From 5c07bf58acd25e4ae96a7a94926a2cb47b4b5acd Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 9 Jun 2025 15:33:00 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-r934-w73g-v4p8.json | 10 +++- .../GHSA-jh4f-5j2m-4v9c.json | 6 +- .../GHSA-2hpw-5cjm-953f.json | 10 +++- .../GHSA-4c4j-w8hm-rjgv.json | 10 +++- .../GHSA-mwc7-wm76-6x7w.json | 9 ++- .../GHSA-32pr-wg5j-9rwr.json | 2 +- .../GHSA-3g2p-5q22-h774.json | 2 +- .../GHSA-7v94-mgqj-cj58.json | 6 +- .../GHSA-mmv5-g2hf-r8cf.json | 2 +- .../GHSA-q652-p9gf-vfq3.json | 5 +- .../GHSA-qxpv-rxq7-rg72.json | 10 +++- .../GHSA-28m4-49gg-78fx.json | 3 +- .../GHSA-2g9r-w7mh-f2h2.json | 6 +- .../GHSA-2h2q-247m-jhjc.json | 48 ++++++++++++++++ .../GHSA-3xwj-8v2h-93qc.json | 56 +++++++++++++++++++ .../GHSA-6j9c-246r-2553.json | 52 +++++++++++++++++ .../GHSA-6p6j-f8q6-5r72.json | 36 ++++++++++++ .../GHSA-6vfc-8w2v-vx36.json | 6 +- .../GHSA-7387-f28m-vqxg.json | 52 +++++++++++++++++ .../GHSA-8h93-38hx-vv92.json | 11 +++- .../GHSA-8qpg-2ff4-h2q5.json | 56 +++++++++++++++++++ .../GHSA-c45x-4cr6-92hc.json | 6 +- .../GHSA-cc4f-xvhj-7frg.json | 52 +++++++++++++++++ .../GHSA-f35w-jcp9-579f.json | 6 +- .../GHSA-jw8p-xr8r-2w5h.json | 36 ++++++++++++ .../GHSA-p5r3-w88m-mm8j.json | 3 +- .../GHSA-pv9r-4f6f-g2p4.json | 3 +- .../GHSA-qv9v-4gh7-4qhp.json | 6 +- .../GHSA-rh23-w5x7-xjm4.json | 6 +- .../GHSA-rpwp-653m-8vhf.json | 6 +- .../GHSA-w29c-vpjf-6hx4.json | 36 ++++++++++++ .../GHSA-w866-3fpp-r6c4.json | 6 +- 32 files changed, 536 insertions(+), 28 deletions(-) create mode 100644 advisories/unreviewed/2025/06/GHSA-2h2q-247m-jhjc/GHSA-2h2q-247m-jhjc.json create mode 100644 advisories/unreviewed/2025/06/GHSA-3xwj-8v2h-93qc/GHSA-3xwj-8v2h-93qc.json create mode 100644 advisories/unreviewed/2025/06/GHSA-6j9c-246r-2553/GHSA-6j9c-246r-2553.json create mode 100644 advisories/unreviewed/2025/06/GHSA-6p6j-f8q6-5r72/GHSA-6p6j-f8q6-5r72.json create mode 100644 advisories/unreviewed/2025/06/GHSA-7387-f28m-vqxg/GHSA-7387-f28m-vqxg.json create mode 100644 advisories/unreviewed/2025/06/GHSA-8qpg-2ff4-h2q5/GHSA-8qpg-2ff4-h2q5.json create mode 100644 advisories/unreviewed/2025/06/GHSA-cc4f-xvhj-7frg/GHSA-cc4f-xvhj-7frg.json create mode 100644 advisories/unreviewed/2025/06/GHSA-jw8p-xr8r-2w5h/GHSA-jw8p-xr8r-2w5h.json create mode 100644 advisories/unreviewed/2025/06/GHSA-w29c-vpjf-6hx4/GHSA-w29c-vpjf-6hx4.json diff --git a/advisories/github-reviewed/2025/04/GHSA-r934-w73g-v4p8/GHSA-r934-w73g-v4p8.json b/advisories/github-reviewed/2025/04/GHSA-r934-w73g-v4p8/GHSA-r934-w73g-v4p8.json index 4afd05bb42e..f8cb3f0d942 100644 --- a/advisories/github-reviewed/2025/04/GHSA-r934-w73g-v4p8/GHSA-r934-w73g-v4p8.json +++ b/advisories/github-reviewed/2025/04/GHSA-r934-w73g-v4p8/GHSA-r934-w73g-v4p8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r934-w73g-v4p8", - "modified": "2025-04-30T17:24:10Z", + "modified": "2025-06-09T15:31:36Z", "published": "2025-04-29T21:31:56Z", "withdrawn": "2025-04-30T17:24:10Z", "aliases": [], @@ -47,6 +47,14 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:4336" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:8672" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:8690" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-3501" diff --git a/advisories/unreviewed/2022/04/GHSA-jh4f-5j2m-4v9c/GHSA-jh4f-5j2m-4v9c.json b/advisories/unreviewed/2022/04/GHSA-jh4f-5j2m-4v9c/GHSA-jh4f-5j2m-4v9c.json index a723e99581c..889d217b087 100644 --- a/advisories/unreviewed/2022/04/GHSA-jh4f-5j2m-4v9c/GHSA-jh4f-5j2m-4v9c.json +++ b/advisories/unreviewed/2022/04/GHSA-jh4f-5j2m-4v9c/GHSA-jh4f-5j2m-4v9c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jh4f-5j2m-4v9c", - "modified": "2022-04-28T00:00:48Z", + "modified": "2025-06-09T15:31:33Z", "published": "2022-04-19T00:00:47Z", "aliases": [ "CVE-2022-29458" @@ -35,6 +35,10 @@ "type": "WEB", "url": "https://support.apple.com/kb/HT213488" }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2022/Oct/28" + }, { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2022/Oct/41" diff --git a/advisories/unreviewed/2022/05/GHSA-2hpw-5cjm-953f/GHSA-2hpw-5cjm-953f.json b/advisories/unreviewed/2022/05/GHSA-2hpw-5cjm-953f/GHSA-2hpw-5cjm-953f.json index 3a018fb063b..f65dd8c39c3 100644 --- a/advisories/unreviewed/2022/05/GHSA-2hpw-5cjm-953f/GHSA-2hpw-5cjm-953f.json +++ b/advisories/unreviewed/2022/05/GHSA-2hpw-5cjm-953f/GHSA-2hpw-5cjm-953f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2hpw-5cjm-953f", - "modified": "2022-05-24T17:43:02Z", + "modified": "2025-06-09T15:31:32Z", "published": "2022-05-24T17:43:02Z", "aliases": [ "CVE-2021-27645" @@ -23,6 +23,14 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7LZNT6KTMCCWPWXEOGSHD3YLYZKUGMH5" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I7TS26LIZSOBLGJEZMJX4PXT5BQDE2WS" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7LZNT6KTMCCWPWXEOGSHD3YLYZKUGMH5" diff --git a/advisories/unreviewed/2022/05/GHSA-4c4j-w8hm-rjgv/GHSA-4c4j-w8hm-rjgv.json b/advisories/unreviewed/2022/05/GHSA-4c4j-w8hm-rjgv/GHSA-4c4j-w8hm-rjgv.json index 5dfed0b8be1..e9e956b52a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-4c4j-w8hm-rjgv/GHSA-4c4j-w8hm-rjgv.json +++ b/advisories/unreviewed/2022/05/GHSA-4c4j-w8hm-rjgv/GHSA-4c4j-w8hm-rjgv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4c4j-w8hm-rjgv", - "modified": "2022-06-08T00:00:37Z", + "modified": "2025-06-09T15:31:33Z", "published": "2022-05-26T00:01:09Z", "aliases": [ "CVE-2022-1348" @@ -23,6 +23,14 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2022-1348" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y7EHGYRE6DSFSBXQIWYDGTSXKO6IFSJQ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZYEB4F37BY6GLEJKP2EPVAVQ6TA3HQKR" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Y7EHGYRE6DSFSBXQIWYDGTSXKO6IFSJQ" diff --git a/advisories/unreviewed/2022/05/GHSA-mwc7-wm76-6x7w/GHSA-mwc7-wm76-6x7w.json b/advisories/unreviewed/2022/05/GHSA-mwc7-wm76-6x7w/GHSA-mwc7-wm76-6x7w.json index 94c39908d90..5c6f3d99de6 100644 --- a/advisories/unreviewed/2022/05/GHSA-mwc7-wm76-6x7w/GHSA-mwc7-wm76-6x7w.json +++ b/advisories/unreviewed/2022/05/GHSA-mwc7-wm76-6x7w/GHSA-mwc7-wm76-6x7w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mwc7-wm76-6x7w", - "modified": "2022-05-17T04:53:12Z", + "modified": "2025-06-09T15:31:31Z", "published": "2022-05-17T04:53:12Z", "aliases": [ "CVE-2010-4226" ], "details": "cpio, as used in build 2007.05.10, 2010.07.28, and possibly other versions, allows remote attackers to overwrite arbitrary files via a symlink within an RPM package archive.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/08/GHSA-32pr-wg5j-9rwr/GHSA-32pr-wg5j-9rwr.json b/advisories/unreviewed/2022/08/GHSA-32pr-wg5j-9rwr/GHSA-32pr-wg5j-9rwr.json index dbc34e82583..a94e0e18b45 100644 --- a/advisories/unreviewed/2022/08/GHSA-32pr-wg5j-9rwr/GHSA-32pr-wg5j-9rwr.json +++ b/advisories/unreviewed/2022/08/GHSA-32pr-wg5j-9rwr/GHSA-32pr-wg5j-9rwr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-32pr-wg5j-9rwr", - "modified": "2022-08-29T20:06:51Z", + "modified": "2025-06-09T15:31:33Z", "published": "2022-08-25T00:00:27Z", "aliases": [ "CVE-2021-3998" diff --git a/advisories/unreviewed/2022/10/GHSA-3g2p-5q22-h774/GHSA-3g2p-5q22-h774.json b/advisories/unreviewed/2022/10/GHSA-3g2p-5q22-h774/GHSA-3g2p-5q22-h774.json index 310e3b94053..a5a054cb301 100644 --- a/advisories/unreviewed/2022/10/GHSA-3g2p-5q22-h774/GHSA-3g2p-5q22-h774.json +++ b/advisories/unreviewed/2022/10/GHSA-3g2p-5q22-h774/GHSA-3g2p-5q22-h774.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3g2p-5q22-h774", - "modified": "2022-10-11T19:00:25Z", + "modified": "2025-06-09T15:31:34Z", "published": "2022-10-10T19:00:18Z", "aliases": [ "CVE-2022-42011" diff --git a/advisories/unreviewed/2022/10/GHSA-7v94-mgqj-cj58/GHSA-7v94-mgqj-cj58.json b/advisories/unreviewed/2022/10/GHSA-7v94-mgqj-cj58/GHSA-7v94-mgqj-cj58.json index a0b7f2157f4..bc44e6fd180 100644 --- a/advisories/unreviewed/2022/10/GHSA-7v94-mgqj-cj58/GHSA-7v94-mgqj-cj58.json +++ b/advisories/unreviewed/2022/10/GHSA-7v94-mgqj-cj58/GHSA-7v94-mgqj-cj58.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7v94-mgqj-cj58", - "modified": "2022-10-11T19:00:25Z", + "modified": "2025-06-09T15:31:35Z", "published": "2022-10-10T19:00:18Z", "aliases": [ "CVE-2022-42012" @@ -57,7 +57,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-20" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-mmv5-g2hf-r8cf/GHSA-mmv5-g2hf-r8cf.json b/advisories/unreviewed/2022/10/GHSA-mmv5-g2hf-r8cf/GHSA-mmv5-g2hf-r8cf.json index b48aaa59dcd..f303b95b980 100644 --- a/advisories/unreviewed/2022/10/GHSA-mmv5-g2hf-r8cf/GHSA-mmv5-g2hf-r8cf.json +++ b/advisories/unreviewed/2022/10/GHSA-mmv5-g2hf-r8cf/GHSA-mmv5-g2hf-r8cf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mmv5-g2hf-r8cf", - "modified": "2022-10-11T19:00:25Z", + "modified": "2025-06-09T15:31:34Z", "published": "2022-10-10T19:00:18Z", "aliases": [ "CVE-2022-42010" diff --git a/advisories/unreviewed/2023/06/GHSA-q652-p9gf-vfq3/GHSA-q652-p9gf-vfq3.json b/advisories/unreviewed/2023/06/GHSA-q652-p9gf-vfq3/GHSA-q652-p9gf-vfq3.json index d10d98d27fc..04adeea5ad6 100644 --- a/advisories/unreviewed/2023/06/GHSA-q652-p9gf-vfq3/GHSA-q652-p9gf-vfq3.json +++ b/advisories/unreviewed/2023/06/GHSA-q652-p9gf-vfq3/GHSA-q652-p9gf-vfq3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q652-p9gf-vfq3", - "modified": "2023-11-15T03:30:25Z", + "modified": "2025-06-09T15:31:35Z", "published": "2023-06-08T03:30:16Z", "aliases": [ "CVE-2023-34969" @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-404" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-qxpv-rxq7-rg72/GHSA-qxpv-rxq7-rg72.json b/advisories/unreviewed/2023/07/GHSA-qxpv-rxq7-rg72/GHSA-qxpv-rxq7-rg72.json index dc0b23ee07a..6d5678cfe62 100644 --- a/advisories/unreviewed/2023/07/GHSA-qxpv-rxq7-rg72/GHSA-qxpv-rxq7-rg72.json +++ b/advisories/unreviewed/2023/07/GHSA-qxpv-rxq7-rg72/GHSA-qxpv-rxq7-rg72.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qxpv-rxq7-rg72", - "modified": "2024-03-21T03:35:30Z", + "modified": "2025-06-09T15:31:35Z", "published": "2023-07-12T18:30:38Z", "aliases": [ "CVE-2023-36266" @@ -19,6 +19,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36266" }, + { + "type": "WEB", + "url": "https://docs.keeper.io/en/enterprise-guide/keeper-forcefield" + }, + { + "type": "WEB", + "url": "https://docs.keeper.io/en/release-notes/desktop/web-vault-+-desktop-app/vault-release-17.2" + }, { "type": "WEB", "url": "https://harkenzo.tlstickle.com/2023-06-12-Keeper-Password-Dumping" diff --git a/advisories/unreviewed/2025/06/GHSA-28m4-49gg-78fx/GHSA-28m4-49gg-78fx.json b/advisories/unreviewed/2025/06/GHSA-28m4-49gg-78fx/GHSA-28m4-49gg-78fx.json index 22ed1b983e1..59c7cd40521 100644 --- a/advisories/unreviewed/2025/06/GHSA-28m4-49gg-78fx/GHSA-28m4-49gg-78fx.json +++ b/advisories/unreviewed/2025/06/GHSA-28m4-49gg-78fx/GHSA-28m4-49gg-78fx.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/06/GHSA-2g9r-w7mh-f2h2/GHSA-2g9r-w7mh-f2h2.json b/advisories/unreviewed/2025/06/GHSA-2g9r-w7mh-f2h2/GHSA-2g9r-w7mh-f2h2.json index 68e364cac81..bd088d64426 100644 --- a/advisories/unreviewed/2025/06/GHSA-2g9r-w7mh-f2h2/GHSA-2g9r-w7mh-f2h2.json +++ b/advisories/unreviewed/2025/06/GHSA-2g9r-w7mh-f2h2/GHSA-2g9r-w7mh-f2h2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2g9r-w7mh-f2h2", - "modified": "2025-06-06T06:30:26Z", + "modified": "2025-06-09T15:31:38Z", "published": "2025-06-06T06:30:26Z", "aliases": [ "CVE-2025-5715" @@ -23,6 +23,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5715" }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1tI0bC8X8546ActlzGlmSU-AhCdD950y4/view" + }, { "type": "WEB", "url": "https://drive.google.com/file/d/1tI0bC8X8546ActlzGlmSU-AhCdD950y4/view?usp=drivesdk" diff --git a/advisories/unreviewed/2025/06/GHSA-2h2q-247m-jhjc/GHSA-2h2q-247m-jhjc.json b/advisories/unreviewed/2025/06/GHSA-2h2q-247m-jhjc/GHSA-2h2q-247m-jhjc.json new file mode 100644 index 00000000000..ad65bd274fc --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-2h2q-247m-jhjc/GHSA-2h2q-247m-jhjc.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2h2q-247m-jhjc", + "modified": "2025-06-09T15:31:42Z", + "published": "2025-06-09T15:31:42Z", + "aliases": [ + "CVE-2025-5880" + ], + "details": "A vulnerability has been found in Whistle 2.9.98 and classified as problematic. This vulnerability affects unknown code of the file /cgi-bin/sessions/get-temp-file. The manipulation of the argument filename leads to path traversal. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5880" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311638" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311638" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.582867" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T14:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-3xwj-8v2h-93qc/GHSA-3xwj-8v2h-93qc.json b/advisories/unreviewed/2025/06/GHSA-3xwj-8v2h-93qc/GHSA-3xwj-8v2h-93qc.json new file mode 100644 index 00000000000..512dd4e94d9 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-3xwj-8v2h-93qc/GHSA-3xwj-8v2h-93qc.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3xwj-8v2h-93qc", + "modified": "2025-06-09T15:31:42Z", + "published": "2025-06-09T15:31:42Z", + "aliases": [ + "CVE-2025-5881" + ], + "details": "A vulnerability was found in code-projects Chat System up to 1.0 and classified as critical. This issue affects some unknown processing of the file /user/confirm_password.php. The manipulation of the argument cid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5881" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/LamentXU123/cve/blob/main/sql4.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311639" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311639" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.592112" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T14:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-6j9c-246r-2553/GHSA-6j9c-246r-2553.json b/advisories/unreviewed/2025/06/GHSA-6j9c-246r-2553/GHSA-6j9c-246r-2553.json new file mode 100644 index 00000000000..24dad96de94 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-6j9c-246r-2553/GHSA-6j9c-246r-2553.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6j9c-246r-2553", + "modified": "2025-06-09T15:31:42Z", + "published": "2025-06-09T15:31:42Z", + "aliases": [ + "CVE-2025-5879" + ], + "details": "A vulnerability, which was classified as problematic, was found in WuKongOpenSource WukongCRM 9.0. This affects an unknown part of the file AdminSysConfigController.java of the component File Upload. The manipulation of the argument File leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5879" + }, + { + "type": "WEB", + "url": "https://github.com/Aiyakami/CVE-1/issues/7" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311637" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311637" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.587201" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T13:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-6p6j-f8q6-5r72/GHSA-6p6j-f8q6-5r72.json b/advisories/unreviewed/2025/06/GHSA-6p6j-f8q6-5r72/GHSA-6p6j-f8q6-5r72.json new file mode 100644 index 00000000000..a9bb51beab1 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-6p6j-f8q6-5r72/GHSA-6p6j-f8q6-5r72.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6p6j-f8q6-5r72", + "modified": "2025-06-09T15:31:42Z", + "published": "2025-06-09T15:31:42Z", + "aliases": [ + "CVE-2025-40669" + ], + "details": "Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an unprivileged attacker to modify the permissions held by each of the application's users, including the user himself by sending a POST request to /PC/Options.aspx?Command=2&Page=-1.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40669" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-tcman-gim-1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T13:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-6vfc-8w2v-vx36/GHSA-6vfc-8w2v-vx36.json b/advisories/unreviewed/2025/06/GHSA-6vfc-8w2v-vx36/GHSA-6vfc-8w2v-vx36.json index 0d1186af1d4..32fce534718 100644 --- a/advisories/unreviewed/2025/06/GHSA-6vfc-8w2v-vx36/GHSA-6vfc-8w2v-vx36.json +++ b/advisories/unreviewed/2025/06/GHSA-6vfc-8w2v-vx36/GHSA-6vfc-8w2v-vx36.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6vfc-8w2v-vx36", - "modified": "2025-06-09T06:30:21Z", + "modified": "2025-06-09T15:31:42Z", "published": "2025-06-09T06:30:21Z", "aliases": [ "CVE-2025-5862" @@ -23,6 +23,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5862" }, + { + "type": "WEB", + "url": "https://lavender-bicycle-a5a.notion.site/Tenda-AC7-formSetPPTPUserList-20a53a41781f806ca124cbdf99bff931" + }, { "type": "WEB", "url": "https://lavender-bicycle-a5a.notion.site/Tenda-AC7-formSetPPTPUserList-20a53a41781f806ca124cbdf99bff931?source=copy_link" diff --git a/advisories/unreviewed/2025/06/GHSA-7387-f28m-vqxg/GHSA-7387-f28m-vqxg.json b/advisories/unreviewed/2025/06/GHSA-7387-f28m-vqxg/GHSA-7387-f28m-vqxg.json new file mode 100644 index 00000000000..069f6582a22 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-7387-f28m-vqxg/GHSA-7387-f28m-vqxg.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7387-f28m-vqxg", + "modified": "2025-06-09T15:31:42Z", + "published": "2025-06-09T15:31:42Z", + "aliases": [ + "CVE-2025-5884" + ], + "details": "A vulnerability, which was classified as problematic, was found in Konica Minolta bizhub up to 20250202. This affects an unknown part of the component Display MFP Information List. The manipulation of the argument Model Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5884" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1A0JEnmnUGNjGsizRu99uz2ynqQ3v9ZKB/view" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311655" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311655" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.493653" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T15:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-8h93-38hx-vv92/GHSA-8h93-38hx-vv92.json b/advisories/unreviewed/2025/06/GHSA-8h93-38hx-vv92/GHSA-8h93-38hx-vv92.json index a0c13a009ac..cca60094bfb 100644 --- a/advisories/unreviewed/2025/06/GHSA-8h93-38hx-vv92/GHSA-8h93-38hx-vv92.json +++ b/advisories/unreviewed/2025/06/GHSA-8h93-38hx-vv92/GHSA-8h93-38hx-vv92.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8h93-38hx-vv92", - "modified": "2025-06-07T09:30:18Z", + "modified": "2025-06-09T15:31:41Z", "published": "2025-06-07T09:30:18Z", "aliases": [ "CVE-2025-5399" ], "details": "Due to a mistake in libcurl's WebSocket code, a malicious server can send a\nparticularly crafted packet which makes libcurl get trapped in an endless\nbusy-loop.\n\nThere is no other way for the application to escape or exit this loop other\nthan killing the thread/process.\n\nThis might be used to DoS libcurl-using application.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -33,7 +38,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-07T08:15:20Z" diff --git a/advisories/unreviewed/2025/06/GHSA-8qpg-2ff4-h2q5/GHSA-8qpg-2ff4-h2q5.json b/advisories/unreviewed/2025/06/GHSA-8qpg-2ff4-h2q5/GHSA-8qpg-2ff4-h2q5.json new file mode 100644 index 00000000000..30d78a5ac74 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-8qpg-2ff4-h2q5/GHSA-8qpg-2ff4-h2q5.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8qpg-2ff4-h2q5", + "modified": "2025-06-09T15:31:42Z", + "published": "2025-06-09T15:31:42Z", + "aliases": [ + "CVE-2025-5877" + ], + "details": "A vulnerability, which was classified as problematic, has been found in Fengoffice Feng Office 3.2.2.1. Affected by this issue is some unknown functionality of the file /application/models/ApplicationDataObject.class.php of the component Document Upload Handler. The manipulation leads to xml external entity reference. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5877" + }, + { + "type": "WEB", + "url": "https://gist.github.com/mcdruid/e78694d754f44884830898be082fcbaa" + }, + { + "type": "WEB", + "url": "https://gist.github.com/mcdruid/e78694d754f44884830898be082fcbaa#steps-to-reproduce" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311636" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311636" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.586971" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-610" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T13:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-c45x-4cr6-92hc/GHSA-c45x-4cr6-92hc.json b/advisories/unreviewed/2025/06/GHSA-c45x-4cr6-92hc/GHSA-c45x-4cr6-92hc.json index 0fa43f2772f..7c287471ad8 100644 --- a/advisories/unreviewed/2025/06/GHSA-c45x-4cr6-92hc/GHSA-c45x-4cr6-92hc.json +++ b/advisories/unreviewed/2025/06/GHSA-c45x-4cr6-92hc/GHSA-c45x-4cr6-92hc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c45x-4cr6-92hc", - "modified": "2025-06-06T21:30:29Z", + "modified": "2025-06-09T15:31:41Z", "published": "2025-06-06T21:30:28Z", "aliases": [ "CVE-2025-5798" @@ -23,6 +23,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5798" }, + { + "type": "WEB", + "url": "https://lavender-bicycle-a5a.notion.site/Tenda-AC8-fromSetSysTime-20a53a41781f807b9489fff42f262e11" + }, { "type": "WEB", "url": "https://lavender-bicycle-a5a.notion.site/Tenda-AC8-fromSetSysTime-20a53a41781f807b9489fff42f262e11?source=copy_link" diff --git a/advisories/unreviewed/2025/06/GHSA-cc4f-xvhj-7frg/GHSA-cc4f-xvhj-7frg.json b/advisories/unreviewed/2025/06/GHSA-cc4f-xvhj-7frg/GHSA-cc4f-xvhj-7frg.json new file mode 100644 index 00000000000..86563e5d977 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-cc4f-xvhj-7frg/GHSA-cc4f-xvhj-7frg.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cc4f-xvhj-7frg", + "modified": "2025-06-09T15:31:42Z", + "published": "2025-06-09T15:31:42Z", + "aliases": [ + "CVE-2025-5885" + ], + "details": "A vulnerability has been found in Konica Minolta bizhub up to 20250202 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5885" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1pECiiSWdB_ERzzGrc--WY63IzZxR6i6L/view" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311656" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311656" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.493666" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T15:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-f35w-jcp9-579f/GHSA-f35w-jcp9-579f.json b/advisories/unreviewed/2025/06/GHSA-f35w-jcp9-579f/GHSA-f35w-jcp9-579f.json index edb27e93a69..421adc51674 100644 --- a/advisories/unreviewed/2025/06/GHSA-f35w-jcp9-579f/GHSA-f35w-jcp9-579f.json +++ b/advisories/unreviewed/2025/06/GHSA-f35w-jcp9-579f/GHSA-f35w-jcp9-579f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f35w-jcp9-579f", - "modified": "2025-06-06T21:30:28Z", + "modified": "2025-06-09T15:31:41Z", "published": "2025-06-06T21:30:28Z", "aliases": [ "CVE-2025-5795" @@ -23,6 +23,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5795" }, + { + "type": "WEB", + "url": "https://lavender-bicycle-a5a.notion.site/Tenda-AC5-fromadvsetlanip-20a53a41781f805389dcd51fa04bc530" + }, { "type": "WEB", "url": "https://lavender-bicycle-a5a.notion.site/Tenda-AC5-fromadvsetlanip-20a53a41781f805389dcd51fa04bc530?source=copy_link" diff --git a/advisories/unreviewed/2025/06/GHSA-jw8p-xr8r-2w5h/GHSA-jw8p-xr8r-2w5h.json b/advisories/unreviewed/2025/06/GHSA-jw8p-xr8r-2w5h/GHSA-jw8p-xr8r-2w5h.json new file mode 100644 index 00000000000..352031316e8 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-jw8p-xr8r-2w5h/GHSA-jw8p-xr8r-2w5h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jw8p-xr8r-2w5h", + "modified": "2025-06-09T15:31:42Z", + "published": "2025-06-09T15:31:42Z", + "aliases": [ + "CVE-2025-40670" + ], + "details": "Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an unprivileged attacker to create a user and assign it many privileges by sending a POST request to /PC/frmGestionUser.aspx/updateUser.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40670" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-tcman-gim-1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T13:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-p5r3-w88m-mm8j/GHSA-p5r3-w88m-mm8j.json b/advisories/unreviewed/2025/06/GHSA-p5r3-w88m-mm8j/GHSA-p5r3-w88m-mm8j.json index e8d7d7ddea4..ab8b9c3c1da 100644 --- a/advisories/unreviewed/2025/06/GHSA-p5r3-w88m-mm8j/GHSA-p5r3-w88m-mm8j.json +++ b/advisories/unreviewed/2025/06/GHSA-p5r3-w88m-mm8j/GHSA-p5r3-w88m-mm8j.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/06/GHSA-pv9r-4f6f-g2p4/GHSA-pv9r-4f6f-g2p4.json b/advisories/unreviewed/2025/06/GHSA-pv9r-4f6f-g2p4/GHSA-pv9r-4f6f-g2p4.json index 19513111237..504ed8d0d94 100644 --- a/advisories/unreviewed/2025/06/GHSA-pv9r-4f6f-g2p4/GHSA-pv9r-4f6f-g2p4.json +++ b/advisories/unreviewed/2025/06/GHSA-pv9r-4f6f-g2p4/GHSA-pv9r-4f6f-g2p4.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/06/GHSA-qv9v-4gh7-4qhp/GHSA-qv9v-4gh7-4qhp.json b/advisories/unreviewed/2025/06/GHSA-qv9v-4gh7-4qhp/GHSA-qv9v-4gh7-4qhp.json index 7840bac9eb3..64c75166bb1 100644 --- a/advisories/unreviewed/2025/06/GHSA-qv9v-4gh7-4qhp/GHSA-qv9v-4gh7-4qhp.json +++ b/advisories/unreviewed/2025/06/GHSA-qv9v-4gh7-4qhp/GHSA-qv9v-4gh7-4qhp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qv9v-4gh7-4qhp", - "modified": "2025-06-06T21:30:28Z", + "modified": "2025-06-09T15:31:41Z", "published": "2025-06-06T21:30:28Z", "aliases": [ "CVE-2025-5794" @@ -23,6 +23,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5794" }, + { + "type": "WEB", + "url": "https://lavender-bicycle-a5a.notion.site/Tenda-AC5-formSetPPTPUserList-20a53a41781f806faf61cef61ed929c0" + }, { "type": "WEB", "url": "https://lavender-bicycle-a5a.notion.site/Tenda-AC5-formSetPPTPUserList-20a53a41781f806faf61cef61ed929c0?source=copy_link" diff --git a/advisories/unreviewed/2025/06/GHSA-rh23-w5x7-xjm4/GHSA-rh23-w5x7-xjm4.json b/advisories/unreviewed/2025/06/GHSA-rh23-w5x7-xjm4/GHSA-rh23-w5x7-xjm4.json index 4712824511e..4fa8ae92d87 100644 --- a/advisories/unreviewed/2025/06/GHSA-rh23-w5x7-xjm4/GHSA-rh23-w5x7-xjm4.json +++ b/advisories/unreviewed/2025/06/GHSA-rh23-w5x7-xjm4/GHSA-rh23-w5x7-xjm4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rh23-w5x7-xjm4", - "modified": "2025-06-06T15:30:53Z", + "modified": "2025-06-09T15:31:41Z", "published": "2025-06-06T15:30:53Z", "aliases": [ "CVE-2025-38001" @@ -42,6 +42,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/a0ec22fa20b252edbe070a9de8501eef63c17ef5" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ac9fe7dd8e730a103ae4481147395cc73492d786" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/e5bee633cc276410337d54b99f77fbc1ad8801e5" diff --git a/advisories/unreviewed/2025/06/GHSA-rpwp-653m-8vhf/GHSA-rpwp-653m-8vhf.json b/advisories/unreviewed/2025/06/GHSA-rpwp-653m-8vhf/GHSA-rpwp-653m-8vhf.json index 7f64bc8a8f3..1a62375e75a 100644 --- a/advisories/unreviewed/2025/06/GHSA-rpwp-653m-8vhf/GHSA-rpwp-653m-8vhf.json +++ b/advisories/unreviewed/2025/06/GHSA-rpwp-653m-8vhf/GHSA-rpwp-653m-8vhf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rpwp-653m-8vhf", - "modified": "2025-06-06T21:30:29Z", + "modified": "2025-06-09T15:31:42Z", "published": "2025-06-06T21:30:29Z", "aliases": [ "CVE-2025-5799" @@ -23,6 +23,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5799" }, + { + "type": "WEB", + "url": "https://lavender-bicycle-a5a.notion.site/Tenda-AC8-fromSetWirelessRepeat-20a53a41781f803d9156f0babaf94fca" + }, { "type": "WEB", "url": "https://lavender-bicycle-a5a.notion.site/Tenda-AC8-fromSetWirelessRepeat-20a53a41781f803d9156f0babaf94fca?source=copy_link" diff --git a/advisories/unreviewed/2025/06/GHSA-w29c-vpjf-6hx4/GHSA-w29c-vpjf-6hx4.json b/advisories/unreviewed/2025/06/GHSA-w29c-vpjf-6hx4/GHSA-w29c-vpjf-6hx4.json new file mode 100644 index 00000000000..a7be85511d4 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-w29c-vpjf-6hx4/GHSA-w29c-vpjf-6hx4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w29c-vpjf-6hx4", + "modified": "2025-06-09T15:31:42Z", + "published": "2025-06-09T15:31:42Z", + "aliases": [ + "CVE-2025-40668" + ], + "details": "Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an attacker, with low privilege level, to change the password of other users through a POST request using the parameters idUser, PasswordActual, PasswordNew and PasswordNewRepeat in /PC/WebService.aspx/validateChangePassword%C3%B1a. To exploit the vulnerability the PasswordActual parameter must be empty.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40668" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-tcman-gim-1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T13:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-w866-3fpp-r6c4/GHSA-w866-3fpp-r6c4.json b/advisories/unreviewed/2025/06/GHSA-w866-3fpp-r6c4/GHSA-w866-3fpp-r6c4.json index 5ecd6ae534c..b85c01eedd7 100644 --- a/advisories/unreviewed/2025/06/GHSA-w866-3fpp-r6c4/GHSA-w866-3fpp-r6c4.json +++ b/advisories/unreviewed/2025/06/GHSA-w866-3fpp-r6c4/GHSA-w866-3fpp-r6c4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w866-3fpp-r6c4", - "modified": "2025-06-09T06:30:22Z", + "modified": "2025-06-09T15:31:42Z", "published": "2025-06-09T06:30:22Z", "aliases": [ "CVE-2025-5861" @@ -23,6 +23,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5861" }, + { + "type": "WEB", + "url": "https://lavender-bicycle-a5a.notion.site/Tenda-AC7-fromadvsetlanip-20a53a41781f80038f4fc4b9d927eb9a" + }, { "type": "WEB", "url": "https://lavender-bicycle-a5a.notion.site/Tenda-AC7-fromadvsetlanip-20a53a41781f80038f4fc4b9d927eb9a?source=copy_link"