From 500019ee6681fae7a92977b48080f7320555a6c0 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 28 Apr 2025 18:32:43 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-j583-4cfp-xf9m.json | 6 +- .../GHSA-3689-vv2m-5qqc.json | 6 +- .../GHSA-3g68-h29c-7326.json | 2 +- .../GHSA-j883-m3xr-7482.json | 2 +- .../GHSA-mvvf-9255-8c4p.json | 2 +- .../GHSA-r824-gq56-gjgx.json | 6 +- .../GHSA-7g6p-x2rr-6mm4.json | 3 +- .../GHSA-jc66-89rv-h4xm.json | 3 +- .../GHSA-rr2j-hf5q-32mg.json | 3 +- .../GHSA-22wj-vp2m-rxhc.json | 48 ++++++++++++++++ .../GHSA-2h4h-cj8f-67g5.json | 15 +++-- .../GHSA-39c9-vmq6-wcfw.json | 36 ++++++++++++ .../GHSA-3h8x-jv2f-mmvp.json | 56 +++++++++++++++++++ .../GHSA-42j8-5f44-47fv.json | 3 +- .../GHSA-4gfp-3h23-q93c.json | 56 +++++++++++++++++++ .../GHSA-4p64-hxgr-8p2m.json | 11 +++- .../GHSA-5xhr-994v-5g9p.json | 52 +++++++++++++++++ .../GHSA-675p-6mmr-fffg.json | 40 +++++++++++++ .../GHSA-84xx-9g7m-wh84.json | 52 +++++++++++++++++ .../GHSA-8cfq-qm7w-3hgc.json | 3 +- .../GHSA-9cjw-338f-2m2w.json | 36 ++++++++++++ .../GHSA-9mh9-7p8c-gr7g.json | 40 +++++++++++++ .../GHSA-9xg6-228h-663v.json | 3 +- .../GHSA-fx6v-2fj6-rmxx.json | 11 +++- .../GHSA-h4mr-59x2-64f9.json | 48 ++++++++++++++++ .../GHSA-h7hv-3j2q-qw9g.json | 11 +++- .../GHSA-h9pw-jprm-xpcc.json | 56 +++++++++++++++++++ .../GHSA-hq76-qh6p-g7m6.json | 56 +++++++++++++++++++ .../GHSA-hr6g-q5gf-9f5f.json | 36 ++++++++++++ .../GHSA-mrq6-622v-vmqp.json | 15 +++-- .../GHSA-p7wm-439m-h6pp.json | 40 +++++++++++++ .../GHSA-ph83-p4wj-c47p.json | 15 +++-- .../GHSA-vrw5-c37h-4jp2.json | 56 +++++++++++++++++++ .../GHSA-xg84-4r3q-gjjw.json | 56 +++++++++++++++++++ 34 files changed, 851 insertions(+), 33 deletions(-) create mode 100644 advisories/unreviewed/2025/04/GHSA-22wj-vp2m-rxhc/GHSA-22wj-vp2m-rxhc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-39c9-vmq6-wcfw/GHSA-39c9-vmq6-wcfw.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3h8x-jv2f-mmvp/GHSA-3h8x-jv2f-mmvp.json create mode 100644 advisories/unreviewed/2025/04/GHSA-4gfp-3h23-q93c/GHSA-4gfp-3h23-q93c.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5xhr-994v-5g9p/GHSA-5xhr-994v-5g9p.json create mode 100644 advisories/unreviewed/2025/04/GHSA-675p-6mmr-fffg/GHSA-675p-6mmr-fffg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-84xx-9g7m-wh84/GHSA-84xx-9g7m-wh84.json create mode 100644 advisories/unreviewed/2025/04/GHSA-9cjw-338f-2m2w/GHSA-9cjw-338f-2m2w.json create mode 100644 advisories/unreviewed/2025/04/GHSA-9mh9-7p8c-gr7g/GHSA-9mh9-7p8c-gr7g.json create mode 100644 advisories/unreviewed/2025/04/GHSA-h4mr-59x2-64f9/GHSA-h4mr-59x2-64f9.json create mode 100644 advisories/unreviewed/2025/04/GHSA-h9pw-jprm-xpcc/GHSA-h9pw-jprm-xpcc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-hq76-qh6p-g7m6/GHSA-hq76-qh6p-g7m6.json create mode 100644 advisories/unreviewed/2025/04/GHSA-hr6g-q5gf-9f5f/GHSA-hr6g-q5gf-9f5f.json create mode 100644 advisories/unreviewed/2025/04/GHSA-p7wm-439m-h6pp/GHSA-p7wm-439m-h6pp.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vrw5-c37h-4jp2/GHSA-vrw5-c37h-4jp2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-xg84-4r3q-gjjw/GHSA-xg84-4r3q-gjjw.json diff --git a/advisories/unreviewed/2022/05/GHSA-j583-4cfp-xf9m/GHSA-j583-4cfp-xf9m.json b/advisories/unreviewed/2022/05/GHSA-j583-4cfp-xf9m/GHSA-j583-4cfp-xf9m.json index c2296734b1a..da4066035d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-j583-4cfp-xf9m/GHSA-j583-4cfp-xf9m.json +++ b/advisories/unreviewed/2022/05/GHSA-j583-4cfp-xf9m/GHSA-j583-4cfp-xf9m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j583-4cfp-xf9m", - "modified": "2025-01-23T18:31:05Z", + "modified": "2025-04-28T18:30:35Z", "published": "2022-05-14T01:28:26Z", "aliases": [ "CVE-2018-14847" @@ -39,6 +39,10 @@ "type": "WEB", "url": "https://github.com/tenable/routeros/tree/master/poc/cve_2018_14847" }, + { + "type": "WEB", + "url": "https://mikrotik.com/supportsec/winbox-vulnerability" + }, { "type": "WEB", "url": "https://n0p.me/winbox-bug-dissection" diff --git a/advisories/unreviewed/2022/11/GHSA-3689-vv2m-5qqc/GHSA-3689-vv2m-5qqc.json b/advisories/unreviewed/2022/11/GHSA-3689-vv2m-5qqc/GHSA-3689-vv2m-5qqc.json index f121345a53a..b0895d19b99 100644 --- a/advisories/unreviewed/2022/11/GHSA-3689-vv2m-5qqc/GHSA-3689-vv2m-5qqc.json +++ b/advisories/unreviewed/2022/11/GHSA-3689-vv2m-5qqc/GHSA-3689-vv2m-5qqc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3689-vv2m-5qqc", - "modified": "2022-11-28T21:30:22Z", + "modified": "2025-04-28T18:30:35Z", "published": "2022-11-23T03:30:22Z", "aliases": [ "CVE-2022-43213" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43213" }, + { + "type": "WEB", + "url": "https://github.com/Qrayyy/CVE/blob/main/Billing%20System%20Project%20v1.0/CVE-2022-43213%28sql%20in%20editorder.php%29.md" + }, { "type": "WEB", "url": "https://github.com/Qrayyy/CVE/blob/main/Billing%20System%20Project%20v1.0/CVE-2022-43213(sql%20in%20editorder.php).md" diff --git a/advisories/unreviewed/2022/11/GHSA-3g68-h29c-7326/GHSA-3g68-h29c-7326.json b/advisories/unreviewed/2022/11/GHSA-3g68-h29c-7326/GHSA-3g68-h29c-7326.json index 4df8f8196c3..70395df9797 100644 --- a/advisories/unreviewed/2022/11/GHSA-3g68-h29c-7326/GHSA-3g68-h29c-7326.json +++ b/advisories/unreviewed/2022/11/GHSA-3g68-h29c-7326/GHSA-3g68-h29c-7326.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3g68-h29c-7326", - "modified": "2022-11-30T06:30:26Z", + "modified": "2025-04-28T18:30:35Z", "published": "2022-11-28T15:30:24Z", "aliases": [ "CVE-2022-3849" diff --git a/advisories/unreviewed/2022/12/GHSA-j883-m3xr-7482/GHSA-j883-m3xr-7482.json b/advisories/unreviewed/2022/12/GHSA-j883-m3xr-7482/GHSA-j883-m3xr-7482.json index 5e59aabdd48..1f24e058147 100644 --- a/advisories/unreviewed/2022/12/GHSA-j883-m3xr-7482/GHSA-j883-m3xr-7482.json +++ b/advisories/unreviewed/2022/12/GHSA-j883-m3xr-7482/GHSA-j883-m3xr-7482.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j883-m3xr-7482", - "modified": "2022-12-14T21:30:18Z", + "modified": "2025-04-28T18:30:36Z", "published": "2022-12-12T15:30:34Z", "aliases": [ "CVE-2022-44653" diff --git a/advisories/unreviewed/2022/12/GHSA-mvvf-9255-8c4p/GHSA-mvvf-9255-8c4p.json b/advisories/unreviewed/2022/12/GHSA-mvvf-9255-8c4p/GHSA-mvvf-9255-8c4p.json index d95e79de6fd..68aba92549d 100644 --- a/advisories/unreviewed/2022/12/GHSA-mvvf-9255-8c4p/GHSA-mvvf-9255-8c4p.json +++ b/advisories/unreviewed/2022/12/GHSA-mvvf-9255-8c4p/GHSA-mvvf-9255-8c4p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mvvf-9255-8c4p", - "modified": "2022-12-14T21:30:18Z", + "modified": "2025-04-28T18:30:35Z", "published": "2022-12-12T15:30:34Z", "aliases": [ "CVE-2022-44652" diff --git a/advisories/unreviewed/2024/07/GHSA-r824-gq56-gjgx/GHSA-r824-gq56-gjgx.json b/advisories/unreviewed/2024/07/GHSA-r824-gq56-gjgx/GHSA-r824-gq56-gjgx.json index f10af35cd31..b3edefbd105 100644 --- a/advisories/unreviewed/2024/07/GHSA-r824-gq56-gjgx/GHSA-r824-gq56-gjgx.json +++ b/advisories/unreviewed/2024/07/GHSA-r824-gq56-gjgx/GHSA-r824-gq56-gjgx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r824-gq56-gjgx", - "modified": "2024-07-08T15:31:55Z", + "modified": "2025-04-28T18:30:41Z", "published": "2024-07-03T21:39:43Z", "aliases": [ "CVE-2024-29510" @@ -30,6 +30,10 @@ { "type": "WEB", "url": "https://www.openwall.com/lists/oss-security/2024/07/03/7" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/critical-vulnerability-in-ghostscript-cve-2024-29510" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-7g6p-x2rr-6mm4/GHSA-7g6p-x2rr-6mm4.json b/advisories/unreviewed/2025/03/GHSA-7g6p-x2rr-6mm4/GHSA-7g6p-x2rr-6mm4.json index f2b82cb2249..a043088a420 100644 --- a/advisories/unreviewed/2025/03/GHSA-7g6p-x2rr-6mm4/GHSA-7g6p-x2rr-6mm4.json +++ b/advisories/unreviewed/2025/03/GHSA-7g6p-x2rr-6mm4/GHSA-7g6p-x2rr-6mm4.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-jc66-89rv-h4xm/GHSA-jc66-89rv-h4xm.json b/advisories/unreviewed/2025/03/GHSA-jc66-89rv-h4xm/GHSA-jc66-89rv-h4xm.json index 3d77eb098ca..905086a3582 100644 --- a/advisories/unreviewed/2025/03/GHSA-jc66-89rv-h4xm/GHSA-jc66-89rv-h4xm.json +++ b/advisories/unreviewed/2025/03/GHSA-jc66-89rv-h4xm/GHSA-jc66-89rv-h4xm.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-rr2j-hf5q-32mg/GHSA-rr2j-hf5q-32mg.json b/advisories/unreviewed/2025/03/GHSA-rr2j-hf5q-32mg/GHSA-rr2j-hf5q-32mg.json index 70f2350c006..1c5e1b3069c 100644 --- a/advisories/unreviewed/2025/03/GHSA-rr2j-hf5q-32mg/GHSA-rr2j-hf5q-32mg.json +++ b/advisories/unreviewed/2025/03/GHSA-rr2j-hf5q-32mg/GHSA-rr2j-hf5q-32mg.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-22wj-vp2m-rxhc/GHSA-22wj-vp2m-rxhc.json b/advisories/unreviewed/2025/04/GHSA-22wj-vp2m-rxhc/GHSA-22wj-vp2m-rxhc.json new file mode 100644 index 00000000000..86a58f70791 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-22wj-vp2m-rxhc/GHSA-22wj-vp2m-rxhc.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-22wj-vp2m-rxhc", + "modified": "2025-04-28T18:30:56Z", + "published": "2025-04-28T18:30:56Z", + "aliases": [ + "CVE-2023-35816" + ], + "details": "DevExpress before 23.1.3 allows arbitrary TypeConverter conversion.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35816" + }, + { + "type": "WEB", + "url": "https://code-white.com/public-vulnerability-list" + }, + { + "type": "WEB", + "url": "https://supportcenter.devexpress.com/ticket/details/t1127422/insecure-arbitrary-typeconverter-conversion" + }, + { + "type": "WEB", + "url": "https://supportcenter.devexpress.com/ticket/details/t1159641/net-desktop-and-web-controls-unsafe-data-type-deserialization" + }, + { + "type": "WEB", + "url": "https://supportcenter.devexpress.com/ticket/details/t394936/devexpress-security-advisory-updated-on-april-27-2023" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-23" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-28T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2h4h-cj8f-67g5/GHSA-2h4h-cj8f-67g5.json b/advisories/unreviewed/2025/04/GHSA-2h4h-cj8f-67g5/GHSA-2h4h-cj8f-67g5.json index fc2c8c756f2..001a135df7f 100644 --- a/advisories/unreviewed/2025/04/GHSA-2h4h-cj8f-67g5/GHSA-2h4h-cj8f-67g5.json +++ b/advisories/unreviewed/2025/04/GHSA-2h4h-cj8f-67g5/GHSA-2h4h-cj8f-67g5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2h4h-cj8f-67g5", - "modified": "2025-04-18T15:31:38Z", + "modified": "2025-04-28T18:30:52Z", "published": "2025-04-18T15:31:38Z", "aliases": [ "CVE-2025-39778" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nobjtool, nvmet: Fix out-of-bounds stack access in nvmet_ctrl_state_show()\n\nThe csts_state_names[] array only has six sparse entries, but the\niteration code in nvmet_ctrl_state_show() iterates seven, resulting in a\npotential out-of-bounds stack read. Fix that.\n\nFixes the following warning with an UBSAN kernel:\n\n vmlinux.o: warning: objtool: .text.nvmet_ctrl_state_show: unexpected end of section", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-18T07:15:44Z" diff --git a/advisories/unreviewed/2025/04/GHSA-39c9-vmq6-wcfw/GHSA-39c9-vmq6-wcfw.json b/advisories/unreviewed/2025/04/GHSA-39c9-vmq6-wcfw/GHSA-39c9-vmq6-wcfw.json new file mode 100644 index 00000000000..f3a4018fe25 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-39c9-vmq6-wcfw/GHSA-39c9-vmq6-wcfw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-39c9-vmq6-wcfw", + "modified": "2025-04-28T18:30:57Z", + "published": "2025-04-28T18:30:57Z", + "aliases": [ + "CVE-2024-12706" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OpenTextâ„¢ Digital Asset Management. T\n\nhe vulnerability could allow an authenticated user to run arbitrary SQL commands on the underlying database. \n\nThis issue affects Digital Asset Management.: through 24.4.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:A/V:C/RE:M/U:Red" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12706" + }, + { + "type": "WEB", + "url": "https://support.opentext.com/csm?id=ot_kb_unauthenticated&sysparm_article=KB0840263" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-28T18:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3h8x-jv2f-mmvp/GHSA-3h8x-jv2f-mmvp.json b/advisories/unreviewed/2025/04/GHSA-3h8x-jv2f-mmvp/GHSA-3h8x-jv2f-mmvp.json new file mode 100644 index 00000000000..6a295cf8f6b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3h8x-jv2f-mmvp/GHSA-3h8x-jv2f-mmvp.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3h8x-jv2f-mmvp", + "modified": "2025-04-28T18:30:57Z", + "published": "2025-04-28T18:30:57Z", + "aliases": [ + "CVE-2025-4026" + ], + "details": "A vulnerability, which was classified as critical, has been found in PHPGurukul Nipah Virus Testing Management System 1.0. This issue affects some unknown processing of the file /profile.php. The manipulation of the argument adminname leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4026" + }, + { + "type": "WEB", + "url": "https://github.com/changan520374/cve/issues/1" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.306389" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.306389" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.558628" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-28T16:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-42j8-5f44-47fv/GHSA-42j8-5f44-47fv.json b/advisories/unreviewed/2025/04/GHSA-42j8-5f44-47fv/GHSA-42j8-5f44-47fv.json index 5c30d6da09f..0f27d0d7b73 100644 --- a/advisories/unreviewed/2025/04/GHSA-42j8-5f44-47fv/GHSA-42j8-5f44-47fv.json +++ b/advisories/unreviewed/2025/04/GHSA-42j8-5f44-47fv/GHSA-42j8-5f44-47fv.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-4gfp-3h23-q93c/GHSA-4gfp-3h23-q93c.json b/advisories/unreviewed/2025/04/GHSA-4gfp-3h23-q93c/GHSA-4gfp-3h23-q93c.json new file mode 100644 index 00000000000..5a62d6f2c41 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4gfp-3h23-q93c/GHSA-4gfp-3h23-q93c.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4gfp-3h23-q93c", + "modified": "2025-04-28T18:30:57Z", + "published": "2025-04-28T18:30:57Z", + "aliases": [ + "CVE-2025-4030" + ], + "details": "A vulnerability was found in PHPGurukul COVID19 Testing Management System 1.0. It has been classified as critical. This affects an unknown part of the file /search-report-result.php. The manipulation of the argument serachdata leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4030" + }, + { + "type": "WEB", + "url": "https://github.com/JunZ-Leo/CVE/issues/2" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.306393" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.306393" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.559199" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-28T18:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4p64-hxgr-8p2m/GHSA-4p64-hxgr-8p2m.json b/advisories/unreviewed/2025/04/GHSA-4p64-hxgr-8p2m/GHSA-4p64-hxgr-8p2m.json index 53175ad0d06..e7f6284ce47 100644 --- a/advisories/unreviewed/2025/04/GHSA-4p64-hxgr-8p2m/GHSA-4p64-hxgr-8p2m.json +++ b/advisories/unreviewed/2025/04/GHSA-4p64-hxgr-8p2m/GHSA-4p64-hxgr-8p2m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4p64-hxgr-8p2m", - "modified": "2025-04-28T06:30:26Z", + "modified": "2025-04-28T18:30:54Z", "published": "2025-04-28T06:30:26Z", "aliases": [ "CVE-2025-0627" ], "details": "The WordPress Tag, Category, and Taxonomy Manager WordPress plugin before 3.30.0 does not sanitise and escape some of its Widgets settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-28T06:15:17Z" diff --git a/advisories/unreviewed/2025/04/GHSA-5xhr-994v-5g9p/GHSA-5xhr-994v-5g9p.json b/advisories/unreviewed/2025/04/GHSA-5xhr-994v-5g9p/GHSA-5xhr-994v-5g9p.json new file mode 100644 index 00000000000..e9326b84908 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5xhr-994v-5g9p/GHSA-5xhr-994v-5g9p.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5xhr-994v-5g9p", + "modified": "2025-04-28T18:30:57Z", + "published": "2025-04-28T18:30:57Z", + "aliases": [ + "CVE-2023-35817" + ], + "details": "DevExpress before 23.1.3 allows AsyncDownloader SSRF.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35817" + }, + { + "type": "WEB", + "url": "https://code-white.com/public-vulnerability-list" + }, + { + "type": "WEB", + "url": "https://supportcenter.devexpress.com/ticket/details/t1157209/server-side-request-forgery-via-asyncdownloader" + }, + { + "type": "WEB", + "url": "https://supportcenter.devexpress.com/ticket/details/t1161404/report-and-dashboard-server-improper-default-configuration-can-lead-to-ssrf-attacks" + }, + { + "type": "WEB", + "url": "https://supportcenter.devexpress.com/ticket/details/t1162045/reporting-bi-dashboard-office-file-api-web-app-configuration-to-help-prevent-ssrf-attacks" + }, + { + "type": "WEB", + "url": "https://supportcenter.devexpress.com/ticket/details/t394936/devexpress-security-advisory-updated-on-april-27-2023" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-28T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-675p-6mmr-fffg/GHSA-675p-6mmr-fffg.json b/advisories/unreviewed/2025/04/GHSA-675p-6mmr-fffg/GHSA-675p-6mmr-fffg.json new file mode 100644 index 00000000000..faea5abd7a7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-675p-6mmr-fffg/GHSA-675p-6mmr-fffg.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-675p-6mmr-fffg", + "modified": "2025-04-28T18:30:57Z", + "published": "2025-04-28T18:30:57Z", + "aliases": [ + "CVE-2024-32499" + ], + "details": "Newforma Project Center Server through 2023.3.0.32259 allows remote code execution because .NET Remoting is exposed.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32499" + }, + { + "type": "WEB", + "url": "https://code-white.com/public-vulnerability-list" + }, + { + "type": "WEB", + "url": "https://www.newforma.com/newforma-project-center" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-28T17:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-84xx-9g7m-wh84/GHSA-84xx-9g7m-wh84.json b/advisories/unreviewed/2025/04/GHSA-84xx-9g7m-wh84/GHSA-84xx-9g7m-wh84.json new file mode 100644 index 00000000000..a3cb8672ce8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-84xx-9g7m-wh84/GHSA-84xx-9g7m-wh84.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-84xx-9g7m-wh84", + "modified": "2025-04-28T18:30:56Z", + "published": "2025-04-28T18:30:56Z", + "aliases": [ + "CVE-2023-35814" + ], + "details": "DevExpress before 23.1.3 does not properly protect XtraReport serialized data in ASP.NET web forms.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35814" + }, + { + "type": "WEB", + "url": "https://code-white.com/public-vulnerability-list" + }, + { + "type": "WEB", + "url": "https://supportcenter.devexpress.com/ticket/details/t1141158/missing-protection-of-xtrareport-serialized-data-in-asp-net-web-forms" + }, + { + "type": "WEB", + "url": "https://supportcenter.devexpress.com/ticket/details/t1158413/the-allowpassingdatasourceconnectionparameterstoclient-method-may-allow-untrusted-access" + }, + { + "type": "WEB", + "url": "https://supportcenter.devexpress.com/ticket/details/t1160535/web-reporting-well-formed-request-to-a-report-control-s-backend-can-use" + }, + { + "type": "WEB", + "url": "https://supportcenter.devexpress.com/ticket/details/t394936/devexpress-security-advisory-updated-on-april-27-2023" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-28T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8cfq-qm7w-3hgc/GHSA-8cfq-qm7w-3hgc.json b/advisories/unreviewed/2025/04/GHSA-8cfq-qm7w-3hgc/GHSA-8cfq-qm7w-3hgc.json index f454afd012f..33124f71992 100644 --- a/advisories/unreviewed/2025/04/GHSA-8cfq-qm7w-3hgc/GHSA-8cfq-qm7w-3hgc.json +++ b/advisories/unreviewed/2025/04/GHSA-8cfq-qm7w-3hgc/GHSA-8cfq-qm7w-3hgc.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-9cjw-338f-2m2w/GHSA-9cjw-338f-2m2w.json b/advisories/unreviewed/2025/04/GHSA-9cjw-338f-2m2w/GHSA-9cjw-338f-2m2w.json new file mode 100644 index 00000000000..65a4c9520ec --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9cjw-338f-2m2w/GHSA-9cjw-338f-2m2w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9cjw-338f-2m2w", + "modified": "2025-04-28T18:30:55Z", + "published": "2025-04-28T18:30:55Z", + "aliases": [ + "CVE-2015-4582" + ], + "details": "The TheCartPress boot-store (aka Boot Store) theme 1.6.4 for WordPress allows header.php tcp_register_error XSS. NOTE: CVE-2015-4582 is not assigned to any Oracle product.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2015-4582" + }, + { + "type": "WEB", + "url": "https://themes.trac.wordpress.org/browser/boot-store/1.6.4/header.php#L348" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-28T16:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9mh9-7p8c-gr7g/GHSA-9mh9-7p8c-gr7g.json b/advisories/unreviewed/2025/04/GHSA-9mh9-7p8c-gr7g/GHSA-9mh9-7p8c-gr7g.json new file mode 100644 index 00000000000..bbaf3f0d5dd --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9mh9-7p8c-gr7g/GHSA-9mh9-7p8c-gr7g.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9mh9-7p8c-gr7g", + "modified": "2025-04-28T18:30:55Z", + "published": "2025-04-28T18:30:55Z", + "aliases": [ + "CVE-2022-41871" + ], + "details": "SEPPmail through 12.1.17 allows command injection within the Admin Portal. An authenticated attacker is able to execute arbitrary code in the context of the user root.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-41871" + }, + { + "type": "WEB", + "url": "https://code-white.com/public-vulnerability-list" + }, + { + "type": "WEB", + "url": "https://www.seppmail.com/products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-28T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9xg6-228h-663v/GHSA-9xg6-228h-663v.json b/advisories/unreviewed/2025/04/GHSA-9xg6-228h-663v/GHSA-9xg6-228h-663v.json index ebfda560190..dc556ded3b2 100644 --- a/advisories/unreviewed/2025/04/GHSA-9xg6-228h-663v/GHSA-9xg6-228h-663v.json +++ b/advisories/unreviewed/2025/04/GHSA-9xg6-228h-663v/GHSA-9xg6-228h-663v.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-fx6v-2fj6-rmxx/GHSA-fx6v-2fj6-rmxx.json b/advisories/unreviewed/2025/04/GHSA-fx6v-2fj6-rmxx/GHSA-fx6v-2fj6-rmxx.json index 51fb03c7c83..5ed8cc471bc 100644 --- a/advisories/unreviewed/2025/04/GHSA-fx6v-2fj6-rmxx/GHSA-fx6v-2fj6-rmxx.json +++ b/advisories/unreviewed/2025/04/GHSA-fx6v-2fj6-rmxx/GHSA-fx6v-2fj6-rmxx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fx6v-2fj6-rmxx", - "modified": "2025-04-28T06:30:26Z", + "modified": "2025-04-28T18:30:53Z", "published": "2025-04-28T06:30:26Z", "aliases": [ "CVE-2024-9771" ], "details": "The WP-Recall WordPress plugin before 16.26.12 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-28T06:15:16Z" diff --git a/advisories/unreviewed/2025/04/GHSA-h4mr-59x2-64f9/GHSA-h4mr-59x2-64f9.json b/advisories/unreviewed/2025/04/GHSA-h4mr-59x2-64f9/GHSA-h4mr-59x2-64f9.json new file mode 100644 index 00000000000..b202d422ad7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-h4mr-59x2-64f9/GHSA-h4mr-59x2-64f9.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h4mr-59x2-64f9", + "modified": "2025-04-28T18:30:57Z", + "published": "2025-04-28T18:30:56Z", + "aliases": [ + "CVE-2023-35815" + ], + "details": "DevExpress before 23.1.3 has a data-source protection mechanism bypass during deserialization on XML data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35815" + }, + { + "type": "WEB", + "url": "https://code-white.com/public-vulnerability-list" + }, + { + "type": "WEB", + "url": "https://supportcenter.devexpress.com/ticket/details/t1141947/data-source-protection-bypass-during-xml-deserialization" + }, + { + "type": "WEB", + "url": "https://supportcenter.devexpress.com/ticket/details/t1159142/web-reporting-data-source-protection-bypassed-during-xml-deserialization" + }, + { + "type": "WEB", + "url": "https://supportcenter.devexpress.com/ticket/details/t394936/devexpress-security-advisory-updated-on-april-27-2023" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-28T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h7hv-3j2q-qw9g/GHSA-h7hv-3j2q-qw9g.json b/advisories/unreviewed/2025/04/GHSA-h7hv-3j2q-qw9g/GHSA-h7hv-3j2q-qw9g.json index b996ae56579..e0e58d71f50 100644 --- a/advisories/unreviewed/2025/04/GHSA-h7hv-3j2q-qw9g/GHSA-h7hv-3j2q-qw9g.json +++ b/advisories/unreviewed/2025/04/GHSA-h7hv-3j2q-qw9g/GHSA-h7hv-3j2q-qw9g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h7hv-3j2q-qw9g", - "modified": "2025-04-28T06:30:26Z", + "modified": "2025-04-28T18:30:53Z", "published": "2025-04-28T06:30:26Z", "aliases": [ "CVE-2024-13688" ], "details": "The Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10 uses a hardcoded password in its Password Protection feature, allowing attacker to bypass the protection offered via a crafted request", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-28T06:15:15Z" diff --git a/advisories/unreviewed/2025/04/GHSA-h9pw-jprm-xpcc/GHSA-h9pw-jprm-xpcc.json b/advisories/unreviewed/2025/04/GHSA-h9pw-jprm-xpcc/GHSA-h9pw-jprm-xpcc.json new file mode 100644 index 00000000000..df4eac77062 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-h9pw-jprm-xpcc/GHSA-h9pw-jprm-xpcc.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9pw-jprm-xpcc", + "modified": "2025-04-28T18:30:58Z", + "published": "2025-04-28T18:30:58Z", + "aliases": [ + "CVE-2025-4031" + ], + "details": "A vulnerability was found in PHPGurukul Pre-School Enrollment System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/aboutus.php. The manipulation of the argument pagetitle leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4031" + }, + { + "type": "WEB", + "url": "https://github.com/tailin1122/myCVE/issues/1" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.306394" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.306394" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.559221" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-28T18:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hq76-qh6p-g7m6/GHSA-hq76-qh6p-g7m6.json b/advisories/unreviewed/2025/04/GHSA-hq76-qh6p-g7m6/GHSA-hq76-qh6p-g7m6.json new file mode 100644 index 00000000000..3dbb09c33c5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hq76-qh6p-g7m6/GHSA-hq76-qh6p-g7m6.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hq76-qh6p-g7m6", + "modified": "2025-04-28T18:30:57Z", + "published": "2025-04-28T18:30:57Z", + "aliases": [ + "CVE-2025-4027" + ], + "details": "A vulnerability, which was classified as critical, was found in PHPGurukul Old Age Home Management System 1.0. Affected is an unknown function of the file /admin/rules.php. The manipulation of the argument pagetitle leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4027" + }, + { + "type": "WEB", + "url": "https://github.com/Q3qc1n/myCVE/issues/2" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.306390" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.306390" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.559159" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-28T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hr6g-q5gf-9f5f/GHSA-hr6g-q5gf-9f5f.json b/advisories/unreviewed/2025/04/GHSA-hr6g-q5gf-9f5f/GHSA-hr6g-q5gf-9f5f.json new file mode 100644 index 00000000000..8930b512130 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hr6g-q5gf-9f5f/GHSA-hr6g-q5gf-9f5f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hr6g-q5gf-9f5f", + "modified": "2025-04-28T18:30:57Z", + "published": "2025-04-28T18:30:57Z", + "aliases": [ + "CVE-2025-46614" + ], + "details": "In Snowflake ODBC Driver before 3.7.0, in certain code paths, the Driver logged the whole SQL query at the INFO level, aka Insertion of Sensitive Information into a Log File.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46614" + }, + { + "type": "WEB", + "url": "https://community.snowflake.com/s/article/Snowflake-Connector-for-ODBC-Security-Advisory-CVE-2025-46614" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-28T16:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mrq6-622v-vmqp/GHSA-mrq6-622v-vmqp.json b/advisories/unreviewed/2025/04/GHSA-mrq6-622v-vmqp/GHSA-mrq6-622v-vmqp.json index de0dc5fb7bd..3b5680ea342 100644 --- a/advisories/unreviewed/2025/04/GHSA-mrq6-622v-vmqp/GHSA-mrq6-622v-vmqp.json +++ b/advisories/unreviewed/2025/04/GHSA-mrq6-622v-vmqp/GHSA-mrq6-622v-vmqp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mrq6-622v-vmqp", - "modified": "2025-04-28T15:31:41Z", + "modified": "2025-04-28T18:30:55Z", "published": "2025-04-28T15:31:41Z", "aliases": [ "CVE-2025-25776" ], "details": "Cross-Site Scripting (XSS) vulnerability exists in the User Registration and User Profile features of Codeastro Bus Ticket Booking System v1.0 allows an attacker to execute arbitrary code into the Full Name and Address fields during user registration or profile editing.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-28T15:15:45Z" diff --git a/advisories/unreviewed/2025/04/GHSA-p7wm-439m-h6pp/GHSA-p7wm-439m-h6pp.json b/advisories/unreviewed/2025/04/GHSA-p7wm-439m-h6pp/GHSA-p7wm-439m-h6pp.json new file mode 100644 index 00000000000..ea8368bfd3c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p7wm-439m-h6pp/GHSA-p7wm-439m-h6pp.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p7wm-439m-h6pp", + "modified": "2025-04-28T18:30:57Z", + "published": "2025-04-28T18:30:57Z", + "aliases": [ + "CVE-2023-42404" + ], + "details": "OneVision Workspace before WS23.1 SR1 (build w31.040) allows arbitrary Java EL execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42404" + }, + { + "type": "WEB", + "url": "https://code-white.com/public-vulnerability-list" + }, + { + "type": "WEB", + "url": "https://www.onevision.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-28T17:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-ph83-p4wj-c47p/GHSA-ph83-p4wj-c47p.json b/advisories/unreviewed/2025/04/GHSA-ph83-p4wj-c47p/GHSA-ph83-p4wj-c47p.json index 77968e3a82e..ecbfd767c59 100644 --- a/advisories/unreviewed/2025/04/GHSA-ph83-p4wj-c47p/GHSA-ph83-p4wj-c47p.json +++ b/advisories/unreviewed/2025/04/GHSA-ph83-p4wj-c47p/GHSA-ph83-p4wj-c47p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-ph83-p4wj-c47p", - "modified": "2025-04-18T15:31:38Z", + "modified": "2025-04-28T18:30:51Z", "published": "2025-04-18T15:31:38Z", "aliases": [ "CVE-2025-39755" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: gpib: Fix cb7210 pcmcia Oops\n\nThe pcmcia_driver struct was still only using the old .name\ninitialization in the drv field. This led to a NULL pointer\nderef Oops in strcmp called from pcmcia_register_driver.\n\nInitialize the pcmcia_driver struct name field.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-18T07:15:44Z" diff --git a/advisories/unreviewed/2025/04/GHSA-vrw5-c37h-4jp2/GHSA-vrw5-c37h-4jp2.json b/advisories/unreviewed/2025/04/GHSA-vrw5-c37h-4jp2/GHSA-vrw5-c37h-4jp2.json new file mode 100644 index 00000000000..26d49fa91fa --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vrw5-c37h-4jp2/GHSA-vrw5-c37h-4jp2.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vrw5-c37h-4jp2", + "modified": "2025-04-28T18:30:57Z", + "published": "2025-04-28T18:30:57Z", + "aliases": [ + "CVE-2025-4029" + ], + "details": "A vulnerability was found in code-projects Personal Diary Management System 1.0 and classified as critical. Affected by this issue is the function addrecord of the component New Record Handler. The manipulation of the argument filename leads to stack-based buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4029" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/zzzxc643/cve/blob/main/Diary%20Management%20System%20Stack%20Buffer%20Overflow.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.306392" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.306392" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.559198" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-28T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xg84-4r3q-gjjw/GHSA-xg84-4r3q-gjjw.json b/advisories/unreviewed/2025/04/GHSA-xg84-4r3q-gjjw/GHSA-xg84-4r3q-gjjw.json new file mode 100644 index 00000000000..f049cc618eb --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xg84-4r3q-gjjw/GHSA-xg84-4r3q-gjjw.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xg84-4r3q-gjjw", + "modified": "2025-04-28T18:30:57Z", + "published": "2025-04-28T18:30:57Z", + "aliases": [ + "CVE-2025-4028" + ], + "details": "A vulnerability has been found in PHPGurukul COVID19 Testing Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /profile.php. The manipulation of the argument mobilenumber leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4028" + }, + { + "type": "WEB", + "url": "https://github.com/JunZ-Leo/CVE/issues/1" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.306391" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.306391" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.559193" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-28T17:15:50Z" + } +} \ No newline at end of file