diff --git a/advisories/unreviewed/2022/10/GHSA-784c-xcf7-3mm9/GHSA-784c-xcf7-3mm9.json b/advisories/unreviewed/2022/10/GHSA-784c-xcf7-3mm9/GHSA-784c-xcf7-3mm9.json index ce23930baf1..c7163561734 100644 --- a/advisories/unreviewed/2022/10/GHSA-784c-xcf7-3mm9/GHSA-784c-xcf7-3mm9.json +++ b/advisories/unreviewed/2022/10/GHSA-784c-xcf7-3mm9/GHSA-784c-xcf7-3mm9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-784c-xcf7-3mm9", - "modified": "2022-10-18T19:00:35Z", + "modified": "2025-05-16T15:30:30Z", "published": "2022-10-14T12:00:25Z", "aliases": [ "CVE-2022-42160" diff --git a/advisories/unreviewed/2022/10/GHSA-83wm-8m7x-7559/GHSA-83wm-8m7x-7559.json b/advisories/unreviewed/2022/10/GHSA-83wm-8m7x-7559/GHSA-83wm-8m7x-7559.json index 9bfe8d49a9c..4a4f54cb389 100644 --- a/advisories/unreviewed/2022/10/GHSA-83wm-8m7x-7559/GHSA-83wm-8m7x-7559.json +++ b/advisories/unreviewed/2022/10/GHSA-83wm-8m7x-7559/GHSA-83wm-8m7x-7559.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-83wm-8m7x-7559", - "modified": "2022-10-13T19:00:17Z", + "modified": "2025-05-16T15:30:30Z", "published": "2022-10-13T12:00:27Z", "aliases": [ "CVE-2018-18447" diff --git a/advisories/unreviewed/2022/10/GHSA-hq39-62g2-phr4/GHSA-hq39-62g2-phr4.json b/advisories/unreviewed/2022/10/GHSA-hq39-62g2-phr4/GHSA-hq39-62g2-phr4.json index 1b04b71640c..b226a78110c 100644 --- a/advisories/unreviewed/2022/10/GHSA-hq39-62g2-phr4/GHSA-hq39-62g2-phr4.json +++ b/advisories/unreviewed/2022/10/GHSA-hq39-62g2-phr4/GHSA-hq39-62g2-phr4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hq39-62g2-phr4", - "modified": "2022-10-14T19:00:32Z", + "modified": "2025-05-16T15:30:29Z", "published": "2022-10-12T12:00:17Z", "aliases": [ "CVE-2022-2720" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-359" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-r2x7-j5fh-23fq/GHSA-r2x7-j5fh-23fq.json b/advisories/unreviewed/2022/10/GHSA-r2x7-j5fh-23fq/GHSA-r2x7-j5fh-23fq.json index d4a9f91a760..b5c3f285f01 100644 --- a/advisories/unreviewed/2022/10/GHSA-r2x7-j5fh-23fq/GHSA-r2x7-j5fh-23fq.json +++ b/advisories/unreviewed/2022/10/GHSA-r2x7-j5fh-23fq/GHSA-r2x7-j5fh-23fq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r2x7-j5fh-23fq", - "modified": "2022-10-13T19:00:17Z", + "modified": "2025-05-16T15:30:30Z", "published": "2022-10-13T12:00:27Z", "aliases": [ "CVE-2018-18446" diff --git a/advisories/unreviewed/2022/10/GHSA-vjfh-j2ff-qxw8/GHSA-vjfh-j2ff-qxw8.json b/advisories/unreviewed/2022/10/GHSA-vjfh-j2ff-qxw8/GHSA-vjfh-j2ff-qxw8.json index 8686efe27b9..10500f91df9 100644 --- a/advisories/unreviewed/2022/10/GHSA-vjfh-j2ff-qxw8/GHSA-vjfh-j2ff-qxw8.json +++ b/advisories/unreviewed/2022/10/GHSA-vjfh-j2ff-qxw8/GHSA-vjfh-j2ff-qxw8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vjfh-j2ff-qxw8", - "modified": "2022-10-18T19:00:35Z", + "modified": "2025-05-16T15:30:30Z", "published": "2022-10-14T12:00:25Z", "aliases": [ "CVE-2022-42159" @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-335", "CWE-338" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/07/GHSA-2cp6-jcj8-ghrh/GHSA-2cp6-jcj8-ghrh.json b/advisories/unreviewed/2024/07/GHSA-2cp6-jcj8-ghrh/GHSA-2cp6-jcj8-ghrh.json index 6fe51d154d3..d8c84eadec4 100644 --- a/advisories/unreviewed/2024/07/GHSA-2cp6-jcj8-ghrh/GHSA-2cp6-jcj8-ghrh.json +++ b/advisories/unreviewed/2024/07/GHSA-2cp6-jcj8-ghrh/GHSA-2cp6-jcj8-ghrh.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-5pqp-q4fm-4p4h/GHSA-5pqp-q4fm-4p4h.json b/advisories/unreviewed/2024/07/GHSA-5pqp-q4fm-4p4h/GHSA-5pqp-q4fm-4p4h.json index b8f4452e579..c2cf2a2fe47 100644 --- a/advisories/unreviewed/2024/07/GHSA-5pqp-q4fm-4p4h/GHSA-5pqp-q4fm-4p4h.json +++ b/advisories/unreviewed/2024/07/GHSA-5pqp-q4fm-4p4h/GHSA-5pqp-q4fm-4p4h.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-918" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-7rh6-j5jq-q5m7/GHSA-7rh6-j5jq-q5m7.json b/advisories/unreviewed/2024/07/GHSA-7rh6-j5jq-q5m7/GHSA-7rh6-j5jq-q5m7.json index 57b1adaa86e..24f5bab5933 100644 --- a/advisories/unreviewed/2024/07/GHSA-7rh6-j5jq-q5m7/GHSA-7rh6-j5jq-q5m7.json +++ b/advisories/unreviewed/2024/07/GHSA-7rh6-j5jq-q5m7/GHSA-7rh6-j5jq-q5m7.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-cc52-c5qx-vgg7/GHSA-cc52-c5qx-vgg7.json b/advisories/unreviewed/2024/07/GHSA-cc52-c5qx-vgg7/GHSA-cc52-c5qx-vgg7.json index 15e87735164..4da6f9a4aa1 100644 --- a/advisories/unreviewed/2024/07/GHSA-cc52-c5qx-vgg7/GHSA-cc52-c5qx-vgg7.json +++ b/advisories/unreviewed/2024/07/GHSA-cc52-c5qx-vgg7/GHSA-cc52-c5qx-vgg7.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-w4jg-m5rc-ppx7/GHSA-w4jg-m5rc-ppx7.json b/advisories/unreviewed/2024/07/GHSA-w4jg-m5rc-ppx7/GHSA-w4jg-m5rc-ppx7.json index b01eb031035..0ab29a51974 100644 --- a/advisories/unreviewed/2024/07/GHSA-w4jg-m5rc-ppx7/GHSA-w4jg-m5rc-ppx7.json +++ b/advisories/unreviewed/2024/07/GHSA-w4jg-m5rc-ppx7/GHSA-w4jg-m5rc-ppx7.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-xfx6-r52c-8v32/GHSA-xfx6-r52c-8v32.json b/advisories/unreviewed/2024/07/GHSA-xfx6-r52c-8v32/GHSA-xfx6-r52c-8v32.json index 9009b0c26bb..659e993125e 100644 --- a/advisories/unreviewed/2024/07/GHSA-xfx6-r52c-8v32/GHSA-xfx6-r52c-8v32.json +++ b/advisories/unreviewed/2024/07/GHSA-xfx6-r52c-8v32/GHSA-xfx6-r52c-8v32.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-5227-22f5-m93m/GHSA-5227-22f5-m93m.json b/advisories/unreviewed/2025/01/GHSA-5227-22f5-m93m/GHSA-5227-22f5-m93m.json index cd00c8d10d6..8c64cee3fcf 100644 --- a/advisories/unreviewed/2025/01/GHSA-5227-22f5-m93m/GHSA-5227-22f5-m93m.json +++ b/advisories/unreviewed/2025/01/GHSA-5227-22f5-m93m/GHSA-5227-22f5-m93m.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-610" + "CWE-610", + "CWE-918" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-6gw3-w4cq-hccr/GHSA-6gw3-w4cq-hccr.json b/advisories/unreviewed/2025/01/GHSA-6gw3-w4cq-hccr/GHSA-6gw3-w4cq-hccr.json index 765a96ef0ac..56416efa77b 100644 --- a/advisories/unreviewed/2025/01/GHSA-6gw3-w4cq-hccr/GHSA-6gw3-w4cq-hccr.json +++ b/advisories/unreviewed/2025/01/GHSA-6gw3-w4cq-hccr/GHSA-6gw3-w4cq-hccr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6gw3-w4cq-hccr", - "modified": "2025-01-13T00:30:54Z", + "modified": "2025-05-16T15:30:32Z", "published": "2025-01-13T00:30:54Z", "aliases": [ "CVE-2024-42179" diff --git a/advisories/unreviewed/2025/01/GHSA-h99c-49qw-qq9r/GHSA-h99c-49qw-qq9r.json b/advisories/unreviewed/2025/01/GHSA-h99c-49qw-qq9r/GHSA-h99c-49qw-qq9r.json index d5d6f0a3cb4..be8c8227691 100644 --- a/advisories/unreviewed/2025/01/GHSA-h99c-49qw-qq9r/GHSA-h99c-49qw-qq9r.json +++ b/advisories/unreviewed/2025/01/GHSA-h99c-49qw-qq9r/GHSA-h99c-49qw-qq9r.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-522" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-pc2q-2r77-c6mp/GHSA-pc2q-2r77-c6mp.json b/advisories/unreviewed/2025/01/GHSA-pc2q-2r77-c6mp/GHSA-pc2q-2r77-c6mp.json index 45712373a2d..bb396f41901 100644 --- a/advisories/unreviewed/2025/01/GHSA-pc2q-2r77-c6mp/GHSA-pc2q-2r77-c6mp.json +++ b/advisories/unreviewed/2025/01/GHSA-pc2q-2r77-c6mp/GHSA-pc2q-2r77-c6mp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pc2q-2r77-c6mp", - "modified": "2025-01-11T09:30:30Z", + "modified": "2025-05-16T15:30:32Z", "published": "2025-01-11T09:30:30Z", "aliases": [ "CVE-2024-42174" @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-203", "CWE-204" ], "severity": "LOW", diff --git a/advisories/unreviewed/2025/04/GHSA-5fx4-fffc-mc96/GHSA-5fx4-fffc-mc96.json b/advisories/unreviewed/2025/04/GHSA-5fx4-fffc-mc96/GHSA-5fx4-fffc-mc96.json index 9d26786abe5..327a8043e22 100644 --- a/advisories/unreviewed/2025/04/GHSA-5fx4-fffc-mc96/GHSA-5fx4-fffc-mc96.json +++ b/advisories/unreviewed/2025/04/GHSA-5fx4-fffc-mc96/GHSA-5fx4-fffc-mc96.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-23" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/04/GHSA-7fmq-3cjw-pvhf/GHSA-7fmq-3cjw-pvhf.json b/advisories/unreviewed/2025/04/GHSA-7fmq-3cjw-pvhf/GHSA-7fmq-3cjw-pvhf.json index dea8201fdd8..b21004e6888 100644 --- a/advisories/unreviewed/2025/04/GHSA-7fmq-3cjw-pvhf/GHSA-7fmq-3cjw-pvhf.json +++ b/advisories/unreviewed/2025/04/GHSA-7fmq-3cjw-pvhf/GHSA-7fmq-3cjw-pvhf.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-295", "CWE-296" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/04/GHSA-7xcg-8h7r-rgfx/GHSA-7xcg-8h7r-rgfx.json b/advisories/unreviewed/2025/04/GHSA-7xcg-8h7r-rgfx/GHSA-7xcg-8h7r-rgfx.json index 4e2a05fa7b7..c523fb058f2 100644 --- a/advisories/unreviewed/2025/04/GHSA-7xcg-8h7r-rgfx/GHSA-7xcg-8h7r-rgfx.json +++ b/advisories/unreviewed/2025/04/GHSA-7xcg-8h7r-rgfx/GHSA-7xcg-8h7r-rgfx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7xcg-8h7r-rgfx", - "modified": "2025-04-15T21:31:47Z", + "modified": "2025-05-16T15:30:35Z", "published": "2025-04-15T21:31:47Z", "aliases": [ "CVE-2025-30712" @@ -15,6 +15,10 @@ ], "affected": [], "references": [ + { + "type": "WEB", + "url": "https://github.com/google/security-research/security/advisories/GHSA-qx2m-rcpc-v43v" + }, { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30712" @@ -26,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-190", "CWE-284" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/04/GHSA-9vr8-xm3r-rrx9/GHSA-9vr8-xm3r-rrx9.json b/advisories/unreviewed/2025/04/GHSA-9vr8-xm3r-rrx9/GHSA-9vr8-xm3r-rrx9.json index ac522b49d27..e51e5c14fac 100644 --- a/advisories/unreviewed/2025/04/GHSA-9vr8-xm3r-rrx9/GHSA-9vr8-xm3r-rrx9.json +++ b/advisories/unreviewed/2025/04/GHSA-9vr8-xm3r-rrx9/GHSA-9vr8-xm3r-rrx9.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-fhm7-xr45-vvhp/GHSA-fhm7-xr45-vvhp.json b/advisories/unreviewed/2025/04/GHSA-fhm7-xr45-vvhp/GHSA-fhm7-xr45-vvhp.json index 8665664f448..6b0abf86d6d 100644 --- a/advisories/unreviewed/2025/04/GHSA-fhm7-xr45-vvhp/GHSA-fhm7-xr45-vvhp.json +++ b/advisories/unreviewed/2025/04/GHSA-fhm7-xr45-vvhp/GHSA-fhm7-xr45-vvhp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fhm7-xr45-vvhp", - "modified": "2025-04-17T21:31:05Z", + "modified": "2025-05-16T15:30:35Z", "published": "2025-04-17T21:31:05Z", "aliases": [ "CVE-2024-42177" diff --git a/advisories/unreviewed/2025/04/GHSA-mmp3-fv2j-fw7v/GHSA-mmp3-fv2j-fw7v.json b/advisories/unreviewed/2025/04/GHSA-mmp3-fv2j-fw7v/GHSA-mmp3-fv2j-fw7v.json index f0ea1f0ebcc..430b8e9e146 100644 --- a/advisories/unreviewed/2025/04/GHSA-mmp3-fv2j-fw7v/GHSA-mmp3-fv2j-fw7v.json +++ b/advisories/unreviewed/2025/04/GHSA-mmp3-fv2j-fw7v/GHSA-mmp3-fv2j-fw7v.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-288" + "CWE-288", + "CWE-306" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-26vj-q53w-3g76/GHSA-26vj-q53w-3g76.json b/advisories/unreviewed/2025/05/GHSA-26vj-q53w-3g76/GHSA-26vj-q53w-3g76.json new file mode 100644 index 00000000000..4d20070fb2a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-26vj-q53w-3g76/GHSA-26vj-q53w-3g76.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-26vj-q53w-3g76", + "modified": "2025-05-16T15:31:03Z", + "published": "2025-05-16T15:31:03Z", + "aliases": [ + "CVE-2025-4777" + ], + "details": "A vulnerability was found in PHPGurukul Park Ticketing Management System 2.0. It has been classified as critical. This affects an unknown part of the file /view-foreigner-ticket.php. The manipulation of the argument viewid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4777" + }, + { + "type": "WEB", + "url": "https://github.com/f1rstb100d/myCVE/issues/3" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309075" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309075" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.572155" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T13:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2f2v-g446-pw52/GHSA-2f2v-g446-pw52.json b/advisories/unreviewed/2025/05/GHSA-2f2v-g446-pw52/GHSA-2f2v-g446-pw52.json index 76ef652fc9c..2d16f29e748 100644 --- a/advisories/unreviewed/2025/05/GHSA-2f2v-g446-pw52/GHSA-2f2v-g446-pw52.json +++ b/advisories/unreviewed/2025/05/GHSA-2f2v-g446-pw52/GHSA-2f2v-g446-pw52.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-2jjg-vj96-f833/GHSA-2jjg-vj96-f833.json b/advisories/unreviewed/2025/05/GHSA-2jjg-vj96-f833/GHSA-2jjg-vj96-f833.json new file mode 100644 index 00000000000..0602ca32582 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2jjg-vj96-f833/GHSA-2jjg-vj96-f833.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2jjg-vj96-f833", + "modified": "2025-05-16T15:31:03Z", + "published": "2025-05-16T15:31:03Z", + "aliases": [ + "CVE-2025-4778" + ], + "details": "A vulnerability was found in PHPGurukul Park Ticketing Management System 2.0. It has been declared as critical. This vulnerability affects unknown code of the file /normal-search.php. The manipulation of the argument searchdata leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4778" + }, + { + "type": "WEB", + "url": "https://github.com/f1rstb100d/myCVE/issues/4" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309076" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309076" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.572161" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T14:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3j83-vjvj-964q/GHSA-3j83-vjvj-964q.json b/advisories/unreviewed/2025/05/GHSA-3j83-vjvj-964q/GHSA-3j83-vjvj-964q.json index 01f85db5720..c4f9da6a16f 100644 --- a/advisories/unreviewed/2025/05/GHSA-3j83-vjvj-964q/GHSA-3j83-vjvj-964q.json +++ b/advisories/unreviewed/2025/05/GHSA-3j83-vjvj-964q/GHSA-3j83-vjvj-964q.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-4762-7j7m-8cjh/GHSA-4762-7j7m-8cjh.json b/advisories/unreviewed/2025/05/GHSA-4762-7j7m-8cjh/GHSA-4762-7j7m-8cjh.json index fce9a854c7c..823ccbe0ecc 100644 --- a/advisories/unreviewed/2025/05/GHSA-4762-7j7m-8cjh/GHSA-4762-7j7m-8cjh.json +++ b/advisories/unreviewed/2025/05/GHSA-4762-7j7m-8cjh/GHSA-4762-7j7m-8cjh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4762-7j7m-8cjh", - "modified": "2025-05-15T18:31:45Z", + "modified": "2025-05-16T15:30:51Z", "published": "2025-05-15T18:31:45Z", "aliases": [ "CVE-2024-52880" ], "details": "An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 05.54.50, kernel 5.6 before version 05.61.50, and kernel 5.7 before version 05.70.50. In VariableRuntimeDxe driver, SecureBootHandler uses DataSize and VariableNameSize when determining if the data or name are in the buffer, but these are supplied by the caller and therefore cannot be trusted.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T16:15:33Z" diff --git a/advisories/unreviewed/2025/05/GHSA-488m-4fx8-f36v/GHSA-488m-4fx8-f36v.json b/advisories/unreviewed/2025/05/GHSA-488m-4fx8-f36v/GHSA-488m-4fx8-f36v.json new file mode 100644 index 00000000000..8def70b0840 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-488m-4fx8-f36v/GHSA-488m-4fx8-f36v.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-488m-4fx8-f36v", + "modified": "2025-05-16T15:31:02Z", + "published": "2025-05-16T15:31:02Z", + "aliases": [ + "CVE-2025-40907" + ], + "details": "FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library.\n\nThe included FastCGI library is affected by CVE-2025-23016, causing an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40907" + }, + { + "type": "WEB", + "url": "https://github.com/FastCGI-Archives/fcgi2/issues/67" + }, + { + "type": "WEB", + "url": "https://github.com/perl-catalyst/FCGI/issues/14" + }, + { + "type": "WEB", + "url": "https://github.com/FastCGI-Archives/fcgi2/releases/tag/2.4.5" + }, + { + "type": "WEB", + "url": "https://patch-diff.githubusercontent.com/raw/FastCGI-Archives/fcgi2/pull/74.patch" + }, + { + "type": "WEB", + "url": "https://www.synacktiv.com/en/publications/cve-2025-23016-exploiting-the-fastcgi-library" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/04/23/4" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T13:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8cgq-rf3m-gjm4/GHSA-8cgq-rf3m-gjm4.json b/advisories/unreviewed/2025/05/GHSA-8cgq-rf3m-gjm4/GHSA-8cgq-rf3m-gjm4.json new file mode 100644 index 00000000000..9a7b60f006b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8cgq-rf3m-gjm4/GHSA-8cgq-rf3m-gjm4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8cgq-rf3m-gjm4", + "modified": "2025-05-16T15:31:03Z", + "published": "2025-05-16T15:31:03Z", + "aliases": [ + "CVE-2025-4211" + ], + "details": "Improper Link Resolution Before File Access ('Link Following') vulnerability in QFileSystemEngine in the Qt corelib module on Windows which potentially allows Symlink Attacks and the use of Malicious Files. Issue originates from CVE-2024-38081. The vulnerability arises from the use of the GetTempPath API, which can be exploited by attackers to manipulate temporary file paths, potentially leading to unauthorized access and privilege escalation. The affected public API in the Qt Framework is QDir::tempPath() and anything that uses it, such as QStandardPaths with TempLocation, QTemporaryDir, and QTemporaryFile.This issue affects all version of Qt up to and including 5.15.18, from 6.0.0 through 6.5.8, from 6.6.0 through 6.8.1. It is fixed in Qt 5.15.19, Qt 6.5.9, Qt 6.8.2, 6.9.0", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4211" + }, + { + "type": "WEB", + "url": "https://codereview.qt-project.org/c/qt/qtbase/+/632231" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T14:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-ch98-wcrf-h5pj/GHSA-ch98-wcrf-h5pj.json b/advisories/unreviewed/2025/05/GHSA-ch98-wcrf-h5pj/GHSA-ch98-wcrf-h5pj.json new file mode 100644 index 00000000000..4d1a97865b5 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-ch98-wcrf-h5pj/GHSA-ch98-wcrf-h5pj.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ch98-wcrf-h5pj", + "modified": "2025-05-16T15:31:02Z", + "published": "2025-05-16T15:31:02Z", + "aliases": [ + "CVE-2025-4773" + ], + "details": "A vulnerability was found in PHPGurukul Online Course Registration 3.1 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/level.php. The manipulation of the argument level leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4773" + }, + { + "type": "WEB", + "url": "https://github.com/FLYFISH567/CVE/issues/6" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309074" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309074" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.572144" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T13:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-crqj-898f-x3m2/GHSA-crqj-898f-x3m2.json b/advisories/unreviewed/2025/05/GHSA-crqj-898f-x3m2/GHSA-crqj-898f-x3m2.json new file mode 100644 index 00000000000..79c2cffc368 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-crqj-898f-x3m2/GHSA-crqj-898f-x3m2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crqj-898f-x3m2", + "modified": "2025-05-16T15:31:03Z", + "published": "2025-05-16T15:31:03Z", + "aliases": [ + "CVE-2025-4600" + ], + "details": "A request smuggling vulnerability existed in the Google Cloud Classic Application Load Balancer due to improper handling of chunked-encoded HTTP requests. This allowed attackers to craft requests that could be misinterpreted by backend servers. The issue was fixed by disallowing stray data after a chunk, and is no longer exploitable. No action is required as Classic Application Load Balancer service after 2025-04-26 is not vulnerable.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4600" + }, + { + "type": "WEB", + "url": "https://cloud.google.com/support/bulletins#gcp-2025-027" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T14:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-f2f6-hpmx-3wwh/GHSA-f2f6-hpmx-3wwh.json b/advisories/unreviewed/2025/05/GHSA-f2f6-hpmx-3wwh/GHSA-f2f6-hpmx-3wwh.json index d930b419668..cd48f3d3fe6 100644 --- a/advisories/unreviewed/2025/05/GHSA-f2f6-hpmx-3wwh/GHSA-f2f6-hpmx-3wwh.json +++ b/advisories/unreviewed/2025/05/GHSA-f2f6-hpmx-3wwh/GHSA-f2f6-hpmx-3wwh.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-f58m-h66f-qwjr/GHSA-f58m-h66f-qwjr.json b/advisories/unreviewed/2025/05/GHSA-f58m-h66f-qwjr/GHSA-f58m-h66f-qwjr.json new file mode 100644 index 00000000000..a9ec7f04d73 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-f58m-h66f-qwjr/GHSA-f58m-h66f-qwjr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f58m-h66f-qwjr", + "modified": "2025-05-16T15:31:02Z", + "published": "2025-05-16T15:31:02Z", + "aliases": [ + "CVE-2025-2305" + ], + "details": "A Path traversal vulnerability in the file\ndownload functionality was identified. This vulnerability allows\nunauthenticated users to download arbitrary files, in the context of the\napplication server, from the Linux server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2305" + }, + { + "type": "WEB", + "url": "https://www.cirosec.de/sa/sa-2025-003" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T13:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fwvg-7877-39cm/GHSA-fwvg-7877-39cm.json b/advisories/unreviewed/2025/05/GHSA-fwvg-7877-39cm/GHSA-fwvg-7877-39cm.json new file mode 100644 index 00000000000..1b4421a589f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fwvg-7877-39cm/GHSA-fwvg-7877-39cm.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fwvg-7877-39cm", + "modified": "2025-05-16T15:31:02Z", + "published": "2025-05-16T15:31:02Z", + "aliases": [ + "CVE-2025-37890" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet_sched: hfsc: Fix a UAF vulnerability in class with netem as child qdisc\n\nAs described in Gerrard's report [1], we have a UAF case when an hfsc class\nhas a netem child qdisc. The crux of the issue is that hfsc is assuming\nthat checking for cl->qdisc->q.qlen == 0 guarantees that it hasn't inserted\nthe class in the vttree or eltree (which is not true for the netem\nduplicate case).\n\nThis patch checks the n_active class variable to make sure that the code\nwon't insert the class in the vttree or eltree twice, catering for the\nreentrant case.\n\n[1] https://lore.kernel.org/netdev/CAHcdcOm+03OD2j6R0=YHKqmy=VgJ8xEOKuP6c7mSgnp-TEJJbw@mail.gmail.com/", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37890" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/141d34391abbb315d68556b7c67ad97885407547" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2e7093c7a8aba5d4f8809f271488e5babe75e202" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6082a87af4c52f58150d40dec1716011d871ac21" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8df7d37d626430035b413b97cee18396b3450bef" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ac39fd4a757584d78ed062d4f6fd913f83bd98b5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e3e949a39a91d1f829a4890e7dfe9417ac72e4d0" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T13:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g45r-4866-8vwq/GHSA-g45r-4866-8vwq.json b/advisories/unreviewed/2025/05/GHSA-g45r-4866-8vwq/GHSA-g45r-4866-8vwq.json index a1706650f95..6ba810174b9 100644 --- a/advisories/unreviewed/2025/05/GHSA-g45r-4866-8vwq/GHSA-g45r-4866-8vwq.json +++ b/advisories/unreviewed/2025/05/GHSA-g45r-4866-8vwq/GHSA-g45r-4866-8vwq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g45r-4866-8vwq", - "modified": "2025-05-15T18:31:47Z", + "modified": "2025-05-16T15:30:51Z", "published": "2025-05-15T18:31:47Z", "aliases": [ "CVE-2025-44110" ], "details": "FluxBB 1.5.11 is vulnerable to Cross Site Scripting (XSS) in via the Forum Description Field in admin_forums.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T18:15:37Z" diff --git a/advisories/unreviewed/2025/05/GHSA-hq7p-p5vr-p695/GHSA-hq7p-p5vr-p695.json b/advisories/unreviewed/2025/05/GHSA-hq7p-p5vr-p695/GHSA-hq7p-p5vr-p695.json index 3dab72688f6..35b5df1dbbb 100644 --- a/advisories/unreviewed/2025/05/GHSA-hq7p-p5vr-p695/GHSA-hq7p-p5vr-p695.json +++ b/advisories/unreviewed/2025/05/GHSA-hq7p-p5vr-p695/GHSA-hq7p-p5vr-p695.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-hxpq-cx68-pw83/GHSA-hxpq-cx68-pw83.json b/advisories/unreviewed/2025/05/GHSA-hxpq-cx68-pw83/GHSA-hxpq-cx68-pw83.json index 9353c73db67..18c19f67cd0 100644 --- a/advisories/unreviewed/2025/05/GHSA-hxpq-cx68-pw83/GHSA-hxpq-cx68-pw83.json +++ b/advisories/unreviewed/2025/05/GHSA-hxpq-cx68-pw83/GHSA-hxpq-cx68-pw83.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-pqjf-9c57-cpg3/GHSA-pqjf-9c57-cpg3.json b/advisories/unreviewed/2025/05/GHSA-pqjf-9c57-cpg3/GHSA-pqjf-9c57-cpg3.json index c529fdbf55b..ca7167d2978 100644 --- a/advisories/unreviewed/2025/05/GHSA-pqjf-9c57-cpg3/GHSA-pqjf-9c57-cpg3.json +++ b/advisories/unreviewed/2025/05/GHSA-pqjf-9c57-cpg3/GHSA-pqjf-9c57-cpg3.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-q97m-8853-pq76/GHSA-q97m-8853-pq76.json b/advisories/unreviewed/2025/05/GHSA-q97m-8853-pq76/GHSA-q97m-8853-pq76.json new file mode 100644 index 00000000000..a0b0faf14a5 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q97m-8853-pq76/GHSA-q97m-8853-pq76.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q97m-8853-pq76", + "modified": "2025-05-16T15:31:02Z", + "published": "2025-05-16T15:31:02Z", + "aliases": [ + "CVE-2024-40120" + ], + "details": "seaweedfs v3.68 was discovered to contain a SQL injection vulnerability via the component /abstract_sql/abstract_sql_store.go.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40120" + }, + { + "type": "WEB", + "url": "https://github.com/seaweedfs/seaweedfs/issues/5710" + }, + { + "type": "WEB", + "url": "https://gist.github.com/sud0why/1b2115c1d644bd3db1c1b3f16684a78c" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T13:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qrqf-gfw2-2f89/GHSA-qrqf-gfw2-2f89.json b/advisories/unreviewed/2025/05/GHSA-qrqf-gfw2-2f89/GHSA-qrqf-gfw2-2f89.json index 28c1002f605..34395670c47 100644 --- a/advisories/unreviewed/2025/05/GHSA-qrqf-gfw2-2f89/GHSA-qrqf-gfw2-2f89.json +++ b/advisories/unreviewed/2025/05/GHSA-qrqf-gfw2-2f89/GHSA-qrqf-gfw2-2f89.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qrqf-gfw2-2f89", - "modified": "2025-05-15T21:31:34Z", + "modified": "2025-05-16T15:30:57Z", "published": "2025-05-15T21:31:34Z", "aliases": [ "CVE-2024-9831" ], "details": "The Taskbuilder WordPress plugin before 3.0.9 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:16:01Z" diff --git a/advisories/unreviewed/2025/05/GHSA-rmwj-ph92-h7fq/GHSA-rmwj-ph92-h7fq.json b/advisories/unreviewed/2025/05/GHSA-rmwj-ph92-h7fq/GHSA-rmwj-ph92-h7fq.json index 3ad9f4b5c3a..f32a04e3187 100644 --- a/advisories/unreviewed/2025/05/GHSA-rmwj-ph92-h7fq/GHSA-rmwj-ph92-h7fq.json +++ b/advisories/unreviewed/2025/05/GHSA-rmwj-ph92-h7fq/GHSA-rmwj-ph92-h7fq.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-vphx-gjg2-4qff/GHSA-vphx-gjg2-4qff.json b/advisories/unreviewed/2025/05/GHSA-vphx-gjg2-4qff/GHSA-vphx-gjg2-4qff.json new file mode 100644 index 00000000000..c70629ed714 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vphx-gjg2-4qff/GHSA-vphx-gjg2-4qff.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vphx-gjg2-4qff", + "modified": "2025-05-16T15:31:03Z", + "published": "2025-05-16T15:31:03Z", + "aliases": [ + "CVE-2025-4780" + ], + "details": "A vulnerability was found in PHPGurukul Park Ticketing Management System 2.0. It has been rated as critical. This issue affects some unknown processing of the file /foreigner-search.php. The manipulation of the argument searchdata leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4780" + }, + { + "type": "WEB", + "url": "https://github.com/f1rstb100d/myCVE/issues/5" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309077" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309077" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.572163" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T14:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vpq5-jxrg-f4m3/GHSA-vpq5-jxrg-f4m3.json b/advisories/unreviewed/2025/05/GHSA-vpq5-jxrg-f4m3/GHSA-vpq5-jxrg-f4m3.json new file mode 100644 index 00000000000..eaac9e14a11 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vpq5-jxrg-f4m3/GHSA-vpq5-jxrg-f4m3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vpq5-jxrg-f4m3", + "modified": "2025-05-16T15:31:02Z", + "published": "2025-05-16T15:31:02Z", + "aliases": [ + "CVE-2025-2306" + ], + "details": "An Improper Access Control vulnerability was\nidentified in the file download functionality. This vulnerability allows users\nto download sensitive documents without authentication, if the URL is known.\n\n\n\nThe attack\nrequires the attacker to know the documents UUIDv4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2306" + }, + { + "type": "WEB", + "url": "https://www.cirosec.de/sa/sa-2025-004" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T13:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wx9f-pj36-96hc/GHSA-wx9f-pj36-96hc.json b/advisories/unreviewed/2025/05/GHSA-wx9f-pj36-96hc/GHSA-wx9f-pj36-96hc.json index eda63b7dcf6..dbc3c0cdfe5 100644 --- a/advisories/unreviewed/2025/05/GHSA-wx9f-pj36-96hc/GHSA-wx9f-pj36-96hc.json +++ b/advisories/unreviewed/2025/05/GHSA-wx9f-pj36-96hc/GHSA-wx9f-pj36-96hc.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-xwfw-xfh4-73wv/GHSA-xwfw-xfh4-73wv.json b/advisories/unreviewed/2025/05/GHSA-xwfw-xfh4-73wv/GHSA-xwfw-xfh4-73wv.json new file mode 100644 index 00000000000..0428a69f32a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xwfw-xfh4-73wv/GHSA-xwfw-xfh4-73wv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xwfw-xfh4-73wv", + "modified": "2025-05-16T15:31:02Z", + "published": "2025-05-16T15:31:02Z", + "aliases": [ + "CVE-2025-40629" + ], + "details": "PNETLab 4.2.10 does not properly sanitize user inputs in its file access mechanisms. This allows attackers to perform directory traversal by manipulating file paths in HTTP requests. Specifically, the application is vulnerable to requests that access sensitive files outside the intended directory.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40629" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/path-traversal-vulnerability-pnetlab" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T13:15:52Z" + } +} \ No newline at end of file