diff --git a/advisories/unreviewed/2024/02/GHSA-wpw2-f6x3-8f7j/GHSA-wpw2-f6x3-8f7j.json b/advisories/unreviewed/2024/02/GHSA-wpw2-f6x3-8f7j/GHSA-wpw2-f6x3-8f7j.json index ead67eb00a9..aa0196da197 100644 --- a/advisories/unreviewed/2024/02/GHSA-wpw2-f6x3-8f7j/GHSA-wpw2-f6x3-8f7j.json +++ b/advisories/unreviewed/2024/02/GHSA-wpw2-f6x3-8f7j/GHSA-wpw2-f6x3-8f7j.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-wpw2-f6x3-8f7j", - "modified": "2024-02-05T06:30:29Z", + "modified": "2025-05-15T12:30:26Z", "published": "2024-02-05T06:30:29Z", "aliases": [ "CVE-2023-5677" ], - "details": "Brandon\nRothel from QED Secure Solutions has found that the VAPIX API tcptest.cgi\ndid not have a sufficient input validation allowing for a possible remote code\nexecution. This flaw can only be exploited after authenticating with an\noperator- or administrator-privileged service account. The impact of exploiting\nthis vulnerability is lower with operator-privileges compared to\nadministrator-privileges service accounts. Axis has released patched AXIS OS\nversions for the highlighted flaw. Please refer to the Axis security advisory\nfor more information and solution. \n\n\n\n\n\n\n\n", + "details": "Brandon\nRothel from QED Secure Solutions has found that the VAPIX API tcptest.cgi\ndid not have a sufficient input validation allowing for a possible remote code\nexecution. This flaw can only be exploited after authenticating with an\noperator- or administrator-privileged service account. The impact of exploiting\nthis vulnerability is lower with operator-privileges compared to\nadministrator-privileges service accounts. Axis has released patched AXIS OS\nversions for the highlighted flaw. Please refer to the Axis security advisory\nfor more information and solution.", "severity": [ { "type": "CVSS_V3", @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5677" }, + { + "type": "WEB", + "url": "https://www.axis.com/dam/public/0a/47/d1/cve-2023-5677-en-US-483444.pdf" + }, { "type": "WEB", "url": "https://www.axis.com/dam/public/a9/dd/f1/cve-2023-5677-en-US-424335.pdf" diff --git a/advisories/unreviewed/2025/04/GHSA-fqm9-qqwf-gq9r/GHSA-fqm9-qqwf-gq9r.json b/advisories/unreviewed/2025/04/GHSA-fqm9-qqwf-gq9r/GHSA-fqm9-qqwf-gq9r.json index ab89c00f3ed..66dc9f6ee8c 100644 --- a/advisories/unreviewed/2025/04/GHSA-fqm9-qqwf-gq9r/GHSA-fqm9-qqwf-gq9r.json +++ b/advisories/unreviewed/2025/04/GHSA-fqm9-qqwf-gq9r/GHSA-fqm9-qqwf-gq9r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fqm9-qqwf-gq9r", - "modified": "2025-04-30T18:31:54Z", + "modified": "2025-05-15T12:30:26Z", "published": "2025-04-23T21:30:36Z", "aliases": [ "CVE-2025-46397" @@ -19,6 +19,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46397" }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-46397" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2362058" + }, { "type": "WEB", "url": "https://sourceforge.net/p/mcj/tickets/192" diff --git a/advisories/unreviewed/2025/04/GHSA-vv86-jpff-556f/GHSA-vv86-jpff-556f.json b/advisories/unreviewed/2025/04/GHSA-vv86-jpff-556f/GHSA-vv86-jpff-556f.json index 70530f231cc..ab1d38385ab 100644 --- a/advisories/unreviewed/2025/04/GHSA-vv86-jpff-556f/GHSA-vv86-jpff-556f.json +++ b/advisories/unreviewed/2025/04/GHSA-vv86-jpff-556f/GHSA-vv86-jpff-556f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vv86-jpff-556f", - "modified": "2025-04-30T18:31:54Z", + "modified": "2025-05-15T12:30:26Z", "published": "2025-04-23T21:30:36Z", "aliases": [ "CVE-2025-46398" @@ -19,6 +19,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46398" }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-46398" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2362055" + }, { "type": "WEB", "url": "https://sourceforge.net/p/mcj/tickets/191" diff --git a/advisories/unreviewed/2025/05/GHSA-67rg-585f-275w/GHSA-67rg-585f-275w.json b/advisories/unreviewed/2025/05/GHSA-67rg-585f-275w/GHSA-67rg-585f-275w.json new file mode 100644 index 00000000000..1bd8dd3af10 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-67rg-585f-275w/GHSA-67rg-585f-275w.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67rg-585f-275w", + "modified": "2025-05-15T12:30:27Z", + "published": "2025-05-15T12:30:27Z", + "aliases": [ + "CVE-2025-4564" + ], + "details": "The TicketBAI Facturas para WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation via the 'delpdf' action in all versions up to, and including, 3.18. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4564" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-ticketbai/trunk/wp-ticketbai.php#L240" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3292061" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2927aa13-b012-41eb-93bd-38a4e5fc5455?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T12:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8vfv-f6xm-p6cm/GHSA-8vfv-f6xm-p6cm.json b/advisories/unreviewed/2025/05/GHSA-8vfv-f6xm-p6cm/GHSA-8vfv-f6xm-p6cm.json new file mode 100644 index 00000000000..4ec8e7674ff --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8vfv-f6xm-p6cm/GHSA-8vfv-f6xm-p6cm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8vfv-f6xm-p6cm", + "modified": "2025-05-15T12:30:27Z", + "published": "2025-05-15T12:30:27Z", + "aliases": [ + "CVE-2025-4762" + ], + "details": "Insecure Direct Object Reference (IDOR) vulnerability in the eSignaViewer component in eSigna product versions 1.0 to 1.5 on all platforms allow an unauthenticated attacker to access arbitrary files in the document system via manipulation of file paths and object identifiers.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4762" + }, + { + "type": "WEB", + "url": "https://edgewatch.com/vulnerability-advisories/path-traversal-and-idor-vulnerabilities-in-esignaviewer-allow-unauthorized-file-access" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T12:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qgwx-rffp-6cx9/GHSA-qgwx-rffp-6cx9.json b/advisories/unreviewed/2025/05/GHSA-qgwx-rffp-6cx9/GHSA-qgwx-rffp-6cx9.json new file mode 100644 index 00000000000..8a91b667d95 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qgwx-rffp-6cx9/GHSA-qgwx-rffp-6cx9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qgwx-rffp-6cx9", + "modified": "2025-05-15T12:30:27Z", + "published": "2025-05-15T12:30:26Z", + "aliases": [ + "CVE-2025-31947" + ], + "details": "Mattermost versions 10.6.x <= 10.6.1, 10.5.x <= 10.5.2, 10.4.x <= 10.4.4, 9.11.x <= 9.11.11 fail to lockout LDAP users following repeated login failures, which allows attackers to lock external LDAP accounts through repeated login failures through Mattermost.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31947" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-645" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T11:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-r7r2-m3vr-c8qc/GHSA-r7r2-m3vr-c8qc.json b/advisories/unreviewed/2025/05/GHSA-r7r2-m3vr-c8qc/GHSA-r7r2-m3vr-c8qc.json new file mode 100644 index 00000000000..f888c61610c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-r7r2-m3vr-c8qc/GHSA-r7r2-m3vr-c8qc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r7r2-m3vr-c8qc", + "modified": "2025-05-15T12:30:27Z", + "published": "2025-05-15T12:30:27Z", + "aliases": [ + "CVE-2025-3446" + ], + "details": "Mattermost versions 10.6.x <= 10.6.1, 10.5.x <= 10.5.2, 10.4.x <= 10.4.4, 9.11.x <= 9.11.11 fail to check the correct permissions which allows authenticated users who only have permission to invite non-guest users to a team to add guest users to that team via the API to add a single user to a team.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3446" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T11:15:48Z" + } +} \ No newline at end of file