From 688dbd912240aa210e6ee42f613a360c0db1d443 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 5 Jun 2025 18:32:13 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-fg7j-3vp4-4qpg.json | 2 +- .../GHSA-3jx4-3grj-xm5w.json | 8 ++- .../GHSA-pcmw-6hxc-hqmx.json | 4 +- .../GHSA-qfhm-jrhg-gr45.json | 2 +- .../GHSA-93h4-qrq6-q2vm.json | 6 +- .../GHSA-vh6j-6rmm-669j.json | 2 +- .../GHSA-c8q2-82x8-w4xj.json | 3 +- .../GHSA-fphv-qpcr-r7v5.json | 5 +- .../GHSA-7c5f-5rc5-g5mc.json | 2 +- .../GHSA-v5rj-qw4c-6pc2.json | 2 +- .../GHSA-wg7g-4jwx-j6rf.json | 2 +- .../GHSA-25hw-f438-3m39.json | 3 +- .../GHSA-36g7-qjqw-vc3v.json | 3 +- .../GHSA-3m9x-xqwx-4x9c.json | 3 +- .../GHSA-4hc5-ch4c-3rjx.json | 3 +- .../GHSA-q5hr-gmh6-grq2.json | 3 +- .../GHSA-24q6-4w37-557f.json | 56 +++++++++++++++++++ .../GHSA-6h2g-7w8f-c35g.json | 56 +++++++++++++++++++ .../GHSA-84jw-rq34-ghwg.json | 52 +++++++++++++++++ .../GHSA-8849-vpvc-g9wp.json | 36 ++++++++++++ .../GHSA-c7r5-764x-hfqw.json | 52 +++++++++++++++++ .../GHSA-cvg9-q978-4569.json | 6 +- .../GHSA-fqr7-x5vp-p2wq.json | 56 +++++++++++++++++++ .../GHSA-vhq3-h89q-3rqx.json | 56 +++++++++++++++++++ .../GHSA-vmfp-2wcq-pwmg.json | 56 +++++++++++++++++++ .../GHSA-w22q-qpw4-g686.json | 36 ++++++++++++ 26 files changed, 494 insertions(+), 21 deletions(-) create mode 100644 advisories/unreviewed/2025/06/GHSA-24q6-4w37-557f/GHSA-24q6-4w37-557f.json create mode 100644 advisories/unreviewed/2025/06/GHSA-6h2g-7w8f-c35g/GHSA-6h2g-7w8f-c35g.json create mode 100644 advisories/unreviewed/2025/06/GHSA-84jw-rq34-ghwg/GHSA-84jw-rq34-ghwg.json create mode 100644 advisories/unreviewed/2025/06/GHSA-8849-vpvc-g9wp/GHSA-8849-vpvc-g9wp.json create mode 100644 advisories/unreviewed/2025/06/GHSA-c7r5-764x-hfqw/GHSA-c7r5-764x-hfqw.json create mode 100644 advisories/unreviewed/2025/06/GHSA-fqr7-x5vp-p2wq/GHSA-fqr7-x5vp-p2wq.json create mode 100644 advisories/unreviewed/2025/06/GHSA-vhq3-h89q-3rqx/GHSA-vhq3-h89q-3rqx.json create mode 100644 advisories/unreviewed/2025/06/GHSA-vmfp-2wcq-pwmg/GHSA-vmfp-2wcq-pwmg.json create mode 100644 advisories/unreviewed/2025/06/GHSA-w22q-qpw4-g686/GHSA-w22q-qpw4-g686.json diff --git a/advisories/unreviewed/2024/01/GHSA-fg7j-3vp4-4qpg/GHSA-fg7j-3vp4-4qpg.json b/advisories/unreviewed/2024/01/GHSA-fg7j-3vp4-4qpg/GHSA-fg7j-3vp4-4qpg.json index 2474c3f7645..d01d9e4bfd4 100644 --- a/advisories/unreviewed/2024/01/GHSA-fg7j-3vp4-4qpg/GHSA-fg7j-3vp4-4qpg.json +++ b/advisories/unreviewed/2024/01/GHSA-fg7j-3vp4-4qpg/GHSA-fg7j-3vp4-4qpg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fg7j-3vp4-4qpg", - "modified": "2024-01-31T00:30:17Z", + "modified": "2025-06-05T18:30:33Z", "published": "2024-01-24T03:31:25Z", "aliases": [ "CVE-2024-22380" diff --git a/advisories/unreviewed/2024/02/GHSA-3jx4-3grj-xm5w/GHSA-3jx4-3grj-xm5w.json b/advisories/unreviewed/2024/02/GHSA-3jx4-3grj-xm5w/GHSA-3jx4-3grj-xm5w.json index 3724de29d0e..878dce75670 100644 --- a/advisories/unreviewed/2024/02/GHSA-3jx4-3grj-xm5w/GHSA-3jx4-3grj-xm5w.json +++ b/advisories/unreviewed/2024/02/GHSA-3jx4-3grj-xm5w/GHSA-3jx4-3grj-xm5w.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-3jx4-3grj-xm5w", - "modified": "2024-02-14T21:30:32Z", + "modified": "2025-06-05T18:30:34Z", "published": "2024-02-07T03:30:32Z", "aliases": [ "CVE-2024-22021" ], - "details": "Vulnerability CVE-2024-22021 allows a Veeam Recovery Orchestrator user with a low privileged role (Plan Author) to retrieve plans from a Scope other than the one they are assigned to. \n", + "details": "Vulnerability CVE-2024-22021 allows a Veeam Recovery Orchestrator user with a low privileged role (Plan Author) to retrieve plans from a Scope other than the one they are assigned to.", "severity": [ { "type": "CVSS_V3", @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-285" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-pcmw-6hxc-hqmx/GHSA-pcmw-6hxc-hqmx.json b/advisories/unreviewed/2024/02/GHSA-pcmw-6hxc-hqmx/GHSA-pcmw-6hxc-hqmx.json index e7a13f4417e..4dda378b60a 100644 --- a/advisories/unreviewed/2024/02/GHSA-pcmw-6hxc-hqmx/GHSA-pcmw-6hxc-hqmx.json +++ b/advisories/unreviewed/2024/02/GHSA-pcmw-6hxc-hqmx/GHSA-pcmw-6hxc-hqmx.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-664" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-qfhm-jrhg-gr45/GHSA-qfhm-jrhg-gr45.json b/advisories/unreviewed/2024/02/GHSA-qfhm-jrhg-gr45/GHSA-qfhm-jrhg-gr45.json index 5e515880905..e4df1335f88 100644 --- a/advisories/unreviewed/2024/02/GHSA-qfhm-jrhg-gr45/GHSA-qfhm-jrhg-gr45.json +++ b/advisories/unreviewed/2024/02/GHSA-qfhm-jrhg-gr45/GHSA-qfhm-jrhg-gr45.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qfhm-jrhg-gr45", - "modified": "2024-02-09T21:30:57Z", + "modified": "2025-06-05T18:30:34Z", "published": "2024-02-02T18:30:32Z", "aliases": [ "CVE-2024-22108" diff --git a/advisories/unreviewed/2024/06/GHSA-93h4-qrq6-q2vm/GHSA-93h4-qrq6-q2vm.json b/advisories/unreviewed/2024/06/GHSA-93h4-qrq6-q2vm/GHSA-93h4-qrq6-q2vm.json index 770b5eca255..308d2cb6988 100644 --- a/advisories/unreviewed/2024/06/GHSA-93h4-qrq6-q2vm/GHSA-93h4-qrq6-q2vm.json +++ b/advisories/unreviewed/2024/06/GHSA-93h4-qrq6-q2vm/GHSA-93h4-qrq6-q2vm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-93h4-qrq6-q2vm", - "modified": "2024-06-12T03:31:15Z", + "modified": "2025-06-05T18:30:34Z", "published": "2024-06-12T03:31:15Z", "aliases": [ "CVE-2024-4892" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/08/GHSA-vh6j-6rmm-669j/GHSA-vh6j-6rmm-669j.json b/advisories/unreviewed/2024/08/GHSA-vh6j-6rmm-669j/GHSA-vh6j-6rmm-669j.json index b0ff716ef28..87b2e1c549f 100644 --- a/advisories/unreviewed/2024/08/GHSA-vh6j-6rmm-669j/GHSA-vh6j-6rmm-669j.json +++ b/advisories/unreviewed/2024/08/GHSA-vh6j-6rmm-669j/GHSA-vh6j-6rmm-669j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vh6j-6rmm-669j", - "modified": "2024-08-02T12:31:43Z", + "modified": "2025-06-05T18:30:34Z", "published": "2024-08-02T12:31:43Z", "aliases": [ "CVE-2024-6704" diff --git a/advisories/unreviewed/2024/10/GHSA-c8q2-82x8-w4xj/GHSA-c8q2-82x8-w4xj.json b/advisories/unreviewed/2024/10/GHSA-c8q2-82x8-w4xj/GHSA-c8q2-82x8-w4xj.json index ad6772a7bb2..b43f88a5397 100644 --- a/advisories/unreviewed/2024/10/GHSA-c8q2-82x8-w4xj/GHSA-c8q2-82x8-w4xj.json +++ b/advisories/unreviewed/2024/10/GHSA-c8q2-82x8-w4xj/GHSA-c8q2-82x8-w4xj.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-75" + "CWE-75", + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-fphv-qpcr-r7v5/GHSA-fphv-qpcr-r7v5.json b/advisories/unreviewed/2024/10/GHSA-fphv-qpcr-r7v5/GHSA-fphv-qpcr-r7v5.json index 2e73ac41599..8e9b1542d56 100644 --- a/advisories/unreviewed/2024/10/GHSA-fphv-qpcr-r7v5/GHSA-fphv-qpcr-r7v5.json +++ b/advisories/unreviewed/2024/10/GHSA-fphv-qpcr-r7v5/GHSA-fphv-qpcr-r7v5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fphv-qpcr-r7v5", - "modified": "2024-10-24T09:31:00Z", + "modified": "2025-06-05T18:30:34Z", "published": "2024-10-24T09:31:00Z", "aliases": [ "CVE-2024-9531" @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-285" + "CWE-285", + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-7c5f-5rc5-g5mc/GHSA-7c5f-5rc5-g5mc.json b/advisories/unreviewed/2024/12/GHSA-7c5f-5rc5-g5mc/GHSA-7c5f-5rc5-g5mc.json index 68cf2235ba5..581c028daee 100644 --- a/advisories/unreviewed/2024/12/GHSA-7c5f-5rc5-g5mc/GHSA-7c5f-5rc5-g5mc.json +++ b/advisories/unreviewed/2024/12/GHSA-7c5f-5rc5-g5mc/GHSA-7c5f-5rc5-g5mc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7c5f-5rc5-g5mc", - "modified": "2024-12-03T09:31:06Z", + "modified": "2025-06-05T18:30:35Z", "published": "2024-12-03T09:31:06Z", "aliases": [ "CVE-2024-11898" diff --git a/advisories/unreviewed/2024/12/GHSA-v5rj-qw4c-6pc2/GHSA-v5rj-qw4c-6pc2.json b/advisories/unreviewed/2024/12/GHSA-v5rj-qw4c-6pc2/GHSA-v5rj-qw4c-6pc2.json index 0017a8aedc8..d22ca258314 100644 --- a/advisories/unreviewed/2024/12/GHSA-v5rj-qw4c-6pc2/GHSA-v5rj-qw4c-6pc2.json +++ b/advisories/unreviewed/2024/12/GHSA-v5rj-qw4c-6pc2/GHSA-v5rj-qw4c-6pc2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v5rj-qw4c-6pc2", - "modified": "2024-12-04T06:31:01Z", + "modified": "2025-06-05T18:30:35Z", "published": "2024-12-04T06:31:01Z", "aliases": [ "CVE-2024-10885" diff --git a/advisories/unreviewed/2025/01/GHSA-wg7g-4jwx-j6rf/GHSA-wg7g-4jwx-j6rf.json b/advisories/unreviewed/2025/01/GHSA-wg7g-4jwx-j6rf/GHSA-wg7g-4jwx-j6rf.json index ba92b19a1d3..8649dd3dc01 100644 --- a/advisories/unreviewed/2025/01/GHSA-wg7g-4jwx-j6rf/GHSA-wg7g-4jwx-j6rf.json +++ b/advisories/unreviewed/2025/01/GHSA-wg7g-4jwx-j6rf/GHSA-wg7g-4jwx-j6rf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wg7g-4jwx-j6rf", - "modified": "2025-01-07T09:30:45Z", + "modified": "2025-06-05T18:30:39Z", "published": "2025-01-07T09:30:45Z", "aliases": [ "CVE-2024-11282" diff --git a/advisories/unreviewed/2025/05/GHSA-25hw-f438-3m39/GHSA-25hw-f438-3m39.json b/advisories/unreviewed/2025/05/GHSA-25hw-f438-3m39/GHSA-25hw-f438-3m39.json index 2a136be10ef..91a94dc8ffe 100644 --- a/advisories/unreviewed/2025/05/GHSA-25hw-f438-3m39/GHSA-25hw-f438-3m39.json +++ b/advisories/unreviewed/2025/05/GHSA-25hw-f438-3m39/GHSA-25hw-f438-3m39.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-36g7-qjqw-vc3v/GHSA-36g7-qjqw-vc3v.json b/advisories/unreviewed/2025/05/GHSA-36g7-qjqw-vc3v/GHSA-36g7-qjqw-vc3v.json index 3d313471c27..ab223f0c68a 100644 --- a/advisories/unreviewed/2025/05/GHSA-36g7-qjqw-vc3v/GHSA-36g7-qjqw-vc3v.json +++ b/advisories/unreviewed/2025/05/GHSA-36g7-qjqw-vc3v/GHSA-36g7-qjqw-vc3v.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-3m9x-xqwx-4x9c/GHSA-3m9x-xqwx-4x9c.json b/advisories/unreviewed/2025/05/GHSA-3m9x-xqwx-4x9c/GHSA-3m9x-xqwx-4x9c.json index eb92ed2ec53..53374a714e9 100644 --- a/advisories/unreviewed/2025/05/GHSA-3m9x-xqwx-4x9c/GHSA-3m9x-xqwx-4x9c.json +++ b/advisories/unreviewed/2025/05/GHSA-3m9x-xqwx-4x9c/GHSA-3m9x-xqwx-4x9c.json @@ -50,7 +50,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-4hc5-ch4c-3rjx/GHSA-4hc5-ch4c-3rjx.json b/advisories/unreviewed/2025/05/GHSA-4hc5-ch4c-3rjx/GHSA-4hc5-ch4c-3rjx.json index 6b234789a5a..9cfd2dabab4 100644 --- a/advisories/unreviewed/2025/05/GHSA-4hc5-ch4c-3rjx/GHSA-4hc5-ch4c-3rjx.json +++ b/advisories/unreviewed/2025/05/GHSA-4hc5-ch4c-3rjx/GHSA-4hc5-ch4c-3rjx.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-q5hr-gmh6-grq2/GHSA-q5hr-gmh6-grq2.json b/advisories/unreviewed/2025/05/GHSA-q5hr-gmh6-grq2/GHSA-q5hr-gmh6-grq2.json index fa5c95ebdac..7a15a606664 100644 --- a/advisories/unreviewed/2025/05/GHSA-q5hr-gmh6-grq2/GHSA-q5hr-gmh6-grq2.json +++ b/advisories/unreviewed/2025/05/GHSA-q5hr-gmh6-grq2/GHSA-q5hr-gmh6-grq2.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/06/GHSA-24q6-4w37-557f/GHSA-24q6-4w37-557f.json b/advisories/unreviewed/2025/06/GHSA-24q6-4w37-557f/GHSA-24q6-4w37-557f.json new file mode 100644 index 00000000000..f31b5cfa674 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-24q6-4w37-557f/GHSA-24q6-4w37-557f.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-24q6-4w37-557f", + "modified": "2025-06-05T18:30:39Z", + "published": "2025-06-05T18:30:39Z", + "aliases": [ + "CVE-2025-5672" + ], + "details": "A vulnerability has been found in TOTOLINK N302R Plus up to 3.4.0-B20201028 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formFilter of the component HTTP POST Request Handler. The manipulation of the argument url leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5672" + }, + { + "type": "WEB", + "url": "https://github.com/byxs0x0/cve2/blob/main/530/2.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311161" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311161" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.590094" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-05T18:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-6h2g-7w8f-c35g/GHSA-6h2g-7w8f-c35g.json b/advisories/unreviewed/2025/06/GHSA-6h2g-7w8f-c35g/GHSA-6h2g-7w8f-c35g.json new file mode 100644 index 00000000000..9c4d6519b78 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-6h2g-7w8f-c35g/GHSA-6h2g-7w8f-c35g.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6h2g-7w8f-c35g", + "modified": "2025-06-05T18:30:39Z", + "published": "2025-06-05T18:30:39Z", + "aliases": [ + "CVE-2025-5670" + ], + "details": "A vulnerability, which was classified as critical, has been found in PHPGurukul Medical Card Generation System 1.0. This issue affects some unknown processing of the file /admin/manage-card.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5670" + }, + { + "type": "WEB", + "url": "https://github.com/f1rstb100d/myCVE/issues/52" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311159" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311159" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.590066" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-05T17:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-84jw-rq34-ghwg/GHSA-84jw-rq34-ghwg.json b/advisories/unreviewed/2025/06/GHSA-84jw-rq34-ghwg/GHSA-84jw-rq34-ghwg.json new file mode 100644 index 00000000000..e701a23a09e --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-84jw-rq34-ghwg/GHSA-84jw-rq34-ghwg.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-84jw-rq34-ghwg", + "modified": "2025-06-05T18:30:39Z", + "published": "2025-06-05T18:30:39Z", + "aliases": [ + "CVE-2025-5666" + ], + "details": "A vulnerability was found in FreeFloat FTP Server 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component XMKD Command Handler. The manipulation leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5666" + }, + { + "type": "WEB", + "url": "https://fitoxs.com/exploit/exploit-8d9aefc49c178ba5c5d3f5464ff43e8e981c28b95c2cf867d3e20c17f4b9f994.txt" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311155" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311155" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.587025" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-05T16:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-8849-vpvc-g9wp/GHSA-8849-vpvc-g9wp.json b/advisories/unreviewed/2025/06/GHSA-8849-vpvc-g9wp/GHSA-8849-vpvc-g9wp.json new file mode 100644 index 00000000000..61b2105c6c2 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-8849-vpvc-g9wp/GHSA-8849-vpvc-g9wp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8849-vpvc-g9wp", + "modified": "2025-06-05T18:30:39Z", + "published": "2025-06-05T18:30:39Z", + "aliases": [ + "CVE-2025-46257" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in BdThemes Element Pack Pro allows Cross Site Request Forgery.This issue affects Element Pack Pro: from n/a before 8.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46257" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bdthemes-element-pack/vulnerability/wordpress-element-pack-pro-plugin-7-18-12-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-05T18:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-c7r5-764x-hfqw/GHSA-c7r5-764x-hfqw.json b/advisories/unreviewed/2025/06/GHSA-c7r5-764x-hfqw/GHSA-c7r5-764x-hfqw.json new file mode 100644 index 00000000000..15a2a9b91b7 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-c7r5-764x-hfqw/GHSA-c7r5-764x-hfqw.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c7r5-764x-hfqw", + "modified": "2025-06-05T18:30:39Z", + "published": "2025-06-05T18:30:39Z", + "aliases": [ + "CVE-2025-5667" + ], + "details": "A vulnerability was found in FreeFloat FTP Server 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the component REIN Command Handler. The manipulation leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5667" + }, + { + "type": "WEB", + "url": "https://fitoxs.com/exploit/exploit-28d5c2bfb3678b7195e43efb6617f46439a1b1cb7e36b7891094a8ad7f8193dc.txt" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311156" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311156" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.587026" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-05T16:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-cvg9-q978-4569/GHSA-cvg9-q978-4569.json b/advisories/unreviewed/2025/06/GHSA-cvg9-q978-4569/GHSA-cvg9-q978-4569.json index f35338ccc27..334dab1042a 100644 --- a/advisories/unreviewed/2025/06/GHSA-cvg9-q978-4569/GHSA-cvg9-q978-4569.json +++ b/advisories/unreviewed/2025/06/GHSA-cvg9-q978-4569/GHSA-cvg9-q978-4569.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cvg9-q978-4569", - "modified": "2025-06-05T15:31:32Z", + "modified": "2025-06-05T18:30:39Z", "published": "2025-06-05T12:31:09Z", "aliases": [ "CVE-2011-10007" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://github.com/richardc/perl-file-find-rule/commit/df58128bcee4c1da78c34d7f3fe1357e575ad56f.patch" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2025/06/msg00006.html" + }, { "type": "WEB", "url": "https://metacpan.org/release/RCLAMP/File-Find-Rule-0.34/source/lib/File/Find/Rule.pm#L423" diff --git a/advisories/unreviewed/2025/06/GHSA-fqr7-x5vp-p2wq/GHSA-fqr7-x5vp-p2wq.json b/advisories/unreviewed/2025/06/GHSA-fqr7-x5vp-p2wq/GHSA-fqr7-x5vp-p2wq.json new file mode 100644 index 00000000000..dc952cc763d --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-fqr7-x5vp-p2wq/GHSA-fqr7-x5vp-p2wq.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fqr7-x5vp-p2wq", + "modified": "2025-06-05T18:30:40Z", + "published": "2025-06-05T18:30:39Z", + "aliases": [ + "CVE-2025-5671" + ], + "details": "A vulnerability, which was classified as critical, was found in TOTOLINK N302R Plus up to 3.4.0-B20201028. Affected is an unknown function of the file /boafrm/formPortFw of the component HTTP POST Request Handler. The manipulation of the argument service_type leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5671" + }, + { + "type": "WEB", + "url": "https://github.com/byxs0x0/cve2/blob/main/530/1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311160" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311160" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.590093" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-05T18:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-vhq3-h89q-3rqx/GHSA-vhq3-h89q-3rqx.json b/advisories/unreviewed/2025/06/GHSA-vhq3-h89q-3rqx/GHSA-vhq3-h89q-3rqx.json new file mode 100644 index 00000000000..47f639cbf88 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-vhq3-h89q-3rqx/GHSA-vhq3-h89q-3rqx.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vhq3-h89q-3rqx", + "modified": "2025-06-05T18:30:39Z", + "published": "2025-06-05T18:30:39Z", + "aliases": [ + "CVE-2025-5669" + ], + "details": "A vulnerability classified as critical was found in PHPGurukul Medical Card Generation System 1.0. This vulnerability affects unknown code of the file /admin/unreadenq.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5669" + }, + { + "type": "WEB", + "url": "https://github.com/f1rstb100d/myCVE/issues/51" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311158" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311158" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.590065" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-05T17:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-vmfp-2wcq-pwmg/GHSA-vmfp-2wcq-pwmg.json b/advisories/unreviewed/2025/06/GHSA-vmfp-2wcq-pwmg/GHSA-vmfp-2wcq-pwmg.json new file mode 100644 index 00000000000..4453e8e2017 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-vmfp-2wcq-pwmg/GHSA-vmfp-2wcq-pwmg.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vmfp-2wcq-pwmg", + "modified": "2025-06-05T18:30:39Z", + "published": "2025-06-05T18:30:39Z", + "aliases": [ + "CVE-2025-5668" + ], + "details": "A vulnerability classified as critical has been found in PHPGurukul Medical Card Generation System 1.0. This affects an unknown part of the file /admin/readenq.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5668" + }, + { + "type": "WEB", + "url": "https://github.com/f1rstb100d/myCVE/issues/50" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311157" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311157" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.590064" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-05T17:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-w22q-qpw4-g686/GHSA-w22q-qpw4-g686.json b/advisories/unreviewed/2025/06/GHSA-w22q-qpw4-g686/GHSA-w22q-qpw4-g686.json new file mode 100644 index 00000000000..80288292676 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-w22q-qpw4-g686/GHSA-w22q-qpw4-g686.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w22q-qpw4-g686", + "modified": "2025-06-05T18:30:39Z", + "published": "2025-06-05T18:30:39Z", + "aliases": [ + "CVE-2025-46258" + ], + "details": "Missing Authorization vulnerability in BdThemes Element Pack Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Element Pack Pro: from n/a before 8.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46258" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bdthemes-element-pack/vulnerability/wordpress-element-pack-pro-plugin-7-18-12-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-05T18:15:22Z" + } +} \ No newline at end of file