diff --git a/advisories/unreviewed/2022/09/GHSA-33v4-4p2r-hcrr/GHSA-33v4-4p2r-hcrr.json b/advisories/unreviewed/2022/09/GHSA-33v4-4p2r-hcrr/GHSA-33v4-4p2r-hcrr.json index 03baf4a8c31..be304705e00 100644 --- a/advisories/unreviewed/2022/09/GHSA-33v4-4p2r-hcrr/GHSA-33v4-4p2r-hcrr.json +++ b/advisories/unreviewed/2022/09/GHSA-33v4-4p2r-hcrr/GHSA-33v4-4p2r-hcrr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-33v4-4p2r-hcrr", - "modified": "2022-10-05T00:00:38Z", + "modified": "2025-05-21T15:30:28Z", "published": "2022-09-30T00:00:45Z", "aliases": [ "CVE-2022-40363" diff --git a/advisories/unreviewed/2022/09/GHSA-3q99-mmr6-6chg/GHSA-3q99-mmr6-6chg.json b/advisories/unreviewed/2022/09/GHSA-3q99-mmr6-6chg/GHSA-3q99-mmr6-6chg.json index 16da8fd516e..546a83e71db 100644 --- a/advisories/unreviewed/2022/09/GHSA-3q99-mmr6-6chg/GHSA-3q99-mmr6-6chg.json +++ b/advisories/unreviewed/2022/09/GHSA-3q99-mmr6-6chg/GHSA-3q99-mmr6-6chg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3q99-mmr6-6chg", - "modified": "2022-10-29T19:00:27Z", + "modified": "2025-05-21T15:30:26Z", "published": "2022-09-29T00:00:27Z", "aliases": [ "CVE-2022-32166" diff --git a/advisories/unreviewed/2022/09/GHSA-433g-q37h-7crr/GHSA-433g-q37h-7crr.json b/advisories/unreviewed/2022/09/GHSA-433g-q37h-7crr/GHSA-433g-q37h-7crr.json index 54f0fc20079..a0963e9e94e 100644 --- a/advisories/unreviewed/2022/09/GHSA-433g-q37h-7crr/GHSA-433g-q37h-7crr.json +++ b/advisories/unreviewed/2022/09/GHSA-433g-q37h-7crr/GHSA-433g-q37h-7crr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-433g-q37h-7crr", - "modified": "2022-10-05T00:00:40Z", + "modified": "2025-05-21T15:30:25Z", "published": "2022-09-28T00:00:18Z", "aliases": [ "CVE-2021-27854" diff --git a/advisories/unreviewed/2022/09/GHSA-4fhf-8ph3-pp6c/GHSA-4fhf-8ph3-pp6c.json b/advisories/unreviewed/2022/09/GHSA-4fhf-8ph3-pp6c/GHSA-4fhf-8ph3-pp6c.json index b1108c1ed17..f100b0b6cc1 100644 --- a/advisories/unreviewed/2022/09/GHSA-4fhf-8ph3-pp6c/GHSA-4fhf-8ph3-pp6c.json +++ b/advisories/unreviewed/2022/09/GHSA-4fhf-8ph3-pp6c/GHSA-4fhf-8ph3-pp6c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4fhf-8ph3-pp6c", - "modified": "2022-10-04T00:00:19Z", + "modified": "2025-05-21T15:30:25Z", "published": "2022-09-28T00:00:18Z", "aliases": [ "CVE-2021-27862" @@ -38,6 +38,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-130", "CWE-290" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/09/GHSA-4rx4-fcrw-j9p7/GHSA-4rx4-fcrw-j9p7.json b/advisories/unreviewed/2022/09/GHSA-4rx4-fcrw-j9p7/GHSA-4rx4-fcrw-j9p7.json index f82ae47401c..7abfc500179 100644 --- a/advisories/unreviewed/2022/09/GHSA-4rx4-fcrw-j9p7/GHSA-4rx4-fcrw-j9p7.json +++ b/advisories/unreviewed/2022/09/GHSA-4rx4-fcrw-j9p7/GHSA-4rx4-fcrw-j9p7.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/09/GHSA-59wm-xj7c-3vq4/GHSA-59wm-xj7c-3vq4.json b/advisories/unreviewed/2022/09/GHSA-59wm-xj7c-3vq4/GHSA-59wm-xj7c-3vq4.json index 5063b652ff2..b1c9d4cc854 100644 --- a/advisories/unreviewed/2022/09/GHSA-59wm-xj7c-3vq4/GHSA-59wm-xj7c-3vq4.json +++ b/advisories/unreviewed/2022/09/GHSA-59wm-xj7c-3vq4/GHSA-59wm-xj7c-3vq4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-59wm-xj7c-3vq4", - "modified": "2022-10-01T00:00:19Z", + "modified": "2025-05-21T15:30:27Z", "published": "2022-09-29T00:00:20Z", "aliases": [ "CVE-2022-23716" diff --git a/advisories/unreviewed/2022/09/GHSA-67q7-2m82-v47j/GHSA-67q7-2m82-v47j.json b/advisories/unreviewed/2022/09/GHSA-67q7-2m82-v47j/GHSA-67q7-2m82-v47j.json index c88450fb44c..d2996a3e027 100644 --- a/advisories/unreviewed/2022/09/GHSA-67q7-2m82-v47j/GHSA-67q7-2m82-v47j.json +++ b/advisories/unreviewed/2022/09/GHSA-67q7-2m82-v47j/GHSA-67q7-2m82-v47j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-67q7-2m82-v47j", - "modified": "2022-10-01T00:00:24Z", + "modified": "2025-05-21T15:30:25Z", "published": "2022-09-28T00:00:17Z", "aliases": [ "CVE-2022-37028" diff --git a/advisories/unreviewed/2022/09/GHSA-6jfx-5cxr-8qxw/GHSA-6jfx-5cxr-8qxw.json b/advisories/unreviewed/2022/09/GHSA-6jfx-5cxr-8qxw/GHSA-6jfx-5cxr-8qxw.json index 2b1a1fa6bbb..7026cd69492 100644 --- a/advisories/unreviewed/2022/09/GHSA-6jfx-5cxr-8qxw/GHSA-6jfx-5cxr-8qxw.json +++ b/advisories/unreviewed/2022/09/GHSA-6jfx-5cxr-8qxw/GHSA-6jfx-5cxr-8qxw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6jfx-5cxr-8qxw", - "modified": "2022-10-01T00:00:21Z", + "modified": "2025-05-21T15:30:26Z", "published": "2022-09-29T00:00:27Z", "aliases": [ "CVE-2022-40486" diff --git a/advisories/unreviewed/2022/09/GHSA-95x6-vp26-h77r/GHSA-95x6-vp26-h77r.json b/advisories/unreviewed/2022/09/GHSA-95x6-vp26-h77r/GHSA-95x6-vp26-h77r.json index f6c28849366..bcd9620d4ee 100644 --- a/advisories/unreviewed/2022/09/GHSA-95x6-vp26-h77r/GHSA-95x6-vp26-h77r.json +++ b/advisories/unreviewed/2022/09/GHSA-95x6-vp26-h77r/GHSA-95x6-vp26-h77r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-95x6-vp26-h77r", - "modified": "2022-09-30T00:00:21Z", + "modified": "2025-05-21T15:30:27Z", "published": "2022-09-29T00:00:20Z", "aliases": [ "CVE-2022-1270" diff --git a/advisories/unreviewed/2022/09/GHSA-cw76-gh48-42j3/GHSA-cw76-gh48-42j3.json b/advisories/unreviewed/2022/09/GHSA-cw76-gh48-42j3/GHSA-cw76-gh48-42j3.json index 82593fff3ab..c68fec3ba06 100644 --- a/advisories/unreviewed/2022/09/GHSA-cw76-gh48-42j3/GHSA-cw76-gh48-42j3.json +++ b/advisories/unreviewed/2022/09/GHSA-cw76-gh48-42j3/GHSA-cw76-gh48-42j3.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-20" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-gwqr-42v8-7m7q/GHSA-gwqr-42v8-7m7q.json b/advisories/unreviewed/2022/09/GHSA-gwqr-42v8-7m7q/GHSA-gwqr-42v8-7m7q.json index e55a6d3f10b..92c4e766d5e 100644 --- a/advisories/unreviewed/2022/09/GHSA-gwqr-42v8-7m7q/GHSA-gwqr-42v8-7m7q.json +++ b/advisories/unreviewed/2022/09/GHSA-gwqr-42v8-7m7q/GHSA-gwqr-42v8-7m7q.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-668" + "CWE-668", + "CWE-863" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/09/GHSA-q6rw-39p5-wphc/GHSA-q6rw-39p5-wphc.json b/advisories/unreviewed/2022/09/GHSA-q6rw-39p5-wphc/GHSA-q6rw-39p5-wphc.json index e0bde5780e2..c883a84f8b1 100644 --- a/advisories/unreviewed/2022/09/GHSA-q6rw-39p5-wphc/GHSA-q6rw-39p5-wphc.json +++ b/advisories/unreviewed/2022/09/GHSA-q6rw-39p5-wphc/GHSA-q6rw-39p5-wphc.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-qww5-j4p3-7mj5/GHSA-qww5-j4p3-7mj5.json b/advisories/unreviewed/2022/09/GHSA-qww5-j4p3-7mj5/GHSA-qww5-j4p3-7mj5.json index a2f2611f13b..1a894f9705e 100644 --- a/advisories/unreviewed/2022/09/GHSA-qww5-j4p3-7mj5/GHSA-qww5-j4p3-7mj5.json +++ b/advisories/unreviewed/2022/09/GHSA-qww5-j4p3-7mj5/GHSA-qww5-j4p3-7mj5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qww5-j4p3-7mj5", - "modified": "2022-09-30T00:00:34Z", + "modified": "2025-05-21T15:30:25Z", "published": "2022-09-28T00:00:17Z", "aliases": [ "CVE-2022-38335" diff --git a/advisories/unreviewed/2022/09/GHSA-v7cg-cf6c-wpmp/GHSA-v7cg-cf6c-wpmp.json b/advisories/unreviewed/2022/09/GHSA-v7cg-cf6c-wpmp/GHSA-v7cg-cf6c-wpmp.json index 9342ddad10b..35ee3d88173 100644 --- a/advisories/unreviewed/2022/09/GHSA-v7cg-cf6c-wpmp/GHSA-v7cg-cf6c-wpmp.json +++ b/advisories/unreviewed/2022/09/GHSA-v7cg-cf6c-wpmp/GHSA-v7cg-cf6c-wpmp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v7cg-cf6c-wpmp", - "modified": "2022-09-29T00:00:18Z", + "modified": "2025-05-21T15:30:26Z", "published": "2022-09-28T00:00:16Z", "aliases": [ "CVE-2022-40877" diff --git a/advisories/unreviewed/2022/09/GHSA-vp8w-34r2-97r4/GHSA-vp8w-34r2-97r4.json b/advisories/unreviewed/2022/09/GHSA-vp8w-34r2-97r4/GHSA-vp8w-34r2-97r4.json index c7792e789f2..bb59df0655b 100644 --- a/advisories/unreviewed/2022/09/GHSA-vp8w-34r2-97r4/GHSA-vp8w-34r2-97r4.json +++ b/advisories/unreviewed/2022/09/GHSA-vp8w-34r2-97r4/GHSA-vp8w-34r2-97r4.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-668" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/09/GHSA-wcc2-hc4j-m2wc/GHSA-wcc2-hc4j-m2wc.json b/advisories/unreviewed/2022/09/GHSA-wcc2-hc4j-m2wc/GHSA-wcc2-hc4j-m2wc.json index f84c7b68bb5..caef29bb17b 100644 --- a/advisories/unreviewed/2022/09/GHSA-wcc2-hc4j-m2wc/GHSA-wcc2-hc4j-m2wc.json +++ b/advisories/unreviewed/2022/09/GHSA-wcc2-hc4j-m2wc/GHSA-wcc2-hc4j-m2wc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wcc2-hc4j-m2wc", - "modified": "2022-10-04T00:00:19Z", + "modified": "2025-05-21T15:30:25Z", "published": "2022-09-28T00:00:18Z", "aliases": [ "CVE-2021-27861" @@ -42,6 +42,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-130", "CWE-290" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/09/GHSA-x537-5w7x-8g44/GHSA-x537-5w7x-8g44.json b/advisories/unreviewed/2022/09/GHSA-x537-5w7x-8g44/GHSA-x537-5w7x-8g44.json index 8cd66bbc431..6ea2fcdb0b6 100644 --- a/advisories/unreviewed/2022/09/GHSA-x537-5w7x-8g44/GHSA-x537-5w7x-8g44.json +++ b/advisories/unreviewed/2022/09/GHSA-x537-5w7x-8g44/GHSA-x537-5w7x-8g44.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x537-5w7x-8g44", - "modified": "2022-09-30T00:00:37Z", + "modified": "2025-05-21T15:30:26Z", "published": "2022-09-29T00:00:27Z", "aliases": [ "CVE-2022-2760" diff --git a/advisories/unreviewed/2025/02/GHSA-q3rr-g46f-jgqr/GHSA-q3rr-g46f-jgqr.json b/advisories/unreviewed/2025/02/GHSA-q3rr-g46f-jgqr/GHSA-q3rr-g46f-jgqr.json index f2be92b4af1..712f9ad5df5 100644 --- a/advisories/unreviewed/2025/02/GHSA-q3rr-g46f-jgqr/GHSA-q3rr-g46f-jgqr.json +++ b/advisories/unreviewed/2025/02/GHSA-q3rr-g46f-jgqr/GHSA-q3rr-g46f-jgqr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q3rr-g46f-jgqr", - "modified": "2025-05-17T00:30:25Z", + "modified": "2025-05-21T15:30:32Z", "published": "2025-02-19T21:31:38Z", "aliases": [ "CVE-2025-0624" @@ -31,6 +31,10 @@ "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-0624" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7702" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:4422" diff --git a/advisories/unreviewed/2025/05/GHSA-26vj-q53w-3g76/GHSA-26vj-q53w-3g76.json b/advisories/unreviewed/2025/05/GHSA-26vj-q53w-3g76/GHSA-26vj-q53w-3g76.json index 4d20070fb2a..ff052fd54a6 100644 --- a/advisories/unreviewed/2025/05/GHSA-26vj-q53w-3g76/GHSA-26vj-q53w-3g76.json +++ b/advisories/unreviewed/2025/05/GHSA-26vj-q53w-3g76/GHSA-26vj-q53w-3g76.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-2mg9-59xm-chrg/GHSA-2mg9-59xm-chrg.json b/advisories/unreviewed/2025/05/GHSA-2mg9-59xm-chrg/GHSA-2mg9-59xm-chrg.json new file mode 100644 index 00000000000..8b903ddecef --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2mg9-59xm-chrg/GHSA-2mg9-59xm-chrg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2mg9-59xm-chrg", + "modified": "2025-05-21T15:30:33Z", + "published": "2025-05-21T15:30:33Z", + "aliases": [ + "CVE-2025-48413" + ], + "details": "The `/etc/passwd` and `/etc/shadow` files reveal hard-coded password hashes for the operating system \"root\" user. The credentials are shipped with the update files. There is no option for deleting or changing their passwords for an enduser. An attacker can use the credentials to log into the device. Authentication can be performed via SSH backdoor or likely via physical access (UART shell).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48413" + }, + { + "type": "WEB", + "url": "https://r.sec-consult.com/echarge" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-798" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T12:16:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2w4w-qvp3-4g7g/GHSA-2w4w-qvp3-4g7g.json b/advisories/unreviewed/2025/05/GHSA-2w4w-qvp3-4g7g/GHSA-2w4w-qvp3-4g7g.json new file mode 100644 index 00000000000..aa3a4dde208 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2w4w-qvp3-4g7g/GHSA-2w4w-qvp3-4g7g.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2w4w-qvp3-4g7g", + "modified": "2025-05-21T15:30:33Z", + "published": "2025-05-21T15:30:33Z", + "aliases": [ + "CVE-2025-48415" + ], + "details": "A USB backdoor feature can be triggered by attaching a USB drive that contains specially crafted \"salia.ini\" files. The .ini file can contain several \"commands\" that could be exploited by an attacker to export or modify the device configuration, enable an SSH backdoor  or perform other administrative actions. Ultimately, this backdoor also allows arbitrary execution of OS commands.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48415" + }, + { + "type": "WEB", + "url": "https://r.sec-consult.com/echarge" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-749" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T13:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-34x7-vxc3-qvr6/GHSA-34x7-vxc3-qvr6.json b/advisories/unreviewed/2025/05/GHSA-34x7-vxc3-qvr6/GHSA-34x7-vxc3-qvr6.json index c9ec1365df5..23e65137b3c 100644 --- a/advisories/unreviewed/2025/05/GHSA-34x7-vxc3-qvr6/GHSA-34x7-vxc3-qvr6.json +++ b/advisories/unreviewed/2025/05/GHSA-34x7-vxc3-qvr6/GHSA-34x7-vxc3-qvr6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-34x7-vxc3-qvr6", - "modified": "2025-05-20T21:30:43Z", + "modified": "2025-05-21T15:30:33Z", "published": "2025-05-20T21:30:43Z", "aliases": [ "CVE-2025-44891" ], "details": "FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the host_ip parameter in the web_snmp_v3host_add_post function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-20T21:15:23Z" diff --git a/advisories/unreviewed/2025/05/GHSA-3gf3-q286-fvmm/GHSA-3gf3-q286-fvmm.json b/advisories/unreviewed/2025/05/GHSA-3gf3-q286-fvmm/GHSA-3gf3-q286-fvmm.json new file mode 100644 index 00000000000..e2ef9975385 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3gf3-q286-fvmm/GHSA-3gf3-q286-fvmm.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3gf3-q286-fvmm", + "modified": "2025-05-21T15:30:33Z", + "published": "2025-05-21T15:30:33Z", + "aliases": [ + "CVE-2025-1420" + ], + "details": "Input provided in a field containing \"activationMessage\" in Konsola Proget is not sanitized correctly, allowing a high-privileged user to perform a Stored Cross-Site Scripting attack.\n\n\nThis issue has been fixed in 2.17.5 version of Konsola Proget (server part of the MDM suite).", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1420" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2025/05/CVE-2025-1415" + }, + { + "type": "WEB", + "url": "https://proget.pl/en/mobile-device-management" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T13:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-448c-v79p-pvxc/GHSA-448c-v79p-pvxc.json b/advisories/unreviewed/2025/05/GHSA-448c-v79p-pvxc/GHSA-448c-v79p-pvxc.json index 50cce63a39d..1e0cd1e90e6 100644 --- a/advisories/unreviewed/2025/05/GHSA-448c-v79p-pvxc/GHSA-448c-v79p-pvxc.json +++ b/advisories/unreviewed/2025/05/GHSA-448c-v79p-pvxc/GHSA-448c-v79p-pvxc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-448c-v79p-pvxc", - "modified": "2025-05-20T21:30:43Z", + "modified": "2025-05-21T15:30:32Z", "published": "2025-05-20T21:30:43Z", "aliases": [ "CVE-2025-44885" ], "details": "FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the remote_ip parameter in the web_snmpv3_remote_engineId_add_post function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-20T20:15:42Z" diff --git a/advisories/unreviewed/2025/05/GHSA-4pr6-763c-5823/GHSA-4pr6-763c-5823.json b/advisories/unreviewed/2025/05/GHSA-4pr6-763c-5823/GHSA-4pr6-763c-5823.json new file mode 100644 index 00000000000..4fc60f06b9e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4pr6-763c-5823/GHSA-4pr6-763c-5823.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4pr6-763c-5823", + "modified": "2025-05-21T15:30:33Z", + "published": "2025-05-21T15:30:33Z", + "aliases": [ + "CVE-2025-1419" + ], + "details": "Input provided in comment section of Konsola Proget is not sanitized correctly, allowing a high-privileged user to perform a Stored Cross-Site Scripting attack.\n\n\nThis issue has been fixed in 2.17.5 version of Konsola Proget (server part of the MDM suite).", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1419" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2025/05/CVE-2025-1415" + }, + { + "type": "WEB", + "url": "https://proget.pl/en/mobile-device-management" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T13:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4wqv-9447-79rg/GHSA-4wqv-9447-79rg.json b/advisories/unreviewed/2025/05/GHSA-4wqv-9447-79rg/GHSA-4wqv-9447-79rg.json index a69e147ffaf..f7d2a3e23e4 100644 --- a/advisories/unreviewed/2025/05/GHSA-4wqv-9447-79rg/GHSA-4wqv-9447-79rg.json +++ b/advisories/unreviewed/2025/05/GHSA-4wqv-9447-79rg/GHSA-4wqv-9447-79rg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4wqv-9447-79rg", - "modified": "2025-05-20T21:30:43Z", + "modified": "2025-05-21T15:30:32Z", "published": "2025-05-20T21:30:43Z", "aliases": [ "CVE-2025-44882" ], "details": "A command injection vulnerability in the component /cgi-bin/firewall.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-20T21:15:23Z" diff --git a/advisories/unreviewed/2025/05/GHSA-5998-p8h7-mvqv/GHSA-5998-p8h7-mvqv.json b/advisories/unreviewed/2025/05/GHSA-5998-p8h7-mvqv/GHSA-5998-p8h7-mvqv.json index fdedb1cb5d5..62af1cbd706 100644 --- a/advisories/unreviewed/2025/05/GHSA-5998-p8h7-mvqv/GHSA-5998-p8h7-mvqv.json +++ b/advisories/unreviewed/2025/05/GHSA-5998-p8h7-mvqv/GHSA-5998-p8h7-mvqv.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-5hhg-f58g-x5j3/GHSA-5hhg-f58g-x5j3.json b/advisories/unreviewed/2025/05/GHSA-5hhg-f58g-x5j3/GHSA-5hhg-f58g-x5j3.json index b783c263113..4ae7a050b0e 100644 --- a/advisories/unreviewed/2025/05/GHSA-5hhg-f58g-x5j3/GHSA-5hhg-f58g-x5j3.json +++ b/advisories/unreviewed/2025/05/GHSA-5hhg-f58g-x5j3/GHSA-5hhg-f58g-x5j3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5hhg-f58g-x5j3", - "modified": "2025-05-20T21:30:43Z", + "modified": "2025-05-21T15:30:33Z", "published": "2025-05-20T21:30:43Z", "aliases": [ "CVE-2025-44894" ], "details": "FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the radDftParamKey parameter in the web_radiusSrv_dftParam_post function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-20T21:15:23Z" diff --git a/advisories/unreviewed/2025/05/GHSA-76cv-j9hj-683m/GHSA-76cv-j9hj-683m.json b/advisories/unreviewed/2025/05/GHSA-76cv-j9hj-683m/GHSA-76cv-j9hj-683m.json new file mode 100644 index 00000000000..7d282d9bba2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-76cv-j9hj-683m/GHSA-76cv-j9hj-683m.json @@ -0,0 +1,60 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-76cv-j9hj-683m", + "modified": "2025-05-21T15:30:34Z", + "published": "2025-05-21T15:30:34Z", + "aliases": [ + "CVE-2025-5029" + ], + "details": "A vulnerability has been found in Kingdee Cloud Galaxy Private Cloud BBC System up to 9.0 Patch April 2025 and classified as critical. Affected by this vulnerability is the function BaseServiceFactory.getFileUploadService.deleteFileAction of the file fileUpload/deleteFileAction.jhtml of the component File Handler. The manipulation of the argument filePath leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5029" + }, + { + "type": "WEB", + "url": "https://vip.kingdee.com/knowledge/708656434111770368" + }, + { + "type": "WEB", + "url": "https://vip.kingdee.com/school/detail/713028702245944320?productLineId=1&lang=zh-CN" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309847" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309847" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.570956" + }, + { + "type": "WEB", + "url": "https://wx.mail.qq.com/s?k=nFbp0U0gSX0QVechIO" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T15:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-78rf-57vv-hcw9/GHSA-78rf-57vv-hcw9.json b/advisories/unreviewed/2025/05/GHSA-78rf-57vv-hcw9/GHSA-78rf-57vv-hcw9.json index 6fb5157b062..de489d4a98b 100644 --- a/advisories/unreviewed/2025/05/GHSA-78rf-57vv-hcw9/GHSA-78rf-57vv-hcw9.json +++ b/advisories/unreviewed/2025/05/GHSA-78rf-57vv-hcw9/GHSA-78rf-57vv-hcw9.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-897f-hr6q-h5f4/GHSA-897f-hr6q-h5f4.json b/advisories/unreviewed/2025/05/GHSA-897f-hr6q-h5f4/GHSA-897f-hr6q-h5f4.json new file mode 100644 index 00000000000..5b5ceaa5366 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-897f-hr6q-h5f4/GHSA-897f-hr6q-h5f4.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-897f-hr6q-h5f4", + "modified": "2025-05-21T15:30:33Z", + "published": "2025-05-21T15:30:33Z", + "aliases": [ + "CVE-2025-1417" + ], + "details": "In Proget MDM, a low-privileged user can access information about changes contained in backups of all devices managed by the MDM (Mobile Device Management). This information include user ids, email addresses, first names, last names and device UUIDs. The last one can be used for exploitation of CVE-2025-1416.\n\nSuccessful exploitation requires UUID of a targeted backup, which cannot be brute forced. \n\nThis issue has been fixed in 2.17.5 version of Konsola Proget (server part of the MDM suite).", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1417" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2025/05/CVE-2025-1415" + }, + { + "type": "WEB", + "url": "https://proget.pl/en/mobile-device-management" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T13:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8rcv-68x9-ffqp/GHSA-8rcv-68x9-ffqp.json b/advisories/unreviewed/2025/05/GHSA-8rcv-68x9-ffqp/GHSA-8rcv-68x9-ffqp.json index e8c9c5540ed..368a41d3b9a 100644 --- a/advisories/unreviewed/2025/05/GHSA-8rcv-68x9-ffqp/GHSA-8rcv-68x9-ffqp.json +++ b/advisories/unreviewed/2025/05/GHSA-8rcv-68x9-ffqp/GHSA-8rcv-68x9-ffqp.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-95c2-647q-689h/GHSA-95c2-647q-689h.json b/advisories/unreviewed/2025/05/GHSA-95c2-647q-689h/GHSA-95c2-647q-689h.json index d5b76e81d84..6935124702c 100644 --- a/advisories/unreviewed/2025/05/GHSA-95c2-647q-689h/GHSA-95c2-647q-689h.json +++ b/advisories/unreviewed/2025/05/GHSA-95c2-647q-689h/GHSA-95c2-647q-689h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-95c2-647q-689h", - "modified": "2025-05-20T21:30:43Z", + "modified": "2025-05-21T15:30:33Z", "published": "2025-05-20T21:30:43Z", "aliases": [ "CVE-2025-44896" ], "details": "FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the bindEditMACName parameter in the web_acl_bindEdit_post function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-20T21:15:23Z" diff --git a/advisories/unreviewed/2025/05/GHSA-9pp5-9c7g-4r83/GHSA-9pp5-9c7g-4r83.json b/advisories/unreviewed/2025/05/GHSA-9pp5-9c7g-4r83/GHSA-9pp5-9c7g-4r83.json new file mode 100644 index 00000000000..d35ed9a4b44 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9pp5-9c7g-4r83/GHSA-9pp5-9c7g-4r83.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9pp5-9c7g-4r83", + "modified": "2025-05-21T15:30:33Z", + "published": "2025-05-21T15:30:33Z", + "aliases": [ + "CVE-2025-41232" + ], + "details": "Spring Security Aspects may not correctly locate method security annotations on private methods. This can cause an authorization bypass.\n\nYour application may be affected by this if the following are true:\n\n * You are using @EnableMethodSecurity(mode=ASPECTJ) and spring-security-aspects, and\n * You have Spring Security method annotations on a private method\nIn that case, the target method may be able to be invoked without proper authorization.\n\nYou are not affected if:\n\n * You are not using @EnableMethodSecurity(mode=ASPECTJ) or spring-security-aspects, or\n * You have no Spring Security-annotated private methods", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-41232" + }, + { + "type": "WEB", + "url": "http://spring.io/security/cve-2025-41232" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-693" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T12:16:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9vf8-3h22-8c7j/GHSA-9vf8-3h22-8c7j.json b/advisories/unreviewed/2025/05/GHSA-9vf8-3h22-8c7j/GHSA-9vf8-3h22-8c7j.json index 2d40edfa91c..c7491ad1914 100644 --- a/advisories/unreviewed/2025/05/GHSA-9vf8-3h22-8c7j/GHSA-9vf8-3h22-8c7j.json +++ b/advisories/unreviewed/2025/05/GHSA-9vf8-3h22-8c7j/GHSA-9vf8-3h22-8c7j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9vf8-3h22-8c7j", - "modified": "2025-05-20T21:30:43Z", + "modified": "2025-05-21T15:30:32Z", "published": "2025-05-20T21:30:43Z", "aliases": [ "CVE-2025-44890" ], "details": "FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the host_ip parameter in the web_snmp_notifyv3_add_post function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-20T20:15:42Z" diff --git a/advisories/unreviewed/2025/05/GHSA-c2rm-m5xr-92gg/GHSA-c2rm-m5xr-92gg.json b/advisories/unreviewed/2025/05/GHSA-c2rm-m5xr-92gg/GHSA-c2rm-m5xr-92gg.json new file mode 100644 index 00000000000..433617a4050 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c2rm-m5xr-92gg/GHSA-c2rm-m5xr-92gg.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2rm-m5xr-92gg", + "modified": "2025-05-21T15:30:34Z", + "published": "2025-05-21T15:30:34Z", + "aliases": [ + "CVE-2024-42922" + ], + "details": "AAPanel v7.0.7 was discovered to contain an OS command injection vulnerability.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42922" + }, + { + "type": "WEB", + "url": "https://gist.github.com/mstfsec/c4c05ddfb1cf8779422ff780587723c8" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T14:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c3j4-92qv-mh62/GHSA-c3j4-92qv-mh62.json b/advisories/unreviewed/2025/05/GHSA-c3j4-92qv-mh62/GHSA-c3j4-92qv-mh62.json index 29b3ea15b55..652cf9c7974 100644 --- a/advisories/unreviewed/2025/05/GHSA-c3j4-92qv-mh62/GHSA-c3j4-92qv-mh62.json +++ b/advisories/unreviewed/2025/05/GHSA-c3j4-92qv-mh62/GHSA-c3j4-92qv-mh62.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c3j4-92qv-mh62", - "modified": "2025-05-20T21:30:43Z", + "modified": "2025-05-21T15:30:32Z", "published": "2025-05-20T21:30:43Z", "aliases": [ "CVE-2025-44880" ], "details": "A command injection vulnerability in the component /cgi-bin/adm.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-20T21:15:23Z" diff --git a/advisories/unreviewed/2025/05/GHSA-c4c6-xhvm-jcxg/GHSA-c4c6-xhvm-jcxg.json b/advisories/unreviewed/2025/05/GHSA-c4c6-xhvm-jcxg/GHSA-c4c6-xhvm-jcxg.json index a70f89de041..bb2d6012bb8 100644 --- a/advisories/unreviewed/2025/05/GHSA-c4c6-xhvm-jcxg/GHSA-c4c6-xhvm-jcxg.json +++ b/advisories/unreviewed/2025/05/GHSA-c4c6-xhvm-jcxg/GHSA-c4c6-xhvm-jcxg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c4c6-xhvm-jcxg", - "modified": "2025-05-20T21:30:42Z", + "modified": "2025-05-21T15:30:32Z", "published": "2025-05-20T21:30:42Z", "aliases": [ "CVE-2025-44884" ], "details": "FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the web_sys_infoContact_post function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-20T20:15:41Z" diff --git a/advisories/unreviewed/2025/05/GHSA-ch98-wcrf-h5pj/GHSA-ch98-wcrf-h5pj.json b/advisories/unreviewed/2025/05/GHSA-ch98-wcrf-h5pj/GHSA-ch98-wcrf-h5pj.json index 4d1a97865b5..cacba3c4e0a 100644 --- a/advisories/unreviewed/2025/05/GHSA-ch98-wcrf-h5pj/GHSA-ch98-wcrf-h5pj.json +++ b/advisories/unreviewed/2025/05/GHSA-ch98-wcrf-h5pj/GHSA-ch98-wcrf-h5pj.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-f4x9-c974-c97m/GHSA-f4x9-c974-c97m.json b/advisories/unreviewed/2025/05/GHSA-f4x9-c974-c97m/GHSA-f4x9-c974-c97m.json index 06b53d8f7f5..87cd41f0964 100644 --- a/advisories/unreviewed/2025/05/GHSA-f4x9-c974-c97m/GHSA-f4x9-c974-c97m.json +++ b/advisories/unreviewed/2025/05/GHSA-f4x9-c974-c97m/GHSA-f4x9-c974-c97m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f4x9-c974-c97m", - "modified": "2025-05-20T21:30:43Z", + "modified": "2025-05-21T15:30:33Z", "published": "2025-05-20T21:30:43Z", "aliases": [ "CVE-2025-44883" ], "details": "FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the tacIp parameter in the web_tacplus_serverEdit_post function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-20T21:15:23Z" diff --git a/advisories/unreviewed/2025/05/GHSA-fr77-hc38-f46p/GHSA-fr77-hc38-f46p.json b/advisories/unreviewed/2025/05/GHSA-fr77-hc38-f46p/GHSA-fr77-hc38-f46p.json index f967e64c935..65b31046e1a 100644 --- a/advisories/unreviewed/2025/05/GHSA-fr77-hc38-f46p/GHSA-fr77-hc38-f46p.json +++ b/advisories/unreviewed/2025/05/GHSA-fr77-hc38-f46p/GHSA-fr77-hc38-f46p.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-g45p-2vh4-m46h/GHSA-g45p-2vh4-m46h.json b/advisories/unreviewed/2025/05/GHSA-g45p-2vh4-m46h/GHSA-g45p-2vh4-m46h.json new file mode 100644 index 00000000000..e1fc2afb4d2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g45p-2vh4-m46h/GHSA-g45p-2vh4-m46h.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g45p-2vh4-m46h", + "modified": "2025-05-21T15:30:33Z", + "published": "2025-05-21T15:30:33Z", + "aliases": [ + "CVE-2025-1421" + ], + "details": "Data provided in a request performed to the server while activating a new device are put in a database. Other high privileged users might download this data as a CSV file and corrupt their PC by opening it in a tool such as Microsoft Excel. The attacker could gain remote access to the user's PC.\n\n\nThis issue has been fixed in 2.17.5 version of Konsola Proget (server part of the MDM suite).", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1421" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2025/05/CVE-2025-1415" + }, + { + "type": "WEB", + "url": "https://proget.pl/en/mobile-device-management" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1236" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T13:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g83m-h37w-pr8h/GHSA-g83m-h37w-pr8h.json b/advisories/unreviewed/2025/05/GHSA-g83m-h37w-pr8h/GHSA-g83m-h37w-pr8h.json index 02e3bb5c1ee..e7fee16118d 100644 --- a/advisories/unreviewed/2025/05/GHSA-g83m-h37w-pr8h/GHSA-g83m-h37w-pr8h.json +++ b/advisories/unreviewed/2025/05/GHSA-g83m-h37w-pr8h/GHSA-g83m-h37w-pr8h.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-434" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-gqgx-hgvf-f75f/GHSA-gqgx-hgvf-f75f.json b/advisories/unreviewed/2025/05/GHSA-gqgx-hgvf-f75f/GHSA-gqgx-hgvf-f75f.json new file mode 100644 index 00000000000..7d0f3139f20 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gqgx-hgvf-f75f/GHSA-gqgx-hgvf-f75f.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqgx-hgvf-f75f", + "modified": "2025-05-21T15:30:33Z", + "published": "2025-05-21T15:30:33Z", + "aliases": [ + "CVE-2025-40775" + ], + "details": "When an incoming DNS protocol message includes a Transaction Signature (TSIG), BIND always checks it. If the TSIG contains an invalid value in the algorithm field, BIND immediately aborts with an assertion failure.\nThis issue affects BIND 9 versions 9.20.0 through 9.20.8 and 9.21.0 through 9.21.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40775" + }, + { + "type": "WEB", + "url": "https://kb.isc.org/docs/cve-2025-40775" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/05/21/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-232" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T13:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-j78m-3c5f-wq4g/GHSA-j78m-3c5f-wq4g.json b/advisories/unreviewed/2025/05/GHSA-j78m-3c5f-wq4g/GHSA-j78m-3c5f-wq4g.json index 3359afbce26..e03f43c64d9 100644 --- a/advisories/unreviewed/2025/05/GHSA-j78m-3c5f-wq4g/GHSA-j78m-3c5f-wq4g.json +++ b/advisories/unreviewed/2025/05/GHSA-j78m-3c5f-wq4g/GHSA-j78m-3c5f-wq4g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j78m-3c5f-wq4g", - "modified": "2025-05-20T21:30:43Z", + "modified": "2025-05-21T15:30:33Z", "published": "2025-05-20T21:30:43Z", "aliases": [ "CVE-2025-44898" ], "details": "FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the theauthName parameter in the web_aaa_loginAuthlistEdit function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-20T21:15:23Z" diff --git a/advisories/unreviewed/2025/05/GHSA-mf3r-gv2f-r4wr/GHSA-mf3r-gv2f-r4wr.json b/advisories/unreviewed/2025/05/GHSA-mf3r-gv2f-r4wr/GHSA-mf3r-gv2f-r4wr.json new file mode 100644 index 00000000000..8f8fd54a00b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mf3r-gv2f-r4wr/GHSA-mf3r-gv2f-r4wr.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mf3r-gv2f-r4wr", + "modified": "2025-05-21T15:30:33Z", + "published": "2025-05-21T15:30:33Z", + "aliases": [ + "CVE-2025-1416" + ], + "details": "In Proget MDM, a low-privileged user can retrieve passwords for managed devices and subsequently use functionalities restricted by the MDM (Mobile Device Management). For it to happen, they must know the UUIDs of targetted devices, which might be obtained by exploiting CVE-2025-1415 or CVE-2025-1417.\n\nThis issue has been fixed in 2.17.5 version of Konsola Proget (server part of the MDM suite).", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1416" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2025/05/CVE-2025-1415" + }, + { + "type": "WEB", + "url": "https://proget.pl/en/mobile-device-management" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T13:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mj8x-rmcg-j8qw/GHSA-mj8x-rmcg-j8qw.json b/advisories/unreviewed/2025/05/GHSA-mj8x-rmcg-j8qw/GHSA-mj8x-rmcg-j8qw.json new file mode 100644 index 00000000000..2cdd1157cee --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mj8x-rmcg-j8qw/GHSA-mj8x-rmcg-j8qw.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mj8x-rmcg-j8qw", + "modified": "2025-05-21T15:30:33Z", + "published": "2025-05-21T15:30:33Z", + "aliases": [ + "CVE-2025-1418" + ], + "details": "A low-privileged user can access information about profiles created in Proget MDM (Mobile Device Management), which contain details about allowed/prohibited functions. The profiles do not reveal any sensitive information (including their usage in connected devices).   \n\n\nThis issue has been fixed in 2.17.5 version of Konsola Proget (server part of the MDM suite).", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1418" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2025/05/CVE-2025-1415" + }, + { + "type": "WEB", + "url": "https://proget.pl/en/mobile-device-management" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T13:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-phcp-455w-63rg/GHSA-phcp-455w-63rg.json b/advisories/unreviewed/2025/05/GHSA-phcp-455w-63rg/GHSA-phcp-455w-63rg.json new file mode 100644 index 00000000000..17e1439ae52 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-phcp-455w-63rg/GHSA-phcp-455w-63rg.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phcp-455w-63rg", + "modified": "2025-05-21T15:30:34Z", + "published": "2025-05-21T15:30:34Z", + "aliases": [ + "CVE-2024-56429" + ], + "details": "itech iLabClient 3.7.1 relies on the hard-coded YngAYdgAE/kKZYu2F2wm6w== key (found in iLabClient.jar) for local users to read or write to the database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56429" + }, + { + "type": "WEB", + "url": "https://github.com/lisa-2905/CVE-2024-56429" + }, + { + "type": "WEB", + "url": "https://itech-gmbh.de/produkte" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-321" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T14:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qmj3-7hgm-pxgp/GHSA-qmj3-7hgm-pxgp.json b/advisories/unreviewed/2025/05/GHSA-qmj3-7hgm-pxgp/GHSA-qmj3-7hgm-pxgp.json new file mode 100644 index 00000000000..2fb937fadcd --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qmj3-7hgm-pxgp/GHSA-qmj3-7hgm-pxgp.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qmj3-7hgm-pxgp", + "modified": "2025-05-21T15:30:34Z", + "published": "2025-05-21T15:30:34Z", + "aliases": [ + "CVE-2025-44895" + ], + "details": "FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ipv4Aclkey parameter in the web_acl_ipv4BasedAceAdd function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44895" + }, + { + "type": "WEB", + "url": "https://lafdrew.github.io/2025/04/18/web-acl-ipv4BasedAceAdd-post-ipv4Acl-StackOverflow" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T14:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rcv8-vxjp-vqcw/GHSA-rcv8-vxjp-vqcw.json b/advisories/unreviewed/2025/05/GHSA-rcv8-vxjp-vqcw/GHSA-rcv8-vxjp-vqcw.json new file mode 100644 index 00000000000..dd5821a80f6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rcv8-vxjp-vqcw/GHSA-rcv8-vxjp-vqcw.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rcv8-vxjp-vqcw", + "modified": "2025-05-21T15:30:33Z", + "published": "2025-05-21T15:30:33Z", + "aliases": [ + "CVE-2025-48416" + ], + "details": "An OpenSSH daemon listens on TCP port 22. There is a hard-coded entry in the \"/etc/shadow\" file in the firmware image for the \"root\" user. However, in the default SSH configuration the \"PermitRootLogin\" is disabled, preventing the root user from logging in via SSH. This configuration can be bypassed/changed by an attacker through multiple paths though.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48416" + }, + { + "type": "WEB", + "url": "https://r.sec-consult.com/echarge" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-912" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T13:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rcw6-7x98-m9g9/GHSA-rcw6-7x98-m9g9.json b/advisories/unreviewed/2025/05/GHSA-rcw6-7x98-m9g9/GHSA-rcw6-7x98-m9g9.json index 12a2e6512da..12f21bcaeaa 100644 --- a/advisories/unreviewed/2025/05/GHSA-rcw6-7x98-m9g9/GHSA-rcw6-7x98-m9g9.json +++ b/advisories/unreviewed/2025/05/GHSA-rcw6-7x98-m9g9/GHSA-rcw6-7x98-m9g9.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-321", "CWE-798" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2025/05/GHSA-v3q8-hfj4-rq9j/GHSA-v3q8-hfj4-rq9j.json b/advisories/unreviewed/2025/05/GHSA-v3q8-hfj4-rq9j/GHSA-v3q8-hfj4-rq9j.json index b9ac8b826bd..2c5a0445642 100644 --- a/advisories/unreviewed/2025/05/GHSA-v3q8-hfj4-rq9j/GHSA-v3q8-hfj4-rq9j.json +++ b/advisories/unreviewed/2025/05/GHSA-v3q8-hfj4-rq9j/GHSA-v3q8-hfj4-rq9j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v3q8-hfj4-rq9j", - "modified": "2025-05-20T21:30:43Z", + "modified": "2025-05-21T15:30:32Z", "published": "2025-05-20T21:30:43Z", "aliases": [ "CVE-2025-44881" ], "details": "A command injection vulnerability in the component /cgi-bin/qos.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-20T20:15:41Z" diff --git a/advisories/unreviewed/2025/05/GHSA-v7fg-84w6-2g4w/GHSA-v7fg-84w6-2g4w.json b/advisories/unreviewed/2025/05/GHSA-v7fg-84w6-2g4w/GHSA-v7fg-84w6-2g4w.json index 3dfb5851b5b..4a19263dfc7 100644 --- a/advisories/unreviewed/2025/05/GHSA-v7fg-84w6-2g4w/GHSA-v7fg-84w6-2g4w.json +++ b/advisories/unreviewed/2025/05/GHSA-v7fg-84w6-2g4w/GHSA-v7fg-84w6-2g4w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v7fg-84w6-2g4w", - "modified": "2025-05-10T12:30:27Z", + "modified": "2025-05-21T15:30:31Z", "published": "2025-05-10T12:30:27Z", "aliases": [ "CVE-2025-3878" diff --git a/advisories/unreviewed/2025/05/GHSA-vj3r-c4pc-hrp4/GHSA-vj3r-c4pc-hrp4.json b/advisories/unreviewed/2025/05/GHSA-vj3r-c4pc-hrp4/GHSA-vj3r-c4pc-hrp4.json index 95311291f59..b39f1ddf137 100644 --- a/advisories/unreviewed/2025/05/GHSA-vj3r-c4pc-hrp4/GHSA-vj3r-c4pc-hrp4.json +++ b/advisories/unreviewed/2025/05/GHSA-vj3r-c4pc-hrp4/GHSA-vj3r-c4pc-hrp4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vj3r-c4pc-hrp4", - "modified": "2025-05-20T21:30:43Z", + "modified": "2025-05-21T15:30:32Z", "published": "2025-05-20T21:30:43Z", "aliases": [ "CVE-2025-44888" ], "details": "FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the stp_conf_name parameter in the web_stp_globalSetting_post function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-20T20:15:42Z" diff --git a/advisories/unreviewed/2025/05/GHSA-w4q6-qj6g-h25w/GHSA-w4q6-qj6g-h25w.json b/advisories/unreviewed/2025/05/GHSA-w4q6-qj6g-h25w/GHSA-w4q6-qj6g-h25w.json index c3c9b43bdc6..dd1943e7001 100644 --- a/advisories/unreviewed/2025/05/GHSA-w4q6-qj6g-h25w/GHSA-w4q6-qj6g-h25w.json +++ b/advisories/unreviewed/2025/05/GHSA-w4q6-qj6g-h25w/GHSA-w4q6-qj6g-h25w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w4q6-qj6g-h25w", - "modified": "2025-05-20T21:30:43Z", + "modified": "2025-05-21T15:30:33Z", "published": "2025-05-20T21:30:43Z", "aliases": [ "CVE-2025-44897" ], "details": "FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the bytftp_srvip parameter in the web_tool_upgradeManager_post function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-20T21:15:23Z" diff --git a/advisories/unreviewed/2025/05/GHSA-wxj8-443r-hmmr/GHSA-wxj8-443r-hmmr.json b/advisories/unreviewed/2025/05/GHSA-wxj8-443r-hmmr/GHSA-wxj8-443r-hmmr.json new file mode 100644 index 00000000000..d93f244a1a2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wxj8-443r-hmmr/GHSA-wxj8-443r-hmmr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wxj8-443r-hmmr", + "modified": "2025-05-21T15:30:34Z", + "published": "2025-05-21T15:30:34Z", + "aliases": [ + "CVE-2025-48417" + ], + "details": "The certificate and private key used for providing transport layer security for connections to the web interface (TCP port 443) is hard-coded in the firmware and are shipped with the update files. An attacker can use the private key to perform man-in-the-middle attacks against users of the admin interface. The files are located in /etc/ssl (e.g. salia.local.crt, salia.local.key and salia.local.pem). There is no option to upload/configure custom TLS certificates.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48417" + }, + { + "type": "WEB", + "url": "https://r.sec-consult.com/echarge" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-321" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T13:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-x9pw-qp8j-96f9/GHSA-x9pw-qp8j-96f9.json b/advisories/unreviewed/2025/05/GHSA-x9pw-qp8j-96f9/GHSA-x9pw-qp8j-96f9.json index 14cde307a68..a1da5069a22 100644 --- a/advisories/unreviewed/2025/05/GHSA-x9pw-qp8j-96f9/GHSA-x9pw-qp8j-96f9.json +++ b/advisories/unreviewed/2025/05/GHSA-x9pw-qp8j-96f9/GHSA-x9pw-qp8j-96f9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x9pw-qp8j-96f9", - "modified": "2025-05-20T21:30:42Z", + "modified": "2025-05-21T15:30:32Z", "published": "2025-05-20T21:30:42Z", "aliases": [ "CVE-2025-44893" ], "details": "FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ruleNamekey parameter in the web_acl_mgmt_Rules_Apply_post function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-20T20:15:42Z" diff --git a/advisories/unreviewed/2025/05/GHSA-xfj4-w5m6-x8f6/GHSA-xfj4-w5m6-x8f6.json b/advisories/unreviewed/2025/05/GHSA-xfj4-w5m6-x8f6/GHSA-xfj4-w5m6-x8f6.json index 29e7903953e..8692a5a60b2 100644 --- a/advisories/unreviewed/2025/05/GHSA-xfj4-w5m6-x8f6/GHSA-xfj4-w5m6-x8f6.json +++ b/advisories/unreviewed/2025/05/GHSA-xfj4-w5m6-x8f6/GHSA-xfj4-w5m6-x8f6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xfj4-w5m6-x8f6", - "modified": "2025-05-20T21:30:43Z", + "modified": "2025-05-21T15:30:32Z", "published": "2025-05-20T21:30:42Z", "aliases": [ "CVE-2025-44886" ], "details": "FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the byruleEditName parameter in the web_acl_mgmt_Rules_Edit_postcontains function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-20T20:15:42Z" diff --git a/advisories/unreviewed/2025/05/GHSA-xj6f-gh33-gmgg/GHSA-xj6f-gh33-gmgg.json b/advisories/unreviewed/2025/05/GHSA-xj6f-gh33-gmgg/GHSA-xj6f-gh33-gmgg.json index 2ca11218a2e..4523cb09046 100644 --- a/advisories/unreviewed/2025/05/GHSA-xj6f-gh33-gmgg/GHSA-xj6f-gh33-gmgg.json +++ b/advisories/unreviewed/2025/05/GHSA-xj6f-gh33-gmgg/GHSA-xj6f-gh33-gmgg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xj6f-gh33-gmgg", - "modified": "2025-05-20T21:30:42Z", + "modified": "2025-05-21T15:30:32Z", "published": "2025-05-20T21:30:42Z", "aliases": [ "CVE-2025-44887" ], "details": "FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the radIpkey parameter in the web_radiusSrv_post function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-20T20:15:42Z" diff --git a/advisories/unreviewed/2025/05/GHSA-xwrw-9qxw-gm75/GHSA-xwrw-9qxw-gm75.json b/advisories/unreviewed/2025/05/GHSA-xwrw-9qxw-gm75/GHSA-xwrw-9qxw-gm75.json new file mode 100644 index 00000000000..b1e68219de3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xwrw-9qxw-gm75/GHSA-xwrw-9qxw-gm75.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xwrw-9qxw-gm75", + "modified": "2025-05-21T15:30:34Z", + "published": "2025-05-21T15:30:34Z", + "aliases": [ + "CVE-2025-44892" + ], + "details": "FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ownekey parameter in the web_rmon_alarm_post_rmon_alarm function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44892" + }, + { + "type": "WEB", + "url": "https://lafdrew.github.io/2025/04/20/web-rmon-alarm-post-rmon-alarm-owne" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T14:15:30Z" + } +} \ No newline at end of file