Publish Advisories

GHSA-53x3-6ggr-2vp5
GHSA-7q4p-93g6-4wf9
GHSA-7qjx-378m-p8hm
GHSA-9c2w-rfmh-q65f
GHSA-c28h-3w95-v6xg
GHSA-c52f-45m8-h2r6
GHSA-gc32-fmf5-c742
GHSA-gf8x-6jh7-3mjv
GHSA-hp9r-wcfh-72pr
GHSA-q3rr-g46f-jgqr
GHSA-wv34-xcj8-f3mq
GHSA-4hg3-3xxj-v749
GHSA-7477-x7rw-jvh6
GHSA-8wxh-j3rh-hq7g
GHSA-9wfr-r3p3-m3fw
GHSA-g3h4-pvrv-w9c2
GHSA-qvh6-jh7v-8fmr
GHSA-r2xw-g69f-4fpr
GHSA-rgc8-9ff9-6j39
This commit is contained in:
advisory-database[bot]
2025-03-17 06:31:56 +00:00
parent 8293738b79
commit 5913d4ba5f
19 changed files with 583 additions and 11 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-53x3-6ggr-2vp5",
"modified": "2025-03-07T00:31:55Z",
"modified": "2025-03-17T06:30:25Z",
"published": "2025-02-28T18:31:04Z",
"aliases": [
"CVE-2025-26263"
@@ -26,6 +26,10 @@
{
"type": "WEB",
"url": "https://www.geovision.com.tw/download/product/GV-ASManager"
},
{
"type": "WEB",
"url": "https://www.geovision.com.tw/download/product/GV-ASManager%20%28Access%20Control%29"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7q4p-93g6-4wf9",
"modified": "2025-03-17T03:30:23Z",
"modified": "2025-03-17T06:30:24Z",
"published": "2025-02-25T18:31:24Z",
"aliases": [
"CVE-2025-26600"
@@ -27,6 +27,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2502"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2861"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2862"
@@ -35,6 +39,14 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2865"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2866"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2873"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2874"
@@ -43,6 +55,14 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2875"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2879"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2880"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2025-26600"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7qjx-378m-p8hm",
"modified": "2025-03-17T03:30:22Z",
"modified": "2025-03-17T06:30:24Z",
"published": "2025-02-25T18:31:24Z",
"aliases": [
"CVE-2025-26597"
@@ -27,6 +27,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2502"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2861"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2862"
@@ -35,6 +39,14 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2865"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2866"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2873"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2874"
@@ -43,6 +55,14 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2875"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2879"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2880"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2025-26597"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9c2w-rfmh-q65f",
"modified": "2025-02-28T18:31:02Z",
"modified": "2025-03-17T06:30:24Z",
"published": "2025-02-28T00:30:51Z",
"aliases": [
"CVE-2025-26264"
@@ -22,6 +22,10 @@
{
"type": "WEB",
"url": "https://github.com/DRAGOWN/CVE-2025-26264"
},
{
"type": "WEB",
"url": "https://www.geovision.com.tw/download/product/GV-ASManager%20%28Access%20Control%29"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c28h-3w95-v6xg",
"modified": "2025-03-17T03:30:23Z",
"modified": "2025-03-17T06:30:24Z",
"published": "2025-02-25T18:31:24Z",
"aliases": [
"CVE-2025-26598"
@@ -27,6 +27,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2502"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2861"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2862"
@@ -35,6 +39,14 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2865"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2866"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2873"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2874"
@@ -43,6 +55,14 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2875"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2879"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2880"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2025-26598"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c52f-45m8-h2r6",
"modified": "2025-03-17T03:30:22Z",
"modified": "2025-03-17T06:30:24Z",
"published": "2025-02-25T18:31:24Z",
"aliases": [
"CVE-2025-26596"
@@ -27,6 +27,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2502"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2861"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2862"
@@ -35,6 +39,14 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2865"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2866"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2873"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2874"
@@ -43,6 +55,14 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2875"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2879"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2880"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2025-26596"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gc32-fmf5-c742",
"modified": "2025-03-17T03:30:22Z",
"modified": "2025-03-17T06:30:24Z",
"published": "2025-02-25T18:31:24Z",
"aliases": [
"CVE-2025-26594"
@@ -27,6 +27,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2502"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2861"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2862"
@@ -35,6 +39,14 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2865"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2866"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2873"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2874"
@@ -43,6 +55,14 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2875"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2879"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2880"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2025-26594"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gf8x-6jh7-3mjv",
"modified": "2025-03-17T03:30:22Z",
"modified": "2025-03-17T06:30:25Z",
"published": "2025-02-25T18:31:24Z",
"aliases": [
"CVE-2025-26601"
@@ -27,6 +27,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2502"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2861"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2862"
@@ -35,6 +39,14 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2865"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2866"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2873"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2874"
@@ -43,6 +55,14 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2875"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2879"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2880"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2025-26601"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hp9r-wcfh-72pr",
"modified": "2025-03-17T03:30:22Z",
"modified": "2025-03-17T06:30:24Z",
"published": "2025-02-25T18:31:24Z",
"aliases": [
"CVE-2025-26595"
@@ -27,6 +27,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2502"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2861"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2862"
@@ -35,6 +39,14 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2865"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2866"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2873"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2874"
@@ -43,6 +55,14 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2875"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2879"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2880"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2025-26595"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q3rr-g46f-jgqr",
"modified": "2025-03-17T03:30:22Z",
"modified": "2025-03-17T06:30:24Z",
"published": "2025-02-19T21:31:38Z",
"aliases": [
"CVE-2025-0624"
@@ -47,6 +47,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2867"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2869"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2025-0624"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wv34-xcj8-f3mq",
"modified": "2025-03-17T03:30:22Z",
"modified": "2025-03-17T06:30:24Z",
"published": "2025-02-25T18:31:24Z",
"aliases": [
"CVE-2025-26599"
@@ -27,6 +27,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2502"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2861"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2862"
@@ -35,6 +39,14 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2865"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2866"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2873"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2874"
@@ -43,6 +55,14 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2875"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2879"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2880"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2025-26599"
@@ -0,0 +1,48 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4hg3-3xxj-v749",
"modified": "2025-03-17T06:30:25Z",
"published": "2025-03-17T06:30:25Z",
"aliases": [
"CVE-2025-2361"
],
"details": "A vulnerability was found in Mercurial SCM 4.5.3/71.19.145.211. It has been declared as problematic. This vulnerability affects unknown code of the component Web Interface. The manipulation of the argument cmd leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2361"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.299860"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.299860"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.514024"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-17T05:15:36Z"
}
}
@@ -0,0 +1,52 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7477-x7rw-jvh6",
"modified": "2025-03-17T06:30:25Z",
"published": "2025-03-17T06:30:25Z",
"aliases": [
"CVE-2025-2363"
],
"details": "A vulnerability classified as critical has been found in lenve VBlog up to 1.0.0. Affected is the function uploadImg of the file blogserver/src/main/java/org/sang/controller/ArticleController.java. The manipulation of the argument filename leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2363"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.299862"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.299862"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.514721"
},
{
"type": "WEB",
"url": "https://www.notion.so/Arbitrary-File-Upload-Vulnerability-in-VBlog-1-0-0-1adc693918ed8067b19ed9c61381024b"
}
],
"database_specific": {
"cwe_ids": [
"CWE-22"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-17T06:15:25Z"
}
}
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8wxh-j3rh-hq7g",
"modified": "2025-03-17T06:30:25Z",
"published": "2025-03-17T06:30:25Z",
"aliases": [
"CVE-2025-2395"
],
"details": "The U-Office Force from e-Excellence has an Improper Authentication vulnerability, allowing unauthenticated remote attackers to use a particular API and alter cookies to log in as an administrator.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2395"
},
{
"type": "WEB",
"url": "https://www.twcert.org.tw/en/cp-139-10012-d5bbc-2.html"
},
{
"type": "WEB",
"url": "https://www.twcert.org.tw/tw/cp-132-10011-3de72-1.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-565"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-17T06:15:25Z"
}
}
@@ -0,0 +1,56 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9wfr-r3p3-m3fw",
"modified": "2025-03-17T06:30:25Z",
"published": "2025-03-17T06:30:25Z",
"aliases": [
"CVE-2025-2360"
],
"details": "A vulnerability classified as critical was found in D-Link DIR-823G 1.0.2B05_20181207. Affected by this vulnerability is the function SetUpnpSettings of the file /HNAP1/ of the component UPnP Service. The manipulation of the argument SOAPAction leads to improper authorization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2360"
},
{
"type": "WEB",
"url": "https://lavender-bicycle-a5a.notion.site/D-Link-DIR-823G-SetUpnpSettings-1ac53a41781f80d1a290c8d5da3e795e?pvs=4"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.299827"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.299827"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.513751"
},
{
"type": "WEB",
"url": "https://www.dlink.com"
}
],
"database_specific": {
"cwe_ids": [
"CWE-266"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-17T04:15:16Z"
}
}
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g3h4-pvrv-w9c2",
"modified": "2025-03-17T06:30:25Z",
"published": "2025-03-17T06:30:25Z",
"aliases": [
"CVE-2025-2396"
],
"details": "The U-Office Force from e-Excellence has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privileges to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2396"
},
{
"type": "WEB",
"url": "https://www.twcert.org.tw/en/cp-139-10014-69aa5-2.html"
},
{
"type": "WEB",
"url": "https://www.twcert.org.tw/tw/cp-132-10013-0d371-1.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-434"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-17T06:15:26Z"
}
}
@@ -0,0 +1,56 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qvh6-jh7v-8fmr",
"modified": "2025-03-17T06:30:25Z",
"published": "2025-03-17T06:30:25Z",
"aliases": [
"CVE-2025-2359"
],
"details": "A vulnerability classified as critical has been found in D-Link DIR-823G 1.0.2B05_20181207. Affected is the function SetDDNSSettings of the file /HNAP1/ of the component DDNS Service. The manipulation of the argument SOAPAction leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2359"
},
{
"type": "WEB",
"url": "https://lavender-bicycle-a5a.notion.site/D-Link-DIR-823G-SetDDNSSettings-1ac53a41781f80d98649dd3cbe106e9b?pvs=4"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.299826"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.299826"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.513750"
},
{
"type": "WEB",
"url": "https://www.dlink.com"
}
],
"database_specific": {
"cwe_ids": [
"CWE-266"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-17T04:15:11Z"
}
}
@@ -0,0 +1,52 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r2xw-g69f-4fpr",
"modified": "2025-03-17T06:30:25Z",
"published": "2025-03-17T06:30:25Z",
"aliases": [
"CVE-2025-2364"
],
"details": "A vulnerability classified as problematic was found in lenve VBlog up to 1.0.0. Affected by this vulnerability is the function addNewArticle of the file blogserver/src/main/java/org/sang/service/ArticleService.java. The manipulation of the argument mdContent/htmlContent leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2364"
},
{
"type": "WEB",
"url": "https://magnificent-dill-351.notion.site/Stored-XSS-Vulnerability-in-VBlog-1-0-0-1adc693918ed80d9bd08e03df0ed7a98"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.299863"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.299863"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.514763"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-17T06:15:25Z"
}
}
@@ -0,0 +1,56 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rgc8-9ff9-6j39",
"modified": "2025-03-17T06:30:25Z",
"published": "2025-03-17T06:30:25Z",
"aliases": [
"CVE-2025-2362"
],
"details": "A vulnerability was found in PHPGurukul Pre-School Enrollment System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/contact-us.php. The manipulation of the argument mobnum leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2362"
},
{
"type": "WEB",
"url": "https://github.com/12T40910/CVE/issues/3"
},
{
"type": "WEB",
"url": "https://phpgurukul.com"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.299861"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.299861"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.514464"
}
],
"database_specific": {
"cwe_ids": [
"CWE-74"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-17T05:15:37Z"
}
}