site Scripting (XSS) vulnerability exists in SeedDMS 6.0.29. A user or rogue admin with the \"Add Category\" permission can inject a malicious XSS payload into the category name field. When a document is subsequently associated with this category, the payload is stored on the server and rendered without proper sanitization or output encoding. This results in the XSS payload executing in the browser of any user who views the document.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25461" + }, + { + "type": "WEB", + "url": "https://github.com/RoNiXxCybSeC0101/CVE-2025-25461" + }, + { + "type": "WEB", + "url": "https://www.seeddms.org" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-28T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-jf75-x4f2-r8c9/GHSA-jf75-x4f2-r8c9.json b/advisories/unreviewed/2025/02/GHSA-jf75-x4f2-r8c9/GHSA-jf75-x4f2-r8c9.json index 8705c1247fe..c0544e54470 100644 --- a/advisories/unreviewed/2025/02/GHSA-jf75-x4f2-r8c9/GHSA-jf75-x4f2-r8c9.json +++ b/advisories/unreviewed/2025/02/GHSA-jf75-x4f2-r8c9/GHSA-jf75-x4f2-r8c9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jf75-x4f2-r8c9", - "modified": "2025-02-28T00:30:51Z", + "modified": "2025-02-28T18:31:03Z", "published": "2025-02-28T00:30:51Z", "aliases": [ "CVE-2024-36047" ], "details": "Infoblox NIOS through 8.6.4 and 9.x through 9.0.3 has Improper Input Validation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-20" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T23:15:37Z" diff --git a/advisories/unreviewed/2025/02/GHSA-jmcm-9g64-4qhv/GHSA-jmcm-9g64-4qhv.json b/advisories/unreviewed/2025/02/GHSA-jmcm-9g64-4qhv/GHSA-jmcm-9g64-4qhv.json new file mode 100644 index 00000000000..97fb6b708a5 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-jmcm-9g64-4qhv/GHSA-jmcm-9g64-4qhv.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jmcm-9g64-4qhv", + "modified": "2025-02-28T18:31:04Z", + "published": "2025-02-28T18:31:04Z", + "aliases": [ + "CVE-2025-26047" + ], + "details": "Loggrove v1.0 is vulnerable to SQL Injection in the read.py file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26047" + }, + { + "type": "WEB", + "url": "https://gitee.com/olajowon/loggrove/issues/IBJXG8" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-28T16:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-jqwh-9m3g-v933/GHSA-jqwh-9m3g-v933.json b/advisories/unreviewed/2025/02/GHSA-jqwh-9m3g-v933/GHSA-jqwh-9m3g-v933.json index 20388cda1cf..355b9ff673d 100644 --- a/advisories/unreviewed/2025/02/GHSA-jqwh-9m3g-v933/GHSA-jqwh-9m3g-v933.json +++ b/advisories/unreviewed/2025/02/GHSA-jqwh-9m3g-v933/GHSA-jqwh-9m3g-v933.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jqwh-9m3g-v933", - "modified": "2025-02-27T21:32:18Z", + "modified": "2025-02-28T18:31:01Z", "published": "2025-02-27T21:32:18Z", "aliases": [ "CVE-2024-51139" ], "details": "Buffer Overflow vulnerability in Vigor2620/LTE200 3.9.8.9 and earlier and Vigor2860/2925 3.9.8 and earlier and Vigor2862/2926 3.9.9.5 and earlier and Vigor2133/2762/2832 3.9.9 and earlier and Vigor165/166 4.2.7 and earlier and Vigor2135/2765/2766 4.4.5.1 and earlier and Vigor2865/2866/2927 4.4.5.3 and earlier and Vigor2962/3910 4.3.2.8/4.4.3.1 and earlier and Vigor3912 4.3.6.1 and earlier allows a remote attacker to execute arbitrary code via the CGI parser's handling of the \"Content-Length\" header of HTTP POST requests.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T21:15:37Z" diff --git a/advisories/unreviewed/2025/02/GHSA-jv4p-6m84-hhpv/GHSA-jv4p-6m84-hhpv.json b/advisories/unreviewed/2025/02/GHSA-jv4p-6m84-hhpv/GHSA-jv4p-6m84-hhpv.json index ef7f132af6e..dd0ef30d040 100644 --- a/advisories/unreviewed/2025/02/GHSA-jv4p-6m84-hhpv/GHSA-jv4p-6m84-hhpv.json +++ b/advisories/unreviewed/2025/02/GHSA-jv4p-6m84-hhpv/GHSA-jv4p-6m84-hhpv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jv4p-6m84-hhpv", - "modified": "2025-02-28T00:30:52Z", + "modified": "2025-02-28T18:31:03Z", "published": "2025-02-28T00:30:52Z", "aliases": [ "CVE-2025-25477" ], "details": "A host header injection vulnerability in SysPass 3.2x allows an attacker to load malicious JS files from an arbitrary domain which would be executed in the victim's browser.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-74" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-28T00:15:36Z" diff --git a/advisories/unreviewed/2025/02/GHSA-m2x9-jx4p-g5c8/GHSA-m2x9-jx4p-g5c8.json b/advisories/unreviewed/2025/02/GHSA-m2x9-jx4p-g5c8/GHSA-m2x9-jx4p-g5c8.json index d54f74bfa0a..ba684238f14 100644 --- a/advisories/unreviewed/2025/02/GHSA-m2x9-jx4p-g5c8/GHSA-m2x9-jx4p-g5c8.json +++ b/advisories/unreviewed/2025/02/GHSA-m2x9-jx4p-g5c8/GHSA-m2x9-jx4p-g5c8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m2x9-jx4p-g5c8", - "modified": "2025-02-27T18:31:14Z", + "modified": "2025-02-28T18:31:00Z", "published": "2025-02-27T18:31:14Z", "aliases": [ "CVE-2025-25334" ], "details": "An issue in Suning Commerce Group Suning EMall iOS 9.5.198 allows attackers to access sensitive user information via supplying a crafted link.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-84" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T16:15:40Z" diff --git a/advisories/unreviewed/2025/02/GHSA-m73p-w5w2-3m5h/GHSA-m73p-w5w2-3m5h.json b/advisories/unreviewed/2025/02/GHSA-m73p-w5w2-3m5h/GHSA-m73p-w5w2-3m5h.json index 4fc1adc8d15..08b90ed730b 100644 --- a/advisories/unreviewed/2025/02/GHSA-m73p-w5w2-3m5h/GHSA-m73p-w5w2-3m5h.json +++ b/advisories/unreviewed/2025/02/GHSA-m73p-w5w2-3m5h/GHSA-m73p-w5w2-3m5h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m73p-w5w2-3m5h", - "modified": "2025-02-28T00:30:51Z", + "modified": "2025-02-28T18:31:02Z", "published": "2025-02-28T00:30:51Z", "aliases": [ "CVE-2024-38292" ], "details": "In XIQ-SE before 24.2.11, due to a missing access control check, a path traversal is possible, which may lead to privilege escalation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-22" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T22:15:38Z" diff --git a/advisories/unreviewed/2025/02/GHSA-p2c8-vcc7-q39q/GHSA-p2c8-vcc7-q39q.json b/advisories/unreviewed/2025/02/GHSA-p2c8-vcc7-q39q/GHSA-p2c8-vcc7-q39q.json index d8cf647a1e4..4ea41245680 100644 --- a/advisories/unreviewed/2025/02/GHSA-p2c8-vcc7-q39q/GHSA-p2c8-vcc7-q39q.json +++ b/advisories/unreviewed/2025/02/GHSA-p2c8-vcc7-q39q/GHSA-p2c8-vcc7-q39q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p2c8-vcc7-q39q", - "modified": "2025-02-28T00:30:51Z", + "modified": "2025-02-28T18:31:02Z", "published": "2025-02-28T00:30:51Z", "aliases": [ "CVE-2025-25570" ], "details": "Vue Vben Admin 2.10.1 allows unauthorized login to the backend due to an issue with hardcoded credentials.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-522" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T22:15:38Z" diff --git a/advisories/unreviewed/2025/02/GHSA-ppc4-h225-m9r2/GHSA-ppc4-h225-m9r2.json b/advisories/unreviewed/2025/02/GHSA-ppc4-h225-m9r2/GHSA-ppc4-h225-m9r2.json index 35f65c2206e..a4294d2652c 100644 --- a/advisories/unreviewed/2025/02/GHSA-ppc4-h225-m9r2/GHSA-ppc4-h225-m9r2.json +++ b/advisories/unreviewed/2025/02/GHSA-ppc4-h225-m9r2/GHSA-ppc4-h225-m9r2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-ppc4-h225-m9r2", - "modified": "2025-02-27T18:31:13Z", + "modified": "2025-02-28T18:30:59Z", "published": "2025-02-27T18:31:13Z", "aliases": [ "CVE-2025-25325" ], "details": "An issue in Yibin Fengguan Network Technology Co., Ltd YuPao DirectHire iOS 8.8.0 allows attackers to access sensitive user information via supplying a crafted link.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-84" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T16:15:39Z" diff --git a/advisories/unreviewed/2025/02/GHSA-pqmh-jm9r-hq9j/GHSA-pqmh-jm9r-hq9j.json b/advisories/unreviewed/2025/02/GHSA-pqmh-jm9r-hq9j/GHSA-pqmh-jm9r-hq9j.json index 38668df0bfd..7453ab3a54e 100644 --- a/advisories/unreviewed/2025/02/GHSA-pqmh-jm9r-hq9j/GHSA-pqmh-jm9r-hq9j.json +++ b/advisories/unreviewed/2025/02/GHSA-pqmh-jm9r-hq9j/GHSA-pqmh-jm9r-hq9j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pqmh-jm9r-hq9j", - "modified": "2025-02-28T15:31:04Z", + "modified": "2025-02-28T18:31:03Z", "published": "2025-02-28T15:31:04Z", "aliases": [ "CVE-2025-25916" ], "details": "wuzhicms v4.1.0 has a Cross Site Scripting (XSS) vulnerability in del function in \\coreframe\\app\\member\\admin\\group.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-28T15:15:13Z" diff --git a/advisories/unreviewed/2025/02/GHSA-q43v-p4wq-wmhv/GHSA-q43v-p4wq-wmhv.json b/advisories/unreviewed/2025/02/GHSA-q43v-p4wq-wmhv/GHSA-q43v-p4wq-wmhv.json index a8e3b986ff6..6b6ace24739 100644 --- a/advisories/unreviewed/2025/02/GHSA-q43v-p4wq-wmhv/GHSA-q43v-p4wq-wmhv.json +++ b/advisories/unreviewed/2025/02/GHSA-q43v-p4wq-wmhv/GHSA-q43v-p4wq-wmhv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q43v-p4wq-wmhv", - "modified": "2025-02-28T00:30:51Z", + "modified": "2025-02-28T18:31:01Z", "published": "2025-02-28T00:30:51Z", "aliases": [ "CVE-2024-38290" ], "details": "In XIQ-SE before 24.2.11, a server misconfiguration may allow user enumeration when specific conditions are met.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T22:15:38Z" diff --git a/advisories/unreviewed/2025/02/GHSA-rhv9-gvq2-f88v/GHSA-rhv9-gvq2-f88v.json b/advisories/unreviewed/2025/02/GHSA-rhv9-gvq2-f88v/GHSA-rhv9-gvq2-f88v.json index de8dbbb09f4..fb002cae499 100644 --- a/advisories/unreviewed/2025/02/GHSA-rhv9-gvq2-f88v/GHSA-rhv9-gvq2-f88v.json +++ b/advisories/unreviewed/2025/02/GHSA-rhv9-gvq2-f88v/GHSA-rhv9-gvq2-f88v.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-v2m3-cppr-8m5q/GHSA-v2m3-cppr-8m5q.json b/advisories/unreviewed/2025/02/GHSA-v2m3-cppr-8m5q/GHSA-v2m3-cppr-8m5q.json index 296ad98f3a9..13f110bfcc3 100644 --- a/advisories/unreviewed/2025/02/GHSA-v2m3-cppr-8m5q/GHSA-v2m3-cppr-8m5q.json +++ b/advisories/unreviewed/2025/02/GHSA-v2m3-cppr-8m5q/GHSA-v2m3-cppr-8m5q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v2m3-cppr-8m5q", - "modified": "2025-02-28T00:30:51Z", + "modified": "2025-02-28T18:31:02Z", "published": "2025-02-28T00:30:51Z", "aliases": [ "CVE-2024-36046" ], "details": "Infoblox NIOS through 8.6.4 executes with more privileges than required.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-269" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T23:15:36Z" diff --git a/advisories/unreviewed/2025/02/GHSA-v32c-r7p2-96qj/GHSA-v32c-r7p2-96qj.json b/advisories/unreviewed/2025/02/GHSA-v32c-r7p2-96qj/GHSA-v32c-r7p2-96qj.json index eeee8277e8c..6bb30839de8 100644 --- a/advisories/unreviewed/2025/02/GHSA-v32c-r7p2-96qj/GHSA-v32c-r7p2-96qj.json +++ b/advisories/unreviewed/2025/02/GHSA-v32c-r7p2-96qj/GHSA-v32c-r7p2-96qj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v32c-r7p2-96qj", - "modified": "2025-02-25T00:31:49Z", + "modified": "2025-02-28T18:30:58Z", "published": "2025-02-25T00:31:49Z", "aliases": [ "CVE-2025-25513" ], "details": "Seacms <=13.3 is vulnerable to SQL Injection in admin_members.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-24T22:15:22Z" diff --git a/advisories/unreviewed/2025/02/GHSA-v68h-2qqv-28r8/GHSA-v68h-2qqv-28r8.json b/advisories/unreviewed/2025/02/GHSA-v68h-2qqv-28r8/GHSA-v68h-2qqv-28r8.json index eb0a2b238fc..833f427b168 100644 --- a/advisories/unreviewed/2025/02/GHSA-v68h-2qqv-28r8/GHSA-v68h-2qqv-28r8.json +++ b/advisories/unreviewed/2025/02/GHSA-v68h-2qqv-28r8/GHSA-v68h-2qqv-28r8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v68h-2qqv-28r8", - "modified": "2025-02-27T18:31:13Z", + "modified": "2025-02-28T18:31:00Z", "published": "2025-02-27T18:31:13Z", "aliases": [ "CVE-2025-25326" ], "details": "An issue in Merchants Union Consumer Finance Company Limited Merchants Union Finance iOS 6.19.0 allows attackers to access sensitive user information via supplying a crafted link.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-84" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T16:15:39Z" diff --git a/advisories/unreviewed/2025/02/GHSA-v8m2-qqpw-r35m/GHSA-v8m2-qqpw-r35m.json b/advisories/unreviewed/2025/02/GHSA-v8m2-qqpw-r35m/GHSA-v8m2-qqpw-r35m.json index fb368b72cd1..972c8b481cb 100644 --- a/advisories/unreviewed/2025/02/GHSA-v8m2-qqpw-r35m/GHSA-v8m2-qqpw-r35m.json +++ b/advisories/unreviewed/2025/02/GHSA-v8m2-qqpw-r35m/GHSA-v8m2-qqpw-r35m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v8m2-qqpw-r35m", - "modified": "2025-02-24T18:32:42Z", + "modified": "2025-02-28T18:30:58Z", "published": "2025-02-24T18:32:42Z", "aliases": [ "CVE-2024-56897" ], "details": "Improper access control in the HTTP server in YI Car Dashcam v3.88 allows unrestricted file downloads, uploads, and API commands. API commands can also be made to make unauthorized modifications to the device settings, such as disabling recording, disabling sounds, factory reset.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-24T16:15:12Z" diff --git a/advisories/unreviewed/2025/02/GHSA-vmf2-mqm7-fcrm/GHSA-vmf2-mqm7-fcrm.json b/advisories/unreviewed/2025/02/GHSA-vmf2-mqm7-fcrm/GHSA-vmf2-mqm7-fcrm.json new file mode 100644 index 00000000000..30a424591bd --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-vmf2-mqm7-fcrm/GHSA-vmf2-mqm7-fcrm.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vmf2-mqm7-fcrm", + "modified": "2025-02-28T18:31:05Z", + "published": "2025-02-28T18:31:05Z", + "aliases": [ + "CVE-2025-25430" + ], + "details": "Trendnet TEW-929DRU 1.0.0.10 contains a Stored Cross-site Scripting (XSS) vulnerability via the configname parameter on the /cbi_addcert.htm page.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25430" + }, + { + "type": "WEB", + "url": "https://instinctive-acapella-fc7.notion.site/Trendnet-TEW-929DRU-XSS-17a15d9d4d2680fbb72ced0a02a64875" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-28T18:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-w66w-gg7v-xc4c/GHSA-w66w-gg7v-xc4c.json b/advisories/unreviewed/2025/02/GHSA-w66w-gg7v-xc4c/GHSA-w66w-gg7v-xc4c.json index 26e4823dbf2..5019848ccd0 100644 --- a/advisories/unreviewed/2025/02/GHSA-w66w-gg7v-xc4c/GHSA-w66w-gg7v-xc4c.json +++ b/advisories/unreviewed/2025/02/GHSA-w66w-gg7v-xc4c/GHSA-w66w-gg7v-xc4c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w66w-gg7v-xc4c", - "modified": "2025-02-27T18:31:14Z", + "modified": "2025-02-28T18:31:00Z", "published": "2025-02-27T18:31:14Z", "aliases": [ "CVE-2025-25329" ], "details": "An issue in Tencent Technology (Beijing) Company Limited Tencent MicroVision iOS 8.137.0 allows attackers to access sensitive user information via supplying a crafted link.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-84" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T17:15:16Z" diff --git a/advisories/unreviewed/2025/02/GHSA-xfxq-4gvm-mf69/GHSA-xfxq-4gvm-mf69.json b/advisories/unreviewed/2025/02/GHSA-xfxq-4gvm-mf69/GHSA-xfxq-4gvm-mf69.json index e9342baf991..8f004c763fe 100644 --- a/advisories/unreviewed/2025/02/GHSA-xfxq-4gvm-mf69/GHSA-xfxq-4gvm-mf69.json +++ b/advisories/unreviewed/2025/02/GHSA-xfxq-4gvm-mf69/GHSA-xfxq-4gvm-mf69.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xfxq-4gvm-mf69", - "modified": "2025-02-28T00:30:52Z", + "modified": "2025-02-28T18:31:03Z", "published": "2025-02-28T00:30:52Z", "aliases": [ "CVE-2024-37567" ], "details": "Infoblox NIOS through 8.6.4 has Improper Access Control for Grids.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T23:15:37Z"