From 76ed122fc0e10365dc4e9a4dd70360b805d111d6 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 12 Mar 2025 18:34:13 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-33p5-m25c-cp6w.json | 2 +- .../GHSA-7737-vff2-9jq5.json | 2 +- .../GHSA-pffm-c6m3-rc4c.json | 2 +- .../GHSA-pmg6-hpcj-x4m9.json | 4 +- .../GHSA-qq48-cwf8-h6fx.json | 4 +- .../GHSA-rqhx-wx74-955g.json | 3 +- .../GHSA-28m3-c955-h29j.json | 4 +- .../GHSA-7fcw-hqq7-pqmf.json | 4 +- .../GHSA-j4j9-wc5g-p586.json | 4 +- .../GHSA-25j6-j45c-6mcv.json | 3 +- .../GHSA-3r96-2wq9-w8xg.json | 3 +- .../GHSA-45j4-9vf9-p9qf.json | 3 +- .../GHSA-4mp8-jq9f-3rjp.json | 3 +- .../GHSA-6w2m-54fm-r889.json | 3 +- .../GHSA-8r2h-632g-2cfh.json | 3 +- .../GHSA-9g76-c57m-qm46.json | 3 +- .../GHSA-cvhw-39j6-rr36.json | 3 +- .../GHSA-fpqg-p42r-7537.json | 3 +- .../GHSA-g24x-vvqc-6c7r.json | 3 +- .../GHSA-gqxp-c76m-phrh.json | 3 +- .../GHSA-gw62-p9fc-rmhv.json | 3 +- .../GHSA-hmv6-rm3q-8vjx.json | 3 +- .../GHSA-m5j7-2c6m-x5wr.json | 3 +- .../GHSA-q84q-gvjv-54c5.json | 3 +- .../GHSA-qpcx-f3pv-5h9x.json | 3 +- .../GHSA-qq35-gxpr-x2xj.json | 3 +- .../GHSA-r95c-pp9g-6pv9.json | 3 +- .../GHSA-vv86-f2p5-m8xv.json | 3 +- .../GHSA-cv79-5xmw-3x8r.json | 2 +- .../GHSA-2cv6-4f2r-jq2c.json | 35 +++++++++++++++ .../GHSA-2w36-grgh-xprc.json | 40 +++++++++++++++++ .../GHSA-2wx7-j39g-4p6g.json | 40 +++++++++++++++++ .../GHSA-323w-6p85-26fr.json | 41 +++++++++++++++++ .../GHSA-35gq-cvrm-xf94.json | 40 +++++++++++++++++ .../GHSA-3f7x-54cr-7w35.json | 15 +++++-- .../GHSA-5mrq-42cr-23mg.json | 40 +++++++++++++++++ .../GHSA-5rg8-g76j-7fw7.json | 15 +++++-- .../GHSA-5xpm-7q7v-rpvf.json | 15 +++++-- .../GHSA-763f-93r5-54qv.json | 29 ++++++++++++ .../GHSA-7j7m-w4qx-7vmf.json | 15 +++++-- .../GHSA-82g5-9hm8-rvm3.json | 40 +++++++++++++++++ .../GHSA-86w8-vhw6-q9qq.json | 15 +++++-- .../GHSA-8hg9-rcgr-qwwm.json | 36 +++++++++++++++ .../GHSA-93q8-2xpx-g486.json | 2 +- .../GHSA-96v5-c2h5-56hm.json | 11 +++-- .../GHSA-9q9q-5rw5-gp2h.json | 36 +++++++++++++++ .../GHSA-9w79-7j73-f648.json | 40 +++++++++++++++++ .../GHSA-9xm2-hxxj-hgq7.json | 15 +++++-- .../GHSA-c3wj-2vf4-295m.json | 33 ++++++++++++++ .../GHSA-cqp7-cmgp-m73g.json | 38 ++++++++++++++++ .../GHSA-cr97-553h-m39w.json | 29 ++++++++++++ .../GHSA-cxh3-prmp-2877.json | 36 +++++++++++++++ .../GHSA-f6jg-88p5-x574.json | 40 +++++++++++++++++ .../GHSA-f769-hvjj-2wv2.json | 40 +++++++++++++++++ .../GHSA-f86q-56fj-v562.json | 36 +++++++++++++++ .../GHSA-fw35-27g6-hvhf.json | 15 +++++-- .../GHSA-hghx-c858-jm7q.json | 40 +++++++++++++++++ .../GHSA-j3vw-gxh2-3r2w.json | 29 ++++++++++++ .../GHSA-jcwm-grfm-4xmh.json | 44 +++++++++++++++++++ .../GHSA-jrp2-pgjj-vwpm.json | 40 +++++++++++++++++ .../GHSA-jwwj-7cm7-g363.json | 40 +++++++++++++++++ .../GHSA-mx4h-4r93-47mh.json | 15 +++++-- .../GHSA-p487-45r6-v8fh.json | 36 +++++++++++++++ .../GHSA-pg35-89w5-5c5h.json | 29 ++++++++++++ .../GHSA-q2xv-553m-pcwq.json | 2 +- .../GHSA-rp6p-7xx7-cr6f.json | 40 +++++++++++++++++ .../GHSA-v888-xcc4-jmr2.json | 15 +++++-- .../GHSA-w9ff-5p26-w67v.json | 40 +++++++++++++++++ .../GHSA-wjvr-8c9r-fgmc.json | 37 ++++++++++++++++ .../GHSA-xr5m-494h-32gf.json | 15 +++++-- 70 files changed, 1222 insertions(+), 75 deletions(-) create mode 100644 advisories/unreviewed/2025/03/GHSA-2cv6-4f2r-jq2c/GHSA-2cv6-4f2r-jq2c.json create mode 100644 advisories/unreviewed/2025/03/GHSA-2w36-grgh-xprc/GHSA-2w36-grgh-xprc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-2wx7-j39g-4p6g/GHSA-2wx7-j39g-4p6g.json create mode 100644 advisories/unreviewed/2025/03/GHSA-323w-6p85-26fr/GHSA-323w-6p85-26fr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-35gq-cvrm-xf94/GHSA-35gq-cvrm-xf94.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5mrq-42cr-23mg/GHSA-5mrq-42cr-23mg.json create mode 100644 advisories/unreviewed/2025/03/GHSA-763f-93r5-54qv/GHSA-763f-93r5-54qv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-82g5-9hm8-rvm3/GHSA-82g5-9hm8-rvm3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8hg9-rcgr-qwwm/GHSA-8hg9-rcgr-qwwm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9q9q-5rw5-gp2h/GHSA-9q9q-5rw5-gp2h.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9w79-7j73-f648/GHSA-9w79-7j73-f648.json create mode 100644 advisories/unreviewed/2025/03/GHSA-c3wj-2vf4-295m/GHSA-c3wj-2vf4-295m.json create mode 100644 advisories/unreviewed/2025/03/GHSA-cqp7-cmgp-m73g/GHSA-cqp7-cmgp-m73g.json create mode 100644 advisories/unreviewed/2025/03/GHSA-cr97-553h-m39w/GHSA-cr97-553h-m39w.json create mode 100644 advisories/unreviewed/2025/03/GHSA-cxh3-prmp-2877/GHSA-cxh3-prmp-2877.json create mode 100644 advisories/unreviewed/2025/03/GHSA-f6jg-88p5-x574/GHSA-f6jg-88p5-x574.json create mode 100644 advisories/unreviewed/2025/03/GHSA-f769-hvjj-2wv2/GHSA-f769-hvjj-2wv2.json create mode 100644 advisories/unreviewed/2025/03/GHSA-f86q-56fj-v562/GHSA-f86q-56fj-v562.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hghx-c858-jm7q/GHSA-hghx-c858-jm7q.json create mode 100644 advisories/unreviewed/2025/03/GHSA-j3vw-gxh2-3r2w/GHSA-j3vw-gxh2-3r2w.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jcwm-grfm-4xmh/GHSA-jcwm-grfm-4xmh.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jrp2-pgjj-vwpm/GHSA-jrp2-pgjj-vwpm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jwwj-7cm7-g363/GHSA-jwwj-7cm7-g363.json create mode 100644 advisories/unreviewed/2025/03/GHSA-p487-45r6-v8fh/GHSA-p487-45r6-v8fh.json create mode 100644 advisories/unreviewed/2025/03/GHSA-pg35-89w5-5c5h/GHSA-pg35-89w5-5c5h.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rp6p-7xx7-cr6f/GHSA-rp6p-7xx7-cr6f.json create mode 100644 advisories/unreviewed/2025/03/GHSA-w9ff-5p26-w67v/GHSA-w9ff-5p26-w67v.json create mode 100644 advisories/unreviewed/2025/03/GHSA-wjvr-8c9r-fgmc/GHSA-wjvr-8c9r-fgmc.json diff --git a/advisories/unreviewed/2023/02/GHSA-33p5-m25c-cp6w/GHSA-33p5-m25c-cp6w.json b/advisories/unreviewed/2023/02/GHSA-33p5-m25c-cp6w/GHSA-33p5-m25c-cp6w.json index e175a82ab6d..32d30c89fed 100644 --- a/advisories/unreviewed/2023/02/GHSA-33p5-m25c-cp6w/GHSA-33p5-m25c-cp6w.json +++ b/advisories/unreviewed/2023/02/GHSA-33p5-m25c-cp6w/GHSA-33p5-m25c-cp6w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-33p5-m25c-cp6w", - "modified": "2023-03-03T21:30:18Z", + "modified": "2025-03-12T18:32:40Z", "published": "2023-02-23T21:30:16Z", "aliases": [ "CVE-2023-23918" diff --git a/advisories/unreviewed/2023/02/GHSA-7737-vff2-9jq5/GHSA-7737-vff2-9jq5.json b/advisories/unreviewed/2023/02/GHSA-7737-vff2-9jq5/GHSA-7737-vff2-9jq5.json index 095f7124b34..a26dd14a319 100644 --- a/advisories/unreviewed/2023/02/GHSA-7737-vff2-9jq5/GHSA-7737-vff2-9jq5.json +++ b/advisories/unreviewed/2023/02/GHSA-7737-vff2-9jq5/GHSA-7737-vff2-9jq5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7737-vff2-9jq5", - "modified": "2023-03-02T18:30:27Z", + "modified": "2025-03-12T18:32:40Z", "published": "2023-02-24T06:30:16Z", "aliases": [ "CVE-2023-22425" diff --git a/advisories/unreviewed/2023/02/GHSA-pffm-c6m3-rc4c/GHSA-pffm-c6m3-rc4c.json b/advisories/unreviewed/2023/02/GHSA-pffm-c6m3-rc4c/GHSA-pffm-c6m3-rc4c.json index d3917be17f2..3da79dabb2f 100644 --- a/advisories/unreviewed/2023/02/GHSA-pffm-c6m3-rc4c/GHSA-pffm-c6m3-rc4c.json +++ b/advisories/unreviewed/2023/02/GHSA-pffm-c6m3-rc4c/GHSA-pffm-c6m3-rc4c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pffm-c6m3-rc4c", - "modified": "2023-03-02T18:30:27Z", + "modified": "2025-03-12T18:32:40Z", "published": "2023-02-24T06:30:16Z", "aliases": [ "CVE-2023-22427" diff --git a/advisories/unreviewed/2023/02/GHSA-pmg6-hpcj-x4m9/GHSA-pmg6-hpcj-x4m9.json b/advisories/unreviewed/2023/02/GHSA-pmg6-hpcj-x4m9/GHSA-pmg6-hpcj-x4m9.json index 3d71907c06d..c18ffa9cdb2 100644 --- a/advisories/unreviewed/2023/02/GHSA-pmg6-hpcj-x4m9/GHSA-pmg6-hpcj-x4m9.json +++ b/advisories/unreviewed/2023/02/GHSA-pmg6-hpcj-x4m9/GHSA-pmg6-hpcj-x4m9.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-20" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-qq48-cwf8-h6fx/GHSA-qq48-cwf8-h6fx.json b/advisories/unreviewed/2023/02/GHSA-qq48-cwf8-h6fx/GHSA-qq48-cwf8-h6fx.json index 7c8e2c797d3..2871288d181 100644 --- a/advisories/unreviewed/2023/02/GHSA-qq48-cwf8-h6fx/GHSA-qq48-cwf8-h6fx.json +++ b/advisories/unreviewed/2023/02/GHSA-qq48-cwf8-h6fx/GHSA-qq48-cwf8-h6fx.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-125" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-rqhx-wx74-955g/GHSA-rqhx-wx74-955g.json b/advisories/unreviewed/2023/02/GHSA-rqhx-wx74-955g/GHSA-rqhx-wx74-955g.json index 7d072ea8c22..1138e3ec053 100644 --- a/advisories/unreviewed/2023/02/GHSA-rqhx-wx74-955g/GHSA-rqhx-wx74-955g.json +++ b/advisories/unreviewed/2023/02/GHSA-rqhx-wx74-955g/GHSA-rqhx-wx74-955g.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-1321" + "CWE-1321", + "CWE-77" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-28m3-c955-h29j/GHSA-28m3-c955-h29j.json b/advisories/unreviewed/2023/05/GHSA-28m3-c955-h29j/GHSA-28m3-c955-h29j.json index f8b828de5a3..6ebb4119f08 100644 --- a/advisories/unreviewed/2023/05/GHSA-28m3-c955-h29j/GHSA-28m3-c955-h29j.json +++ b/advisories/unreviewed/2023/05/GHSA-28m3-c955-h29j/GHSA-28m3-c955-h29j.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-7fcw-hqq7-pqmf/GHSA-7fcw-hqq7-pqmf.json b/advisories/unreviewed/2024/04/GHSA-7fcw-hqq7-pqmf/GHSA-7fcw-hqq7-pqmf.json index cd48e71ab1d..1fdfc01b4ed 100644 --- a/advisories/unreviewed/2024/04/GHSA-7fcw-hqq7-pqmf/GHSA-7fcw-hqq7-pqmf.json +++ b/advisories/unreviewed/2024/04/GHSA-7fcw-hqq7-pqmf/GHSA-7fcw-hqq7-pqmf.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-7fcw-hqq7-pqmf", - "modified": "2024-04-01T12:30:44Z", + "modified": "2025-03-12T18:32:41Z", "published": "2024-04-01T12:30:44Z", "aliases": [ "CVE-2024-3130" ], - "details": "Hard-coded Credentials in CoolKit eWeLlink app are before 5.4.x on Android and IOS allows local attacker to unauthorized access to sensitive data via Decryption algorithm and key obtained after decompiling app\n\n", + "details": "Hard-coded Credentials in CoolKit eWeLlink app are before 5.4.x on Android and IOS allows local attacker to unauthorized access to sensitive data via Decryption algorithm and key obtained after decompiling app", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-j4j9-wc5g-p586/GHSA-j4j9-wc5g-p586.json b/advisories/unreviewed/2024/04/GHSA-j4j9-wc5g-p586/GHSA-j4j9-wc5g-p586.json index c49501b2581..fef7ed1a9db 100644 --- a/advisories/unreviewed/2024/04/GHSA-j4j9-wc5g-p586/GHSA-j4j9-wc5g-p586.json +++ b/advisories/unreviewed/2024/04/GHSA-j4j9-wc5g-p586/GHSA-j4j9-wc5g-p586.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-925" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-25j6-j45c-6mcv/GHSA-25j6-j45c-6mcv.json b/advisories/unreviewed/2024/05/GHSA-25j6-j45c-6mcv/GHSA-25j6-j45c-6mcv.json index 763c937a5da..12d003df742 100644 --- a/advisories/unreviewed/2024/05/GHSA-25j6-j45c-6mcv/GHSA-25j6-j45c-6mcv.json +++ b/advisories/unreviewed/2024/05/GHSA-25j6-j45c-6mcv/GHSA-25j6-j45c-6mcv.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-3r96-2wq9-w8xg/GHSA-3r96-2wq9-w8xg.json b/advisories/unreviewed/2024/05/GHSA-3r96-2wq9-w8xg/GHSA-3r96-2wq9-w8xg.json index 48991709420..7552ddd013f 100644 --- a/advisories/unreviewed/2024/05/GHSA-3r96-2wq9-w8xg/GHSA-3r96-2wq9-w8xg.json +++ b/advisories/unreviewed/2024/05/GHSA-3r96-2wq9-w8xg/GHSA-3r96-2wq9-w8xg.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-45j4-9vf9-p9qf/GHSA-45j4-9vf9-p9qf.json b/advisories/unreviewed/2024/05/GHSA-45j4-9vf9-p9qf/GHSA-45j4-9vf9-p9qf.json index 91f8b115493..978f7f64d47 100644 --- a/advisories/unreviewed/2024/05/GHSA-45j4-9vf9-p9qf/GHSA-45j4-9vf9-p9qf.json +++ b/advisories/unreviewed/2024/05/GHSA-45j4-9vf9-p9qf/GHSA-45j4-9vf9-p9qf.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-4mp8-jq9f-3rjp/GHSA-4mp8-jq9f-3rjp.json b/advisories/unreviewed/2024/05/GHSA-4mp8-jq9f-3rjp/GHSA-4mp8-jq9f-3rjp.json index 38507d13e51..7c4d2278710 100644 --- a/advisories/unreviewed/2024/05/GHSA-4mp8-jq9f-3rjp/GHSA-4mp8-jq9f-3rjp.json +++ b/advisories/unreviewed/2024/05/GHSA-4mp8-jq9f-3rjp/GHSA-4mp8-jq9f-3rjp.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-6w2m-54fm-r889/GHSA-6w2m-54fm-r889.json b/advisories/unreviewed/2024/05/GHSA-6w2m-54fm-r889/GHSA-6w2m-54fm-r889.json index 2c374a0bd52..61117ade13f 100644 --- a/advisories/unreviewed/2024/05/GHSA-6w2m-54fm-r889/GHSA-6w2m-54fm-r889.json +++ b/advisories/unreviewed/2024/05/GHSA-6w2m-54fm-r889/GHSA-6w2m-54fm-r889.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-8r2h-632g-2cfh/GHSA-8r2h-632g-2cfh.json b/advisories/unreviewed/2024/05/GHSA-8r2h-632g-2cfh/GHSA-8r2h-632g-2cfh.json index ace09c0fda9..63756d91542 100644 --- a/advisories/unreviewed/2024/05/GHSA-8r2h-632g-2cfh/GHSA-8r2h-632g-2cfh.json +++ b/advisories/unreviewed/2024/05/GHSA-8r2h-632g-2cfh/GHSA-8r2h-632g-2cfh.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-9g76-c57m-qm46/GHSA-9g76-c57m-qm46.json b/advisories/unreviewed/2024/05/GHSA-9g76-c57m-qm46/GHSA-9g76-c57m-qm46.json index 7b4ea884afc..e06d0bedae2 100644 --- a/advisories/unreviewed/2024/05/GHSA-9g76-c57m-qm46/GHSA-9g76-c57m-qm46.json +++ b/advisories/unreviewed/2024/05/GHSA-9g76-c57m-qm46/GHSA-9g76-c57m-qm46.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-cvhw-39j6-rr36/GHSA-cvhw-39j6-rr36.json b/advisories/unreviewed/2024/05/GHSA-cvhw-39j6-rr36/GHSA-cvhw-39j6-rr36.json index f2f4d63b90e..0fa0fe399e1 100644 --- a/advisories/unreviewed/2024/05/GHSA-cvhw-39j6-rr36/GHSA-cvhw-39j6-rr36.json +++ b/advisories/unreviewed/2024/05/GHSA-cvhw-39j6-rr36/GHSA-cvhw-39j6-rr36.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-fpqg-p42r-7537/GHSA-fpqg-p42r-7537.json b/advisories/unreviewed/2024/05/GHSA-fpqg-p42r-7537/GHSA-fpqg-p42r-7537.json index f6333c60500..719e54721c4 100644 --- a/advisories/unreviewed/2024/05/GHSA-fpqg-p42r-7537/GHSA-fpqg-p42r-7537.json +++ b/advisories/unreviewed/2024/05/GHSA-fpqg-p42r-7537/GHSA-fpqg-p42r-7537.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-g24x-vvqc-6c7r/GHSA-g24x-vvqc-6c7r.json b/advisories/unreviewed/2024/05/GHSA-g24x-vvqc-6c7r/GHSA-g24x-vvqc-6c7r.json index a161b834c73..a1bb2c4c716 100644 --- a/advisories/unreviewed/2024/05/GHSA-g24x-vvqc-6c7r/GHSA-g24x-vvqc-6c7r.json +++ b/advisories/unreviewed/2024/05/GHSA-g24x-vvqc-6c7r/GHSA-g24x-vvqc-6c7r.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-gqxp-c76m-phrh/GHSA-gqxp-c76m-phrh.json b/advisories/unreviewed/2024/05/GHSA-gqxp-c76m-phrh/GHSA-gqxp-c76m-phrh.json index c4044397959..48040cd4363 100644 --- a/advisories/unreviewed/2024/05/GHSA-gqxp-c76m-phrh/GHSA-gqxp-c76m-phrh.json +++ b/advisories/unreviewed/2024/05/GHSA-gqxp-c76m-phrh/GHSA-gqxp-c76m-phrh.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-gw62-p9fc-rmhv/GHSA-gw62-p9fc-rmhv.json b/advisories/unreviewed/2024/05/GHSA-gw62-p9fc-rmhv/GHSA-gw62-p9fc-rmhv.json index 69b06051328..de52dad592e 100644 --- a/advisories/unreviewed/2024/05/GHSA-gw62-p9fc-rmhv/GHSA-gw62-p9fc-rmhv.json +++ b/advisories/unreviewed/2024/05/GHSA-gw62-p9fc-rmhv/GHSA-gw62-p9fc-rmhv.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-hmv6-rm3q-8vjx/GHSA-hmv6-rm3q-8vjx.json b/advisories/unreviewed/2024/05/GHSA-hmv6-rm3q-8vjx/GHSA-hmv6-rm3q-8vjx.json index ef385e46f76..e70af9a7a98 100644 --- a/advisories/unreviewed/2024/05/GHSA-hmv6-rm3q-8vjx/GHSA-hmv6-rm3q-8vjx.json +++ b/advisories/unreviewed/2024/05/GHSA-hmv6-rm3q-8vjx/GHSA-hmv6-rm3q-8vjx.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-m5j7-2c6m-x5wr/GHSA-m5j7-2c6m-x5wr.json b/advisories/unreviewed/2024/05/GHSA-m5j7-2c6m-x5wr/GHSA-m5j7-2c6m-x5wr.json index 1637a18b05b..750d1e8836c 100644 --- a/advisories/unreviewed/2024/05/GHSA-m5j7-2c6m-x5wr/GHSA-m5j7-2c6m-x5wr.json +++ b/advisories/unreviewed/2024/05/GHSA-m5j7-2c6m-x5wr/GHSA-m5j7-2c6m-x5wr.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-q84q-gvjv-54c5/GHSA-q84q-gvjv-54c5.json b/advisories/unreviewed/2024/05/GHSA-q84q-gvjv-54c5/GHSA-q84q-gvjv-54c5.json index a95a943f11d..460a01e99f6 100644 --- a/advisories/unreviewed/2024/05/GHSA-q84q-gvjv-54c5/GHSA-q84q-gvjv-54c5.json +++ b/advisories/unreviewed/2024/05/GHSA-q84q-gvjv-54c5/GHSA-q84q-gvjv-54c5.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-qpcx-f3pv-5h9x/GHSA-qpcx-f3pv-5h9x.json b/advisories/unreviewed/2024/05/GHSA-qpcx-f3pv-5h9x/GHSA-qpcx-f3pv-5h9x.json index 31ab147f9a0..54ce385963d 100644 --- a/advisories/unreviewed/2024/05/GHSA-qpcx-f3pv-5h9x/GHSA-qpcx-f3pv-5h9x.json +++ b/advisories/unreviewed/2024/05/GHSA-qpcx-f3pv-5h9x/GHSA-qpcx-f3pv-5h9x.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-qq35-gxpr-x2xj/GHSA-qq35-gxpr-x2xj.json b/advisories/unreviewed/2024/05/GHSA-qq35-gxpr-x2xj/GHSA-qq35-gxpr-x2xj.json index 28e78d06640..788601b0f1d 100644 --- a/advisories/unreviewed/2024/05/GHSA-qq35-gxpr-x2xj/GHSA-qq35-gxpr-x2xj.json +++ b/advisories/unreviewed/2024/05/GHSA-qq35-gxpr-x2xj/GHSA-qq35-gxpr-x2xj.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-r95c-pp9g-6pv9/GHSA-r95c-pp9g-6pv9.json b/advisories/unreviewed/2024/05/GHSA-r95c-pp9g-6pv9/GHSA-r95c-pp9g-6pv9.json index 19509661f8c..be4a67565ed 100644 --- a/advisories/unreviewed/2024/05/GHSA-r95c-pp9g-6pv9/GHSA-r95c-pp9g-6pv9.json +++ b/advisories/unreviewed/2024/05/GHSA-r95c-pp9g-6pv9/GHSA-r95c-pp9g-6pv9.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-vv86-f2p5-m8xv/GHSA-vv86-f2p5-m8xv.json b/advisories/unreviewed/2024/05/GHSA-vv86-f2p5-m8xv/GHSA-vv86-f2p5-m8xv.json index 85aa2d32ede..16d116709cb 100644 --- a/advisories/unreviewed/2024/05/GHSA-vv86-f2p5-m8xv/GHSA-vv86-f2p5-m8xv.json +++ b/advisories/unreviewed/2024/05/GHSA-vv86-f2p5-m8xv/GHSA-vv86-f2p5-m8xv.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-cv79-5xmw-3x8r/GHSA-cv79-5xmw-3x8r.json b/advisories/unreviewed/2024/09/GHSA-cv79-5xmw-3x8r/GHSA-cv79-5xmw-3x8r.json index d09edffe013..59657b4b1c4 100644 --- a/advisories/unreviewed/2024/09/GHSA-cv79-5xmw-3x8r/GHSA-cv79-5xmw-3x8r.json +++ b/advisories/unreviewed/2024/09/GHSA-cv79-5xmw-3x8r/GHSA-cv79-5xmw-3x8r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cv79-5xmw-3x8r", - "modified": "2024-09-25T03:30:36Z", + "modified": "2025-03-12T18:32:46Z", "published": "2024-09-25T03:30:36Z", "aliases": [ "CVE-2024-7491" diff --git a/advisories/unreviewed/2025/03/GHSA-2cv6-4f2r-jq2c/GHSA-2cv6-4f2r-jq2c.json b/advisories/unreviewed/2025/03/GHSA-2cv6-4f2r-jq2c/GHSA-2cv6-4f2r-jq2c.json new file mode 100644 index 00000000000..c95722721ba --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2cv6-4f2r-jq2c/GHSA-2cv6-4f2r-jq2c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2cv6-4f2r-jq2c", + "modified": "2025-03-12T18:32:53Z", + "published": "2025-03-12T18:32:53Z", + "aliases": [ + "CVE-2025-27867" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix HTTP Webconsole Plugin.\n\nThis issue affects Apache Felix HTTP Webconsole Plugin: from Version 1.X through 1.2.0.\n\nUsers are recommended to upgrade to version 1.2.2, which fixes the issue.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27867" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/y83f2rvm8bccr5ctgv7mzxd69p6f77dp" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/03/12/3" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-12T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2w36-grgh-xprc/GHSA-2w36-grgh-xprc.json b/advisories/unreviewed/2025/03/GHSA-2w36-grgh-xprc/GHSA-2w36-grgh-xprc.json new file mode 100644 index 00000000000..8ffd0344342 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2w36-grgh-xprc/GHSA-2w36-grgh-xprc.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2w36-grgh-xprc", + "modified": "2025-03-12T18:32:53Z", + "published": "2025-03-12T18:32:52Z", + "aliases": [ + "CVE-2025-20143" + ], + "details": "A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker with high privileges to bypass the Secure Boot functionality and load unverified software on an affected device. To exploit this vulnerability, the attacker must have root-system privileges on the affected device.\n\nThis vulnerability is due to insufficient verification of modules in the software load process. An attacker could exploit this vulnerability by manipulating the loaded binaries to bypass some of the integrity checks that are performed during the booting process. A successful exploit could allow the attacker to control the boot configuration, which could enable them to bypass the requirement to run Cisco-signed images or alter the security properties of the running system.\nNote: This vulnerability affects Cisco IOS XR Software, not the Secure Boot feature.\nCisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20143" + }, + { + "type": "WEB", + "url": "https://blog.apnic.net/2024/09/02/crafting-endless-as-paths-in-bgp" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb-lkm-zNErZjbZ" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-347" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-12T16:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2wx7-j39g-4p6g/GHSA-2wx7-j39g-4p6g.json b/advisories/unreviewed/2025/03/GHSA-2wx7-j39g-4p6g/GHSA-2wx7-j39g-4p6g.json new file mode 100644 index 00000000000..67626d89b03 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2wx7-j39g-4p6g/GHSA-2wx7-j39g-4p6g.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2wx7-j39g-4p6g", + "modified": "2025-03-12T18:32:52Z", + "published": "2025-03-12T18:32:52Z", + "aliases": [ + "CVE-2025-20141" + ], + "details": "A vulnerability in the handling of specific packets that are punted from a line card to a route processor in Cisco IOS XR Software Release 7.9.2 could allow an unauthenticated, adjacent attacker to cause control plane traffic to stop working on multiple Cisco IOS XR platforms. \n\nThis vulnerability is due to incorrect handling of packets that are punted to the route processor. An attacker could exploit this vulnerability by sending traffic, which must be handled by the Linux stack on the route processor, to an affected device. A successful exploit could allow the attacker to cause control plane traffic to stop working, resulting in a denial of service (DoS) condition.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20141" + }, + { + "type": "WEB", + "url": "https://blog.apnic.net/2024/09/02/crafting-endless-as-paths-in-bgp" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-xr792-bWfVDPY" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-12T16:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-323w-6p85-26fr/GHSA-323w-6p85-26fr.json b/advisories/unreviewed/2025/03/GHSA-323w-6p85-26fr/GHSA-323w-6p85-26fr.json new file mode 100644 index 00000000000..5d7e2288889 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-323w-6p85-26fr/GHSA-323w-6p85-26fr.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-323w-6p85-26fr", + "modified": "2025-03-12T18:32:53Z", + "published": "2025-03-12T18:32:53Z", + "aliases": [ + "CVE-2025-26260" + ], + "details": "Plenti <= 0.7.16 is vulnerable to code execution. Users uploading '.svelte' files with the /postLocal endpoint can define the file name as javascript codes. The server executes the uploaded file name in host, and cause code execution.", + "severity": [], + "affected": [], + "references": [ + { + "type": "WEB", + "url": "https://github.com/plentico/plenti/security/advisories/GHSA-mj4v-hp69-27x5" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26260" + }, + { + "type": "WEB", + "url": "https://ahmetakan.com/2025/02/14/cve-2025-26260" + }, + { + "type": "WEB", + "url": "https://github.com/ahmetak4n/vulnerability-playground/tree/main/vulnerability-research/CVE-2025-26260" + }, + { + "type": "WEB", + "url": "https://github.com/plentico/plenti/releases/tag/v0.7.17" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-12T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-35gq-cvrm-xf94/GHSA-35gq-cvrm-xf94.json b/advisories/unreviewed/2025/03/GHSA-35gq-cvrm-xf94/GHSA-35gq-cvrm-xf94.json new file mode 100644 index 00000000000..df42904c10b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-35gq-cvrm-xf94/GHSA-35gq-cvrm-xf94.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-35gq-cvrm-xf94", + "modified": "2025-03-12T18:32:53Z", + "published": "2025-03-12T18:32:53Z", + "aliases": [ + "CVE-2025-27017" + ], + "details": "Apache NiFi 1.13.0 through 2.2.0 includes the username and password used to authenticate with MongoDB in the NiFi provenance events that MongoDB components generate during processing. An authorized user with read access to the provenance events of those processors may see the credentials information. Upgrading to Apache NiFi 2.3.0 is the recommended mitigation, which removes the credentials from provenance event records.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:U/V:C/RE:L/U:Green" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27017" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/d4n5474jkhp82dvnht13pjtlfx7bhn5q" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/03/11/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-538" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-12T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3f7x-54cr-7w35/GHSA-3f7x-54cr-7w35.json b/advisories/unreviewed/2025/03/GHSA-3f7x-54cr-7w35/GHSA-3f7x-54cr-7w35.json index 5abf2547ce4..0347b98b6ad 100644 --- a/advisories/unreviewed/2025/03/GHSA-3f7x-54cr-7w35/GHSA-3f7x-54cr-7w35.json +++ b/advisories/unreviewed/2025/03/GHSA-3f7x-54cr-7w35/GHSA-3f7x-54cr-7w35.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3f7x-54cr-7w35", - "modified": "2025-03-12T15:32:05Z", + "modified": "2025-03-12T18:32:52Z", "published": "2025-03-12T15:32:05Z", "aliases": [ "CVE-2025-22954" ], "details": "Koha <= 21.11 is contains a SQL Injection vulnerability in /serials/lateissues-export.pl via the supplierid parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-12T15:15:39Z" diff --git a/advisories/unreviewed/2025/03/GHSA-5mrq-42cr-23mg/GHSA-5mrq-42cr-23mg.json b/advisories/unreviewed/2025/03/GHSA-5mrq-42cr-23mg/GHSA-5mrq-42cr-23mg.json new file mode 100644 index 00000000000..4d24d922ed8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5mrq-42cr-23mg/GHSA-5mrq-42cr-23mg.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5mrq-42cr-23mg", + "modified": "2025-03-12T18:32:52Z", + "published": "2025-03-12T18:32:52Z", + "aliases": [ + "CVE-2025-1960" + ], + "details": "CWE-1188: Initialization of a Resource with an Insecure Default vulnerability exists that could cause an\nattacker to execute unauthorized commands when a system’s default password credentials have not been\nchanged on first use. The default username is not displayed correctly in the WebHMI interface.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1960" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2025-070-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2025-070-03.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1188" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-12T16:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5rg8-g76j-7fw7/GHSA-5rg8-g76j-7fw7.json b/advisories/unreviewed/2025/03/GHSA-5rg8-g76j-7fw7/GHSA-5rg8-g76j-7fw7.json index 365f0689785..20eb7b04ef5 100644 --- a/advisories/unreviewed/2025/03/GHSA-5rg8-g76j-7fw7/GHSA-5rg8-g76j-7fw7.json +++ b/advisories/unreviewed/2025/03/GHSA-5rg8-g76j-7fw7/GHSA-5rg8-g76j-7fw7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5rg8-g76j-7fw7", - "modified": "2025-03-12T15:32:06Z", + "modified": "2025-03-12T18:32:52Z", "published": "2025-03-12T15:32:06Z", "aliases": [ "CVE-2025-27915" ], "details": "An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Classic Web Client due to insufficient sanitization of HTML content in ICS files. When a user views an e-mail message containing a malicious ICS entry, its embedded JavaScript executes via an ontoggle event inside a
tag. This allows an attacker to run arbitrary JavaScript within the victim's session, potentially leading to unauthorized actions such as setting e-mail filters to redirect messages to an attacker-controlled address. As a result, an attacker can perform unauthorized actions on the victim's account, including e-mail redirection and data exfiltration.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-12T15:15:39Z" diff --git a/advisories/unreviewed/2025/03/GHSA-5xpm-7q7v-rpvf/GHSA-5xpm-7q7v-rpvf.json b/advisories/unreviewed/2025/03/GHSA-5xpm-7q7v-rpvf/GHSA-5xpm-7q7v-rpvf.json index 384d0ff2f3b..7191eca9025 100644 --- a/advisories/unreviewed/2025/03/GHSA-5xpm-7q7v-rpvf/GHSA-5xpm-7q7v-rpvf.json +++ b/advisories/unreviewed/2025/03/GHSA-5xpm-7q7v-rpvf/GHSA-5xpm-7q7v-rpvf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5xpm-7q7v-rpvf", - "modified": "2025-03-11T21:30:35Z", + "modified": "2025-03-12T18:32:52Z", "published": "2025-03-11T21:30:35Z", "aliases": [ "CVE-2025-25925" ], "details": "A stored cross-scripting (XSS) vulnerability in Openmrs v2.4.3 Build 0ff0ed allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the personName.middleName parameter at /openmrs/admin/patients/shortPatientForm.form.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-11T20:15:16Z" diff --git a/advisories/unreviewed/2025/03/GHSA-763f-93r5-54qv/GHSA-763f-93r5-54qv.json b/advisories/unreviewed/2025/03/GHSA-763f-93r5-54qv/GHSA-763f-93r5-54qv.json new file mode 100644 index 00000000000..b12dd5a9954 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-763f-93r5-54qv/GHSA-763f-93r5-54qv.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-763f-93r5-54qv", + "modified": "2025-03-12T18:32:53Z", + "published": "2025-03-12T18:32:53Z", + "aliases": [ + "CVE-2025-25567" + ], + "details": "SoftEther VPN 5.02.5187 is vulnerable to Buffer Overflow in Internat.c via the UniToStrForSingleChars function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25567" + }, + { + "type": "WEB", + "url": "https://lzydry.github.io/CVE-2025-25567" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-12T16:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7j7m-w4qx-7vmf/GHSA-7j7m-w4qx-7vmf.json b/advisories/unreviewed/2025/03/GHSA-7j7m-w4qx-7vmf/GHSA-7j7m-w4qx-7vmf.json index 6e7bf8427f9..d3373af60bc 100644 --- a/advisories/unreviewed/2025/03/GHSA-7j7m-w4qx-7vmf/GHSA-7j7m-w4qx-7vmf.json +++ b/advisories/unreviewed/2025/03/GHSA-7j7m-w4qx-7vmf/GHSA-7j7m-w4qx-7vmf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7j7m-w4qx-7vmf", - "modified": "2025-03-11T21:30:36Z", + "modified": "2025-03-12T18:32:52Z", "published": "2025-03-11T21:30:36Z", "aliases": [ "CVE-2025-25928" ], "details": "A Cross-Site Request Forgery (CSRF) in the component /admin/users/user.form of Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitrary operations via a crafted GET request.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-11T20:15:17Z" diff --git a/advisories/unreviewed/2025/03/GHSA-82g5-9hm8-rvm3/GHSA-82g5-9hm8-rvm3.json b/advisories/unreviewed/2025/03/GHSA-82g5-9hm8-rvm3/GHSA-82g5-9hm8-rvm3.json new file mode 100644 index 00000000000..5a5b817587d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-82g5-9hm8-rvm3/GHSA-82g5-9hm8-rvm3.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-82g5-9hm8-rvm3", + "modified": "2025-03-12T18:32:52Z", + "published": "2025-03-12T18:32:52Z", + "aliases": [ + "CVE-2025-20144" + ], + "details": "A vulnerability in the hybrid access control list (ACL) processing of IPv4 packets in Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass a configured ACL.\n\nThis vulnerability is due to incorrect handling of packets when a specific configuration of the hybrid ACL exists. An attacker could exploit this vulnerability by attempting to send traffic through an affected device. A successful exploit could allow the attacker to bypass a configured ACL on the affected device.\nFor more information, see the section of this advisory.\nCisco has released software updates that address this vulnerability. There are workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20144" + }, + { + "type": "WEB", + "url": "https://blog.apnic.net/2024/09/02/crafting-endless-as-paths-in-bgp" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ncs-hybridacl-crMZFfKQ" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-12T16:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-86w8-vhw6-q9qq/GHSA-86w8-vhw6-q9qq.json b/advisories/unreviewed/2025/03/GHSA-86w8-vhw6-q9qq/GHSA-86w8-vhw6-q9qq.json index 66a1dc4d8d2..e826dc6311e 100644 --- a/advisories/unreviewed/2025/03/GHSA-86w8-vhw6-q9qq/GHSA-86w8-vhw6-q9qq.json +++ b/advisories/unreviewed/2025/03/GHSA-86w8-vhw6-q9qq/GHSA-86w8-vhw6-q9qq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-86w8-vhw6-q9qq", - "modified": "2025-03-12T15:32:06Z", + "modified": "2025-03-12T18:32:52Z", "published": "2025-03-12T15:32:06Z", "aliases": [ "CVE-2024-27763" ], "details": "XPixelGroup BasicSR through 1.4.2 might locally allow code execution in contrived situations where \"scontrol show hostname\" is executed in the presence of a crafted SLURM_NODELIST environment variable.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-12T15:15:39Z" diff --git a/advisories/unreviewed/2025/03/GHSA-8hg9-rcgr-qwwm/GHSA-8hg9-rcgr-qwwm.json b/advisories/unreviewed/2025/03/GHSA-8hg9-rcgr-qwwm/GHSA-8hg9-rcgr-qwwm.json new file mode 100644 index 00000000000..57b8d9327bf --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8hg9-rcgr-qwwm/GHSA-8hg9-rcgr-qwwm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8hg9-rcgr-qwwm", + "modified": "2025-03-12T18:32:53Z", + "published": "2025-03-12T18:32:53Z", + "aliases": [ + "CVE-2025-25566" + ], + "details": "Memory Leak vulnerability in SoftEtherVPN 5.02.5187 allows an attacker to cause a denial of service via the UnixMemoryAlloc function.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25566" + }, + { + "type": "WEB", + "url": "https://lzydry.github.io/CVE-2025-25566" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-12T16:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-93q8-2xpx-g486/GHSA-93q8-2xpx-g486.json b/advisories/unreviewed/2025/03/GHSA-93q8-2xpx-g486/GHSA-93q8-2xpx-g486.json index 2193be9f2cc..b100d61a7d3 100644 --- a/advisories/unreviewed/2025/03/GHSA-93q8-2xpx-g486/GHSA-93q8-2xpx-g486.json +++ b/advisories/unreviewed/2025/03/GHSA-93q8-2xpx-g486/GHSA-93q8-2xpx-g486.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-93q8-2xpx-g486", - "modified": "2025-03-08T12:30:31Z", + "modified": "2025-03-12T18:32:51Z", "published": "2025-03-08T12:30:30Z", "aliases": [ "CVE-2025-1323" diff --git a/advisories/unreviewed/2025/03/GHSA-96v5-c2h5-56hm/GHSA-96v5-c2h5-56hm.json b/advisories/unreviewed/2025/03/GHSA-96v5-c2h5-56hm/GHSA-96v5-c2h5-56hm.json index 6017c580f59..e1d8d59ff44 100644 --- a/advisories/unreviewed/2025/03/GHSA-96v5-c2h5-56hm/GHSA-96v5-c2h5-56hm.json +++ b/advisories/unreviewed/2025/03/GHSA-96v5-c2h5-56hm/GHSA-96v5-c2h5-56hm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-96v5-c2h5-56hm", - "modified": "2025-03-12T15:32:06Z", + "modified": "2025-03-12T18:32:52Z", "published": "2025-03-12T15:32:06Z", "aliases": [ "CVE-2025-29891" ], "details": "Bypass/Injection vulnerability in Apache Camel.\n\nThis issue affects Apache Camel: from 4.10.0 before 4.10.2, from 4.8.0 before 4.8.5, from 3.10.0 before 3.22.4.\n\nUsers are recommended to upgrade to version 4.10.2 for 4.10.x LTS, 4.8.5 for 4.8.x LTS and 3.22.4 for 3.x releases.\n\nThis vulnerability is present in Camel's default incoming header filter, that allows an attacker to include Camel specific headers that for some Camel components can alter the behaviours such as the camel-bean component, or the camel-exec component.\n\nIf you have Camel applications that are directly connected to the internet via HTTP, then an attacker could include parameters in the HTTP requests that are sent to the Camel application that incorrectly get translated into headers. \n\nThe headers could be both provided as request parameters for an HTTP methods invocation or as part of the payload of the HTTP methods invocation.\n\nAll the known Camel HTTP component such as camel-servlet, camel-jetty, camel-undertow, camel-platform-http, and camel-netty-http would be vulnerable out of the box.\n\nThis CVE is related to the CVE-2025-27636: while they have the same root cause and are fixed with the same fix, CVE-2025-27636 was assumed to only be exploitable if an attacker could add malicious HTTP headers, while we have now determined that it is also exploitable via HTTP parameters. Like in CVE-2025-27636, exploitation is only possible if the Camel route uses particular vulnerable components.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-164" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-12T15:15:40Z" diff --git a/advisories/unreviewed/2025/03/GHSA-9q9q-5rw5-gp2h/GHSA-9q9q-5rw5-gp2h.json b/advisories/unreviewed/2025/03/GHSA-9q9q-5rw5-gp2h/GHSA-9q9q-5rw5-gp2h.json new file mode 100644 index 00000000000..ae352995107 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9q9q-5rw5-gp2h/GHSA-9q9q-5rw5-gp2h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9q9q-5rw5-gp2h", + "modified": "2025-03-12T18:32:52Z", + "published": "2025-03-12T18:32:52Z", + "aliases": [ + "CVE-2025-1984" + ], + "details": "Xerox Desktop Print Experience application contains a Local Privilege Escalation (LPE) vulnerability, which allows a low-privileged user to gain SYSTEM-level access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1984" + }, + { + "type": "WEB", + "url": "https://securitydocs.business.xerox.com/wp-content/uploads/2025/03/Xerox-Security-Bulletin-XRX25-004-for-Xerox-FreeFlow-Print-Server-v7.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-12T16:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9w79-7j73-f648/GHSA-9w79-7j73-f648.json b/advisories/unreviewed/2025/03/GHSA-9w79-7j73-f648/GHSA-9w79-7j73-f648.json new file mode 100644 index 00000000000..5ba3a7135f4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9w79-7j73-f648/GHSA-9w79-7j73-f648.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9w79-7j73-f648", + "modified": "2025-03-12T18:32:52Z", + "published": "2025-03-12T18:32:52Z", + "aliases": [ + "CVE-2025-0813" + ], + "details": "CWE-287: Improper Authentication vulnerability exists that could cause an Authentication Bypass when an\nunauthorized user without permission rights has physical access to the EPAS-UI computer and is able to\nreboot the workstation and interrupt the normal boot process.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0813" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2025-070-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2025-070-02.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-12T16:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9xm2-hxxj-hgq7/GHSA-9xm2-hxxj-hgq7.json b/advisories/unreviewed/2025/03/GHSA-9xm2-hxxj-hgq7/GHSA-9xm2-hxxj-hgq7.json index 36386350788..14aaca15f39 100644 --- a/advisories/unreviewed/2025/03/GHSA-9xm2-hxxj-hgq7/GHSA-9xm2-hxxj-hgq7.json +++ b/advisories/unreviewed/2025/03/GHSA-9xm2-hxxj-hgq7/GHSA-9xm2-hxxj-hgq7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9xm2-hxxj-hgq7", - "modified": "2025-03-11T21:30:36Z", + "modified": "2025-03-12T18:32:52Z", "published": "2025-03-11T21:30:36Z", "aliases": [ "CVE-2025-25929" ], "details": "A reflected cross-site scripting (XSS) vulnerability in the component /legacyui/quickReportServlet of Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted payload injected into the reportType parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-11T20:15:17Z" diff --git a/advisories/unreviewed/2025/03/GHSA-c3wj-2vf4-295m/GHSA-c3wj-2vf4-295m.json b/advisories/unreviewed/2025/03/GHSA-c3wj-2vf4-295m/GHSA-c3wj-2vf4-295m.json new file mode 100644 index 00000000000..b33afd2203f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-c3wj-2vf4-295m/GHSA-c3wj-2vf4-295m.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c3wj-2vf4-295m", + "modified": "2025-03-12T18:32:53Z", + "published": "2025-03-12T18:32:53Z", + "aliases": [ + "CVE-2025-25683" + ], + "details": "AlekSIS-Core is vulnerable to Incorrect Access Control. Unauthenticated users can access all PDF files. This affects AlekSIS-Core 3.0, 3.1, 3.1.1, 3.1.2, 3.1.3, 3.1.4, 3.1.5, 3.1.6, 3.2.0 and 3.2.1.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25683" + }, + { + "type": "WEB", + "url": "https://aleksis.org/news/2025/01/security-advisory-cve-2025-25683-pdf-files-accessible-without-authentication" + }, + { + "type": "WEB", + "url": "https://edugit.org/AlekSIS/official/AlekSIS-Core/-/issues/1180" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-12T17:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cqp7-cmgp-m73g/GHSA-cqp7-cmgp-m73g.json b/advisories/unreviewed/2025/03/GHSA-cqp7-cmgp-m73g/GHSA-cqp7-cmgp-m73g.json new file mode 100644 index 00000000000..463c56961f9 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-cqp7-cmgp-m73g/GHSA-cqp7-cmgp-m73g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cqp7-cmgp-m73g", + "modified": "2025-03-12T18:32:52Z", + "published": "2025-03-12T18:32:52Z", + "aliases": [ + "CVE-2025-20145" + ], + "details": "A vulnerability in the access control list (ACL) processing in the egress direction of Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass a configured ACL.\n\nThis vulnerability exists because certain packets are handled incorrectly when they are received on an ingress interface on one line card and destined out of an egress interface on another line card where the egress ACL is configured. An attacker could exploit this vulnerability by attempting to send traffic through an affected device. A successful exploit could allow the attacker to bypass an egress ACL on the affected device.\nFor more information about this vulnerability, see the section of this advisory.\nCisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20145" + }, + { + "type": "WEB", + "url": "https://blog.apnic.net/2024/09/02/crafting-endless-as-paths-in-bgp" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-modular-ACL-u5MEPXMm" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-12T16:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cr97-553h-m39w/GHSA-cr97-553h-m39w.json b/advisories/unreviewed/2025/03/GHSA-cr97-553h-m39w/GHSA-cr97-553h-m39w.json new file mode 100644 index 00000000000..436f2ee175c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-cr97-553h-m39w/GHSA-cr97-553h-m39w.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cr97-553h-m39w", + "modified": "2025-03-12T18:32:53Z", + "published": "2025-03-12T18:32:53Z", + "aliases": [ + "CVE-2025-25568" + ], + "details": "SoftEtherVPN 5.02.5187 is vulnerable to Use after Free in the Command.c file via the CheckNetworkAcceptThread function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25568" + }, + { + "type": "WEB", + "url": "https://lzydry.github.io/CVE-2025-25568" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-12T16:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cxh3-prmp-2877/GHSA-cxh3-prmp-2877.json b/advisories/unreviewed/2025/03/GHSA-cxh3-prmp-2877/GHSA-cxh3-prmp-2877.json new file mode 100644 index 00000000000..9ff8c114728 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-cxh3-prmp-2877/GHSA-cxh3-prmp-2877.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cxh3-prmp-2877", + "modified": "2025-03-12T18:32:52Z", + "published": "2025-03-12T18:32:52Z", + "aliases": [ + "CVE-2025-0883" + ], + "details": "Improper Neutralization of Script in an Error Message Web Page vulnerability in OpenText™ Service Manager. \n\nThe vulnerability could reveal sensitive information retained by the browser.\n\nThis issue affects Service Manager: 9.70, 9.71, 9.72, 9.80.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:N/R:A/V:C/RE:M/U:Green" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0883" + }, + { + "type": "WEB", + "url": "https://portal.microfocus.com/s/article/KM000037099?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-81" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-12T16:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-f6jg-88p5-x574/GHSA-f6jg-88p5-x574.json b/advisories/unreviewed/2025/03/GHSA-f6jg-88p5-x574/GHSA-f6jg-88p5-x574.json new file mode 100644 index 00000000000..0fc8e1930a5 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-f6jg-88p5-x574/GHSA-f6jg-88p5-x574.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f6jg-88p5-x574", + "modified": "2025-03-12T18:32:53Z", + "published": "2025-03-12T18:32:53Z", + "aliases": [ + "CVE-2025-20146" + ], + "details": "A vulnerability in the Layer 3 multicast feature of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers, ASR 9902 Compact High-Performance Routers, and ASR 9903 Compact High-Performance Routers could allow an unauthenticated, remote attacker to cause a line card to reset, resulting in a denial of service (DoS) condition.\n\nThis vulnerability is due to the incorrect handling of malformed IPv4 multicast packets that are received on line cards where the interface has either an IPv4 access control list (ACL) or a QoS policy applied. An attacker could exploit this vulnerability by sending crafted IPv4 multicast packets through an affected device. A successful exploit could allow the attacker to cause line card exceptions or a hard reset. Traffic over that line card would be lost while the line card reloads.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20146" + }, + { + "type": "WEB", + "url": "https://blog.apnic.net/2024/09/02/crafting-endless-as-paths-in-bgp" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-multicast-ERMrSvq7" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-12T16:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-f769-hvjj-2wv2/GHSA-f769-hvjj-2wv2.json b/advisories/unreviewed/2025/03/GHSA-f769-hvjj-2wv2/GHSA-f769-hvjj-2wv2.json new file mode 100644 index 00000000000..823f016138a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-f769-hvjj-2wv2/GHSA-f769-hvjj-2wv2.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f769-hvjj-2wv2", + "modified": "2025-03-12T18:32:53Z", + "published": "2025-03-12T18:32:53Z", + "aliases": [ + "CVE-2025-20209" + ], + "details": "A vulnerability in the Internet Key Exchange version 2 (IKEv2) function of Cisco IOS XR Software could allow an unauthenticated, remote attacker to prevent an affected device from processing any control plane UDP packets. \n\nThis vulnerability is due to improper handling of malformed IKEv2 packets. An attacker could exploit this vulnerability by sending malformed IKEv2 packets to an affected device. A successful exploit could allow the attacker to prevent the affected device from processing any control plane UDP packets, resulting in a denial of service (DoS) condition.\nCisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20209" + }, + { + "type": "WEB", + "url": "https://blog.apnic.net/2024/09/02/crafting-endless-as-paths-in-bgp" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-xrike-9wYGpRGq" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-12T16:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-f86q-56fj-v562/GHSA-f86q-56fj-v562.json b/advisories/unreviewed/2025/03/GHSA-f86q-56fj-v562/GHSA-f86q-56fj-v562.json new file mode 100644 index 00000000000..1e88a1cb1ad --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-f86q-56fj-v562/GHSA-f86q-56fj-v562.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f86q-56fj-v562", + "modified": "2025-03-12T18:32:52Z", + "published": "2025-03-12T18:32:52Z", + "aliases": [ + "CVE-2025-0884" + ], + "details": "Unquoted Search Path or Element vulnerability in OpenText™ Service Manager. \n\nThe vulnerability could allow a user to gain SYSTEM privileges through Privilege Escalation.\n\nThis issue affects Service Manager: 9.70, 9.71, 9.72.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:N/R:A/V:C/RE:M/U:Green" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0884" + }, + { + "type": "WEB", + "url": "https://portal.microfocus.com/s/article/KM000036731?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-428" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-12T16:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fw35-27g6-hvhf/GHSA-fw35-27g6-hvhf.json b/advisories/unreviewed/2025/03/GHSA-fw35-27g6-hvhf/GHSA-fw35-27g6-hvhf.json index 4c7ced887b7..9106db0eb33 100644 --- a/advisories/unreviewed/2025/03/GHSA-fw35-27g6-hvhf/GHSA-fw35-27g6-hvhf.json +++ b/advisories/unreviewed/2025/03/GHSA-fw35-27g6-hvhf/GHSA-fw35-27g6-hvhf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fw35-27g6-hvhf", - "modified": "2025-03-11T18:32:13Z", + "modified": "2025-03-12T18:32:52Z", "published": "2025-03-11T18:32:13Z", "aliases": [ "CVE-2025-25747" ], "details": "Cross Site Scripting vulnerability in DigitalDruid HotelDruid v.3.0.7 allows an attacker to execute arbitrary code and obtain sensitive information via the ripristina_backup parameter in the crea_backup.php endpoint", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-11T16:15:17Z" diff --git a/advisories/unreviewed/2025/03/GHSA-hghx-c858-jm7q/GHSA-hghx-c858-jm7q.json b/advisories/unreviewed/2025/03/GHSA-hghx-c858-jm7q/GHSA-hghx-c858-jm7q.json new file mode 100644 index 00000000000..34769e113a7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hghx-c858-jm7q/GHSA-hghx-c858-jm7q.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hghx-c858-jm7q", + "modified": "2025-03-12T18:32:53Z", + "published": "2025-03-12T18:32:53Z", + "aliases": [ + "CVE-2025-20177" + ], + "details": "A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker to bypass Cisco IOS XR image signature verification and load unverified software on an affected device. To exploit this vulnerability, the attacker must have root-system privileges on the affected device.\n\nThis vulnerability is due to incomplete validation of files in the boot verification process. An attacker could exploit this vulnerability by manipulating the system configuration options to bypass some of the integrity checks that are performed during the boot process. A successful exploit could allow the attacker to control the boot configuration, which could enable them to bypass the requirement to run Cisco-signed images or alter the security properties of the running system.\nNote: Because exploitation of this vulnerability could result in the attacker bypassing Cisco image verification, Cisco has raised the Security Impact Rating (SIR) of this advisory from Medium to High.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20177" + }, + { + "type": "WEB", + "url": "https://blog.apnic.net/2024/09/02/crafting-endless-as-paths-in-bgp" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ios-xr-verii-bypass-HhPwQRvx" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-274" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-12T16:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-j3vw-gxh2-3r2w/GHSA-j3vw-gxh2-3r2w.json b/advisories/unreviewed/2025/03/GHSA-j3vw-gxh2-3r2w/GHSA-j3vw-gxh2-3r2w.json new file mode 100644 index 00000000000..421fa081664 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-j3vw-gxh2-3r2w/GHSA-j3vw-gxh2-3r2w.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j3vw-gxh2-3r2w", + "modified": "2025-03-12T18:32:53Z", + "published": "2025-03-12T18:32:53Z", + "aliases": [ + "CVE-2024-34398" + ], + "details": "An issue was discovered in BMC Remedy Mid Tier 7.6.04. The web application allows stored HTML Injection by authenticated remote attackers.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34398" + }, + { + "type": "WEB", + "url": "https://www.gruppotim.it/it/footer/red-team.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-12T17:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jcwm-grfm-4xmh/GHSA-jcwm-grfm-4xmh.json b/advisories/unreviewed/2025/03/GHSA-jcwm-grfm-4xmh/GHSA-jcwm-grfm-4xmh.json new file mode 100644 index 00000000000..2d4c03481e4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jcwm-grfm-4xmh/GHSA-jcwm-grfm-4xmh.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jcwm-grfm-4xmh", + "modified": "2025-03-12T18:32:52Z", + "published": "2025-03-12T18:32:52Z", + "aliases": [ + "CVE-2025-1683" + ], + "details": "Improper link resolution before file access in the Nomad module of the 1E Client, in versions prior to 25.3, enables an attacker with local unprivileged access on a Windows system to delete arbitrary files on the device by exploiting symbolic links.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1683" + }, + { + "type": "WEB", + "url": "https://capec.mitre.org/data/definitions/27.html" + }, + { + "type": "WEB", + "url": "https://cwe.mitre.org/data/definitions/59.html" + }, + { + "type": "WEB", + "url": "https://www.1e.com/trust-security-compliance/cve-info" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-12T16:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jrp2-pgjj-vwpm/GHSA-jrp2-pgjj-vwpm.json b/advisories/unreviewed/2025/03/GHSA-jrp2-pgjj-vwpm/GHSA-jrp2-pgjj-vwpm.json new file mode 100644 index 00000000000..3a310391c6f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jrp2-pgjj-vwpm/GHSA-jrp2-pgjj-vwpm.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jrp2-pgjj-vwpm", + "modified": "2025-03-12T18:32:53Z", + "published": "2025-03-12T18:32:53Z", + "aliases": [ + "CVE-2025-2002" + ], + "details": "CWE-532: Insertion of Sensitive Information into Log Files vulnerability exists that could cause the disclosure\nof FTP server credentials when the FTP server is deployed, and the device is placed in debug mode by an\nadministrative user and the debug files are exported from the device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2002" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2025-070-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2025-070-01.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-12T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jwwj-7cm7-g363/GHSA-jwwj-7cm7-g363.json b/advisories/unreviewed/2025/03/GHSA-jwwj-7cm7-g363/GHSA-jwwj-7cm7-g363.json new file mode 100644 index 00000000000..4d452decede --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jwwj-7cm7-g363/GHSA-jwwj-7cm7-g363.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jwwj-7cm7-g363", + "modified": "2025-03-12T18:32:52Z", + "published": "2025-03-12T18:32:52Z", + "aliases": [ + "CVE-2025-20138" + ], + "details": "A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying operating system of an affected device.\n\nThis vulnerability is due to insufficient validation of user arguments that are passed to specific CLI commands. An attacker with a low-privileged account could exploit this vulnerability by using crafted commands at the prompt. A successful exploit could allow the attacker to elevate privileges to root and execute arbitrary commands.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20138" + }, + { + "type": "WEB", + "url": "https://blog.apnic.net/2024/09/02/crafting-endless-as-paths-in-bgp" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-priv-esc-GFQjxvOF" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-12T16:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mx4h-4r93-47mh/GHSA-mx4h-4r93-47mh.json b/advisories/unreviewed/2025/03/GHSA-mx4h-4r93-47mh/GHSA-mx4h-4r93-47mh.json index b2e5920614b..ebd2fdf4f3e 100644 --- a/advisories/unreviewed/2025/03/GHSA-mx4h-4r93-47mh/GHSA-mx4h-4r93-47mh.json +++ b/advisories/unreviewed/2025/03/GHSA-mx4h-4r93-47mh/GHSA-mx4h-4r93-47mh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mx4h-4r93-47mh", - "modified": "2025-03-11T21:30:36Z", + "modified": "2025-03-12T18:32:52Z", "published": "2025-03-11T21:30:36Z", "aliases": [ "CVE-2025-25927" ], "details": "A Cross-Site Request Forgery (CSRF) in Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitrary operations via a crafted GET request.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-11T20:15:17Z" diff --git a/advisories/unreviewed/2025/03/GHSA-p487-45r6-v8fh/GHSA-p487-45r6-v8fh.json b/advisories/unreviewed/2025/03/GHSA-p487-45r6-v8fh/GHSA-p487-45r6-v8fh.json new file mode 100644 index 00000000000..6cc67f80235 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-p487-45r6-v8fh/GHSA-p487-45r6-v8fh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p487-45r6-v8fh", + "modified": "2025-03-12T18:32:53Z", + "published": "2025-03-12T18:32:53Z", + "aliases": [ + "CVE-2025-25711" + ], + "details": "An issue in dtp.ae tNexus Airport View v.2.8 allows a remote attacker to escalate privileges via the ProfileID value to the [/tnexus/rest/admin/updateUser] API endpoint", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25711" + }, + { + "type": "WEB", + "url": "https://github.com/z5jt/vulnerability-research/tree/main/CVE-2025-25710" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-281" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-12T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-pg35-89w5-5c5h/GHSA-pg35-89w5-5c5h.json b/advisories/unreviewed/2025/03/GHSA-pg35-89w5-5c5h/GHSA-pg35-89w5-5c5h.json new file mode 100644 index 00000000000..1a245b78049 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-pg35-89w5-5c5h/GHSA-pg35-89w5-5c5h.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pg35-89w5-5c5h", + "modified": "2025-03-12T18:32:53Z", + "published": "2025-03-12T18:32:53Z", + "aliases": [ + "CVE-2025-25565" + ], + "details": "SoftEther VPN 5.02.5187 is vulnerable to Buffer Overflow in the Command.c file via the PtMakeCert and PtMakeCert2048 functions.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25565" + }, + { + "type": "WEB", + "url": "https://lzydry.github.io/CVE-2025-25565" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-12T16:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-q2xv-553m-pcwq/GHSA-q2xv-553m-pcwq.json b/advisories/unreviewed/2025/03/GHSA-q2xv-553m-pcwq/GHSA-q2xv-553m-pcwq.json index 41b1490e84a..e12ed05a561 100644 --- a/advisories/unreviewed/2025/03/GHSA-q2xv-553m-pcwq/GHSA-q2xv-553m-pcwq.json +++ b/advisories/unreviewed/2025/03/GHSA-q2xv-553m-pcwq/GHSA-q2xv-553m-pcwq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q2xv-553m-pcwq", - "modified": "2025-03-08T06:30:42Z", + "modified": "2025-03-12T18:32:50Z", "published": "2025-03-08T06:30:42Z", "aliases": [ "CVE-2024-12114" diff --git a/advisories/unreviewed/2025/03/GHSA-rp6p-7xx7-cr6f/GHSA-rp6p-7xx7-cr6f.json b/advisories/unreviewed/2025/03/GHSA-rp6p-7xx7-cr6f/GHSA-rp6p-7xx7-cr6f.json new file mode 100644 index 00000000000..025d8d7daf1 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rp6p-7xx7-cr6f/GHSA-rp6p-7xx7-cr6f.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rp6p-7xx7-cr6f", + "modified": "2025-03-12T18:32:52Z", + "published": "2025-03-12T18:32:52Z", + "aliases": [ + "CVE-2025-20115" + ], + "details": "A vulnerability in confederation implementation for the Border Gateway Protocol (BGP) in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.\n\nThis vulnerability is due to a memory corruption that occurs when a BGP update is created with an AS_CONFED_SEQUENCE attribute that has 255 autonomous system numbers (AS numbers). An attacker could exploit this vulnerability by sending a crafted BGP update message, or the network could be designed in such a manner that the AS_CONFED_SEQUENCE attribute grows to 255 AS numbers or more. A successful exploit could allow the attacker to cause memory corruption, which may cause the BGP process to restart, resulting in a DoS condition. To exploit this vulnerability, an attacker must control a BGP confederation speaker within the same autonomous system as the victim, or the network must be designed in such a manner that the AS_CONFED_SEQUENCE attribute grows to 255 AS numbers or more.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20115" + }, + { + "type": "WEB", + "url": "https://blog.apnic.net/2024/09/02/crafting-endless-as-paths-in-bgp" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-bgp-dos-O7stePhX" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-12T16:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-v888-xcc4-jmr2/GHSA-v888-xcc4-jmr2.json b/advisories/unreviewed/2025/03/GHSA-v888-xcc4-jmr2/GHSA-v888-xcc4-jmr2.json index c2808a4f128..3640ee156d6 100644 --- a/advisories/unreviewed/2025/03/GHSA-v888-xcc4-jmr2/GHSA-v888-xcc4-jmr2.json +++ b/advisories/unreviewed/2025/03/GHSA-v888-xcc4-jmr2/GHSA-v888-xcc4-jmr2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v888-xcc4-jmr2", - "modified": "2025-03-11T00:31:49Z", + "modified": "2025-03-12T18:32:52Z", "published": "2025-03-11T00:31:49Z", "aliases": [ "CVE-2025-27910" ], "details": "tianti v2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /user/ajax/upd/status. This vulnerability allows attackers to execute arbitrary operations via a crafted GET or POST request.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-10T22:15:27Z" diff --git a/advisories/unreviewed/2025/03/GHSA-w9ff-5p26-w67v/GHSA-w9ff-5p26-w67v.json b/advisories/unreviewed/2025/03/GHSA-w9ff-5p26-w67v/GHSA-w9ff-5p26-w67v.json new file mode 100644 index 00000000000..951f1668e30 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-w9ff-5p26-w67v/GHSA-w9ff-5p26-w67v.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w9ff-5p26-w67v", + "modified": "2025-03-12T18:32:52Z", + "published": "2025-03-12T18:32:52Z", + "aliases": [ + "CVE-2025-20142" + ], + "details": "A vulnerability in the IPv4 access control list (ACL) feature and quality of service (QoS) policy feature of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers, ASR 9902 Compact High-Performance Routers, and ASR 9903 Compact High-Performance Routers could allow an unauthenticated, remote attacker to cause a line card to reset, resulting in a denial of service (DoS) condition.\n\nThis vulnerability is due to the incorrect handling of malformed IPv4 packets that are received on line cards where the interface has either an IPv4 ACL or QoS policy applied. An attacker could exploit this vulnerability by sending crafted IPv4 packets through an affected device. A successful exploit could allow the attacker to cause network processor errors, resulting in a reset or shutdown of the network process. Traffic over that line card would be lost while the line card reloads.\nNote: This vulnerability has predominantly been observed in Layer 2 VPN (L2VPN) environments where an IPv4 ACL or QoS policy has been applied to the bridge virtual interface. Layer 3 configurations where the interface has either an IPv4 ACL or QoS policy applied are also affected, though the vulnerability has not been observed.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20142" + }, + { + "type": "WEB", + "url": "https://blog.apnic.net/2024/09/02/crafting-endless-as-paths-in-bgp" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ipv4uni-LfM3cfBu" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-12T16:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wjvr-8c9r-fgmc/GHSA-wjvr-8c9r-fgmc.json b/advisories/unreviewed/2025/03/GHSA-wjvr-8c9r-fgmc/GHSA-wjvr-8c9r-fgmc.json new file mode 100644 index 00000000000..64276f72ca6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wjvr-8c9r-fgmc/GHSA-wjvr-8c9r-fgmc.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wjvr-8c9r-fgmc", + "modified": "2025-03-12T18:32:53Z", + "published": "2025-03-12T18:32:53Z", + "aliases": [ + "CVE-2025-25774" + ], + "details": "An issue was discovered in Open5GS v2.7.2. When a UE switches between two gNBs and sends a handover request at a specific time, it may cause an exception in the AMF's internal state machine, leading to an AMF crash and resulting in a Denial of Service (DoS).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25774" + }, + { + "type": "WEB", + "url": "https://github.com/open5gs/open5gs/issues/3671" + }, + { + "type": "WEB", + "url": "https://github.com/open5gs/open5gs/commit/2e68706f1eea029d5172ccad946e78b352c031d0" + }, + { + "type": "WEB", + "url": "https://github.com/guoweifk/BugReport/blob/main/Open5GS%20AMF%20Denial%20of%20Service%20via%20GMM%20State%20Handling%20in%20Handover" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-12T17:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xr5m-494h-32gf/GHSA-xr5m-494h-32gf.json b/advisories/unreviewed/2025/03/GHSA-xr5m-494h-32gf/GHSA-xr5m-494h-32gf.json index 462dabb5258..f4697ad20f5 100644 --- a/advisories/unreviewed/2025/03/GHSA-xr5m-494h-32gf/GHSA-xr5m-494h-32gf.json +++ b/advisories/unreviewed/2025/03/GHSA-xr5m-494h-32gf/GHSA-xr5m-494h-32gf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xr5m-494h-32gf", - "modified": "2025-03-12T15:32:05Z", + "modified": "2025-03-12T18:32:52Z", "published": "2025-03-12T15:32:05Z", "aliases": [ "CVE-2025-27914" ], "details": "An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Reflected Cross-Site Scripting (XSS) vulnerability exists in the /h/rest endpoint, allowing authenticated attackers to inject and execute arbitrary JavaScript in a victim's session. Exploitation requires a valid auth token and involves a crafted URL with manipulated query parameters that triggers XSS when accessed by a victim.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-12T15:15:39Z"