diff --git a/advisories/unreviewed/2022/11/GHSA-25xc-r4x7-g46h/GHSA-25xc-r4x7-g46h.json b/advisories/unreviewed/2022/11/GHSA-25xc-r4x7-g46h/GHSA-25xc-r4x7-g46h.json index 84eef3fee9b..9b04e80a647 100644 --- a/advisories/unreviewed/2022/11/GHSA-25xc-r4x7-g46h/GHSA-25xc-r4x7-g46h.json +++ b/advisories/unreviewed/2022/11/GHSA-25xc-r4x7-g46h/GHSA-25xc-r4x7-g46h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-25xc-r4x7-g46h", - "modified": "2022-11-28T15:30:24Z", + "modified": "2025-04-29T18:30:40Z", "published": "2022-11-22T03:30:57Z", "aliases": [ "CVE-2022-36179" diff --git a/advisories/unreviewed/2022/11/GHSA-43jv-mfhv-x3hx/GHSA-43jv-mfhv-x3hx.json b/advisories/unreviewed/2022/11/GHSA-43jv-mfhv-x3hx/GHSA-43jv-mfhv-x3hx.json index 8194a5c7ce4..fcb4e573de6 100644 --- a/advisories/unreviewed/2022/11/GHSA-43jv-mfhv-x3hx/GHSA-43jv-mfhv-x3hx.json +++ b/advisories/unreviewed/2022/11/GHSA-43jv-mfhv-x3hx/GHSA-43jv-mfhv-x3hx.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-862", "CWE-863" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2022/11/GHSA-45gh-mj8m-cxx5/GHSA-45gh-mj8m-cxx5.json b/advisories/unreviewed/2022/11/GHSA-45gh-mj8m-cxx5/GHSA-45gh-mj8m-cxx5.json index 24a364f2883..3deab07dad3 100644 --- a/advisories/unreviewed/2022/11/GHSA-45gh-mj8m-cxx5/GHSA-45gh-mj8m-cxx5.json +++ b/advisories/unreviewed/2022/11/GHSA-45gh-mj8m-cxx5/GHSA-45gh-mj8m-cxx5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-45gh-mj8m-cxx5", - "modified": "2022-11-23T18:30:28Z", + "modified": "2025-04-29T18:30:38Z", "published": "2022-11-22T00:30:32Z", "aliases": [ "CVE-2022-44786" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-98" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-f585-354r-gp9r/GHSA-f585-354r-gp9r.json b/advisories/unreviewed/2022/11/GHSA-f585-354r-gp9r/GHSA-f585-354r-gp9r.json index d9993f7bc10..1c519dcd31d 100644 --- a/advisories/unreviewed/2022/11/GHSA-f585-354r-gp9r/GHSA-f585-354r-gp9r.json +++ b/advisories/unreviewed/2022/11/GHSA-f585-354r-gp9r/GHSA-f585-354r-gp9r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f585-354r-gp9r", - "modified": "2022-11-28T15:30:24Z", + "modified": "2025-04-29T18:30:40Z", "published": "2022-11-22T03:30:57Z", "aliases": [ "CVE-2022-36180" diff --git a/advisories/unreviewed/2022/11/GHSA-fg2f-j7rp-247h/GHSA-fg2f-j7rp-247h.json b/advisories/unreviewed/2022/11/GHSA-fg2f-j7rp-247h/GHSA-fg2f-j7rp-247h.json index d7f9bfc16af..e5c4227f98d 100644 --- a/advisories/unreviewed/2022/11/GHSA-fg2f-j7rp-247h/GHSA-fg2f-j7rp-247h.json +++ b/advisories/unreviewed/2022/11/GHSA-fg2f-j7rp-247h/GHSA-fg2f-j7rp-247h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fg2f-j7rp-247h", - "modified": "2022-11-23T18:30:28Z", + "modified": "2025-04-29T18:30:40Z", "published": "2022-11-22T21:30:17Z", "aliases": [ "CVE-2022-45536" diff --git a/advisories/unreviewed/2022/11/GHSA-h8c4-2223-6jqc/GHSA-h8c4-2223-6jqc.json b/advisories/unreviewed/2022/11/GHSA-h8c4-2223-6jqc/GHSA-h8c4-2223-6jqc.json index ca4fec7fe5a..14fb6173658 100644 --- a/advisories/unreviewed/2022/11/GHSA-h8c4-2223-6jqc/GHSA-h8c4-2223-6jqc.json +++ b/advisories/unreviewed/2022/11/GHSA-h8c4-2223-6jqc/GHSA-h8c4-2223-6jqc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h8c4-2223-6jqc", - "modified": "2022-11-23T18:30:28Z", + "modified": "2025-04-29T18:30:39Z", "published": "2022-11-22T00:30:32Z", "aliases": [ "CVE-2022-44788" diff --git a/advisories/unreviewed/2022/11/GHSA-jvw4-hhr9-8575/GHSA-jvw4-hhr9-8575.json b/advisories/unreviewed/2022/11/GHSA-jvw4-hhr9-8575/GHSA-jvw4-hhr9-8575.json index 6f8d7b50e0a..66b9fd581e1 100644 --- a/advisories/unreviewed/2022/11/GHSA-jvw4-hhr9-8575/GHSA-jvw4-hhr9-8575.json +++ b/advisories/unreviewed/2022/11/GHSA-jvw4-hhr9-8575/GHSA-jvw4-hhr9-8575.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jvw4-hhr9-8575", - "modified": "2022-11-23T21:30:32Z", + "modified": "2025-04-29T18:30:37Z", "published": "2022-11-22T00:30:32Z", "aliases": [ "CVE-2022-44784" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-306" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-x4mx-9pgm-93r4/GHSA-x4mx-9pgm-93r4.json b/advisories/unreviewed/2022/11/GHSA-x4mx-9pgm-93r4/GHSA-x4mx-9pgm-93r4.json index 2d08e94045e..10c96bfaa49 100644 --- a/advisories/unreviewed/2022/11/GHSA-x4mx-9pgm-93r4/GHSA-x4mx-9pgm-93r4.json +++ b/advisories/unreviewed/2022/11/GHSA-x4mx-9pgm-93r4/GHSA-x4mx-9pgm-93r4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x4mx-9pgm-93r4", - "modified": "2022-11-23T18:30:28Z", + "modified": "2025-04-29T18:30:39Z", "published": "2022-11-22T00:30:32Z", "aliases": [ "CVE-2022-44787" diff --git a/advisories/unreviewed/2022/11/GHSA-xm35-83v5-99x8/GHSA-xm35-83v5-99x8.json b/advisories/unreviewed/2022/11/GHSA-xm35-83v5-99x8/GHSA-xm35-83v5-99x8.json index 018def4b194..233830803ed 100644 --- a/advisories/unreviewed/2022/11/GHSA-xm35-83v5-99x8/GHSA-xm35-83v5-99x8.json +++ b/advisories/unreviewed/2022/11/GHSA-xm35-83v5-99x8/GHSA-xm35-83v5-99x8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xm35-83v5-99x8", - "modified": "2022-11-23T18:30:28Z", + "modified": "2025-04-29T18:30:38Z", "published": "2022-11-22T00:30:32Z", "aliases": [ "CVE-2022-44785" diff --git a/advisories/unreviewed/2022/12/GHSA-278r-549p-g687/GHSA-278r-549p-g687.json b/advisories/unreviewed/2022/12/GHSA-278r-549p-g687/GHSA-278r-549p-g687.json index cdb5be0e43e..e427f3f344c 100644 --- a/advisories/unreviewed/2022/12/GHSA-278r-549p-g687/GHSA-278r-549p-g687.json +++ b/advisories/unreviewed/2022/12/GHSA-278r-549p-g687/GHSA-278r-549p-g687.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-278r-549p-g687", - "modified": "2022-12-14T00:30:23Z", + "modified": "2025-04-29T18:30:46Z", "published": "2022-12-12T15:30:33Z", "aliases": [ "CVE-2022-44647" diff --git a/advisories/unreviewed/2022/12/GHSA-2xvx-8cff-qx52/GHSA-2xvx-8cff-qx52.json b/advisories/unreviewed/2022/12/GHSA-2xvx-8cff-qx52/GHSA-2xvx-8cff-qx52.json index 45acb5e9f61..9f96518ee3d 100644 --- a/advisories/unreviewed/2022/12/GHSA-2xvx-8cff-qx52/GHSA-2xvx-8cff-qx52.json +++ b/advisories/unreviewed/2022/12/GHSA-2xvx-8cff-qx52/GHSA-2xvx-8cff-qx52.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-4v2g-fxcq-4j44/GHSA-4v2g-fxcq-4j44.json b/advisories/unreviewed/2024/03/GHSA-4v2g-fxcq-4j44/GHSA-4v2g-fxcq-4j44.json index 1957c6ebd47..7771d298cb9 100644 --- a/advisories/unreviewed/2024/03/GHSA-4v2g-fxcq-4j44/GHSA-4v2g-fxcq-4j44.json +++ b/advisories/unreviewed/2024/03/GHSA-4v2g-fxcq-4j44/GHSA-4v2g-fxcq-4j44.json @@ -49,7 +49,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-476" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-73f5-wqmw-37vp/GHSA-73f5-wqmw-37vp.json b/advisories/unreviewed/2024/03/GHSA-73f5-wqmw-37vp/GHSA-73f5-wqmw-37vp.json index 59f8f6e9bc6..285dc2461e3 100644 --- a/advisories/unreviewed/2024/03/GHSA-73f5-wqmw-37vp/GHSA-73f5-wqmw-37vp.json +++ b/advisories/unreviewed/2024/03/GHSA-73f5-wqmw-37vp/GHSA-73f5-wqmw-37vp.json @@ -49,7 +49,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-c8hq-5hxw-3w26/GHSA-c8hq-5hxw-3w26.json b/advisories/unreviewed/2024/04/GHSA-c8hq-5hxw-3w26/GHSA-c8hq-5hxw-3w26.json index 68e4849ef03..b536851bd8e 100644 --- a/advisories/unreviewed/2024/04/GHSA-c8hq-5hxw-3w26/GHSA-c8hq-5hxw-3w26.json +++ b/advisories/unreviewed/2024/04/GHSA-c8hq-5hxw-3w26/GHSA-c8hq-5hxw-3w26.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-401" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-qp87-7fwc-x65r/GHSA-qp87-7fwc-x65r.json b/advisories/unreviewed/2024/04/GHSA-qp87-7fwc-x65r/GHSA-qp87-7fwc-x65r.json index 14b46d7d51f..ecc515dafdf 100644 --- a/advisories/unreviewed/2024/04/GHSA-qp87-7fwc-x65r/GHSA-qp87-7fwc-x65r.json +++ b/advisories/unreviewed/2024/04/GHSA-qp87-7fwc-x65r/GHSA-qp87-7fwc-x65r.json @@ -49,7 +49,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-96xh-5wq4-m4cc/GHSA-96xh-5wq4-m4cc.json b/advisories/unreviewed/2025/02/GHSA-96xh-5wq4-m4cc/GHSA-96xh-5wq4-m4cc.json index 7fa90fe5cfa..3f5775fe687 100644 --- a/advisories/unreviewed/2025/02/GHSA-96xh-5wq4-m4cc/GHSA-96xh-5wq4-m4cc.json +++ b/advisories/unreviewed/2025/02/GHSA-96xh-5wq4-m4cc/GHSA-96xh-5wq4-m4cc.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-3pjj-2f8w-vhh5/GHSA-3pjj-2f8w-vhh5.json b/advisories/unreviewed/2025/03/GHSA-3pjj-2f8w-vhh5/GHSA-3pjj-2f8w-vhh5.json index d8a11b17a05..41243451b23 100644 --- a/advisories/unreviewed/2025/03/GHSA-3pjj-2f8w-vhh5/GHSA-3pjj-2f8w-vhh5.json +++ b/advisories/unreviewed/2025/03/GHSA-3pjj-2f8w-vhh5/GHSA-3pjj-2f8w-vhh5.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-5pwg-63cp-76fj/GHSA-5pwg-63cp-76fj.json b/advisories/unreviewed/2025/03/GHSA-5pwg-63cp-76fj/GHSA-5pwg-63cp-76fj.json index 7c04c09f4c3..46dc693bb8d 100644 --- a/advisories/unreviewed/2025/03/GHSA-5pwg-63cp-76fj/GHSA-5pwg-63cp-76fj.json +++ b/advisories/unreviewed/2025/03/GHSA-5pwg-63cp-76fj/GHSA-5pwg-63cp-76fj.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-5wqh-pcq3-r3px/GHSA-5wqh-pcq3-r3px.json b/advisories/unreviewed/2025/03/GHSA-5wqh-pcq3-r3px/GHSA-5wqh-pcq3-r3px.json index 43f1b77aebe..7840def7ac5 100644 --- a/advisories/unreviewed/2025/03/GHSA-5wqh-pcq3-r3px/GHSA-5wqh-pcq3-r3px.json +++ b/advisories/unreviewed/2025/03/GHSA-5wqh-pcq3-r3px/GHSA-5wqh-pcq3-r3px.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-cw73-w3vc-7g28/GHSA-cw73-w3vc-7g28.json b/advisories/unreviewed/2025/03/GHSA-cw73-w3vc-7g28/GHSA-cw73-w3vc-7g28.json index f7fe45291d2..bfed2d21a1c 100644 --- a/advisories/unreviewed/2025/03/GHSA-cw73-w3vc-7g28/GHSA-cw73-w3vc-7g28.json +++ b/advisories/unreviewed/2025/03/GHSA-cw73-w3vc-7g28/GHSA-cw73-w3vc-7g28.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-rr43-5qf6-chvx/GHSA-rr43-5qf6-chvx.json b/advisories/unreviewed/2025/03/GHSA-rr43-5qf6-chvx/GHSA-rr43-5qf6-chvx.json index fe88d175853..330cecf9423 100644 --- a/advisories/unreviewed/2025/03/GHSA-rr43-5qf6-chvx/GHSA-rr43-5qf6-chvx.json +++ b/advisories/unreviewed/2025/03/GHSA-rr43-5qf6-chvx/GHSA-rr43-5qf6-chvx.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-wwgv-3xwq-6qmc/GHSA-wwgv-3xwq-6qmc.json b/advisories/unreviewed/2025/03/GHSA-wwgv-3xwq-6qmc/GHSA-wwgv-3xwq-6qmc.json index 4929282d6a8..7277da00592 100644 --- a/advisories/unreviewed/2025/03/GHSA-wwgv-3xwq-6qmc/GHSA-wwgv-3xwq-6qmc.json +++ b/advisories/unreviewed/2025/03/GHSA-wwgv-3xwq-6qmc/GHSA-wwgv-3xwq-6qmc.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-2h62-wf4g-8rpr/GHSA-2h62-wf4g-8rpr.json b/advisories/unreviewed/2025/04/GHSA-2h62-wf4g-8rpr/GHSA-2h62-wf4g-8rpr.json new file mode 100644 index 00000000000..f35d93d45a4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2h62-wf4g-8rpr/GHSA-2h62-wf4g-8rpr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2h62-wf4g-8rpr", + "modified": "2025-04-29T18:31:00Z", + "published": "2025-04-29T18:31:00Z", + "aliases": [ + "CVE-2025-4095" + ], + "details": "Registry Access Management (RAM) is a security feature allowing administrators to restrict access for their developers to only allowed registries. When a MacOS configuration profile is used to enforce organization sign-in, the RAM policies are not being applied, which would allow Docker Desktop users to pull down unapproved, and potentially malicious images from any registry.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4095" + }, + { + "type": "WEB", + "url": "https://docs.docker.com/security/for-admins/hardened-desktop/registry-access-management" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T18:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3255-g96h-946g/GHSA-3255-g96h-946g.json b/advisories/unreviewed/2025/04/GHSA-3255-g96h-946g/GHSA-3255-g96h-946g.json new file mode 100644 index 00000000000..194533b7aa2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3255-g96h-946g/GHSA-3255-g96h-946g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3255-g96h-946g", + "modified": "2025-04-29T18:30:58Z", + "published": "2025-04-29T18:30:58Z", + "aliases": [ + "CVE-2025-40619" + ], + "details": "Bookgy does not provide for proper authorisation control in multiple areas of the application. This deficiency could allow a malicious actor, without authentication, to reach private areas and/or areas intended for other roles.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40619" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-bookgy" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3324-7ggx-p2gq/GHSA-3324-7ggx-p2gq.json b/advisories/unreviewed/2025/04/GHSA-3324-7ggx-p2gq/GHSA-3324-7ggx-p2gq.json index b1d54ab1f56..2fc7d6f2c24 100644 --- a/advisories/unreviewed/2025/04/GHSA-3324-7ggx-p2gq/GHSA-3324-7ggx-p2gq.json +++ b/advisories/unreviewed/2025/04/GHSA-3324-7ggx-p2gq/GHSA-3324-7ggx-p2gq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3324-7ggx-p2gq", - "modified": "2025-04-01T00:30:45Z", + "modified": "2025-04-29T18:30:52Z", "published": "2025-04-01T00:30:45Z", "aliases": [ "CVE-2025-3059" ], "details": "Vulnerability in Drupal Profile Private.This issue affects Profile Private: *.*.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:30Z" diff --git a/advisories/unreviewed/2025/04/GHSA-34w4-3qr3-m637/GHSA-34w4-3qr3-m637.json b/advisories/unreviewed/2025/04/GHSA-34w4-3qr3-m637/GHSA-34w4-3qr3-m637.json index ef1ae0dab28..5442bc305fa 100644 --- a/advisories/unreviewed/2025/04/GHSA-34w4-3qr3-m637/GHSA-34w4-3qr3-m637.json +++ b/advisories/unreviewed/2025/04/GHSA-34w4-3qr3-m637/GHSA-34w4-3qr3-m637.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-34w4-3qr3-m637", - "modified": "2025-04-01T00:30:33Z", + "modified": "2025-04-29T18:30:47Z", "published": "2025-04-01T00:30:33Z", "aliases": [ "CVE-2025-31676" ], "details": "Weak Authentication vulnerability in Drupal Email TFA allows Brute Force.This issue affects Email TFA: from 0.0.0 before 2.0.3.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-1390" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T22:15:20Z" diff --git a/advisories/unreviewed/2025/04/GHSA-3ffx-985x-rcv3/GHSA-3ffx-985x-rcv3.json b/advisories/unreviewed/2025/04/GHSA-3ffx-985x-rcv3/GHSA-3ffx-985x-rcv3.json new file mode 100644 index 00000000000..342e3ea4d03 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3ffx-985x-rcv3/GHSA-3ffx-985x-rcv3.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3ffx-985x-rcv3", + "modified": "2025-04-29T18:30:58Z", + "published": "2025-04-29T18:30:58Z", + "aliases": [ + "CVE-2025-25403" + ], + "details": "Slims (Senayan Library Management Systems) 9 Bulian V9.6.1 is vulnerable to SQL Injection in admin/modules/master_file/coll_type.php.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25403" + }, + { + "type": "WEB", + "url": "https://github.com/slims/slims9_bulian/issues/273" + }, + { + "type": "WEB", + "url": "https://github.com/christopherralinanggoman/cve-skripsi/blob/main/my_reports/slims-9-bulian-coll-type-report.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T16:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3mvr-vp9h-cr29/GHSA-3mvr-vp9h-cr29.json b/advisories/unreviewed/2025/04/GHSA-3mvr-vp9h-cr29/GHSA-3mvr-vp9h-cr29.json index 675cdf6380a..3ffe858d949 100644 --- a/advisories/unreviewed/2025/04/GHSA-3mvr-vp9h-cr29/GHSA-3mvr-vp9h-cr29.json +++ b/advisories/unreviewed/2025/04/GHSA-3mvr-vp9h-cr29/GHSA-3mvr-vp9h-cr29.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3mvr-vp9h-cr29", - "modified": "2025-04-29T15:31:53Z", + "modified": "2025-04-29T18:30:57Z", "published": "2025-04-29T15:31:53Z", "aliases": [ "CVE-2025-4087" ], "details": "A vulnerability was identified in Firefox where XPath parsing could trigger undefined behavior due to missing null checks during attribute access. This could lead to out-of-bounds read access and potentially, memory corruption. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Thunderbird < 138, and Thunderbird ESR < 128.10.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-29T14:15:35Z" diff --git a/advisories/unreviewed/2025/04/GHSA-3rr5-vgfq-8c8h/GHSA-3rr5-vgfq-8c8h.json b/advisories/unreviewed/2025/04/GHSA-3rr5-vgfq-8c8h/GHSA-3rr5-vgfq-8c8h.json new file mode 100644 index 00000000000..34b7cd17a97 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3rr5-vgfq-8c8h/GHSA-3rr5-vgfq-8c8h.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3rr5-vgfq-8c8h", + "modified": "2025-04-29T18:30:59Z", + "published": "2025-04-29T18:30:59Z", + "aliases": [ + "CVE-2025-45956" + ], + "details": "A SQL injection vulnerability in manage_damage.php in Sourcecodester Computer Laboratory Management System v1.0 allows an authenticated attacker to execute arbitrary SQL commands via the \"id\" parameter", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45956" + }, + { + "type": "WEB", + "url": "https://github.com/lloydik/CLMS-vulnerabilities/blob/main/SQLi-CLMS-PoC.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T17:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3wr4-hqc2-phf3/GHSA-3wr4-hqc2-phf3.json b/advisories/unreviewed/2025/04/GHSA-3wr4-hqc2-phf3/GHSA-3wr4-hqc2-phf3.json new file mode 100644 index 00000000000..5b88892a431 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3wr4-hqc2-phf3/GHSA-3wr4-hqc2-phf3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3wr4-hqc2-phf3", + "modified": "2025-04-29T18:30:57Z", + "published": "2025-04-29T18:30:57Z", + "aliases": [ + "CVE-2025-23177" + ], + "details": "CWE-427: Uncontrolled Search Path Element", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23177" + }, + { + "type": "WEB", + "url": "https://www.gov.il/en/departments/dynamiccollectors/cve_advisories_listing?skip=0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T16:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3xjw-75cj-9fvw/GHSA-3xjw-75cj-9fvw.json b/advisories/unreviewed/2025/04/GHSA-3xjw-75cj-9fvw/GHSA-3xjw-75cj-9fvw.json index cc6ae21e2c2..74beb9ac7ab 100644 --- a/advisories/unreviewed/2025/04/GHSA-3xjw-75cj-9fvw/GHSA-3xjw-75cj-9fvw.json +++ b/advisories/unreviewed/2025/04/GHSA-3xjw-75cj-9fvw/GHSA-3xjw-75cj-9fvw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3xjw-75cj-9fvw", - "modified": "2025-04-18T15:31:38Z", + "modified": "2025-04-29T18:30:52Z", "published": "2025-04-18T15:31:37Z", "aliases": [ "CVE-2025-37893" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: BPF: Fix off-by-one error in build_prologue()\n\nVincent reported that running BPF progs with tailcalls on LoongArch\ncauses kernel hard lockup. Debugging the issues shows that the JITed\nimage missing a jirl instruction at the end of the epilogue.\n\nThere are two passes in JIT compiling, the first pass set the flags and\nthe second pass generates JIT code based on those flags. With BPF progs\nmixing bpf2bpf and tailcalls, build_prologue() generates N insns in the\nfirst pass and then generates N+1 insns in the second pass. This makes\nepilogue_offset off by one and we will jump to some unexpected insn and\ncause lockup. Fix this by inserting a nop insn.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-193" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-18T07:15:42Z" diff --git a/advisories/unreviewed/2025/04/GHSA-4rmx-r8gj-vj26/GHSA-4rmx-r8gj-vj26.json b/advisories/unreviewed/2025/04/GHSA-4rmx-r8gj-vj26/GHSA-4rmx-r8gj-vj26.json index acc7129462f..5b573dbb59d 100644 --- a/advisories/unreviewed/2025/04/GHSA-4rmx-r8gj-vj26/GHSA-4rmx-r8gj-vj26.json +++ b/advisories/unreviewed/2025/04/GHSA-4rmx-r8gj-vj26/GHSA-4rmx-r8gj-vj26.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4rmx-r8gj-vj26", - "modified": "2025-04-25T21:31:33Z", + "modified": "2025-04-29T18:30:57Z", "published": "2025-04-25T21:31:33Z", "aliases": [ "CVE-2025-32986" ], "details": "NETSCOUT nGeniusONE before 6.4.0 b2350 has a Sensitive File Accessible Without Proper Authentication to an endpoint.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-25T21:15:39Z" diff --git a/advisories/unreviewed/2025/04/GHSA-54jr-pmx4-5pvr/GHSA-54jr-pmx4-5pvr.json b/advisories/unreviewed/2025/04/GHSA-54jr-pmx4-5pvr/GHSA-54jr-pmx4-5pvr.json index c4614f3f777..70aa2637b61 100644 --- a/advisories/unreviewed/2025/04/GHSA-54jr-pmx4-5pvr/GHSA-54jr-pmx4-5pvr.json +++ b/advisories/unreviewed/2025/04/GHSA-54jr-pmx4-5pvr/GHSA-54jr-pmx4-5pvr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-54jr-pmx4-5pvr", - "modified": "2025-04-29T15:31:53Z", + "modified": "2025-04-29T18:30:57Z", "published": "2025-04-29T15:31:53Z", "aliases": [ "CVE-2025-4086" ], "details": "A specially crafted filename containing a large number of encoded newline characters could obscure the file's extension when displayed in the download dialog.\n*This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 138 and Thunderbird < 138.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-451" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-29T14:15:35Z" diff --git a/advisories/unreviewed/2025/04/GHSA-559r-938h-gh79/GHSA-559r-938h-gh79.json b/advisories/unreviewed/2025/04/GHSA-559r-938h-gh79/GHSA-559r-938h-gh79.json new file mode 100644 index 00000000000..d1108a4753a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-559r-938h-gh79/GHSA-559r-938h-gh79.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-559r-938h-gh79", + "modified": "2025-04-29T18:30:59Z", + "published": "2025-04-29T18:30:59Z", + "aliases": [ + "CVE-2025-4072" + ], + "details": "A vulnerability was found in PHPGurukul Online Nurse Hiring System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/edit-nurse.php. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Multiple parameters might be affected.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4072" + }, + { + "type": "WEB", + "url": "https://github.com/Iandweb/CVE/issues/1" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.306509" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.306509" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.559939" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T17:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-59f6-q63c-5833/GHSA-59f6-q63c-5833.json b/advisories/unreviewed/2025/04/GHSA-59f6-q63c-5833/GHSA-59f6-q63c-5833.json new file mode 100644 index 00000000000..3860f09c92b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-59f6-q63c-5833/GHSA-59f6-q63c-5833.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-59f6-q63c-5833", + "modified": "2025-04-29T18:30:58Z", + "published": "2025-04-29T18:30:58Z", + "aliases": [ + "CVE-2025-32354" + ], + "details": "In Zimbra Collaboration (ZCS) 9.0 through 10.1, a Cross-Site Request Forgery (CSRF) vulnerability exists in the GraphQL endpoint (/service/extension/graphql) of Zimbra webmail due to a lack of CSRF token validation. This allows attackers to perform unauthorized GraphQL operations, such as modifying contacts, changing account settings, and accessing sensitive user data when an authenticated user visits a malicious website.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32354" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Security_Center" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.4#Security_Fixes" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T16:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5cwq-8g5w-gmhm/GHSA-5cwq-8g5w-gmhm.json b/advisories/unreviewed/2025/04/GHSA-5cwq-8g5w-gmhm/GHSA-5cwq-8g5w-gmhm.json index ac53016382a..d64f4f254a3 100644 --- a/advisories/unreviewed/2025/04/GHSA-5cwq-8g5w-gmhm/GHSA-5cwq-8g5w-gmhm.json +++ b/advisories/unreviewed/2025/04/GHSA-5cwq-8g5w-gmhm/GHSA-5cwq-8g5w-gmhm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5cwq-8g5w-gmhm", - "modified": "2025-04-25T21:31:33Z", + "modified": "2025-04-29T18:30:54Z", "published": "2025-04-25T21:31:33Z", "aliases": [ "CVE-2025-32979" ], "details": "NETSCOUT nGeniusONE before 6.4.0 b2350 allows Arbitrary File Creation by authenticated users.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-378" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-25T21:15:38Z" diff --git a/advisories/unreviewed/2025/04/GHSA-5f2p-3q97-rpw3/GHSA-5f2p-3q97-rpw3.json b/advisories/unreviewed/2025/04/GHSA-5f2p-3q97-rpw3/GHSA-5f2p-3q97-rpw3.json new file mode 100644 index 00000000000..b993da729b5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5f2p-3q97-rpw3/GHSA-5f2p-3q97-rpw3.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5f2p-3q97-rpw3", + "modified": "2025-04-29T18:31:00Z", + "published": "2025-04-29T18:31:00Z", + "aliases": [ + "CVE-2025-4077" + ], + "details": "A vulnerability classified as critical was found in code-projects School Billing System 1.0. This vulnerability affects the function searchrec. The manipulation of the argument Name leads to stack-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4077" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/zzzxc643/cve/blob/main/SCHOOL_BILLING_SYSTEM.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.306514" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.306514" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.560534" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T18:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5wfx-74q9-f9jq/GHSA-5wfx-74q9-f9jq.json b/advisories/unreviewed/2025/04/GHSA-5wfx-74q9-f9jq/GHSA-5wfx-74q9-f9jq.json new file mode 100644 index 00000000000..cbe72ba9bb1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5wfx-74q9-f9jq/GHSA-5wfx-74q9-f9jq.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5wfx-74q9-f9jq", + "modified": "2025-04-29T18:31:00Z", + "published": "2025-04-29T18:30:59Z", + "aliases": [ + "CVE-2025-4074" + ], + "details": "A vulnerability was found in PHPGurukul Curfew e-Pass Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/pass-bwdates-report.php. The manipulation of the argument fromdate/todate leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4074" + }, + { + "type": "WEB", + "url": "https://github.com/bluechips-zhao/myCVE/issues/3" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.306511" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.306511" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.559983" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T18:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-63pj-8c5p-x939/GHSA-63pj-8c5p-x939.json b/advisories/unreviewed/2025/04/GHSA-63pj-8c5p-x939/GHSA-63pj-8c5p-x939.json index 582ad5416e5..3caca1a3a15 100644 --- a/advisories/unreviewed/2025/04/GHSA-63pj-8c5p-x939/GHSA-63pj-8c5p-x939.json +++ b/advisories/unreviewed/2025/04/GHSA-63pj-8c5p-x939/GHSA-63pj-8c5p-x939.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-63pj-8c5p-x939", - "modified": "2025-04-29T15:31:53Z", + "modified": "2025-04-29T18:30:58Z", "published": "2025-04-29T15:31:53Z", "aliases": [ "CVE-2025-4090" ], "details": "A vulnerability existed in Firefox for Android where potentially sensitive library locations were logged via Logcat. This vulnerability affects Firefox < 138 and Thunderbird < 138.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-29T14:15:35Z" diff --git a/advisories/unreviewed/2025/04/GHSA-6762-8x76-3vrf/GHSA-6762-8x76-3vrf.json b/advisories/unreviewed/2025/04/GHSA-6762-8x76-3vrf/GHSA-6762-8x76-3vrf.json new file mode 100644 index 00000000000..91c580b739d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6762-8x76-3vrf/GHSA-6762-8x76-3vrf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6762-8x76-3vrf", + "modified": "2025-04-29T18:30:57Z", + "published": "2025-04-29T18:30:57Z", + "aliases": [ + "CVE-2025-23179" + ], + "details": "CWE-798: Use of Hard-coded Credentials", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23179" + }, + { + "type": "WEB", + "url": "https://www.gov.il/en/departments/dynamiccollectors/cve_advisories_listing?skip=0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-798" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T16:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8ccv-3j8r-hx7f/GHSA-8ccv-3j8r-hx7f.json b/advisories/unreviewed/2025/04/GHSA-8ccv-3j8r-hx7f/GHSA-8ccv-3j8r-hx7f.json index 8ef6d4fd5ce..9bb976009a4 100644 --- a/advisories/unreviewed/2025/04/GHSA-8ccv-3j8r-hx7f/GHSA-8ccv-3j8r-hx7f.json +++ b/advisories/unreviewed/2025/04/GHSA-8ccv-3j8r-hx7f/GHSA-8ccv-3j8r-hx7f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8ccv-3j8r-hx7f", - "modified": "2025-04-18T15:31:38Z", + "modified": "2025-04-29T18:30:52Z", "published": "2025-04-18T15:31:38Z", "aliases": [ "CVE-2025-37925" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\njfs: reject on-disk inodes of an unsupported type\n\nSyzbot has reported the following BUG:\n\nkernel BUG at fs/inode.c:668!\nOops: invalid opcode: 0000 [#1] PREEMPT SMP KASAN PTI\nCPU: 3 UID: 0 PID: 139 Comm: jfsCommit Not tainted 6.12.0-rc4-syzkaller-00085-g4e46774408d9 #0\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-3.fc41 04/01/2014\nRIP: 0010:clear_inode+0x168/0x190\nCode: 4c 89 f7 e8 ba fe e5 ff e9 61 ff ff ff 44 89 f1 80 e1 07 80 c1 03 38 c1 7c c1 4c 89 f7 e8 90 ff e5 ff eb b7\n 0b e8 01 5d 7f ff 90 0f 0b e8 f9 5c 7f ff 90 0f 0b e8 f1 5c 7f\nRSP: 0018:ffffc900027dfae8 EFLAGS: 00010093\nRAX: ffffffff82157a87 RBX: 0000000000000001 RCX: ffff888104d4b980\nRDX: 0000000000000000 RSI: 0000000000000001 RDI: 0000000000000000\nRBP: ffffc900027dfc90 R08: ffffffff82157977 R09: fffff520004fbf38\nR10: dffffc0000000000 R11: fffff520004fbf38 R12: dffffc0000000000\nR13: ffff88811315bc00 R14: ffff88811315bda8 R15: ffff88811315bb80\nFS: 0000000000000000(0000) GS:ffff888135f00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00005565222e0578 CR3: 0000000026ef0000 CR4: 00000000000006f0\nCall Trace:\n \n ? __die_body+0x5f/0xb0\n ? die+0x9e/0xc0\n ? do_trap+0x15a/0x3a0\n ? clear_inode+0x168/0x190\n ? do_error_trap+0x1dc/0x2c0\n ? clear_inode+0x168/0x190\n ? __pfx_do_error_trap+0x10/0x10\n ? report_bug+0x3cd/0x500\n ? handle_invalid_op+0x34/0x40\n ? clear_inode+0x168/0x190\n ? exc_invalid_op+0x38/0x50\n ? asm_exc_invalid_op+0x1a/0x20\n ? clear_inode+0x57/0x190\n ? clear_inode+0x167/0x190\n ? clear_inode+0x168/0x190\n ? clear_inode+0x167/0x190\n jfs_evict_inode+0xb5/0x440\n ? __pfx_jfs_evict_inode+0x10/0x10\n evict+0x4ea/0x9b0\n ? __pfx_evict+0x10/0x10\n ? iput+0x713/0xa50\n txUpdateMap+0x931/0xb10\n ? __pfx_txUpdateMap+0x10/0x10\n jfs_lazycommit+0x49a/0xb80\n ? _raw_spin_unlock_irqrestore+0x8f/0x140\n ? lockdep_hardirqs_on+0x99/0x150\n ? __pfx_jfs_lazycommit+0x10/0x10\n ? __pfx_default_wake_function+0x10/0x10\n ? __kthread_parkme+0x169/0x1d0\n ? __pfx_jfs_lazycommit+0x10/0x10\n kthread+0x2f2/0x390\n ? __pfx_jfs_lazycommit+0x10/0x10\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x4d/0x80\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1a/0x30\n \n\nThis happens when 'clear_inode()' makes an attempt to finalize an underlying\nJFS inode of unknown type. According to JFS layout description from\nhttps://jfs.sourceforge.net/project/pub/jfslayout.pdf, inode types from 5 to\n15 are reserved for future extensions and should not be encountered on a valid\nfilesystem. So add an extra check for valid inode type in 'copy_from_dinode()'.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-18T07:15:43Z" diff --git a/advisories/unreviewed/2025/04/GHSA-8cvj-85rh-hgr2/GHSA-8cvj-85rh-hgr2.json b/advisories/unreviewed/2025/04/GHSA-8cvj-85rh-hgr2/GHSA-8cvj-85rh-hgr2.json new file mode 100644 index 00000000000..3fe90e7cc34 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8cvj-85rh-hgr2/GHSA-8cvj-85rh-hgr2.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8cvj-85rh-hgr2", + "modified": "2025-04-29T18:30:59Z", + "published": "2025-04-29T18:30:59Z", + "aliases": [ + "CVE-2025-4071" + ], + "details": "A vulnerability has been found in PHPGurukul COVID19 Testing Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /test-details.php. The manipulation of the argument Status leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4071" + }, + { + "type": "WEB", + "url": "https://github.com/2634257398/CVE-/issues/1" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.306508" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.306508" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.559904" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8g34-67c6-v26f/GHSA-8g34-67c6-v26f.json b/advisories/unreviewed/2025/04/GHSA-8g34-67c6-v26f/GHSA-8g34-67c6-v26f.json new file mode 100644 index 00000000000..4ab595b2919 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8g34-67c6-v26f/GHSA-8g34-67c6-v26f.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8g34-67c6-v26f", + "modified": "2025-04-29T18:30:58Z", + "published": "2025-04-29T18:30:58Z", + "aliases": [ + "CVE-2025-25962" + ], + "details": "An issue in Coresmartcontracts Uniswap v.3.0 and fixed in v.4.0 allows a remote attacker to escalate privileges via the _modifyPosition function", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25962" + }, + { + "type": "WEB", + "url": "https://github.com/CVEProject/docs/blob/gh-pages/requester/reservation-guidelines.md" + }, + { + "type": "WEB", + "url": "https://medium.com/@cnetsec/access-control-vulnerability-in-uniswap-v3-cve-2025-25962-f7cf21536978" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T16:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8pjq-x38c-gm89/GHSA-8pjq-x38c-gm89.json b/advisories/unreviewed/2025/04/GHSA-8pjq-x38c-gm89/GHSA-8pjq-x38c-gm89.json index 0c52278414e..67ace820032 100644 --- a/advisories/unreviewed/2025/04/GHSA-8pjq-x38c-gm89/GHSA-8pjq-x38c-gm89.json +++ b/advisories/unreviewed/2025/04/GHSA-8pjq-x38c-gm89/GHSA-8pjq-x38c-gm89.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8pjq-x38c-gm89", - "modified": "2025-04-25T21:31:33Z", + "modified": "2025-04-29T18:30:56Z", "published": "2025-04-25T21:31:33Z", "aliases": [ "CVE-2025-32982" ], "details": "NETSCOUT nGeniusONE before 6.4.0 b2350 has a Broken Authorization Schema for the report module.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-285" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-25T21:15:39Z" diff --git a/advisories/unreviewed/2025/04/GHSA-969p-47jr-q9pv/GHSA-969p-47jr-q9pv.json b/advisories/unreviewed/2025/04/GHSA-969p-47jr-q9pv/GHSA-969p-47jr-q9pv.json new file mode 100644 index 00000000000..a3327d41e83 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-969p-47jr-q9pv/GHSA-969p-47jr-q9pv.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-969p-47jr-q9pv", + "modified": "2025-04-29T18:30:59Z", + "published": "2025-04-29T18:30:59Z", + "aliases": [ + "CVE-2025-4070" + ], + "details": "A vulnerability, which was classified as critical, was found in PHPGurukul Rail Pass Management System 1.0. This affects an unknown part of the file /admin/changeimage.php. The manipulation of the argument editid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4070" + }, + { + "type": "WEB", + "url": "https://github.com/Arcueicl/cve/issues/1" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.306507" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.306507" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.559620" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-995j-2jcg-pg6h/GHSA-995j-2jcg-pg6h.json b/advisories/unreviewed/2025/04/GHSA-995j-2jcg-pg6h/GHSA-995j-2jcg-pg6h.json new file mode 100644 index 00000000000..a07929a3acc --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-995j-2jcg-pg6h/GHSA-995j-2jcg-pg6h.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-995j-2jcg-pg6h", + "modified": "2025-04-29T18:30:58Z", + "published": "2025-04-29T18:30:58Z", + "aliases": [ + "CVE-2025-4068" + ], + "details": "A vulnerability classified as critical was found in code-projects Simple Movie Ticket Booking System 1.0. Affected by this vulnerability is the function changeprize. The manipulation of the argument prize leads to stack-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4068" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/zzzxc643/cve/blob/main/MOVIE_TICKET_BOOKING_SYSTEM.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.306505" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.306505" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.559479" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c47v-4q6r-838w/GHSA-c47v-4q6r-838w.json b/advisories/unreviewed/2025/04/GHSA-c47v-4q6r-838w/GHSA-c47v-4q6r-838w.json new file mode 100644 index 00000000000..664ee05895b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c47v-4q6r-838w/GHSA-c47v-4q6r-838w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c47v-4q6r-838w", + "modified": "2025-04-29T18:30:58Z", + "published": "2025-04-29T18:30:58Z", + "aliases": [ + "CVE-2025-40616" + ], + "details": "Reflected Cross-Site Scripting (XSS) vulnerability in Bookgy. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through the \"IDRESERVA\" parameter in /bkg_imprimir_comprobante.php.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40616" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-bookgy" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c587-35qx-9wwg/GHSA-c587-35qx-9wwg.json b/advisories/unreviewed/2025/04/GHSA-c587-35qx-9wwg/GHSA-c587-35qx-9wwg.json new file mode 100644 index 00000000000..aad3ffa8547 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c587-35qx-9wwg/GHSA-c587-35qx-9wwg.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c587-35qx-9wwg", + "modified": "2025-04-29T18:31:00Z", + "published": "2025-04-29T18:31:00Z", + "aliases": [ + "CVE-2025-4076" + ], + "details": "A vulnerability classified as critical has been found in LB-LINK BL-AC3600 up to 1.0.22. This affects the function easy_uci_set_option_string_0 of the file /cgi-bin/lighttpd.cgi of the component Password Handler. The manipulation of the argument routepwd leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4076" + }, + { + "type": "WEB", + "url": "https://github.com/GrayLxton/BLink_poc" + }, + { + "type": "WEB", + "url": "https://github.com/GrayLxton/BLink_poc/blob/main/poc.py" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.306513" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.306513" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.560232" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T18:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c888-p9w6-29rv/GHSA-c888-p9w6-29rv.json b/advisories/unreviewed/2025/04/GHSA-c888-p9w6-29rv/GHSA-c888-p9w6-29rv.json index fd89a8b65ed..9f9fe402b50 100644 --- a/advisories/unreviewed/2025/04/GHSA-c888-p9w6-29rv/GHSA-c888-p9w6-29rv.json +++ b/advisories/unreviewed/2025/04/GHSA-c888-p9w6-29rv/GHSA-c888-p9w6-29rv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c888-p9w6-29rv", - "modified": "2025-04-29T15:31:53Z", + "modified": "2025-04-29T18:30:58Z", "published": "2025-04-29T15:31:53Z", "aliases": [ "CVE-2025-4093" ], "details": "Memory safety bug present in Firefox ESR 128.9, and Thunderbird 128.9. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 128.10 and Thunderbird ESR < 128.10.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-29T14:15:35Z" diff --git a/advisories/unreviewed/2025/04/GHSA-c99q-9gjf-fc69/GHSA-c99q-9gjf-fc69.json b/advisories/unreviewed/2025/04/GHSA-c99q-9gjf-fc69/GHSA-c99q-9gjf-fc69.json new file mode 100644 index 00000000000..8432c3aafd6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c99q-9gjf-fc69/GHSA-c99q-9gjf-fc69.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c99q-9gjf-fc69", + "modified": "2025-04-29T18:30:59Z", + "published": "2025-04-29T18:30:59Z", + "aliases": [ + "CVE-2025-23181" + ], + "details": "CWE-250: Execution with Unnecessary Privileges", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23181" + }, + { + "type": "WEB", + "url": "https://www.gov.il/en/departments/dynamiccollectors/cve_advisories_listing?skip=0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-250" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T17:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f24m-7jrp-68fr/GHSA-f24m-7jrp-68fr.json b/advisories/unreviewed/2025/04/GHSA-f24m-7jrp-68fr/GHSA-f24m-7jrp-68fr.json index a39d1629ef6..812011ed0bd 100644 --- a/advisories/unreviewed/2025/04/GHSA-f24m-7jrp-68fr/GHSA-f24m-7jrp-68fr.json +++ b/advisories/unreviewed/2025/04/GHSA-f24m-7jrp-68fr/GHSA-f24m-7jrp-68fr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f24m-7jrp-68fr", - "modified": "2025-04-26T06:32:46Z", + "modified": "2025-04-29T18:30:57Z", "published": "2025-04-26T06:32:46Z", "aliases": [ "CVE-2025-2907" ], "details": "The Order Delivery Date WordPress plugin before 12.3.1 does not have authorization and CSRF checks when importing settings. Furthermore it also lacks proper checks to only update options relevant to the Order Delivery Date WordPress plugin before 12.3.1. This leads to attackers being able to modify the default_user_role to administrator and users_can_register, allowing them to register as an administrator of the site for complete site takeover.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-26T06:15:16Z" diff --git a/advisories/unreviewed/2025/04/GHSA-f4pj-f2qw-57cr/GHSA-f4pj-f2qw-57cr.json b/advisories/unreviewed/2025/04/GHSA-f4pj-f2qw-57cr/GHSA-f4pj-f2qw-57cr.json index 1db737a092c..0327f143fae 100644 --- a/advisories/unreviewed/2025/04/GHSA-f4pj-f2qw-57cr/GHSA-f4pj-f2qw-57cr.json +++ b/advisories/unreviewed/2025/04/GHSA-f4pj-f2qw-57cr/GHSA-f4pj-f2qw-57cr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f4pj-f2qw-57cr", - "modified": "2025-04-29T15:31:53Z", + "modified": "2025-04-29T18:30:57Z", "published": "2025-04-29T15:31:53Z", "aliases": [ "CVE-2025-4089" ], "details": "Due to insufficient escaping of special characters in the \"copy as cURL\" feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability affects Firefox < 138 and Thunderbird < 138.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-29T14:15:35Z" diff --git a/advisories/unreviewed/2025/04/GHSA-fj6q-h8w7-mx3g/GHSA-fj6q-h8w7-mx3g.json b/advisories/unreviewed/2025/04/GHSA-fj6q-h8w7-mx3g/GHSA-fj6q-h8w7-mx3g.json index 4e59773a09b..700dcbbe182 100644 --- a/advisories/unreviewed/2025/04/GHSA-fj6q-h8w7-mx3g/GHSA-fj6q-h8w7-mx3g.json +++ b/advisories/unreviewed/2025/04/GHSA-fj6q-h8w7-mx3g/GHSA-fj6q-h8w7-mx3g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fj6q-h8w7-mx3g", - "modified": "2025-04-29T03:30:33Z", + "modified": "2025-04-29T18:30:57Z", "published": "2025-04-29T03:30:33Z", "aliases": [ "CVE-2025-31203" ], "details": "An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.4, tvOS 18.4, iPadOS 17.7.6, macOS Sonoma 14.7.5, iOS 18.4 and iPadOS 18.4, watchOS 11.4, visionOS 2.4. An attacker on the local network may be able to cause a denial-of-service.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-190" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-29T03:15:35Z" diff --git a/advisories/unreviewed/2025/04/GHSA-gxhp-4g3m-x7p8/GHSA-gxhp-4g3m-x7p8.json b/advisories/unreviewed/2025/04/GHSA-gxhp-4g3m-x7p8/GHSA-gxhp-4g3m-x7p8.json new file mode 100644 index 00000000000..fa41346a733 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gxhp-4g3m-x7p8/GHSA-gxhp-4g3m-x7p8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gxhp-4g3m-x7p8", + "modified": "2025-04-29T18:30:58Z", + "published": "2025-04-29T18:30:58Z", + "aliases": [ + "CVE-2025-40615" + ], + "details": "Reflected Cross-Site Scripting (XSS) vulnerability in Bookgy. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through the \"TEXTO\" parameter in /api/api_ajustes.php.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40615" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-bookgy" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h656-x889-hh62/GHSA-h656-x889-hh62.json b/advisories/unreviewed/2025/04/GHSA-h656-x889-hh62/GHSA-h656-x889-hh62.json index 7ffd06dcfee..a7f97cd5c79 100644 --- a/advisories/unreviewed/2025/04/GHSA-h656-x889-hh62/GHSA-h656-x889-hh62.json +++ b/advisories/unreviewed/2025/04/GHSA-h656-x889-hh62/GHSA-h656-x889-hh62.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h656-x889-hh62", - "modified": "2025-04-25T21:31:33Z", + "modified": "2025-04-29T18:30:55Z", "published": "2025-04-25T21:31:33Z", "aliases": [ "CVE-2025-32981" ], "details": "NETSCOUT nGeniusONE before 6.4.0 b2350 allows local users to leverage Insecure Permissions for the nGeniusCLI File.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-25T21:15:39Z" diff --git a/advisories/unreviewed/2025/04/GHSA-j55m-95wq-jp26/GHSA-j55m-95wq-jp26.json b/advisories/unreviewed/2025/04/GHSA-j55m-95wq-jp26/GHSA-j55m-95wq-jp26.json new file mode 100644 index 00000000000..52d138efbf9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j55m-95wq-jp26/GHSA-j55m-95wq-jp26.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j55m-95wq-jp26", + "modified": "2025-04-29T18:30:59Z", + "published": "2025-04-29T18:30:59Z", + "aliases": [ + "CVE-2025-23180" + ], + "details": "CWE-250: Execution with Unnecessary Privileges", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23180" + }, + { + "type": "WEB", + "url": "https://www.gov.il/en/departments/dynamiccollectors/cve_advisories_listing?skip=0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-250" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T17:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j58c-ww9w-pwp5/GHSA-j58c-ww9w-pwp5.json b/advisories/unreviewed/2025/04/GHSA-j58c-ww9w-pwp5/GHSA-j58c-ww9w-pwp5.json new file mode 100644 index 00000000000..ea141350084 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j58c-ww9w-pwp5/GHSA-j58c-ww9w-pwp5.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j58c-ww9w-pwp5", + "modified": "2025-04-29T18:30:59Z", + "published": "2025-04-29T18:30:59Z", + "aliases": [ + "CVE-2025-0716" + ], + "details": "Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '' SVG elements in AngularJS allows attackers to bypass common image source restrictions. This can lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing  and also negatively affect the application's performance and behavior by using too large or slow-to-load images.\n\nThis issue affects all versions of AngularJS.\n\nNote:\nThe AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0716" + }, + { + "type": "WEB", + "url": "https://codepen.io/herodevs/pen/qEWQmpd/a86a0d29310e12c7a3756768e6c7b915" + }, + { + "type": "WEB", + "url": "https://www.herodevs.com/vulnerability-directory/cve-2025-0716" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-791" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T17:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j5qc-xcfm-cq6p/GHSA-j5qc-xcfm-cq6p.json b/advisories/unreviewed/2025/04/GHSA-j5qc-xcfm-cq6p/GHSA-j5qc-xcfm-cq6p.json index 98ec15e760e..85ae77a3039 100644 --- a/advisories/unreviewed/2025/04/GHSA-j5qc-xcfm-cq6p/GHSA-j5qc-xcfm-cq6p.json +++ b/advisories/unreviewed/2025/04/GHSA-j5qc-xcfm-cq6p/GHSA-j5qc-xcfm-cq6p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j5qc-xcfm-cq6p", - "modified": "2025-04-18T15:31:37Z", + "modified": "2025-04-29T18:30:52Z", "published": "2025-04-18T15:31:37Z", "aliases": [ "CVE-2025-37860" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsfc: fix NULL dereferences in ef100_process_design_param()\n\nSince cited commit, ef100_probe_main() and hence also\n ef100_check_design_params() run before efx->net_dev is created;\n consequently, we cannot netif_set_tso_max_size() or _segs() at this\n point.\nMove those netif calls to ef100_probe_netdev(), and also replace\n netif_err within the design params code with pci_err.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-18T07:15:42Z" diff --git a/advisories/unreviewed/2025/04/GHSA-jgr2-rf9j-5fh3/GHSA-jgr2-rf9j-5fh3.json b/advisories/unreviewed/2025/04/GHSA-jgr2-rf9j-5fh3/GHSA-jgr2-rf9j-5fh3.json index 2baff67661d..ef236f78b9d 100644 --- a/advisories/unreviewed/2025/04/GHSA-jgr2-rf9j-5fh3/GHSA-jgr2-rf9j-5fh3.json +++ b/advisories/unreviewed/2025/04/GHSA-jgr2-rf9j-5fh3/GHSA-jgr2-rf9j-5fh3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jgr2-rf9j-5fh3", - "modified": "2025-04-29T15:31:53Z", + "modified": "2025-04-29T18:30:58Z", "published": "2025-04-29T15:31:53Z", "aliases": [ "CVE-2025-4091" ], "details": "Memory safety bugs present in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Thunderbird < 138, and Thunderbird ESR < 128.10.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-29T14:15:35Z" diff --git a/advisories/unreviewed/2025/04/GHSA-jv2r-997x-hv7m/GHSA-jv2r-997x-hv7m.json b/advisories/unreviewed/2025/04/GHSA-jv2r-997x-hv7m/GHSA-jv2r-997x-hv7m.json index 463b6e4f970..6d9ec039e3c 100644 --- a/advisories/unreviewed/2025/04/GHSA-jv2r-997x-hv7m/GHSA-jv2r-997x-hv7m.json +++ b/advisories/unreviewed/2025/04/GHSA-jv2r-997x-hv7m/GHSA-jv2r-997x-hv7m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jv2r-997x-hv7m", - "modified": "2025-04-29T15:31:53Z", + "modified": "2025-04-29T18:30:57Z", "published": "2025-04-29T15:31:53Z", "aliases": [ "CVE-2025-4092" ], "details": "Memory safety bugs present in Firefox 137 and Thunderbird 137. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 138 and Thunderbird < 138.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-29T14:15:35Z" diff --git a/advisories/unreviewed/2025/04/GHSA-m593-pjhp-f33p/GHSA-m593-pjhp-f33p.json b/advisories/unreviewed/2025/04/GHSA-m593-pjhp-f33p/GHSA-m593-pjhp-f33p.json new file mode 100644 index 00000000000..bdff1da9710 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m593-pjhp-f33p/GHSA-m593-pjhp-f33p.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m593-pjhp-f33p", + "modified": "2025-04-29T18:31:00Z", + "published": "2025-04-29T18:31:00Z", + "aliases": [ + "CVE-2025-4075" + ], + "details": "A vulnerability was found in VMSMan up to 20250416. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument Email with the input \"> leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4075" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.306512" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.306512" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.560212" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T18:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-phfx-9rhx-m3x9/GHSA-phfx-9rhx-m3x9.json b/advisories/unreviewed/2025/04/GHSA-phfx-9rhx-m3x9/GHSA-phfx-9rhx-m3x9.json new file mode 100644 index 00000000000..a2b22f5e510 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-phfx-9rhx-m3x9/GHSA-phfx-9rhx-m3x9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phfx-9rhx-m3x9", + "modified": "2025-04-29T18:30:58Z", + "published": "2025-04-29T18:30:58Z", + "aliases": [ + "CVE-2025-40618" + ], + "details": "SQL injection vulnerability in Bookgy. This vulnerability could allow an attacker to retrieve, create, update and delete databases by sending an HTTP request through the \"IDRESERVA\"  parameter in /bkg_imprimir_comprobante.php", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40618" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-bookgy" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-q6q7-9hj5-2656/GHSA-q6q7-9hj5-2656.json b/advisories/unreviewed/2025/04/GHSA-q6q7-9hj5-2656/GHSA-q6q7-9hj5-2656.json new file mode 100644 index 00000000000..3edec67145a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-q6q7-9hj5-2656/GHSA-q6q7-9hj5-2656.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q6q7-9hj5-2656", + "modified": "2025-04-29T18:30:58Z", + "published": "2025-04-29T18:30:58Z", + "aliases": [ + "CVE-2025-23178" + ], + "details": "CWE-923: Improper Restriction of Communication Channel to Intended Endpoints", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23178" + }, + { + "type": "WEB", + "url": "https://www.gov.il/en/departments/dynamiccollectors/cve_advisories_listing?skip=0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-923" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T16:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qfvm-vf5w-76fc/GHSA-qfvm-vf5w-76fc.json b/advisories/unreviewed/2025/04/GHSA-qfvm-vf5w-76fc/GHSA-qfvm-vf5w-76fc.json new file mode 100644 index 00000000000..3fa232700cc --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qfvm-vf5w-76fc/GHSA-qfvm-vf5w-76fc.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qfvm-vf5w-76fc", + "modified": "2025-04-29T18:30:59Z", + "published": "2025-04-29T18:30:58Z", + "aliases": [ + "CVE-2025-4069" + ], + "details": "A vulnerability, which was classified as critical, has been found in code-projects Product Management System 1.0. Affected by this issue is the function add_item. The manipulation of the argument st.productname leads to stack-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4069" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/zzzxc643/cve/blob/main/PRODUCT_MANAGEMENT_SYSTEM.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.306506" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.306506" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.559516" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qq46-fm3f-6h37/GHSA-qq46-fm3f-6h37.json b/advisories/unreviewed/2025/04/GHSA-qq46-fm3f-6h37/GHSA-qq46-fm3f-6h37.json new file mode 100644 index 00000000000..2f55beb7e1c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qq46-fm3f-6h37/GHSA-qq46-fm3f-6h37.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qq46-fm3f-6h37", + "modified": "2025-04-29T18:30:58Z", + "published": "2025-04-29T18:30:57Z", + "aliases": [ + "CVE-2025-1551" + ], + "details": "IBM Operational Decision Manager 8.11.0.1, 8.11.1.0, 8.12.0.1, and 9.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1551" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7232032" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T16:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-r58q-xq2p-rf3w/GHSA-r58q-xq2p-rf3w.json b/advisories/unreviewed/2025/04/GHSA-r58q-xq2p-rf3w/GHSA-r58q-xq2p-rf3w.json index 74c57ca6d12..b9c2b790c4b 100644 --- a/advisories/unreviewed/2025/04/GHSA-r58q-xq2p-rf3w/GHSA-r58q-xq2p-rf3w.json +++ b/advisories/unreviewed/2025/04/GHSA-r58q-xq2p-rf3w/GHSA-r58q-xq2p-rf3w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r58q-xq2p-rf3w", - "modified": "2025-04-25T21:31:33Z", + "modified": "2025-04-29T18:30:55Z", "published": "2025-04-25T21:31:33Z", "aliases": [ "CVE-2025-32980" ], "details": "NETSCOUT nGeniusONE before 6.4.0 b2350 has a Weak Sudo Configuration.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-266" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-25T21:15:38Z" diff --git a/advisories/unreviewed/2025/04/GHSA-r7f2-jfpq-8j9r/GHSA-r7f2-jfpq-8j9r.json b/advisories/unreviewed/2025/04/GHSA-r7f2-jfpq-8j9r/GHSA-r7f2-jfpq-8j9r.json index 20e1f75ed77..8d3a7de8961 100644 --- a/advisories/unreviewed/2025/04/GHSA-r7f2-jfpq-8j9r/GHSA-r7f2-jfpq-8j9r.json +++ b/advisories/unreviewed/2025/04/GHSA-r7f2-jfpq-8j9r/GHSA-r7f2-jfpq-8j9r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r7f2-jfpq-8j9r", - "modified": "2025-04-25T21:31:33Z", + "modified": "2025-04-29T18:30:57Z", "published": "2025-04-25T21:31:33Z", "aliases": [ "CVE-2025-32985" ], "details": "NETSCOUT nGeniusONE before 6.4.0 b2350 has Hardcoded Credentials that can be obtained from JAR files.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-798" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-25T21:15:39Z" diff --git a/advisories/unreviewed/2025/04/GHSA-v836-66v3-26j5/GHSA-v836-66v3-26j5.json b/advisories/unreviewed/2025/04/GHSA-v836-66v3-26j5/GHSA-v836-66v3-26j5.json new file mode 100644 index 00000000000..49f538ec054 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v836-66v3-26j5/GHSA-v836-66v3-26j5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v836-66v3-26j5", + "modified": "2025-04-29T18:30:58Z", + "published": "2025-04-29T18:30:58Z", + "aliases": [ + "CVE-2025-40617" + ], + "details": "SQL injection vulnerability in Bookgy. This vulnerability could allow an attacker to retrieve, create, update and delete databases by sending an HTTP request through the \"IDTIPO\", \"IDPISTA\" and \"IDSOCIO\" parameters in /bkg_seleccionar_hora_ajax.php.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40617" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-bookgy" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vjq9-rqqq-vrgq/GHSA-vjq9-rqqq-vrgq.json b/advisories/unreviewed/2025/04/GHSA-vjq9-rqqq-vrgq/GHSA-vjq9-rqqq-vrgq.json new file mode 100644 index 00000000000..31488cea8e7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vjq9-rqqq-vrgq/GHSA-vjq9-rqqq-vrgq.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vjq9-rqqq-vrgq", + "modified": "2025-04-29T18:30:59Z", + "published": "2025-04-29T18:30:59Z", + "aliases": [ + "CVE-2025-4073" + ], + "details": "A vulnerability was found in PHPGurukul Student Record System 3.20. It has been classified as critical. Affected is an unknown function of the file /change-password.php. The manipulation of the argument currentpassword leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4073" + }, + { + "type": "WEB", + "url": "https://github.com/bleakTS/myCVE/issues/1" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.306510" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.306510" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.559947" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T17:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vmwg-3cwg-gccp/GHSA-vmwg-3cwg-gccp.json b/advisories/unreviewed/2025/04/GHSA-vmwg-3cwg-gccp/GHSA-vmwg-3cwg-gccp.json index be60d4d7308..ac54c020f07 100644 --- a/advisories/unreviewed/2025/04/GHSA-vmwg-3cwg-gccp/GHSA-vmwg-3cwg-gccp.json +++ b/advisories/unreviewed/2025/04/GHSA-vmwg-3cwg-gccp/GHSA-vmwg-3cwg-gccp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vmwg-3cwg-gccp", - "modified": "2025-04-29T03:30:34Z", + "modified": "2025-04-29T18:30:57Z", "published": "2025-04-29T03:30:33Z", "aliases": [ "CVE-2025-31202" ], "details": "A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4. An attacker on the local network may be able to cause a denial-of-service.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-29T03:15:35Z" diff --git a/advisories/unreviewed/2025/04/GHSA-vvxh-6r52-hj35/GHSA-vvxh-6r52-hj35.json b/advisories/unreviewed/2025/04/GHSA-vvxh-6r52-hj35/GHSA-vvxh-6r52-hj35.json index aceefe56867..ec57e848641 100644 --- a/advisories/unreviewed/2025/04/GHSA-vvxh-6r52-hj35/GHSA-vvxh-6r52-hj35.json +++ b/advisories/unreviewed/2025/04/GHSA-vvxh-6r52-hj35/GHSA-vvxh-6r52-hj35.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vvxh-6r52-hj35", - "modified": "2025-04-29T15:31:53Z", + "modified": "2025-04-29T18:30:57Z", "published": "2025-04-29T15:31:53Z", "aliases": [ "CVE-2025-4088" ], "details": "A security vulnerability in Firefox allowed malicious sites to use redirects to send credentialed requests to arbitrary endpoints on any site that had invoked the Storage Access API. This enabled potential Cross-Site Request Forgery attacks across origins. This vulnerability affects Firefox < 138 and Thunderbird < 138.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-29T14:15:35Z" diff --git a/advisories/unreviewed/2025/04/GHSA-w7jc-wqpw-qxqq/GHSA-w7jc-wqpw-qxqq.json b/advisories/unreviewed/2025/04/GHSA-w7jc-wqpw-qxqq/GHSA-w7jc-wqpw-qxqq.json index fe4b006a135..f8bcc259bc1 100644 --- a/advisories/unreviewed/2025/04/GHSA-w7jc-wqpw-qxqq/GHSA-w7jc-wqpw-qxqq.json +++ b/advisories/unreviewed/2025/04/GHSA-w7jc-wqpw-qxqq/GHSA-w7jc-wqpw-qxqq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w7jc-wqpw-qxqq", - "modified": "2025-04-18T15:31:38Z", + "modified": "2025-04-29T18:30:52Z", "published": "2025-04-18T15:31:37Z", "aliases": [ "CVE-2025-37785" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix OOB read when checking dotdot dir\n\nMounting a corrupted filesystem with directory which contains '.' dir\nentry with rec_len == block size results in out-of-bounds read (later\non, when the corrupted directory is removed).\n\next4_empty_dir() assumes every ext4 directory contains at least '.'\nand '..' as directory entries in the first data block. It first loads\nthe '.' dir entry, performs sanity checks by calling ext4_check_dir_entry()\nand then uses its rec_len member to compute the location of '..' dir\nentry (in ext4_next_entry). It assumes the '..' dir entry fits into the\nsame data block.\n\nIf the rec_len of '.' is precisely one block (4KB), it slips through the\nsanity checks (it is considered the last directory entry in the data\nblock) and leaves \"struct ext4_dir_entry_2 *de\" point exactly past the\nmemory slot allocated to the data block. The following call to\next4_check_dir_entry() on new value of de then dereferences this pointer\nwhich results in out-of-bounds mem access.\n\nFix this by extending __ext4_check_dir_entry() to check for '.' dir\nentries that reach the end of data block. Make sure to ignore the phony\ndir entries for checksum (by checking name_len for non-zero).\n\nNote: This is reported by KASAN as use-after-free in case another\nstructure was recently freed from the slot past the bound, but it is\nreally an OOB read.\n\nThis issue was found by syzkaller tool.\n\nCall Trace:\n[ 38.594108] BUG: KASAN: slab-use-after-free in __ext4_check_dir_entry+0x67e/0x710\n[ 38.594649] Read of size 2 at addr ffff88802b41a004 by task syz-executor/5375\n[ 38.595158]\n[ 38.595288] CPU: 0 UID: 0 PID: 5375 Comm: syz-executor Not tainted 6.14.0-rc7 #1\n[ 38.595298] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014\n[ 38.595304] Call Trace:\n[ 38.595308] \n[ 38.595311] dump_stack_lvl+0xa7/0xd0\n[ 38.595325] print_address_description.constprop.0+0x2c/0x3f0\n[ 38.595339] ? __ext4_check_dir_entry+0x67e/0x710\n[ 38.595349] print_report+0xaa/0x250\n[ 38.595359] ? __ext4_check_dir_entry+0x67e/0x710\n[ 38.595368] ? kasan_addr_to_slab+0x9/0x90\n[ 38.595378] kasan_report+0xab/0xe0\n[ 38.595389] ? __ext4_check_dir_entry+0x67e/0x710\n[ 38.595400] __ext4_check_dir_entry+0x67e/0x710\n[ 38.595410] ext4_empty_dir+0x465/0x990\n[ 38.595421] ? __pfx_ext4_empty_dir+0x10/0x10\n[ 38.595432] ext4_rmdir.part.0+0x29a/0xd10\n[ 38.595441] ? __dquot_initialize+0x2a7/0xbf0\n[ 38.595455] ? __pfx_ext4_rmdir.part.0+0x10/0x10\n[ 38.595464] ? __pfx___dquot_initialize+0x10/0x10\n[ 38.595478] ? down_write+0xdb/0x140\n[ 38.595487] ? __pfx_down_write+0x10/0x10\n[ 38.595497] ext4_rmdir+0xee/0x140\n[ 38.595506] vfs_rmdir+0x209/0x670\n[ 38.595517] ? lookup_one_qstr_excl+0x3b/0x190\n[ 38.595529] do_rmdir+0x363/0x3c0\n[ 38.595537] ? __pfx_do_rmdir+0x10/0x10\n[ 38.595544] ? strncpy_from_user+0x1ff/0x2e0\n[ 38.595561] __x64_sys_unlinkat+0xf0/0x130\n[ 38.595570] do_syscall_64+0x5b/0x180\n[ 38.595583] entry_SYSCALL_64_after_hwframe+0x76/0x7e", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-18T07:15:42Z" diff --git a/advisories/unreviewed/2025/04/GHSA-wpwc-6ghv-2w64/GHSA-wpwc-6ghv-2w64.json b/advisories/unreviewed/2025/04/GHSA-wpwc-6ghv-2w64/GHSA-wpwc-6ghv-2w64.json new file mode 100644 index 00000000000..19ea3922842 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wpwc-6ghv-2w64/GHSA-wpwc-6ghv-2w64.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wpwc-6ghv-2w64", + "modified": "2025-04-29T18:30:59Z", + "published": "2025-04-29T18:30:59Z", + "aliases": [ + "CVE-2025-3911" + ], + "details": "Recording of environment variables, configured for running containers, in Docker Desktop application logs could lead to unintentional disclosure of sensitive information such as api keys, passwords, etc.\n\nA malicious actor with read access to these logs could obtain sensitive credentials information and further use it to gain unauthorized access to other systems. Starting with version 4.41.0, Docker Desktop no longer logs environment variables set by the user.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3911" + }, + { + "type": "WEB", + "url": "https://docs.docker.com/desktop/troubleshoot-and-support/troubleshoot/#check-the-logs" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T18:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xmww-383x-h57w/GHSA-xmww-383x-h57w.json b/advisories/unreviewed/2025/04/GHSA-xmww-383x-h57w/GHSA-xmww-383x-h57w.json index 271ef8f513b..72fcf09352a 100644 --- a/advisories/unreviewed/2025/04/GHSA-xmww-383x-h57w/GHSA-xmww-383x-h57w.json +++ b/advisories/unreviewed/2025/04/GHSA-xmww-383x-h57w/GHSA-xmww-383x-h57w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xmww-383x-h57w", - "modified": "2025-04-29T03:30:33Z", + "modified": "2025-04-29T18:30:57Z", "published": "2025-04-29T03:30:33Z", "aliases": [ "CVE-2025-30445" ], "details": "A type confusion issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, tvOS 18.4, macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sonoma 14.7.5, iOS 18.4 and iPadOS 18.4, visionOS 2.4. An attacker on the local network may cause an unexpected app termination.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-843" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-29T03:15:34Z"