From 411d373a32f01a1e80b420cd02a18aea8cd2382b Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sat, 10 May 2025 03:31:54 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-9pgf-v4c5-vh54.json | 3 +- .../GHSA-4gfp-3h23-q93c.json | 3 +- .../GHSA-6233-jj46-vp44.json | 6 +- .../GHSA-h9pw-jprm-xpcc.json | 3 +- .../GHSA-m6rq-x2h2-222p.json | 2 +- .../GHSA-mwxx-fm83-xr9c.json | 3 +- .../GHSA-vrw5-c37h-4jp2.json | 3 +- .../GHSA-w2gx-jrw9-w3hf.json | 3 +- .../GHSA-w7mr-p347-2rxr.json | 2 +- .../GHSA-xg84-4r3q-gjjw.json | 3 +- .../GHSA-2cf4-4hv6-ccxc.json | 36 ++++++++++++ .../GHSA-3m4v-8v7m-fjqh.json | 15 +++-- .../GHSA-4ff9-j95w-cmww.json | 25 +++++++++ .../GHSA-4hrx-7c6v-v9v5.json | 15 +++-- .../GHSA-58x9-xjx8-r53g.json | 25 +++++++++ .../GHSA-5g2m-h52j-gj53.json | 15 +++-- .../GHSA-6wp9-fhmq-qf9x.json | 15 +++-- .../GHSA-99vm-2jmg-q6cj.json | 15 +++-- .../GHSA-crgq-r5hp-5v47.json | 15 +++-- .../GHSA-fxh7-543f-qcr8.json | 15 +++-- .../GHSA-h587-5rxq-8q3h.json | 25 +++++++++ .../GHSA-hxm6-cc9v-9f63.json | 15 +++-- .../GHSA-j6gv-6vjg-4pvq.json | 25 +++++++++ .../GHSA-j855-9499-vqxr.json | 25 +++++++++ .../GHSA-m748-97q2-p947.json | 25 +++++++++ .../GHSA-mfq7-c6w4-qhg9.json | 25 +++++++++ .../GHSA-p237-25qw-vm93.json | 25 +++++++++ .../GHSA-qr56-hpqq-mc7v.json | 15 +++-- .../GHSA-rvhv-2qpm-56c6.json | 15 +++-- .../GHSA-wgch-pw4j-vppr.json | 25 +++++++++ .../GHSA-xxqc-wcch-833f.json | 56 +++++++++++++++++++ 31 files changed, 448 insertions(+), 50 deletions(-) create mode 100644 advisories/unreviewed/2025/05/GHSA-2cf4-4hv6-ccxc/GHSA-2cf4-4hv6-ccxc.json create mode 100644 advisories/unreviewed/2025/05/GHSA-4ff9-j95w-cmww/GHSA-4ff9-j95w-cmww.json create mode 100644 advisories/unreviewed/2025/05/GHSA-58x9-xjx8-r53g/GHSA-58x9-xjx8-r53g.json create mode 100644 advisories/unreviewed/2025/05/GHSA-h587-5rxq-8q3h/GHSA-h587-5rxq-8q3h.json create mode 100644 advisories/unreviewed/2025/05/GHSA-j6gv-6vjg-4pvq/GHSA-j6gv-6vjg-4pvq.json create mode 100644 advisories/unreviewed/2025/05/GHSA-j855-9499-vqxr/GHSA-j855-9499-vqxr.json create mode 100644 advisories/unreviewed/2025/05/GHSA-m748-97q2-p947/GHSA-m748-97q2-p947.json create mode 100644 advisories/unreviewed/2025/05/GHSA-mfq7-c6w4-qhg9/GHSA-mfq7-c6w4-qhg9.json create mode 100644 advisories/unreviewed/2025/05/GHSA-p237-25qw-vm93/GHSA-p237-25qw-vm93.json create mode 100644 advisories/unreviewed/2025/05/GHSA-wgch-pw4j-vppr/GHSA-wgch-pw4j-vppr.json create mode 100644 advisories/unreviewed/2025/05/GHSA-xxqc-wcch-833f/GHSA-xxqc-wcch-833f.json diff --git a/advisories/unreviewed/2022/10/GHSA-9pgf-v4c5-vh54/GHSA-9pgf-v4c5-vh54.json b/advisories/unreviewed/2022/10/GHSA-9pgf-v4c5-vh54/GHSA-9pgf-v4c5-vh54.json index f6d81e2864c..6cccefaf862 100644 --- a/advisories/unreviewed/2022/10/GHSA-9pgf-v4c5-vh54/GHSA-9pgf-v4c5-vh54.json +++ b/advisories/unreviewed/2022/10/GHSA-9pgf-v4c5-vh54/GHSA-9pgf-v4c5-vh54.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-276" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-4gfp-3h23-q93c/GHSA-4gfp-3h23-q93c.json b/advisories/unreviewed/2025/04/GHSA-4gfp-3h23-q93c/GHSA-4gfp-3h23-q93c.json index 5a62d6f2c41..470ac94e8fc 100644 --- a/advisories/unreviewed/2025/04/GHSA-4gfp-3h23-q93c/GHSA-4gfp-3h23-q93c.json +++ b/advisories/unreviewed/2025/04/GHSA-4gfp-3h23-q93c/GHSA-4gfp-3h23-q93c.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-6233-jj46-vp44/GHSA-6233-jj46-vp44.json b/advisories/unreviewed/2025/04/GHSA-6233-jj46-vp44/GHSA-6233-jj46-vp44.json index b9dc248b21d..7dc476043c1 100644 --- a/advisories/unreviewed/2025/04/GHSA-6233-jj46-vp44/GHSA-6233-jj46-vp44.json +++ b/advisories/unreviewed/2025/04/GHSA-6233-jj46-vp44/GHSA-6233-jj46-vp44.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6233-jj46-vp44", - "modified": "2025-04-28T21:30:43Z", + "modified": "2025-05-10T03:30:21Z", "published": "2025-04-28T21:30:43Z", "aliases": [ "CVE-2025-3224" ], "details": "A vulnerability in the update process of Docker Desktop for Windows versions prior to 4.41.0 could allow a local, low-privileged attacker to escalate privileges to SYSTEM. During an update, Docker Desktop attempts to delete files and subdirectories under the path C:\\ProgramData\\Docker\\config with high privileges. However, this directory often does not exist by default, and C:\\ProgramData\\ allows normal users to create new directories. By creating a malicious Docker\\config folder structure at this location, an attacker can force the privileged update process to delete or manipulate arbitrary system files, leading to Elevation of Privilege.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2025/04/GHSA-h9pw-jprm-xpcc/GHSA-h9pw-jprm-xpcc.json b/advisories/unreviewed/2025/04/GHSA-h9pw-jprm-xpcc/GHSA-h9pw-jprm-xpcc.json index df4eac77062..27c55acafc9 100644 --- a/advisories/unreviewed/2025/04/GHSA-h9pw-jprm-xpcc/GHSA-h9pw-jprm-xpcc.json +++ b/advisories/unreviewed/2025/04/GHSA-h9pw-jprm-xpcc/GHSA-h9pw-jprm-xpcc.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-m6rq-x2h2-222p/GHSA-m6rq-x2h2-222p.json b/advisories/unreviewed/2025/04/GHSA-m6rq-x2h2-222p/GHSA-m6rq-x2h2-222p.json index c1959c53886..a22dacc2201 100644 --- a/advisories/unreviewed/2025/04/GHSA-m6rq-x2h2-222p/GHSA-m6rq-x2h2-222p.json +++ b/advisories/unreviewed/2025/04/GHSA-m6rq-x2h2-222p/GHSA-m6rq-x2h2-222p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m6rq-x2h2-222p", - "modified": "2025-04-28T21:30:43Z", + "modified": "2025-05-10T03:30:21Z", "published": "2025-04-28T21:30:43Z", "aliases": [ "CVE-2024-11922" diff --git a/advisories/unreviewed/2025/04/GHSA-mwxx-fm83-xr9c/GHSA-mwxx-fm83-xr9c.json b/advisories/unreviewed/2025/04/GHSA-mwxx-fm83-xr9c/GHSA-mwxx-fm83-xr9c.json index 8b00c9746c0..7bf8cb54827 100644 --- a/advisories/unreviewed/2025/04/GHSA-mwxx-fm83-xr9c/GHSA-mwxx-fm83-xr9c.json +++ b/advisories/unreviewed/2025/04/GHSA-mwxx-fm83-xr9c/GHSA-mwxx-fm83-xr9c.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-vrw5-c37h-4jp2/GHSA-vrw5-c37h-4jp2.json b/advisories/unreviewed/2025/04/GHSA-vrw5-c37h-4jp2/GHSA-vrw5-c37h-4jp2.json index 26d49fa91fa..26457683480 100644 --- a/advisories/unreviewed/2025/04/GHSA-vrw5-c37h-4jp2/GHSA-vrw5-c37h-4jp2.json +++ b/advisories/unreviewed/2025/04/GHSA-vrw5-c37h-4jp2/GHSA-vrw5-c37h-4jp2.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-w2gx-jrw9-w3hf/GHSA-w2gx-jrw9-w3hf.json b/advisories/unreviewed/2025/04/GHSA-w2gx-jrw9-w3hf/GHSA-w2gx-jrw9-w3hf.json index 1db9271e7ff..e571a061c06 100644 --- a/advisories/unreviewed/2025/04/GHSA-w2gx-jrw9-w3hf/GHSA-w2gx-jrw9-w3hf.json +++ b/advisories/unreviewed/2025/04/GHSA-w2gx-jrw9-w3hf/GHSA-w2gx-jrw9-w3hf.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-w7mr-p347-2rxr/GHSA-w7mr-p347-2rxr.json b/advisories/unreviewed/2025/04/GHSA-w7mr-p347-2rxr/GHSA-w7mr-p347-2rxr.json index 20c2122e266..53a7a664213 100644 --- a/advisories/unreviewed/2025/04/GHSA-w7mr-p347-2rxr/GHSA-w7mr-p347-2rxr.json +++ b/advisories/unreviewed/2025/04/GHSA-w7mr-p347-2rxr/GHSA-w7mr-p347-2rxr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w7mr-p347-2rxr", - "modified": "2025-04-28T21:30:43Z", + "modified": "2025-05-10T03:30:21Z", "published": "2025-04-28T21:30:43Z", "aliases": [ "CVE-2025-0049" diff --git a/advisories/unreviewed/2025/04/GHSA-xg84-4r3q-gjjw/GHSA-xg84-4r3q-gjjw.json b/advisories/unreviewed/2025/04/GHSA-xg84-4r3q-gjjw/GHSA-xg84-4r3q-gjjw.json index f049cc618eb..61f463675f2 100644 --- a/advisories/unreviewed/2025/04/GHSA-xg84-4r3q-gjjw/GHSA-xg84-4r3q-gjjw.json +++ b/advisories/unreviewed/2025/04/GHSA-xg84-4r3q-gjjw/GHSA-xg84-4r3q-gjjw.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-2cf4-4hv6-ccxc/GHSA-2cf4-4hv6-ccxc.json b/advisories/unreviewed/2025/05/GHSA-2cf4-4hv6-ccxc/GHSA-2cf4-4hv6-ccxc.json new file mode 100644 index 00000000000..c8058d9a53d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2cf4-4hv6-ccxc/GHSA-2cf4-4hv6-ccxc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2cf4-4hv6-ccxc", + "modified": "2025-05-10T03:30:23Z", + "published": "2025-05-10T03:30:23Z", + "aliases": [ + "CVE-2025-1137" + ], + "details": "IBM Storage Scale 5.2.2.0 and 5.2.2.1, under certain configurations, could allow an authenticated user to execute privileged commands due to improper input neutralization.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1137" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7233085" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-10T03:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3m4v-8v7m-fjqh/GHSA-3m4v-8v7m-fjqh.json b/advisories/unreviewed/2025/05/GHSA-3m4v-8v7m-fjqh/GHSA-3m4v-8v7m-fjqh.json index 0edc5bebeea..ab4607cad2c 100644 --- a/advisories/unreviewed/2025/05/GHSA-3m4v-8v7m-fjqh/GHSA-3m4v-8v7m-fjqh.json +++ b/advisories/unreviewed/2025/05/GHSA-3m4v-8v7m-fjqh/GHSA-3m4v-8v7m-fjqh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3m4v-8v7m-fjqh", - "modified": "2025-05-09T18:30:37Z", + "modified": "2025-05-10T03:30:22Z", "published": "2025-05-09T18:30:37Z", "aliases": [ "CVE-2025-28203" ], "details": "Victure RX1800 EN_V1.0.0_r12_110933 was discovered to contain a command injection vulnerability.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-09T16:15:24Z" diff --git a/advisories/unreviewed/2025/05/GHSA-4ff9-j95w-cmww/GHSA-4ff9-j95w-cmww.json b/advisories/unreviewed/2025/05/GHSA-4ff9-j95w-cmww/GHSA-4ff9-j95w-cmww.json new file mode 100644 index 00000000000..c32a6fcc333 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4ff9-j95w-cmww/GHSA-4ff9-j95w-cmww.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4ff9-j95w-cmww", + "modified": "2025-05-10T03:30:23Z", + "published": "2025-05-10T03:30:23Z", + "aliases": [ + "CVE-2025-47768" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47768" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-10T03:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4hrx-7c6v-v9v5/GHSA-4hrx-7c6v-v9v5.json b/advisories/unreviewed/2025/05/GHSA-4hrx-7c6v-v9v5/GHSA-4hrx-7c6v-v9v5.json index 4cf1c23f5a7..ba92bf2b6fc 100644 --- a/advisories/unreviewed/2025/05/GHSA-4hrx-7c6v-v9v5/GHSA-4hrx-7c6v-v9v5.json +++ b/advisories/unreviewed/2025/05/GHSA-4hrx-7c6v-v9v5/GHSA-4hrx-7c6v-v9v5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4hrx-7c6v-v9v5", - "modified": "2025-05-09T18:30:37Z", + "modified": "2025-05-10T03:30:22Z", "published": "2025-05-09T18:30:37Z", "aliases": [ "CVE-2025-28201" ], "details": "An issue in Victure RX1800 EN_V1.0.0_r12_110933 allows physically proximate attackers to execute arbitrary code or gain root access.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-09T16:15:24Z" diff --git a/advisories/unreviewed/2025/05/GHSA-58x9-xjx8-r53g/GHSA-58x9-xjx8-r53g.json b/advisories/unreviewed/2025/05/GHSA-58x9-xjx8-r53g/GHSA-58x9-xjx8-r53g.json new file mode 100644 index 00000000000..a49df4a73f4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-58x9-xjx8-r53g/GHSA-58x9-xjx8-r53g.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-58x9-xjx8-r53g", + "modified": "2025-05-10T03:30:23Z", + "published": "2025-05-10T03:30:23Z", + "aliases": [ + "CVE-2025-47763" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47763" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-10T03:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5g2m-h52j-gj53/GHSA-5g2m-h52j-gj53.json b/advisories/unreviewed/2025/05/GHSA-5g2m-h52j-gj53/GHSA-5g2m-h52j-gj53.json index 6a4e90d45bc..b314b969e0f 100644 --- a/advisories/unreviewed/2025/05/GHSA-5g2m-h52j-gj53/GHSA-5g2m-h52j-gj53.json +++ b/advisories/unreviewed/2025/05/GHSA-5g2m-h52j-gj53/GHSA-5g2m-h52j-gj53.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5g2m-h52j-gj53", - "modified": "2025-05-09T18:30:37Z", + "modified": "2025-05-10T03:30:22Z", "published": "2025-05-09T18:30:37Z", "aliases": [ "CVE-2025-45513" ], "details": "Tenda FH451 V1.0.0.9 has a stack overflow vulnerability in the function.P2pListFilter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-09T16:15:24Z" diff --git a/advisories/unreviewed/2025/05/GHSA-6wp9-fhmq-qf9x/GHSA-6wp9-fhmq-qf9x.json b/advisories/unreviewed/2025/05/GHSA-6wp9-fhmq-qf9x/GHSA-6wp9-fhmq-qf9x.json index d50fe6f1413..e4a0425d8f5 100644 --- a/advisories/unreviewed/2025/05/GHSA-6wp9-fhmq-qf9x/GHSA-6wp9-fhmq-qf9x.json +++ b/advisories/unreviewed/2025/05/GHSA-6wp9-fhmq-qf9x/GHSA-6wp9-fhmq-qf9x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6wp9-fhmq-qf9x", - "modified": "2025-05-09T18:30:38Z", + "modified": "2025-05-10T03:30:22Z", "published": "2025-05-09T18:30:38Z", "aliases": [ "CVE-2025-46188" ], "details": "SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in superadmin_phpmyadmin.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-09T16:15:24Z" diff --git a/advisories/unreviewed/2025/05/GHSA-99vm-2jmg-q6cj/GHSA-99vm-2jmg-q6cj.json b/advisories/unreviewed/2025/05/GHSA-99vm-2jmg-q6cj/GHSA-99vm-2jmg-q6cj.json index 6145e429481..c5ed17db67d 100644 --- a/advisories/unreviewed/2025/05/GHSA-99vm-2jmg-q6cj/GHSA-99vm-2jmg-q6cj.json +++ b/advisories/unreviewed/2025/05/GHSA-99vm-2jmg-q6cj/GHSA-99vm-2jmg-q6cj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-99vm-2jmg-q6cj", - "modified": "2025-05-09T18:30:39Z", + "modified": "2025-05-10T03:30:22Z", "published": "2025-05-09T18:30:39Z", "aliases": [ "CVE-2025-29509" ], "details": "Jan v0.5.14 and before is vulnerable to remote code execution (RCE) when the user clicks on a rendered link in the conversation, due to opening external website in the app and the exposure of electronAPI, with a lack of filtering of URL when calling shell.openExternal().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-09T17:15:50Z" diff --git a/advisories/unreviewed/2025/05/GHSA-crgq-r5hp-5v47/GHSA-crgq-r5hp-5v47.json b/advisories/unreviewed/2025/05/GHSA-crgq-r5hp-5v47/GHSA-crgq-r5hp-5v47.json index c13ac34b7a7..2e86281e2b5 100644 --- a/advisories/unreviewed/2025/05/GHSA-crgq-r5hp-5v47/GHSA-crgq-r5hp-5v47.json +++ b/advisories/unreviewed/2025/05/GHSA-crgq-r5hp-5v47/GHSA-crgq-r5hp-5v47.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-crgq-r5hp-5v47", - "modified": "2025-05-09T18:30:37Z", + "modified": "2025-05-10T03:30:22Z", "published": "2025-05-09T18:30:37Z", "aliases": [ "CVE-2025-28202" ], "details": "Incorrect access control in Victure RX1800 EN_V1.0.0_r12_110933 allows attackers to enable SSH and Telnet services without authentication.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-862" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-09T16:15:24Z" diff --git a/advisories/unreviewed/2025/05/GHSA-fxh7-543f-qcr8/GHSA-fxh7-543f-qcr8.json b/advisories/unreviewed/2025/05/GHSA-fxh7-543f-qcr8/GHSA-fxh7-543f-qcr8.json index 83fc73f10e4..38a6e4a5fea 100644 --- a/advisories/unreviewed/2025/05/GHSA-fxh7-543f-qcr8/GHSA-fxh7-543f-qcr8.json +++ b/advisories/unreviewed/2025/05/GHSA-fxh7-543f-qcr8/GHSA-fxh7-543f-qcr8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fxh7-543f-qcr8", - "modified": "2025-05-09T18:30:38Z", + "modified": "2025-05-10T03:30:22Z", "published": "2025-05-09T18:30:38Z", "aliases": [ "CVE-2025-46189" ], "details": "SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_order_customer_update.php via the order_id POST parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-09T16:15:24Z" diff --git a/advisories/unreviewed/2025/05/GHSA-h587-5rxq-8q3h/GHSA-h587-5rxq-8q3h.json b/advisories/unreviewed/2025/05/GHSA-h587-5rxq-8q3h/GHSA-h587-5rxq-8q3h.json new file mode 100644 index 00000000000..701484389eb --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h587-5rxq-8q3h/GHSA-h587-5rxq-8q3h.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h587-5rxq-8q3h", + "modified": "2025-05-10T03:30:23Z", + "published": "2025-05-10T03:30:23Z", + "aliases": [ + "CVE-2025-47769" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47769" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-10T03:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hxm6-cc9v-9f63/GHSA-hxm6-cc9v-9f63.json b/advisories/unreviewed/2025/05/GHSA-hxm6-cc9v-9f63/GHSA-hxm6-cc9v-9f63.json index d5470fc8a8d..26e39f2e025 100644 --- a/advisories/unreviewed/2025/05/GHSA-hxm6-cc9v-9f63/GHSA-hxm6-cc9v-9f63.json +++ b/advisories/unreviewed/2025/05/GHSA-hxm6-cc9v-9f63/GHSA-hxm6-cc9v-9f63.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hxm6-cc9v-9f63", - "modified": "2025-05-09T18:30:39Z", + "modified": "2025-05-10T03:30:22Z", "published": "2025-05-09T18:30:39Z", "aliases": [ "CVE-2025-46191" ], "details": "Arbitrary File Upload in user_payment_update.php in SourceCodester Client Database Management System 1.0 allows unauthenticated users to upload arbitrary files via the uploaded_file_cancelled field. Due to the absence of proper file extension checks, MIME type validation, and authentication, attackers can upload executable PHP files to a web-accessible directory (/files/). This allows them to execute arbitrary commands remotely by accessing the uploaded script, resulting in full Remote Code Execution (RCE) without authentication.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-09T17:15:51Z" diff --git a/advisories/unreviewed/2025/05/GHSA-j6gv-6vjg-4pvq/GHSA-j6gv-6vjg-4pvq.json b/advisories/unreviewed/2025/05/GHSA-j6gv-6vjg-4pvq/GHSA-j6gv-6vjg-4pvq.json new file mode 100644 index 00000000000..51bb9fc3e4e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-j6gv-6vjg-4pvq/GHSA-j6gv-6vjg-4pvq.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6gv-6vjg-4pvq", + "modified": "2025-05-10T03:30:23Z", + "published": "2025-05-10T03:30:23Z", + "aliases": [ + "CVE-2025-47766" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47766" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-10T03:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-j855-9499-vqxr/GHSA-j855-9499-vqxr.json b/advisories/unreviewed/2025/05/GHSA-j855-9499-vqxr/GHSA-j855-9499-vqxr.json new file mode 100644 index 00000000000..729f86db68e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-j855-9499-vqxr/GHSA-j855-9499-vqxr.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j855-9499-vqxr", + "modified": "2025-05-10T03:30:23Z", + "published": "2025-05-10T03:30:23Z", + "aliases": [ + "CVE-2025-47770" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47770" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-10T03:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-m748-97q2-p947/GHSA-m748-97q2-p947.json b/advisories/unreviewed/2025/05/GHSA-m748-97q2-p947/GHSA-m748-97q2-p947.json new file mode 100644 index 00000000000..ccc34c4fe01 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-m748-97q2-p947/GHSA-m748-97q2-p947.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m748-97q2-p947", + "modified": "2025-05-10T03:30:23Z", + "published": "2025-05-10T03:30:23Z", + "aliases": [ + "CVE-2025-47764" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47764" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-10T03:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mfq7-c6w4-qhg9/GHSA-mfq7-c6w4-qhg9.json b/advisories/unreviewed/2025/05/GHSA-mfq7-c6w4-qhg9/GHSA-mfq7-c6w4-qhg9.json new file mode 100644 index 00000000000..eab7b250ea6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mfq7-c6w4-qhg9/GHSA-mfq7-c6w4-qhg9.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mfq7-c6w4-qhg9", + "modified": "2025-05-10T03:30:23Z", + "published": "2025-05-10T03:30:23Z", + "aliases": [ + "CVE-2025-47762" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47762" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-10T03:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p237-25qw-vm93/GHSA-p237-25qw-vm93.json b/advisories/unreviewed/2025/05/GHSA-p237-25qw-vm93/GHSA-p237-25qw-vm93.json new file mode 100644 index 00000000000..94056c5196a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p237-25qw-vm93/GHSA-p237-25qw-vm93.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p237-25qw-vm93", + "modified": "2025-05-10T03:30:23Z", + "published": "2025-05-10T03:30:23Z", + "aliases": [ + "CVE-2025-47765" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47765" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-10T03:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qr56-hpqq-mc7v/GHSA-qr56-hpqq-mc7v.json b/advisories/unreviewed/2025/05/GHSA-qr56-hpqq-mc7v/GHSA-qr56-hpqq-mc7v.json index 1da03fcc6a0..fd845b3bf9d 100644 --- a/advisories/unreviewed/2025/05/GHSA-qr56-hpqq-mc7v/GHSA-qr56-hpqq-mc7v.json +++ b/advisories/unreviewed/2025/05/GHSA-qr56-hpqq-mc7v/GHSA-qr56-hpqq-mc7v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qr56-hpqq-mc7v", - "modified": "2025-05-09T18:30:39Z", + "modified": "2025-05-10T03:30:22Z", "published": "2025-05-09T18:30:39Z", "aliases": [ "CVE-2025-46190" ], "details": "SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_delivery_update.php via the order_id POST parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-09T17:15:51Z" diff --git a/advisories/unreviewed/2025/05/GHSA-rvhv-2qpm-56c6/GHSA-rvhv-2qpm-56c6.json b/advisories/unreviewed/2025/05/GHSA-rvhv-2qpm-56c6/GHSA-rvhv-2qpm-56c6.json index 9f1df0c89dc..40f6f45770c 100644 --- a/advisories/unreviewed/2025/05/GHSA-rvhv-2qpm-56c6/GHSA-rvhv-2qpm-56c6.json +++ b/advisories/unreviewed/2025/05/GHSA-rvhv-2qpm-56c6/GHSA-rvhv-2qpm-56c6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rvhv-2qpm-56c6", - "modified": "2025-05-09T18:30:39Z", + "modified": "2025-05-10T03:30:23Z", "published": "2025-05-09T18:30:39Z", "aliases": [ "CVE-2025-46192" ], "details": "SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_payment_update.php via the order_id POST parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-09T17:15:51Z" diff --git a/advisories/unreviewed/2025/05/GHSA-wgch-pw4j-vppr/GHSA-wgch-pw4j-vppr.json b/advisories/unreviewed/2025/05/GHSA-wgch-pw4j-vppr/GHSA-wgch-pw4j-vppr.json new file mode 100644 index 00000000000..cf8d446e1db --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wgch-pw4j-vppr/GHSA-wgch-pw4j-vppr.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wgch-pw4j-vppr", + "modified": "2025-05-10T03:30:23Z", + "published": "2025-05-10T03:30:23Z", + "aliases": [ + "CVE-2025-47767" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47767" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-10T03:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xxqc-wcch-833f/GHSA-xxqc-wcch-833f.json b/advisories/unreviewed/2025/05/GHSA-xxqc-wcch-833f/GHSA-xxqc-wcch-833f.json new file mode 100644 index 00000000000..081e43ab760 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xxqc-wcch-833f/GHSA-xxqc-wcch-833f.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xxqc-wcch-833f", + "modified": "2025-05-10T03:30:23Z", + "published": "2025-05-10T03:30:23Z", + "aliases": [ + "CVE-2025-4495" + ], + "details": "A vulnerability has been found in JAdmin-JAVA JAdmin 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /memoAjax/save. The manipulation of the argument ID leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4495" + }, + { + "type": "WEB", + "url": "https://github.com/JAdmin-JAVA/JAdmin/issues/2" + }, + { + "type": "WEB", + "url": "https://github.com/JAdmin-JAVA/JAdmin/issues/2#issue-3012512653" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.308209" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.308209" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.566985" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-10T01:15:51Z" + } +} \ No newline at end of file