From 502a56936bb1f30bd6e258ba40501d5cc20d8ba6 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 12 May 2025 15:31:47 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-mvrw-4465-r2jc.json | 2 +- .../GHSA-pv4h-p8jr-6cv2.json | 15 +++++--- .../GHSA-cwwf-74gf-jf68.json | 4 ++- .../GHSA-h93v-cpw2-8m3x.json | 4 ++- .../GHSA-hp7j-hj47-34vh.json | 2 +- .../GHSA-p689-3c5j-vchp.json | 4 ++- .../GHSA-f8cp-cqvw-c2xf.json | 36 +++++++++++++++++++ .../GHSA-2823-wfgm-j3hr.json | 15 +++++--- .../GHSA-5fjr-xr2p-8c46.json | 15 +++++--- .../GHSA-87v4-c5h4-88xg.json | 15 +++++--- .../GHSA-v4fw-ww7x-63fp.json | 15 +++++--- .../GHSA-4cwh-m6gc-c4p6.json | 15 +++++--- .../GHSA-7q2c-3wqx-c54w.json | 6 +++- .../GHSA-8fqh-f3cp-hqjx.json | 33 +++++++++++++++++ .../GHSA-99vm-2jmg-q6cj.json | 1 + .../GHSA-f74c-m4cg-rgj3.json | 33 +++++++++++++++++ .../GHSA-g988-pqhg-r7m5.json | 33 +++++++++++++++++ .../GHSA-gp6q-p5qw-43q6.json | 29 +++++++++++++++ .../GHSA-hmxm-mp3w-5hrg.json | 15 +++++--- .../GHSA-m53m-r8mm-799v.json | 33 +++++++++++++++++ .../GHSA-pmf4-qhrq-85qv.json | 33 +++++++++++++++++ .../GHSA-v2gm-5jqw-x4qc.json | 15 +++++--- .../GHSA-vp89-77x6-5qqm.json | 15 +++++--- .../GHSA-vqww-7r9g-2fhx.json | 33 +++++++++++++++++ .../GHSA-xfvq-95g5-jfq9.json | 6 +++- 25 files changed, 384 insertions(+), 43 deletions(-) create mode 100644 advisories/unreviewed/2024/10/GHSA-f8cp-cqvw-c2xf/GHSA-f8cp-cqvw-c2xf.json create mode 100644 advisories/unreviewed/2025/05/GHSA-8fqh-f3cp-hqjx/GHSA-8fqh-f3cp-hqjx.json create mode 100644 advisories/unreviewed/2025/05/GHSA-f74c-m4cg-rgj3/GHSA-f74c-m4cg-rgj3.json create mode 100644 advisories/unreviewed/2025/05/GHSA-g988-pqhg-r7m5/GHSA-g988-pqhg-r7m5.json create mode 100644 advisories/unreviewed/2025/05/GHSA-gp6q-p5qw-43q6/GHSA-gp6q-p5qw-43q6.json create mode 100644 advisories/unreviewed/2025/05/GHSA-m53m-r8mm-799v/GHSA-m53m-r8mm-799v.json create mode 100644 advisories/unreviewed/2025/05/GHSA-pmf4-qhrq-85qv/GHSA-pmf4-qhrq-85qv.json create mode 100644 advisories/unreviewed/2025/05/GHSA-vqww-7r9g-2fhx/GHSA-vqww-7r9g-2fhx.json diff --git a/advisories/unreviewed/2024/01/GHSA-mvrw-4465-r2jc/GHSA-mvrw-4465-r2jc.json b/advisories/unreviewed/2024/01/GHSA-mvrw-4465-r2jc/GHSA-mvrw-4465-r2jc.json index 51a28f760c0..00666b91ea6 100644 --- a/advisories/unreviewed/2024/01/GHSA-mvrw-4465-r2jc/GHSA-mvrw-4465-r2jc.json +++ b/advisories/unreviewed/2024/01/GHSA-mvrw-4465-r2jc/GHSA-mvrw-4465-r2jc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mvrw-4465-r2jc", - "modified": "2024-01-19T15:30:19Z", + "modified": "2025-05-12T15:30:35Z", "published": "2024-01-16T18:31:08Z", "aliases": [ "CVE-2021-24870" diff --git a/advisories/unreviewed/2024/02/GHSA-pv4h-p8jr-6cv2/GHSA-pv4h-p8jr-6cv2.json b/advisories/unreviewed/2024/02/GHSA-pv4h-p8jr-6cv2/GHSA-pv4h-p8jr-6cv2.json index d3a4b557d01..89018b89e6e 100644 --- a/advisories/unreviewed/2024/02/GHSA-pv4h-p8jr-6cv2/GHSA-pv4h-p8jr-6cv2.json +++ b/advisories/unreviewed/2024/02/GHSA-pv4h-p8jr-6cv2/GHSA-pv4h-p8jr-6cv2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pv4h-p8jr-6cv2", - "modified": "2024-06-10T18:30:52Z", + "modified": "2025-05-12T15:30:37Z", "published": "2024-02-14T18:30:25Z", "aliases": [ "CVE-2023-50868" ], "details": "The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the \"NSEC3\" issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -112,8 +117,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-14T16:15:45Z" diff --git a/advisories/unreviewed/2024/05/GHSA-cwwf-74gf-jf68/GHSA-cwwf-74gf-jf68.json b/advisories/unreviewed/2024/05/GHSA-cwwf-74gf-jf68/GHSA-cwwf-74gf-jf68.json index af140f2b0e9..f2b6dca55e2 100644 --- a/advisories/unreviewed/2024/05/GHSA-cwwf-74gf-jf68/GHSA-cwwf-74gf-jf68.json +++ b/advisories/unreviewed/2024/05/GHSA-cwwf-74gf-jf68/GHSA-cwwf-74gf-jf68.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-h93v-cpw2-8m3x/GHSA-h93v-cpw2-8m3x.json b/advisories/unreviewed/2024/05/GHSA-h93v-cpw2-8m3x/GHSA-h93v-cpw2-8m3x.json index fc144e6e9df..7cf476c4d67 100644 --- a/advisories/unreviewed/2024/05/GHSA-h93v-cpw2-8m3x/GHSA-h93v-cpw2-8m3x.json +++ b/advisories/unreviewed/2024/05/GHSA-h93v-cpw2-8m3x/GHSA-h93v-cpw2-8m3x.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-hp7j-hj47-34vh/GHSA-hp7j-hj47-34vh.json b/advisories/unreviewed/2024/05/GHSA-hp7j-hj47-34vh/GHSA-hp7j-hj47-34vh.json index d756ca0c0e2..cb7c7d00830 100644 --- a/advisories/unreviewed/2024/05/GHSA-hp7j-hj47-34vh/GHSA-hp7j-hj47-34vh.json +++ b/advisories/unreviewed/2024/05/GHSA-hp7j-hj47-34vh/GHSA-hp7j-hj47-34vh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hp7j-hj47-34vh", - "modified": "2024-07-03T18:42:37Z", + "modified": "2025-05-12T15:30:38Z", "published": "2024-05-20T15:31:44Z", "aliases": [ "CVE-2023-49330" diff --git a/advisories/unreviewed/2024/05/GHSA-p689-3c5j-vchp/GHSA-p689-3c5j-vchp.json b/advisories/unreviewed/2024/05/GHSA-p689-3c5j-vchp/GHSA-p689-3c5j-vchp.json index d992b3373fc..a3232bff613 100644 --- a/advisories/unreviewed/2024/05/GHSA-p689-3c5j-vchp/GHSA-p689-3c5j-vchp.json +++ b/advisories/unreviewed/2024/05/GHSA-p689-3c5j-vchp/GHSA-p689-3c5j-vchp.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/10/GHSA-f8cp-cqvw-c2xf/GHSA-f8cp-cqvw-c2xf.json b/advisories/unreviewed/2024/10/GHSA-f8cp-cqvw-c2xf/GHSA-f8cp-cqvw-c2xf.json new file mode 100644 index 00000000000..74f5d5ff981 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-f8cp-cqvw-c2xf/GHSA-f8cp-cqvw-c2xf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f8cp-cqvw-c2xf", + "modified": "2025-05-12T15:30:36Z", + "published": "2024-10-10T21:30:41Z", + "aliases": [ + "CVE-2023-24542" + ], + "details": "Unquoted search path or element in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24542" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00851.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-428" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T14:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2823-wfgm-j3hr/GHSA-2823-wfgm-j3hr.json b/advisories/unreviewed/2025/04/GHSA-2823-wfgm-j3hr/GHSA-2823-wfgm-j3hr.json index d67c92db84a..cb38528d19b 100644 --- a/advisories/unreviewed/2025/04/GHSA-2823-wfgm-j3hr/GHSA-2823-wfgm-j3hr.json +++ b/advisories/unreviewed/2025/04/GHSA-2823-wfgm-j3hr/GHSA-2823-wfgm-j3hr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2823-wfgm-j3hr", - "modified": "2025-04-21T18:32:09Z", + "modified": "2025-05-12T15:30:40Z", "published": "2025-04-21T18:32:09Z", "aliases": [ "CVE-2025-29446" ], "details": "open-webui v0.5.16 is vulnerable to SSRF in routers/ollama.py in function verify_connection.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-918" + ], + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-21T17:15:23Z" diff --git a/advisories/unreviewed/2025/04/GHSA-5fjr-xr2p-8c46/GHSA-5fjr-xr2p-8c46.json b/advisories/unreviewed/2025/04/GHSA-5fjr-xr2p-8c46/GHSA-5fjr-xr2p-8c46.json index b472e202f75..3e7dc91381d 100644 --- a/advisories/unreviewed/2025/04/GHSA-5fjr-xr2p-8c46/GHSA-5fjr-xr2p-8c46.json +++ b/advisories/unreviewed/2025/04/GHSA-5fjr-xr2p-8c46/GHSA-5fjr-xr2p-8c46.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5fjr-xr2p-8c46", - "modified": "2025-04-21T18:32:09Z", + "modified": "2025-05-12T15:30:40Z", "published": "2025-04-21T18:32:09Z", "aliases": [ "CVE-2025-28099" ], "details": "opencms V2.3 is vulnerable to Arbitrary file read in src/main/webapp/view/admin/document/dataPage.jsp,", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-21T17:15:23Z" diff --git a/advisories/unreviewed/2025/04/GHSA-87v4-c5h4-88xg/GHSA-87v4-c5h4-88xg.json b/advisories/unreviewed/2025/04/GHSA-87v4-c5h4-88xg/GHSA-87v4-c5h4-88xg.json index a349358ea9c..a83b2ee0400 100644 --- a/advisories/unreviewed/2025/04/GHSA-87v4-c5h4-88xg/GHSA-87v4-c5h4-88xg.json +++ b/advisories/unreviewed/2025/04/GHSA-87v4-c5h4-88xg/GHSA-87v4-c5h4-88xg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-87v4-c5h4-88xg", - "modified": "2025-04-21T18:32:09Z", + "modified": "2025-05-12T15:30:40Z", "published": "2025-04-21T18:32:09Z", "aliases": [ "CVE-2025-28103" ], "details": "Incorrect access control in laskBlog v2.6.1 allows attackers to arbitrarily delete user accounts via a crafted request.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-21T18:15:22Z" diff --git a/advisories/unreviewed/2025/04/GHSA-v4fw-ww7x-63fp/GHSA-v4fw-ww7x-63fp.json b/advisories/unreviewed/2025/04/GHSA-v4fw-ww7x-63fp/GHSA-v4fw-ww7x-63fp.json index cc2b9d12ff7..428299c57d7 100644 --- a/advisories/unreviewed/2025/04/GHSA-v4fw-ww7x-63fp/GHSA-v4fw-ww7x-63fp.json +++ b/advisories/unreviewed/2025/04/GHSA-v4fw-ww7x-63fp/GHSA-v4fw-ww7x-63fp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v4fw-ww7x-63fp", - "modified": "2025-04-21T18:32:09Z", + "modified": "2025-05-12T15:30:40Z", "published": "2025-04-21T18:32:09Z", "aliases": [ "CVE-2024-57394" ], "details": "The quarantine - restore function in Qi-ANXIN Tianqing Endpoint Security Management System v10.0 allows user to restore a malicious file to an arbitrary file path. Attackers can write malicious DLL to system path and perform privilege escalation by leveraging Windows DLL hijacking vulnerabilities.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-73" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-21T18:15:18Z" diff --git a/advisories/unreviewed/2025/05/GHSA-4cwh-m6gc-c4p6/GHSA-4cwh-m6gc-c4p6.json b/advisories/unreviewed/2025/05/GHSA-4cwh-m6gc-c4p6/GHSA-4cwh-m6gc-c4p6.json index d58d460f00f..faa29e52a98 100644 --- a/advisories/unreviewed/2025/05/GHSA-4cwh-m6gc-c4p6/GHSA-4cwh-m6gc-c4p6.json +++ b/advisories/unreviewed/2025/05/GHSA-4cwh-m6gc-c4p6/GHSA-4cwh-m6gc-c4p6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4cwh-m6gc-c4p6", - "modified": "2025-05-08T18:30:42Z", + "modified": "2025-05-12T15:30:40Z", "published": "2025-05-08T18:30:42Z", "aliases": [ "CVE-2025-45843" ], "details": "TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid parameter in the setWiFiGuestCfg function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-08T16:15:26Z" diff --git a/advisories/unreviewed/2025/05/GHSA-7q2c-3wqx-c54w/GHSA-7q2c-3wqx-c54w.json b/advisories/unreviewed/2025/05/GHSA-7q2c-3wqx-c54w/GHSA-7q2c-3wqx-c54w.json index a72152b4f06..09137180b79 100644 --- a/advisories/unreviewed/2025/05/GHSA-7q2c-3wqx-c54w/GHSA-7q2c-3wqx-c54w.json +++ b/advisories/unreviewed/2025/05/GHSA-7q2c-3wqx-c54w/GHSA-7q2c-3wqx-c54w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7q2c-3wqx-c54w", - "modified": "2025-05-11T12:30:29Z", + "modified": "2025-05-12T15:30:42Z", "published": "2025-05-11T12:30:29Z", "aliases": [ "CVE-2025-4539" @@ -38,6 +38,10 @@ { "type": "WEB", "url": "https://www.yuque.com/ba1ma0-an29k/nnxoap/dgxzuhd90e19grpg?singleDoc" + }, + { + "type": "WEB", + "url": "https://www.yuque.com/ba1ma0-an29k/nnxoap/dgxzuhd90e19grpg?singleDoc#%20%E3%80%8Atodesk%20program%20has%20a%20privilege%20escalation%20vulnerability%E3%80%8B" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/05/GHSA-8fqh-f3cp-hqjx/GHSA-8fqh-f3cp-hqjx.json b/advisories/unreviewed/2025/05/GHSA-8fqh-f3cp-hqjx/GHSA-8fqh-f3cp-hqjx.json new file mode 100644 index 00000000000..f77ba6146ae --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8fqh-f3cp-hqjx/GHSA-8fqh-f3cp-hqjx.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8fqh-f3cp-hqjx", + "modified": "2025-05-12T15:30:44Z", + "published": "2025-05-12T15:30:44Z", + "aliases": [ + "CVE-2025-46611" + ], + "details": "Cross Site Scripting vulnerability in ARTEC EMA Mail v6.92 allows an attacker to execute arbitrary code via a crafted script.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46611" + }, + { + "type": "WEB", + "url": "https://www.artec-it.com/en-us/ema.html" + }, + { + "type": "WEB", + "url": "https://www.syss.de/pentest-blog/csrf-und-xss-schwachstelle-in-ema-mail-von-artec-it-solutions-syss-2025-020/-021" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T15:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-99vm-2jmg-q6cj/GHSA-99vm-2jmg-q6cj.json b/advisories/unreviewed/2025/05/GHSA-99vm-2jmg-q6cj/GHSA-99vm-2jmg-q6cj.json index c5ed17db67d..d051433ebc9 100644 --- a/advisories/unreviewed/2025/05/GHSA-99vm-2jmg-q6cj/GHSA-99vm-2jmg-q6cj.json +++ b/advisories/unreviewed/2025/05/GHSA-99vm-2jmg-q6cj/GHSA-99vm-2jmg-q6cj.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-77", "CWE-94" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2025/05/GHSA-f74c-m4cg-rgj3/GHSA-f74c-m4cg-rgj3.json b/advisories/unreviewed/2025/05/GHSA-f74c-m4cg-rgj3/GHSA-f74c-m4cg-rgj3.json new file mode 100644 index 00000000000..79376bf0e13 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-f74c-m4cg-rgj3/GHSA-f74c-m4cg-rgj3.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f74c-m4cg-rgj3", + "modified": "2025-05-12T15:30:43Z", + "published": "2025-05-12T15:30:43Z", + "aliases": [ + "CVE-2024-56524" + ], + "details": "Radware Cloud Web Application Firewall (WAF) before 2025-05-07 allows remote attackers to bypass firewall filters by adding a special character to the request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56524" + }, + { + "type": "WEB", + "url": "https://radware.com/solutions/cloud-security" + }, + { + "type": "WEB", + "url": "https://www.kb.cert.org/vuls/id/722229" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T15:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g988-pqhg-r7m5/GHSA-g988-pqhg-r7m5.json b/advisories/unreviewed/2025/05/GHSA-g988-pqhg-r7m5/GHSA-g988-pqhg-r7m5.json new file mode 100644 index 00000000000..c96f325bc79 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g988-pqhg-r7m5/GHSA-g988-pqhg-r7m5.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g988-pqhg-r7m5", + "modified": "2025-05-12T15:30:44Z", + "published": "2025-05-12T15:30:44Z", + "aliases": [ + "CVE-2025-26841" + ], + "details": "Cross Site Scripting vulnerability in WPEVEREST Everest Forms before 3.0.9 allows an attacker to execute arbitrary code via a file upload.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26841" + }, + { + "type": "WEB", + "url": "https://everestforms.net" + }, + { + "type": "WEB", + "url": "https://gist.github.com/knilkantha/71458e9a787157653d5603fe6880bc05" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T15:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gp6q-p5qw-43q6/GHSA-gp6q-p5qw-43q6.json b/advisories/unreviewed/2025/05/GHSA-gp6q-p5qw-43q6/GHSA-gp6q-p5qw-43q6.json new file mode 100644 index 00000000000..27cb7a04287 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gp6q-p5qw-43q6/GHSA-gp6q-p5qw-43q6.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gp6q-p5qw-43q6", + "modified": "2025-05-12T15:30:42Z", + "published": "2025-05-12T15:30:42Z", + "aliases": [ + "CVE-2025-45835" + ], + "details": "A null pointer dereference vulnerability was discovered in Netis WF2880 v2.1.40207. The vulnerability exists in the FUN_004904c8 function of the cgitest.cgi file. Attackers can trigger this vulnerability by controlling the environment variable value CONTENT_LENGTH, causing the program to crash and potentially leading to a denial-of-service (DoS) attack.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45835" + }, + { + "type": "WEB", + "url": "https://github.com/Chinesexilinyu/Netis-WF2880-cgitest.cgi-Null-Pointer-Dereference-Vulnerability/tree/main/1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T14:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hmxm-mp3w-5hrg/GHSA-hmxm-mp3w-5hrg.json b/advisories/unreviewed/2025/05/GHSA-hmxm-mp3w-5hrg/GHSA-hmxm-mp3w-5hrg.json index bdfd545e78a..6571b40d434 100644 --- a/advisories/unreviewed/2025/05/GHSA-hmxm-mp3w-5hrg/GHSA-hmxm-mp3w-5hrg.json +++ b/advisories/unreviewed/2025/05/GHSA-hmxm-mp3w-5hrg/GHSA-hmxm-mp3w-5hrg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hmxm-mp3w-5hrg", - "modified": "2025-05-08T18:30:42Z", + "modified": "2025-05-12T15:30:40Z", "published": "2025-05-08T18:30:42Z", "aliases": [ "CVE-2023-51328" ], "details": "PHPJabbers Cleaning Business Software v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the \"c_name, name\" parameters.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-08T16:15:23Z" diff --git a/advisories/unreviewed/2025/05/GHSA-m53m-r8mm-799v/GHSA-m53m-r8mm-799v.json b/advisories/unreviewed/2025/05/GHSA-m53m-r8mm-799v/GHSA-m53m-r8mm-799v.json new file mode 100644 index 00000000000..a056bea89ed --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-m53m-r8mm-799v/GHSA-m53m-r8mm-799v.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m53m-r8mm-799v", + "modified": "2025-05-12T15:30:44Z", + "published": "2025-05-12T15:30:44Z", + "aliases": [ + "CVE-2025-26846" + ], + "details": "An issue was discovered in Znuny before 7.1.4. Permissions are not checked properly when using the Generic Interface to update ticket metadata.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26846" + }, + { + "type": "WEB", + "url": "https://www.znuny.com" + }, + { + "type": "WEB", + "url": "https://www.znuny.org/en/advisories/zsa-2025-02" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T15:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-pmf4-qhrq-85qv/GHSA-pmf4-qhrq-85qv.json b/advisories/unreviewed/2025/05/GHSA-pmf4-qhrq-85qv/GHSA-pmf4-qhrq-85qv.json new file mode 100644 index 00000000000..d89f36b55fb --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pmf4-qhrq-85qv/GHSA-pmf4-qhrq-85qv.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pmf4-qhrq-85qv", + "modified": "2025-05-12T15:30:42Z", + "published": "2025-05-12T15:30:42Z", + "aliases": [ + "CVE-2024-56523" + ], + "details": "Radware Cloud Web Application Firewall (WAF) before 2025-05-07 allows remote attackers to bypass firewall filters by placing random data in the HTTP request body when using the HTTP GET method.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56523" + }, + { + "type": "WEB", + "url": "https://radware.com/solutions/cloud-security" + }, + { + "type": "WEB", + "url": "https://www.kb.cert.org/vuls/id/722229" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T15:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v2gm-5jqw-x4qc/GHSA-v2gm-5jqw-x4qc.json b/advisories/unreviewed/2025/05/GHSA-v2gm-5jqw-x4qc/GHSA-v2gm-5jqw-x4qc.json index 18fa20bf290..7fb0652c6be 100644 --- a/advisories/unreviewed/2025/05/GHSA-v2gm-5jqw-x4qc/GHSA-v2gm-5jqw-x4qc.json +++ b/advisories/unreviewed/2025/05/GHSA-v2gm-5jqw-x4qc/GHSA-v2gm-5jqw-x4qc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v2gm-5jqw-x4qc", - "modified": "2025-05-03T00:30:32Z", + "modified": "2025-05-12T15:30:40Z", "published": "2025-05-03T00:30:32Z", "aliases": [ "CVE-2024-55069" ], "details": "ffmpeg 7.1 is vulnerable to Null Pointer Dereference in function iamf_read_header in /libavformat/iamfdec.c.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-02T22:15:16Z" diff --git a/advisories/unreviewed/2025/05/GHSA-vp89-77x6-5qqm/GHSA-vp89-77x6-5qqm.json b/advisories/unreviewed/2025/05/GHSA-vp89-77x6-5qqm/GHSA-vp89-77x6-5qqm.json index 9b053abc467..42d20097c11 100644 --- a/advisories/unreviewed/2025/05/GHSA-vp89-77x6-5qqm/GHSA-vp89-77x6-5qqm.json +++ b/advisories/unreviewed/2025/05/GHSA-vp89-77x6-5qqm/GHSA-vp89-77x6-5qqm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vp89-77x6-5qqm", - "modified": "2025-05-08T18:30:42Z", + "modified": "2025-05-12T15:30:40Z", "published": "2025-05-08T18:30:42Z", "aliases": [ "CVE-2025-45842" ], "details": "TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid5g parameter in the setWiFiEasyCfg function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-08T16:15:26Z" diff --git a/advisories/unreviewed/2025/05/GHSA-vqww-7r9g-2fhx/GHSA-vqww-7r9g-2fhx.json b/advisories/unreviewed/2025/05/GHSA-vqww-7r9g-2fhx/GHSA-vqww-7r9g-2fhx.json new file mode 100644 index 00000000000..d0156780268 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vqww-7r9g-2fhx/GHSA-vqww-7r9g-2fhx.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vqww-7r9g-2fhx", + "modified": "2025-05-12T15:30:44Z", + "published": "2025-05-12T15:30:44Z", + "aliases": [ + "CVE-2025-46610" + ], + "details": "ARTEC EMA Mail 6.92 allows CSRF.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46610" + }, + { + "type": "WEB", + "url": "https://www.artec-it.com/en-us/ema.html" + }, + { + "type": "WEB", + "url": "https://www.syss.de/pentest-blog/csrf-und-xss-schwachstelle-in-ema-mail-von-artec-it-solutions-syss-2025-020/-021" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T15:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xfvq-95g5-jfq9/GHSA-xfvq-95g5-jfq9.json b/advisories/unreviewed/2025/05/GHSA-xfvq-95g5-jfq9/GHSA-xfvq-95g5-jfq9.json index ee26d99f526..f6a9d874a67 100644 --- a/advisories/unreviewed/2025/05/GHSA-xfvq-95g5-jfq9/GHSA-xfvq-95g5-jfq9.json +++ b/advisories/unreviewed/2025/05/GHSA-xfvq-95g5-jfq9/GHSA-xfvq-95g5-jfq9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xfvq-95g5-jfq9", - "modified": "2025-05-07T18:30:50Z", + "modified": "2025-05-12T15:30:40Z", "published": "2025-05-07T18:30:50Z", "aliases": [ "CVE-2025-32819" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32819" }, + { + "type": "WEB", + "url": "https://old.rapid7.com/blog/post/2025/05/07/multiple-vulnerabilities-in-sonicwall-sma-100-series-2025" + }, { "type": "WEB", "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0011"