From 8727e824c50e68f08eda673338fcdbd2a3b97ef6 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 25 Apr 2025 00:33:12 +0000 Subject: [PATCH] Publish Advisories GHSA-2vgj-6cm5-qr57 GHSA-3g4x-5gh5-43g8 GHSA-3g8j-cv76-rvm5 GHSA-7rfh-xp3x-jh62 GHSA-85qv-xfxj-mxh8 GHSA-89j9-cchw-j26m GHSA-98jx-6mg2-r43f GHSA-grw8-qwrc-c9v2 GHSA-m6cm-6rg5-wfc9 --- .../GHSA-2vgj-6cm5-qr57.json | 40 ++++++++++++++++ .../GHSA-3g4x-5gh5-43g8.json | 44 +++++++++++++++++ .../GHSA-3g8j-cv76-rvm5.json | 40 ++++++++++++++++ .../GHSA-7rfh-xp3x-jh62.json | 44 +++++++++++++++++ .../GHSA-85qv-xfxj-mxh8.json | 48 +++++++++++++++++++ .../GHSA-89j9-cchw-j26m.json | 40 ++++++++++++++++ .../GHSA-98jx-6mg2-r43f.json | 40 ++++++++++++++++ .../GHSA-grw8-qwrc-c9v2.json | 40 ++++++++++++++++ .../GHSA-m6cm-6rg5-wfc9.json | 44 +++++++++++++++++ 9 files changed, 380 insertions(+) create mode 100644 advisories/unreviewed/2025/04/GHSA-2vgj-6cm5-qr57/GHSA-2vgj-6cm5-qr57.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3g4x-5gh5-43g8/GHSA-3g4x-5gh5-43g8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3g8j-cv76-rvm5/GHSA-3g8j-cv76-rvm5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7rfh-xp3x-jh62/GHSA-7rfh-xp3x-jh62.json create mode 100644 advisories/unreviewed/2025/04/GHSA-85qv-xfxj-mxh8/GHSA-85qv-xfxj-mxh8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-89j9-cchw-j26m/GHSA-89j9-cchw-j26m.json create mode 100644 advisories/unreviewed/2025/04/GHSA-98jx-6mg2-r43f/GHSA-98jx-6mg2-r43f.json create mode 100644 advisories/unreviewed/2025/04/GHSA-grw8-qwrc-c9v2/GHSA-grw8-qwrc-c9v2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-m6cm-6rg5-wfc9/GHSA-m6cm-6rg5-wfc9.json diff --git a/advisories/unreviewed/2025/04/GHSA-2vgj-6cm5-qr57/GHSA-2vgj-6cm5-qr57.json b/advisories/unreviewed/2025/04/GHSA-2vgj-6cm5-qr57/GHSA-2vgj-6cm5-qr57.json new file mode 100644 index 00000000000..79d3fda332a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2vgj-6cm5-qr57/GHSA-2vgj-6cm5-qr57.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2vgj-6cm5-qr57", + "modified": "2025-04-25T00:32:02Z", + "published": "2025-04-25T00:32:02Z", + "aliases": [ + "CVE-2025-46275" + ], + "details": "WGS-80HPT-V2 and WGS-4215-8T2S are missing authentication that could \nallow an attacker to create an administrator account without knowing any\n existing credentials.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46275" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-114-06" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-24T23:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3g4x-5gh5-43g8/GHSA-3g4x-5gh5-43g8.json b/advisories/unreviewed/2025/04/GHSA-3g4x-5gh5-43g8/GHSA-3g4x-5gh5-43g8.json new file mode 100644 index 00000000000..e3a492eb513 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3g4x-5gh5-43g8/GHSA-3g4x-5gh5-43g8.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3g4x-5gh5-43g8", + "modified": "2025-04-25T00:32:02Z", + "published": "2025-04-25T00:32:02Z", + "aliases": [ + "CVE-2025-2185" + ], + "details": "ALBEDO Telecom Net.Time - PTP/NTP clock (Serial No. NBC0081P) software release 1.4.4 is vulnerable to an insufficient session expiration vulnerability, which\n could permit an attacker to transmit passwords over unencrypted \nconnections, resulting in the product becoming vulnerable to \ninterception.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2185" + }, + { + "type": "WEB", + "url": "https://www.albedotelecom.com/contactus.php" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-114-02" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-613" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-25T00:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3g8j-cv76-rvm5/GHSA-3g8j-cv76-rvm5.json b/advisories/unreviewed/2025/04/GHSA-3g8j-cv76-rvm5/GHSA-3g8j-cv76-rvm5.json new file mode 100644 index 00000000000..148e50dccc7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3g8j-cv76-rvm5/GHSA-3g8j-cv76-rvm5.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3g8j-cv76-rvm5", + "modified": "2025-04-25T00:32:02Z", + "published": "2025-04-25T00:32:02Z", + "aliases": [ + "CVE-2025-46274" + ], + "details": "UNI-NMS-Lite uses hard-coded credentials that could allow an \nunauthenticated attacker to read, manipulate and create entries in the \nmanaged database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46274" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-114-06" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-798" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-24T23:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7rfh-xp3x-jh62/GHSA-7rfh-xp3x-jh62.json b/advisories/unreviewed/2025/04/GHSA-7rfh-xp3x-jh62/GHSA-7rfh-xp3x-jh62.json new file mode 100644 index 00000000000..6bbf3abeecb --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7rfh-xp3x-jh62/GHSA-7rfh-xp3x-jh62.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7rfh-xp3x-jh62", + "modified": "2025-04-25T00:32:02Z", + "published": "2025-04-25T00:32:02Z", + "aliases": [ + "CVE-2025-3606" + ], + "details": "Vestel AC Charger \nversion \n\n3.75.0 contains a vulnerability that \ncould enable an attacker to access files containing sensitive \ninformation, such as credentials which could be used to further \ncompromise the device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3606" + }, + { + "type": "WEB", + "url": "https://firebasestorage.googleapis.com/v0/b/vestel-shield.firebasestorage.app/o/PRODUCTION%2F1%2FVSA-1_R2.pdf?alt=media&token=8201f299-5014-4720-9200-f1b335736ac1" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-114-03" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-25T00:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-85qv-xfxj-mxh8/GHSA-85qv-xfxj-mxh8.json b/advisories/unreviewed/2025/04/GHSA-85qv-xfxj-mxh8/GHSA-85qv-xfxj-mxh8.json new file mode 100644 index 00000000000..c5d628bfd37 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-85qv-xfxj-mxh8/GHSA-85qv-xfxj-mxh8.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-85qv-xfxj-mxh8", + "modified": "2025-04-25T00:32:02Z", + "published": "2025-04-25T00:32:02Z", + "aliases": [ + "CVE-2025-3749" + ], + "details": "The Breeze Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cal_size’ parameter in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3749" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wt-display-breeze/trunk/includes/shortcodes.php#L114" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3280146" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/wt-display-breeze/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/527dd2c7-5bbb-4c79-aa3c-7d70ddd26163?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-24T23:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-89j9-cchw-j26m/GHSA-89j9-cchw-j26m.json b/advisories/unreviewed/2025/04/GHSA-89j9-cchw-j26m/GHSA-89j9-cchw-j26m.json new file mode 100644 index 00000000000..5dc00703d75 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-89j9-cchw-j26m/GHSA-89j9-cchw-j26m.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-89j9-cchw-j26m", + "modified": "2025-04-25T00:32:02Z", + "published": "2025-04-25T00:32:02Z", + "aliases": [ + "CVE-2025-46272" + ], + "details": "WGS-80HPT-V2 and WGS-4215-8T2S are vulnerable to a command injection \nattack that could allow an unauthenticated attacker to execute OS \ncommands on the host system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46272" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-114-06" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-24T23:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-98jx-6mg2-r43f/GHSA-98jx-6mg2-r43f.json b/advisories/unreviewed/2025/04/GHSA-98jx-6mg2-r43f/GHSA-98jx-6mg2-r43f.json new file mode 100644 index 00000000000..73bd4818726 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-98jx-6mg2-r43f/GHSA-98jx-6mg2-r43f.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-98jx-6mg2-r43f", + "modified": "2025-04-25T00:32:02Z", + "published": "2025-04-25T00:32:02Z", + "aliases": [ + "CVE-2025-46273" + ], + "details": "UNI-NMS-Lite uses hard-coded credentials that could allow an \nunauthenticated attacker to gain administrative privileges to all \nUNI-NMS managed devices.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46273" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-114-06" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-798" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-24T23:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-grw8-qwrc-c9v2/GHSA-grw8-qwrc-c9v2.json b/advisories/unreviewed/2025/04/GHSA-grw8-qwrc-c9v2/GHSA-grw8-qwrc-c9v2.json new file mode 100644 index 00000000000..aa098f2107e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-grw8-qwrc-c9v2/GHSA-grw8-qwrc-c9v2.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-grw8-qwrc-c9v2", + "modified": "2025-04-25T00:32:02Z", + "published": "2025-04-25T00:32:02Z", + "aliases": [ + "CVE-2025-46271" + ], + "details": "UNI-NMS-Lite is vulnerable to a command injection attack that could \nallow an unauthenticated attacker to read or manipulate device data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46271" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-114-06" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-24T23:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m6cm-6rg5-wfc9/GHSA-m6cm-6rg5-wfc9.json b/advisories/unreviewed/2025/04/GHSA-m6cm-6rg5-wfc9/GHSA-m6cm-6rg5-wfc9.json new file mode 100644 index 00000000000..8dff80d6757 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m6cm-6rg5-wfc9/GHSA-m6cm-6rg5-wfc9.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m6cm-6rg5-wfc9", + "modified": "2025-04-25T00:32:02Z", + "published": "2025-04-25T00:32:02Z", + "aliases": [ + "CVE-2025-1294" + ], + "details": "The eForm - WordPress Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.18.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1294" + }, + { + "type": "WEB", + "url": "https://codecanyon.net/item/eform-wordpress-form-builder/3180835" + }, + { + "type": "WEB", + "url": "https://eform.live/changelog" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6c5db375-e865-47ba-a3dd-462c55d066fd?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-24T23:15:14Z" + } +} \ No newline at end of file