diff --git a/advisories/unreviewed/2023/03/GHSA-mjfv-7q85-fj8m/GHSA-mjfv-7q85-fj8m.json b/advisories/unreviewed/2023/03/GHSA-mjfv-7q85-fj8m/GHSA-mjfv-7q85-fj8m.json index 3fd40bd263d..e08462bbdbe 100644 --- a/advisories/unreviewed/2023/03/GHSA-mjfv-7q85-fj8m/GHSA-mjfv-7q85-fj8m.json +++ b/advisories/unreviewed/2023/03/GHSA-mjfv-7q85-fj8m/GHSA-mjfv-7q85-fj8m.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-287" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-rm99-52xq-2r9w/GHSA-rm99-52xq-2r9w.json b/advisories/unreviewed/2023/03/GHSA-rm99-52xq-2r9w/GHSA-rm99-52xq-2r9w.json index ce9e6199a44..5d6a031be2d 100644 --- a/advisories/unreviewed/2023/03/GHSA-rm99-52xq-2r9w/GHSA-rm99-52xq-2r9w.json +++ b/advisories/unreviewed/2023/03/GHSA-rm99-52xq-2r9w/GHSA-rm99-52xq-2r9w.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-177" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-vm8m-8vm4-x33v/GHSA-vm8m-8vm4-x33v.json b/advisories/unreviewed/2023/03/GHSA-vm8m-8vm4-x33v/GHSA-vm8m-8vm4-x33v.json index b9535894379..b12910ead34 100644 --- a/advisories/unreviewed/2023/03/GHSA-vm8m-8vm4-x33v/GHSA-vm8m-8vm4-x33v.json +++ b/advisories/unreviewed/2023/03/GHSA-vm8m-8vm4-x33v/GHSA-vm8m-8vm4-x33v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vm8m-8vm4-x33v", - "modified": "2023-03-13T15:30:17Z", + "modified": "2025-03-06T21:31:19Z", "published": "2023-03-06T21:30:18Z", "aliases": [ "CVE-2023-0093" diff --git a/advisories/unreviewed/2023/06/GHSA-fjhg-vc4c-336q/GHSA-fjhg-vc4c-336q.json b/advisories/unreviewed/2023/06/GHSA-fjhg-vc4c-336q/GHSA-fjhg-vc4c-336q.json index 39692c19409..7d3d1574ef9 100644 --- a/advisories/unreviewed/2023/06/GHSA-fjhg-vc4c-336q/GHSA-fjhg-vc4c-336q.json +++ b/advisories/unreviewed/2023/06/GHSA-fjhg-vc4c-336q/GHSA-fjhg-vc4c-336q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fjhg-vc4c-336q", - "modified": "2024-04-04T05:06:51Z", + "modified": "2025-03-06T21:31:20Z", "published": "2023-06-23T15:30:44Z", "aliases": [ "CVE-2023-36274" @@ -22,6 +22,14 @@ { "type": "WEB", "url": "https://github.com/LibreDWG/libredwg/issues/677#BUG2" + }, + { + "type": "WEB", + "url": "https://github.com/LibreDWG/libredwg/commit/8651fa27dd2de731e706e2ba09f0d28e4e0dce33" + }, + { + "type": "WEB", + "url": "https://github.com/LibreDWG/libredwg/blob/0.11/src/out_dxf.c#L1792" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/06/GHSA-fx57-4pvv-5x6q/GHSA-fx57-4pvv-5x6q.json b/advisories/unreviewed/2023/06/GHSA-fx57-4pvv-5x6q/GHSA-fx57-4pvv-5x6q.json index b4a8ed71553..416e8bc63a0 100644 --- a/advisories/unreviewed/2023/06/GHSA-fx57-4pvv-5x6q/GHSA-fx57-4pvv-5x6q.json +++ b/advisories/unreviewed/2023/06/GHSA-fx57-4pvv-5x6q/GHSA-fx57-4pvv-5x6q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fx57-4pvv-5x6q", - "modified": "2024-04-04T05:06:46Z", + "modified": "2025-03-06T21:31:20Z", "published": "2023-06-23T15:30:44Z", "aliases": [ "CVE-2023-36271" @@ -22,6 +22,14 @@ { "type": "WEB", "url": "https://github.com/LibreDWG/libredwg/issues/681#BUG2" + }, + { + "type": "WEB", + "url": "https://github.com/LibreDWG/libredwg/commit/c1ed1d91e28a6ddc7a9b5479d4795d58fb6be0ca" + }, + { + "type": "WEB", + "url": "https://github.com/LibreDWG/libredwg/blob/0.10/src/bits.c#L1677C11-L1683C17" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/06/GHSA-v7hc-4p56-pcfx/GHSA-v7hc-4p56-pcfx.json b/advisories/unreviewed/2023/06/GHSA-v7hc-4p56-pcfx/GHSA-v7hc-4p56-pcfx.json index 2f9d3cfdeee..a4a3082401b 100644 --- a/advisories/unreviewed/2023/06/GHSA-v7hc-4p56-pcfx/GHSA-v7hc-4p56-pcfx.json +++ b/advisories/unreviewed/2023/06/GHSA-v7hc-4p56-pcfx/GHSA-v7hc-4p56-pcfx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v7hc-4p56-pcfx", - "modified": "2024-04-04T05:06:47Z", + "modified": "2025-03-06T21:31:20Z", "published": "2023-06-23T15:30:44Z", "aliases": [ "CVE-2023-36272" @@ -22,6 +22,14 @@ { "type": "WEB", "url": "https://github.com/LibreDWG/libredwg/issues/681#BUG1" + }, + { + "type": "WEB", + "url": "https://github.com/LibreDWG/libredwg/commit/c1ed1d91e28a6ddc7a9b5479d4795d58fb6be0ca" + }, + { + "type": "WEB", + "url": "https://github.com/LibreDWG/libredwg/blob/0.10/src/bits.c#L1677C11-L1683C17" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/12/GHSA-qp49-g67r-vh5q/GHSA-qp49-g67r-vh5q.json b/advisories/unreviewed/2024/12/GHSA-qp49-g67r-vh5q/GHSA-qp49-g67r-vh5q.json index 7b110196501..d617b971f5b 100644 --- a/advisories/unreviewed/2024/12/GHSA-qp49-g67r-vh5q/GHSA-qp49-g67r-vh5q.json +++ b/advisories/unreviewed/2024/12/GHSA-qp49-g67r-vh5q/GHSA-qp49-g67r-vh5q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qp49-g67r-vh5q", - "modified": "2024-12-10T18:31:07Z", + "modified": "2025-03-06T21:31:22Z", "published": "2024-12-10T18:31:07Z", "aliases": [ "CVE-2024-53245" diff --git a/advisories/unreviewed/2025/01/GHSA-9pcx-8wcv-8m4v/GHSA-9pcx-8wcv-8m4v.json b/advisories/unreviewed/2025/01/GHSA-9pcx-8wcv-8m4v/GHSA-9pcx-8wcv-8m4v.json index 98ec1e2c3e1..2d5abeb8ff3 100644 --- a/advisories/unreviewed/2025/01/GHSA-9pcx-8wcv-8m4v/GHSA-9pcx-8wcv-8m4v.json +++ b/advisories/unreviewed/2025/01/GHSA-9pcx-8wcv-8m4v/GHSA-9pcx-8wcv-8m4v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9pcx-8wcv-8m4v", - "modified": "2025-01-08T09:30:38Z", + "modified": "2025-03-06T21:31:23Z", "published": "2025-01-08T09:30:38Z", "aliases": [ "CVE-2024-12584" diff --git a/advisories/unreviewed/2025/01/GHSA-9ppf-383x-3hmv/GHSA-9ppf-383x-3hmv.json b/advisories/unreviewed/2025/01/GHSA-9ppf-383x-3hmv/GHSA-9ppf-383x-3hmv.json index 245f2f51335..4b845c274dc 100644 --- a/advisories/unreviewed/2025/01/GHSA-9ppf-383x-3hmv/GHSA-9ppf-383x-3hmv.json +++ b/advisories/unreviewed/2025/01/GHSA-9ppf-383x-3hmv/GHSA-9ppf-383x-3hmv.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-35" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/02/GHSA-2g8h-33rh-hp24/GHSA-2g8h-33rh-hp24.json b/advisories/unreviewed/2025/02/GHSA-2g8h-33rh-hp24/GHSA-2g8h-33rh-hp24.json index 8aa6364f9cf..3f2fc6356ba 100644 --- a/advisories/unreviewed/2025/02/GHSA-2g8h-33rh-hp24/GHSA-2g8h-33rh-hp24.json +++ b/advisories/unreviewed/2025/02/GHSA-2g8h-33rh-hp24/GHSA-2g8h-33rh-hp24.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2g8h-33rh-hp24", - "modified": "2025-02-28T06:30:48Z", + "modified": "2025-03-06T21:31:25Z", "published": "2025-02-28T06:30:48Z", "aliases": [ "CVE-2024-13796" diff --git a/advisories/unreviewed/2025/02/GHSA-44w2-c6gq-2xxx/GHSA-44w2-c6gq-2xxx.json b/advisories/unreviewed/2025/02/GHSA-44w2-c6gq-2xxx/GHSA-44w2-c6gq-2xxx.json index aaef0676628..bcb2623e04b 100644 --- a/advisories/unreviewed/2025/02/GHSA-44w2-c6gq-2xxx/GHSA-44w2-c6gq-2xxx.json +++ b/advisories/unreviewed/2025/02/GHSA-44w2-c6gq-2xxx/GHSA-44w2-c6gq-2xxx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-44w2-c6gq-2xxx", - "modified": "2025-02-22T21:30:52Z", + "modified": "2025-03-06T21:31:25Z", "published": "2025-02-06T06:31:26Z", "aliases": [ "CVE-2024-38316" diff --git a/advisories/unreviewed/2025/02/GHSA-46vg-h2w6-gh78/GHSA-46vg-h2w6-gh78.json b/advisories/unreviewed/2025/02/GHSA-46vg-h2w6-gh78/GHSA-46vg-h2w6-gh78.json index 7e1e0b86691..03af5d6f46c 100644 --- a/advisories/unreviewed/2025/02/GHSA-46vg-h2w6-gh78/GHSA-46vg-h2w6-gh78.json +++ b/advisories/unreviewed/2025/02/GHSA-46vg-h2w6-gh78/GHSA-46vg-h2w6-gh78.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-46vg-h2w6-gh78", - "modified": "2025-02-28T15:31:04Z", + "modified": "2025-03-06T21:31:26Z", "published": "2025-02-28T15:31:04Z", "aliases": [ "CVE-2025-26326" ], "details": "A vulnerability in the remote connection complements of the NVDA (Nonvisual Desktop Access) 2024.4.1 and 2024.4.2 was identified, which allows an attacker to obtain total control of the remote system when guessing a weak password. The problem occurs because the complements accept any password typed by the user and do not have an additional authentication or checking mechanism by the computer that will be accessed. Tests indicate that over 1,000 systems use easy to guess passwords, many with less than 4 to 6 characters, including common sequences. This enables brute strength or attempt and error attacks on the part of malicious invaders. Vulnerability can be explored by a remote striker who knows or can guess the password used in the connection. As a result, the invader gets complete access to the affected system and can run commands, modify files and compromise user security.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-287" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-28T15:15:13Z" diff --git a/advisories/unreviewed/2025/02/GHSA-79wv-5cfm-5wm8/GHSA-79wv-5cfm-5wm8.json b/advisories/unreviewed/2025/02/GHSA-79wv-5cfm-5wm8/GHSA-79wv-5cfm-5wm8.json index 406ee13d245..21c8361cd4e 100644 --- a/advisories/unreviewed/2025/02/GHSA-79wv-5cfm-5wm8/GHSA-79wv-5cfm-5wm8.json +++ b/advisories/unreviewed/2025/02/GHSA-79wv-5cfm-5wm8/GHSA-79wv-5cfm-5wm8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-79wv-5cfm-5wm8", - "modified": "2025-02-28T18:31:04Z", + "modified": "2025-03-06T21:31:26Z", "published": "2025-02-28T18:31:04Z", "aliases": [ "CVE-2024-44754" ], "details": "Cryptographic key extraction from internal flash in Minut M2 with firmware version #15142 allows physically proximate attackers to inject modified firmware into any other Minut M2 product via USB.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-522" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-28T16:15:37Z" diff --git a/advisories/unreviewed/2025/02/GHSA-9ffm-4mfx-v85f/GHSA-9ffm-4mfx-v85f.json b/advisories/unreviewed/2025/02/GHSA-9ffm-4mfx-v85f/GHSA-9ffm-4mfx-v85f.json index 86652dc7d17..f984f57b0eb 100644 --- a/advisories/unreviewed/2025/02/GHSA-9ffm-4mfx-v85f/GHSA-9ffm-4mfx-v85f.json +++ b/advisories/unreviewed/2025/02/GHSA-9ffm-4mfx-v85f/GHSA-9ffm-4mfx-v85f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9ffm-4mfx-v85f", - "modified": "2025-02-28T06:30:48Z", + "modified": "2025-03-06T21:31:25Z", "published": "2025-02-28T06:30:48Z", "aliases": [ "CVE-2025-1757" diff --git a/advisories/unreviewed/2025/02/GHSA-gvrr-q7f9-rx5j/GHSA-gvrr-q7f9-rx5j.json b/advisories/unreviewed/2025/02/GHSA-gvrr-q7f9-rx5j/GHSA-gvrr-q7f9-rx5j.json index 7207ebcf679..dcf2429dd72 100644 --- a/advisories/unreviewed/2025/02/GHSA-gvrr-q7f9-rx5j/GHSA-gvrr-q7f9-rx5j.json +++ b/advisories/unreviewed/2025/02/GHSA-gvrr-q7f9-rx5j/GHSA-gvrr-q7f9-rx5j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gvrr-q7f9-rx5j", - "modified": "2025-02-06T06:31:26Z", + "modified": "2025-03-06T21:31:25Z", "published": "2025-02-06T06:31:26Z", "aliases": [ "CVE-2024-56473" @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-116", "CWE-117" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/02/GHSA-jmcm-9g64-4qhv/GHSA-jmcm-9g64-4qhv.json b/advisories/unreviewed/2025/02/GHSA-jmcm-9g64-4qhv/GHSA-jmcm-9g64-4qhv.json index 97fb6b708a5..e01203bd866 100644 --- a/advisories/unreviewed/2025/02/GHSA-jmcm-9g64-4qhv/GHSA-jmcm-9g64-4qhv.json +++ b/advisories/unreviewed/2025/02/GHSA-jmcm-9g64-4qhv/GHSA-jmcm-9g64-4qhv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jmcm-9g64-4qhv", - "modified": "2025-02-28T18:31:04Z", + "modified": "2025-03-06T21:31:26Z", "published": "2025-02-28T18:31:04Z", "aliases": [ "CVE-2025-26047" ], "details": "Loggrove v1.0 is vulnerable to SQL Injection in the read.py file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-28T16:15:40Z" diff --git a/advisories/unreviewed/2025/03/GHSA-2jvp-r7m9-xhpr/GHSA-2jvp-r7m9-xhpr.json b/advisories/unreviewed/2025/03/GHSA-2jvp-r7m9-xhpr/GHSA-2jvp-r7m9-xhpr.json new file mode 100644 index 00000000000..f2d29409c82 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2jvp-r7m9-xhpr/GHSA-2jvp-r7m9-xhpr.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2jvp-r7m9-xhpr", + "modified": "2025-03-06T21:31:27Z", + "published": "2025-03-06T21:31:27Z", + "aliases": [ + "CVE-2025-25497" + ], + "details": "An issue in account management interface in Netsweeper Server v.8.2.6 and earlier (fixed in v.8.2.7) allows unauthorized changes to the \"Account Owner\" field due to client-side-only restrictions and a lack of server-side validation. This vulnerability enables account ownership reassignment to or away from any user.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25497" + }, + { + "type": "WEB", + "url": "https://helpdesk.netsweeper.com/docs/8_2_Docs/8_2_Netsweeper_Docs/Content/Release_Notes/Netsweeper_Release_Notes/8_2_Release_Notes/8_2_7_Release_and_Downloads.htm" + }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/188626" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T20:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7cgj-hhfq-rgx4/GHSA-7cgj-hhfq-rgx4.json b/advisories/unreviewed/2025/03/GHSA-7cgj-hhfq-rgx4/GHSA-7cgj-hhfq-rgx4.json new file mode 100644 index 00000000000..2a0656b7d51 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7cgj-hhfq-rgx4/GHSA-7cgj-hhfq-rgx4.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7cgj-hhfq-rgx4", + "modified": "2025-03-06T21:31:26Z", + "published": "2025-03-06T21:31:26Z", + "aliases": [ + "CVE-2024-50600" + ], + "details": "An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, W920, W930, and W1000. Lack of a boundary check in STOP_KEEP_ALIVE_OFFLOAD leads to out-of-bounds access. An attacker can send a malformed message to the target through the Wi-Fi driver.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50600" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T19:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9gpw-rmhm-r2vm/GHSA-9gpw-rmhm-r2vm.json b/advisories/unreviewed/2025/03/GHSA-9gpw-rmhm-r2vm/GHSA-9gpw-rmhm-r2vm.json new file mode 100644 index 00000000000..650f0dc60b1 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9gpw-rmhm-r2vm/GHSA-9gpw-rmhm-r2vm.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9gpw-rmhm-r2vm", + "modified": "2025-03-06T21:31:25Z", + "published": "2025-03-06T21:31:25Z", + "aliases": [ + "CVE-2025-25825" + ], + "details": "A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Titile in the article category section.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25825" + }, + { + "type": "WEB", + "url": "https://github.com/Ka7arotto/emlog/blob/main/xss-4.md" + }, + { + "type": "WEB", + "url": "https://www.emlog.net" + }, + { + "type": "WEB", + "url": "http://emlogpro.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T15:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-f2xx-646h-c4q2/GHSA-f2xx-646h-c4q2.json b/advisories/unreviewed/2025/03/GHSA-f2xx-646h-c4q2/GHSA-f2xx-646h-c4q2.json new file mode 100644 index 00000000000..d38d950eac9 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-f2xx-646h-c4q2/GHSA-f2xx-646h-c4q2.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f2xx-646h-c4q2", + "modified": "2025-03-06T21:31:27Z", + "published": "2025-03-06T21:31:27Z", + "aliases": [ + "CVE-2025-2036" + ], + "details": "A vulnerability was found in s-a-zhd Ecommerce-Website-using-PHP 1.0. It has been classified as critical. This affects an unknown part of the file details.php. The manipulation of the argument pro_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2036" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.298779" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.298779" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.512405" + }, + { + "type": "WEB", + "url": "https://www.websecurityinsights.my.id/2025/03/e-commerce-10-detailsphpproid-sql.html?m=1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T19:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fpj9-jj78-pv6w/GHSA-fpj9-jj78-pv6w.json b/advisories/unreviewed/2025/03/GHSA-fpj9-jj78-pv6w/GHSA-fpj9-jj78-pv6w.json new file mode 100644 index 00000000000..b5b04b84e72 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fpj9-jj78-pv6w/GHSA-fpj9-jj78-pv6w.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fpj9-jj78-pv6w", + "modified": "2025-03-06T21:31:25Z", + "published": "2025-03-06T21:31:25Z", + "aliases": [ + "CVE-2025-25827" + ], + "details": "A Server-Side Request Forgery (SSRF) in the component sort.php of Emlog Pro v2.5.4 allows attackers to scan local and internal ports via supplying a crafted URL.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25827" + }, + { + "type": "WEB", + "url": "https://github.com/Ka7arotto/emlog/blob/main/ssrf.md" + }, + { + "type": "WEB", + "url": "https://www.emlog.net" + }, + { + "type": "WEB", + "url": "http://emlogpro.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T15:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hhgh-4vpc-8c58/GHSA-hhgh-4vpc-8c58.json b/advisories/unreviewed/2025/03/GHSA-hhgh-4vpc-8c58/GHSA-hhgh-4vpc-8c58.json new file mode 100644 index 00000000000..f56189034d8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hhgh-4vpc-8c58/GHSA-hhgh-4vpc-8c58.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hhgh-4vpc-8c58", + "modified": "2025-03-06T21:31:27Z", + "published": "2025-03-06T21:31:27Z", + "aliases": [ + "CVE-2025-2038" + ], + "details": "A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /upload/. The manipulation leads to exposure of information through directory listing. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2038" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/intercpt/XSS1/blob/main/Directorylisting.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.298781" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.298781" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.512558" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-548" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T20:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hv2c-wf43-5v98/GHSA-hv2c-wf43-5v98.json b/advisories/unreviewed/2025/03/GHSA-hv2c-wf43-5v98/GHSA-hv2c-wf43-5v98.json new file mode 100644 index 00000000000..dc8e91b4d1b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hv2c-wf43-5v98/GHSA-hv2c-wf43-5v98.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hv2c-wf43-5v98", + "modified": "2025-03-06T21:31:27Z", + "published": "2025-03-06T21:31:27Z", + "aliases": [ + "CVE-2025-2040" + ], + "details": "A vulnerability classified as critical was found in zhijiantianya ruoyi-vue-pro 2.4.1. Affected by this vulnerability is an unknown functionality of the file /admin-api/bpm/model/deploy. The manipulation leads to improper neutralization of special elements used in a template engine. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2040" + }, + { + "type": "WEB", + "url": "https://github.com/uglory-gll/javasec/blob/main/ruoyi-vue-pro.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.298783" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.298783" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.512574" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-791" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T20:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-j8h4-gqcq-8cwq/GHSA-j8h4-gqcq-8cwq.json b/advisories/unreviewed/2025/03/GHSA-j8h4-gqcq-8cwq/GHSA-j8h4-gqcq-8cwq.json new file mode 100644 index 00000000000..be998bc1604 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-j8h4-gqcq-8cwq/GHSA-j8h4-gqcq-8cwq.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j8h4-gqcq-8cwq", + "modified": "2025-03-06T21:31:25Z", + "published": "2025-03-06T21:31:25Z", + "aliases": [ + "CVE-2025-25823" + ], + "details": "A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the article header at /admin/article.php.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25823" + }, + { + "type": "WEB", + "url": "https://github.com/Ka7arotto/emlog/blob/main/xss-3.md" + }, + { + "type": "WEB", + "url": "https://www.emlog.net" + }, + { + "type": "WEB", + "url": "http://emlogpro.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T15:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-p3fp-8748-vqfq/GHSA-p3fp-8748-vqfq.json b/advisories/unreviewed/2025/03/GHSA-p3fp-8748-vqfq/GHSA-p3fp-8748-vqfq.json new file mode 100644 index 00000000000..2d8dfbb611a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-p3fp-8748-vqfq/GHSA-p3fp-8748-vqfq.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p3fp-8748-vqfq", + "modified": "2025-03-06T21:31:27Z", + "published": "2025-03-06T21:31:26Z", + "aliases": [ + "CVE-2025-26699" + ], + "details": "An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 before 4.2.20. The django.utils.text.wrap() method and wordwrap template filter are subject to a potential denial-of-service attack when used with very long strings.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26699" + }, + { + "type": "WEB", + "url": "https://docs.djangoproject.com/en/dev/releases/security" + }, + { + "type": "WEB", + "url": "https://groups.google.com/g/django-announce" + }, + { + "type": "WEB", + "url": "https://www.djangoproject.com/weblog/2025/mar/06/security-releases" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/03/06/12" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T19:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-p3j9-7cr8-32qx/GHSA-p3j9-7cr8-32qx.json b/advisories/unreviewed/2025/03/GHSA-p3j9-7cr8-32qx/GHSA-p3j9-7cr8-32qx.json new file mode 100644 index 00000000000..e4331de7365 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-p3j9-7cr8-32qx/GHSA-p3j9-7cr8-32qx.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p3j9-7cr8-32qx", + "modified": "2025-03-06T21:31:28Z", + "published": "2025-03-06T21:31:28Z", + "aliases": [ + "CVE-2025-2042" + ], + "details": "A vulnerability has been found in huang-yk student-manage 1.0 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2042" + }, + { + "type": "WEB", + "url": "https://github.com/Jingyi-u/student-manage/tree/main" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.298786" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.298786" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.512940" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T21:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-pfpf-6q8p-prjp/GHSA-pfpf-6q8p-prjp.json b/advisories/unreviewed/2025/03/GHSA-pfpf-6q8p-prjp/GHSA-pfpf-6q8p-prjp.json new file mode 100644 index 00000000000..38a32998234 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-pfpf-6q8p-prjp/GHSA-pfpf-6q8p-prjp.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pfpf-6q8p-prjp", + "modified": "2025-03-06T21:31:27Z", + "published": "2025-03-06T21:31:27Z", + "aliases": [ + "CVE-2025-25763" + ], + "details": "crmeb CRMEB-KY v5.4.0 and before has a SQL Injection vulnerability at getRead() in /system/SystemDatabackupServices.php", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25763" + }, + { + "type": "WEB", + "url": "https://github.com/J-0k3r/CVE-2025-25763" + }, + { + "type": "WEB", + "url": "https://github.com/J-0k3r/sql/blob/main/sql.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T21:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-pwx5-jwh9-q63q/GHSA-pwx5-jwh9-q63q.json b/advisories/unreviewed/2025/03/GHSA-pwx5-jwh9-q63q/GHSA-pwx5-jwh9-q63q.json new file mode 100644 index 00000000000..aef292dded2 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-pwx5-jwh9-q63q/GHSA-pwx5-jwh9-q63q.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pwx5-jwh9-q63q", + "modified": "2025-03-06T21:31:27Z", + "published": "2025-03-06T21:31:27Z", + "aliases": [ + "CVE-2025-26167" + ], + "details": "Buffalo LS520D 4.53 is vulnerable to Arbitrary file read, which allows unauthenticated attackers to access the NAS web UI and read arbitrary internal files.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26167" + }, + { + "type": "WEB", + "url": "https://github.com/SpikeReply/advisories/blob/0f15f5aefb959fbaff049da7cc3e36733e25b580/cve/buffalo/cve-2025-26167.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T19:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-r7j7-c9pj-h2v7/GHSA-r7j7-c9pj-h2v7.json b/advisories/unreviewed/2025/03/GHSA-r7j7-c9pj-h2v7/GHSA-r7j7-c9pj-h2v7.json new file mode 100644 index 00000000000..ee340138ee1 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-r7j7-c9pj-h2v7/GHSA-r7j7-c9pj-h2v7.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r7j7-c9pj-h2v7", + "modified": "2025-03-06T21:31:26Z", + "published": "2025-03-06T21:31:26Z", + "aliases": [ + "CVE-2025-25361" + ], + "details": "An arbitrary file upload vulnerability in the component /cms/CmsWebFileAdminController.java of PublicCMS v4.0.202406 allows attackers to execute arbitrary code via uploading a crafted svg or xml file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25361" + }, + { + "type": "WEB", + "url": "https://github.com/c0rdXy/POC/blob/master/CVE/PublicCMS/XSS_02/XSS_02.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T19:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rmpm-29gh-jcrf/GHSA-rmpm-29gh-jcrf.json b/advisories/unreviewed/2025/03/GHSA-rmpm-29gh-jcrf/GHSA-rmpm-29gh-jcrf.json new file mode 100644 index 00000000000..4eb64b5d764 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rmpm-29gh-jcrf/GHSA-rmpm-29gh-jcrf.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rmpm-29gh-jcrf", + "modified": "2025-03-06T21:31:27Z", + "published": "2025-03-06T21:31:27Z", + "aliases": [ + "CVE-2025-2039" + ], + "details": "A vulnerability classified as critical has been found in code-projects Blood Bank Management System 1.0. Affected is an unknown function of the file /admin/delete_members.php. The manipulation of the argument member_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2039" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/intercpt/XSS1/blob/main/SQL4.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.298782" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.298782" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.512564" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T20:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-vcg7-hgwp-h3g9/GHSA-vcg7-hgwp-h3g9.json b/advisories/unreviewed/2025/03/GHSA-vcg7-hgwp-h3g9/GHSA-vcg7-hgwp-h3g9.json new file mode 100644 index 00000000000..1a11af5832b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-vcg7-hgwp-h3g9/GHSA-vcg7-hgwp-h3g9.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vcg7-hgwp-h3g9", + "modified": "2025-03-06T21:31:27Z", + "published": "2025-03-06T21:31:27Z", + "aliases": [ + "CVE-2025-2041" + ], + "details": "A vulnerability, which was classified as critical, has been found in s-a-zhd Ecommerce-Website-using-PHP 1.0. Affected by this issue is some unknown functionality of the file /shop.php. The manipulation of the argument p_cat leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2041" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.298784" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.298784" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.512709" + }, + { + "type": "WEB", + "url": "https://www.websecurityinsights.my.id/2025/03/e-commerce-10-shopphppcat-sql-injection.html?m=1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T21:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-vv6v-f4pv-qm5r/GHSA-vv6v-f4pv-qm5r.json b/advisories/unreviewed/2025/03/GHSA-vv6v-f4pv-qm5r/GHSA-vv6v-f4pv-qm5r.json new file mode 100644 index 00000000000..ce95932e399 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-vv6v-f4pv-qm5r/GHSA-vv6v-f4pv-qm5r.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vv6v-f4pv-qm5r", + "modified": "2025-03-06T21:31:27Z", + "published": "2025-03-06T21:31:27Z", + "aliases": [ + "CVE-2025-2037" + ], + "details": "A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /user_dashboard/delete_requester.php. The manipulation of the argument requester_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2037" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/intercpt/XSS1/blob/main/SQL1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.298780" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.298780" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.512550" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T19:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-x2cr-cpw2-j9x5/GHSA-x2cr-cpw2-j9x5.json b/advisories/unreviewed/2025/03/GHSA-x2cr-cpw2-j9x5/GHSA-x2cr-cpw2-j9x5.json new file mode 100644 index 00000000000..230b54fa3e4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-x2cr-cpw2-j9x5/GHSA-x2cr-cpw2-j9x5.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x2cr-cpw2-j9x5", + "modified": "2025-03-06T21:31:26Z", + "published": "2025-03-06T21:31:26Z", + "aliases": [ + "CVE-2025-25381" + ], + "details": "Incorrect access control in the KSRTC AWATAR app of Karnataka State Road Transport Corporation v1.3.0 allows to view sensitive information such as usernames and passwords.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25381" + }, + { + "type": "WEB", + "url": "https://github.com/edwin-0990/CVE_ID/blob/main/CVE-2025-25381/README.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T19:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xfr2-g2r2-vf88/GHSA-xfr2-g2r2-vf88.json b/advisories/unreviewed/2025/03/GHSA-xfr2-g2r2-vf88/GHSA-xfr2-g2r2-vf88.json new file mode 100644 index 00000000000..b5cb4c38b9f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xfr2-g2r2-vf88/GHSA-xfr2-g2r2-vf88.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xfr2-g2r2-vf88", + "modified": "2025-03-06T21:31:27Z", + "published": "2025-03-06T21:31:27Z", + "aliases": [ + "CVE-2024-57972" + ], + "details": "A vulnerability in the pairing request method in Microsoft HoloLens 1 and 2 - Windows Holographic 10.0.17763.3046 through 10.0.22621.1244 allows remote attackers to cause a Denial of Service via the Device Portal framework.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57972" + }, + { + "type": "WEB", + "url": "https://github.com/tania-silva/Hololens" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T21:15:14Z" + } +} \ No newline at end of file