Publish Advisories

GHSA-3gf2-723m-w3fv
GHSA-3498-94v2-7qqw
GHSA-3797-gmjf-45gm
GHSA-p3v7-wjmc-7fh8
GHSA-w829-6hpw-frjf
GHSA-cfmr-vrgj-vqwv
GHSA-2vq2-xc55-3j5m
GHSA-4hjv-8mmr-jxwv
GHSA-7cv2-wjgm-j7rm
GHSA-3ff9-v8g6-rg9q
GHSA-5gc6-2564-mq66
GHSA-7m65-wj64-957x
GHSA-8prh-632c-4gfj
GHSA-c8vj-q55w-r7h8
GHSA-mhg6-w3h6-f286
GHSA-mj3f-8797-c7r5
GHSA-p64m-3pg6-g8pq
GHSA-w3vc-hpm9-2h9q
GHSA-wxg6-4cwm-4rjf
GHSA-x3mr-mm28-qg7m
This commit is contained in:
advisory-database[bot]
2025-05-30 21:32:35 +00:00
parent 556d262cdf
commit 8ea485b7b6
20 changed files with 625 additions and 97 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3gf2-723m-w3fv",
"modified": "2022-03-17T00:05:31Z",
"modified": "2025-05-30T21:30:52Z",
"published": "2022-02-19T00:01:37Z",
"aliases": [
"CVE-2022-25313"
@@ -31,6 +31,14 @@
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2022/03/msg00007.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3UFRBA3UQVIQKXTBUQXDWQOVWNBKLERU"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y27XO3JMKAOMQZVPS3B4MJGEAHCZF5OM"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3UFRBA3UQVIQKXTBUQXDWQOVWNBKLERU"
@@ -62,7 +70,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-400"
"CWE-400",
"CWE-674"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3498-94v2-7qqw",
"modified": "2022-05-24T16:56:44Z",
"modified": "2025-05-30T21:30:52Z",
"published": "2022-05-24T16:56:44Z",
"aliases": [
"CVE-2019-5094"
@@ -23,6 +23,14 @@
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2019/09/msg00029.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2AKETJ6BREDUHRWQTV35SPGG5C6H7KSI"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6DOBCYQKCTTWXBLMUPJ5TX3FY7JNCOKY"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2AKETJ6BREDUHRWQTV35SPGG5C6H7KSI"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3797-gmjf-45gm",
"modified": "2022-09-14T00:00:52Z",
"modified": "2025-05-30T21:30:52Z",
"published": "2022-05-24T17:17:32Z",
"aliases": [
"CVE-2020-12762"
@@ -29,47 +29,7 @@
},
{
"type": "WEB",
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdf"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2020/05/msg00032.html"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2020/05/msg00034.html"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2020/07/msg00031.html"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/06/msg00023.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CBR36IXYBHITAZFB5PFBJTED22WO5ONB"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CQQRRGBQCAWNCCJ2HN3W5SSCZ4QGMXQI"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W226TSCJBEOXDUFVKNWNH7ETG7AR6MCS"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202006-13"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20210521-0001"
},
{
"type": "WEB",
"url": "https://usn.ubuntu.com/4360-1"
"url": "https://www.debian.org/security/2020/dsa-4741"
},
{
"type": "WEB",
@@ -77,7 +37,59 @@
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2020/dsa-4741"
"url": "https://usn.ubuntu.com/4360-1"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20210521-0001"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202006-13"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W226TSCJBEOXDUFVKNWNH7ETG7AR6MCS"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CQQRRGBQCAWNCCJ2HN3W5SSCZ4QGMXQI"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CBR36IXYBHITAZFB5PFBJTED22WO5ONB"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W226TSCJBEOXDUFVKNWNH7ETG7AR6MCS"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CQQRRGBQCAWNCCJ2HN3W5SSCZ4QGMXQI"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CBR36IXYBHITAZFB5PFBJTED22WO5ONB"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/06/msg00023.html"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2020/07/msg00031.html"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2020/05/msg00034.html"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2020/05/msg00032.html"
},
{
"type": "WEB",
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdf"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p3v7-wjmc-7fh8",
"modified": "2022-07-26T00:00:47Z",
"modified": "2025-05-30T21:30:52Z",
"published": "2022-05-24T19:10:56Z",
"aliases": [
"CVE-2021-38604"
@@ -23,6 +23,10 @@
"type": "WEB",
"url": "https://blog.tuxcare.com/cve/tuxcare-team-identifies-cve-2021-38604-a-new-vulnerability-in-glibc"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GYEXYM37RCJWJ6B5KQUYQI4NZBDDYSXP"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GYEXYM37RCJWJ6B5KQUYQI4NZBDDYSXP"
@@ -39,6 +43,14 @@
"type": "WEB",
"url": "https://sourceware.org/bugzilla/show_bug.cgi?id=28213"
},
{
"type": "WEB",
"url": "https://sourceware.org/git/?p=glibc.git%3Ba=commit%3Bh=4cc79c217744743077bf7a0ec5e0a4318f1e6641"
},
{
"type": "WEB",
"url": "https://sourceware.org/git/?p=glibc.git%3Ba=commit%3Bh=b805aebd42364fe696e417808a700fdb9800c9e8"
},
{
"type": "WEB",
"url": "https://sourceware.org/git/?p=glibc.git;a=commit;h=4cc79c217744743077bf7a0ec5e0a4318f1e6641"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w829-6hpw-frjf",
"modified": "2022-07-29T00:00:49Z",
"modified": "2025-05-30T21:30:53Z",
"published": "2022-05-24T16:55:26Z",
"aliases": [
"CVE-2019-15903"
@@ -35,6 +35,14 @@
"type": "WEB",
"url": "https://github.com/libexpat/libexpat/commit/c20b758c332d9a13afbbb276d30db1d183a85d43"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2019:3210"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20190926-0004"
},
{
"type": "WEB",
"url": "https://support.apple.com/kb/HT210785"
@@ -107,10 +115,6 @@
"type": "WEB",
"url": "https://www.tenable.com/security/tns-2021-11"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2019:3210"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2019:3237"
@@ -127,6 +131,18 @@
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2019/11/msg00017.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A4TZKPJFTURRLXIGLB34WVKQ5HGY6JJA"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BDUTI5TVQWIGGQXPEVI4T2ENHFSBMIBP"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/S26LGXXQ7YF2BP3RGOWELBFKM6BHF6UG"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/A4TZKPJFTURRLXIGLB34WVKQ5HGY6JJA"
@@ -175,10 +191,6 @@
"type": "WEB",
"url": "https://security.gentoo.org/glsa/201911-08"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20190926-0004"
},
{
"type": "WEB",
"url": "http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00080.html"
@@ -150,6 +150,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-120",
"CWE-787"
],
"severity": "CRITICAL",
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2vq2-xc55-3j5m",
"modified": "2022-09-17T00:00:42Z",
"modified": "2025-05-30T21:30:54Z",
"published": "2022-09-15T00:00:25Z",
"aliases": [
"CVE-2022-40674"
@@ -29,35 +29,7 @@
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2022/09/msg00029.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GSVZN3IJ6OCPSJL7AEX3ZHSHAHFOGESK"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/J2IGJNHFV53PYST7VQV3T4NHVYAMXA36"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LQB6FJAM5YQ35SF5B2MN25Y2FX56EOEZ"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WE2ZKEPGFCZ7R6DRVH3K6RBJPT42ZBEG"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XCGBVQQ47URGJAZWHCISHDWF6QBTV2LE"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202209-24"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202211-06"
"url": "https://www.debian.org/security/2022/dsa-5236"
},
{
"type": "WEB",
@@ -65,7 +37,55 @@
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2022/dsa-5236"
"url": "https://security.gentoo.org/glsa/202211-06"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202209-24"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XCGBVQQ47URGJAZWHCISHDWF6QBTV2LE"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WE2ZKEPGFCZ7R6DRVH3K6RBJPT42ZBEG"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LQB6FJAM5YQ35SF5B2MN25Y2FX56EOEZ"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/J2IGJNHFV53PYST7VQV3T4NHVYAMXA36"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GSVZN3IJ6OCPSJL7AEX3ZHSHAHFOGESK"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XCGBVQQ47URGJAZWHCISHDWF6QBTV2LE"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WE2ZKEPGFCZ7R6DRVH3K6RBJPT42ZBEG"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LQB6FJAM5YQ35SF5B2MN25Y2FX56EOEZ"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J2IGJNHFV53PYST7VQV3T4NHVYAMXA36"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GSVZN3IJ6OCPSJL7AEX3ZHSHAHFOGESK"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2022/09/msg00029.html"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4hjv-8mmr-jxwv",
"modified": "2022-10-24T19:00:20Z",
"modified": "2025-05-30T21:30:54Z",
"published": "2022-10-24T19:00:20Z",
"aliases": [
"CVE-2022-43680"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7cv2-wjgm-j7rm",
"modified": "2024-02-01T18:31:06Z",
"modified": "2025-05-30T21:30:55Z",
"published": "2023-04-24T21:30:30Z",
"aliases": [
"CVE-2023-28484"
@@ -0,0 +1,56 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3ff9-v8g6-rg9q",
"modified": "2025-05-30T21:30:58Z",
"published": "2025-05-30T21:30:58Z",
"aliases": [
"CVE-2025-5363"
],
"details": "A vulnerability has been found in Campcodes Online Hospital Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /doctor/index.php. The manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5363"
},
{
"type": "WEB",
"url": "https://github.com/yuanchaoxxxxx/CVE/issues/3"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.310657"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.310657"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.586698"
},
{
"type": "WEB",
"url": "https://www.campcodes.com"
}
],
"database_specific": {
"cwe_ids": [
"CWE-74"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-30T21:15:21Z"
}
}
@@ -0,0 +1,56 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5gc6-2564-mq66",
"modified": "2025-05-30T21:30:58Z",
"published": "2025-05-30T21:30:58Z",
"aliases": [
"CVE-2025-5362"
],
"details": "A vulnerability, which was classified as critical, was found in Campcodes Online Hospital Management System 1.0. Affected is an unknown function of the file /admin/doctor-specilization.php. The manipulation of the argument doctorspecilization leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5362"
},
{
"type": "WEB",
"url": "https://github.com/ASantsSec/CVE/issues/10"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.310656"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.310656"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.586596"
},
{
"type": "WEB",
"url": "https://www.campcodes.com"
}
],
"database_specific": {
"cwe_ids": [
"CWE-74"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-30T21:15:21Z"
}
}
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7m65-wj64-957x",
"modified": "2025-05-30T21:30:57Z",
"published": "2025-05-30T21:30:57Z",
"aliases": [
"CVE-2025-2501"
],
"details": "An untrusted search path vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2501"
},
{
"type": "WEB",
"url": "https://iknow.lenovo.com.cn/detail/428586"
}
],
"database_specific": {
"cwe_ids": [
"CWE-426"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-30T20:15:42Z"
}
}
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8prh-632c-4gfj",
"modified": "2025-05-30T21:30:58Z",
"published": "2025-05-30T21:30:57Z",
"aliases": [
"CVE-2025-2503"
],
"details": "An improper permission handling vulnerability was reported in Lenovo PC Manager that could allow a local attacker to perform arbitrary file deletions as an elevated user.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2503"
},
{
"type": "WEB",
"url": "https://iknow.lenovo.com.cn/detail/428586"
}
],
"database_specific": {
"cwe_ids": [
"CWE-280"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-30T20:15:42Z"
}
}
@@ -0,0 +1,56 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c8vj-q55w-r7h8",
"modified": "2025-05-30T21:30:57Z",
"published": "2025-05-30T21:30:57Z",
"aliases": [
"CVE-2025-5359"
],
"details": "A vulnerability classified as critical has been found in Campcodes Online Hospital Management System 1.0. This affects an unknown part of the file /appointment-history.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5359"
},
{
"type": "WEB",
"url": "https://github.com/ASantsSec/CVE/issues/7"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.310653"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.310653"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.586590"
},
{
"type": "WEB",
"url": "https://www.campcodes.com"
}
],
"database_specific": {
"cwe_ids": [
"CWE-74"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-30T19:15:30Z"
}
}
@@ -0,0 +1,56 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mhg6-w3h6-f286",
"modified": "2025-05-30T21:30:58Z",
"published": "2025-05-30T21:30:58Z",
"aliases": [
"CVE-2025-5360"
],
"details": "A vulnerability classified as critical was found in Campcodes Online Hospital Management System 1.0. This vulnerability affects unknown code of the file /book-appointment.php. The manipulation of the argument doctor leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5360"
},
{
"type": "WEB",
"url": "https://github.com/ASantsSec/CVE/issues/8"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.310654"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.310654"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.586591"
},
{
"type": "WEB",
"url": "https://www.campcodes.com"
}
],
"database_specific": {
"cwe_ids": [
"CWE-74"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-30T20:15:44Z"
}
}
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mj3f-8797-c7r5",
"modified": "2025-05-30T21:30:57Z",
"published": "2025-05-30T21:30:57Z",
"aliases": [
"CVE-2025-1479"
],
"details": "An open debug interface was reported in the Legion Space software included on certain Legion devices that could allow a local attacker to execute arbitrary code.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1479"
},
{
"type": "WEB",
"url": "https://support.lenovo.com/us/en/product_security/LEN-186929"
}
],
"database_specific": {
"cwe_ids": [
"CWE-489"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-30T20:15:32Z"
}
}
@@ -0,0 +1,56 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p64m-3pg6-g8pq",
"modified": "2025-05-30T21:30:58Z",
"published": "2025-05-30T21:30:58Z",
"aliases": [
"CVE-2025-5361"
],
"details": "A vulnerability, which was classified as critical, has been found in Campcodes Online Hospital Management System 1.0. This issue affects some unknown processing of the file /contact.php. The manipulation of the argument fullname leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5361"
},
{
"type": "WEB",
"url": "https://github.com/ASantsSec/CVE/issues/9"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.310655"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.310655"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.586592"
},
{
"type": "WEB",
"url": "https://www.campcodes.com"
}
],
"database_specific": {
"cwe_ids": [
"CWE-74"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-30T20:15:44Z"
}
}
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w3vc-hpm9-2h9q",
"modified": "2025-05-28T18:33:29Z",
"modified": "2025-05-30T21:30:56Z",
"published": "2025-05-28T18:33:29Z",
"aliases": [
"CVE-2024-57338"
],
"details": "An arbitrary file upload vulnerability in M2Soft CROWNIX Report & ERS v5.x to v5.5.14.1070, v7.x to v7.4.3.960, and v8.x to v8.2.0.345 allows attackers to execute arbitrary code via supplying a crafted file.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-77"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-28T18:15:25Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wxg6-4cwm-4rjf",
"modified": "2025-05-28T18:33:29Z",
"modified": "2025-05-30T21:30:55Z",
"published": "2025-05-28T18:33:29Z",
"aliases": [
"CVE-2024-57337"
],
"details": "An arbitrary file upload vulnerability in the opcode 500 functionality of M2Soft CROWNIX Report & ERS v5.x to v5.5.14.1070, v7.x to v7.4.3.960, and v8.x to v8.2.0.345 allows attackers to execute arbitrary code via supplying a crafted file.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-77"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-28T18:15:25Z"
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x3mr-mm28-qg7m",
"modified": "2025-05-30T21:30:57Z",
"published": "2025-05-30T21:30:57Z",
"aliases": [
"CVE-2025-2502"
],
"details": "An improper default permissions vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2502"
},
{
"type": "WEB",
"url": "https://iknow.lenovo.com.cn/detail/428586"
}
],
"database_specific": {
"cwe_ids": [
"CWE-276"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-30T20:15:42Z"
}
}