From 93b33b7fa58e87a064dc59d4eb30219c2e12e335 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 10 Jun 2025 12:31:39 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-cjw9-x8qr-5wpf.json | 6 ++- .../GHSA-fq4p-236v-8g34.json | 6 ++- .../GHSA-p2mq-5mvf-j4j6.json | 6 ++- .../GHSA-6545-29c2-j2r5.json | 4 +- .../GHSA-89vx-m8mc-p558.json | 2 +- .../GHSA-9fcp-xcwr-cjm9.json | 4 +- .../GHSA-c6wh-53mq-4gr9.json | 4 +- .../GHSA-fq7q-wgm6-7rqj.json | 4 +- .../GHSA-pw53-33fx-vf55.json | 2 +- .../GHSA-r77g-4w8g-2vqq.json | 4 +- .../GHSA-25ww-mhx2-69ff.json | 36 +++++++++++++ .../GHSA-3429-h97r-hqqx.json | 31 +++++++++++ .../GHSA-3hvp-qhfg-j3vj.json | 31 +++++++++++ .../GHSA-3vj2-mww6-fh3x.json | 40 ++++++++++++++ .../GHSA-4h25-6mgv-2q43.json | 36 +++++++++++++ .../GHSA-55jr-mfpr-5vwv.json | 40 ++++++++++++++ .../GHSA-6236-fhhc-64mr.json | 31 +++++++++++ .../GHSA-6wvr-wrjw-5g3c.json | 31 +++++++++++ .../GHSA-7p84-3xrw-mfhg.json | 36 +++++++++++++ .../GHSA-7wrh-jx7h-gpfr.json | 52 +++++++++++++++++++ .../GHSA-8g3x-gq5f-v54w.json | 36 +++++++++++++ .../GHSA-8h63-5g4g-f8h5.json | 40 ++++++++++++++ .../GHSA-8mwm-vx53-284j.json | 36 +++++++++++++ .../GHSA-c2wc-64f2-wxpp.json | 36 +++++++++++++ .../GHSA-gqmw-jrgv-446q.json | 31 +++++++++++ .../GHSA-h5mc-fvr9-pr54.json | 36 +++++++++++++ .../GHSA-h8v5-mvp3-hf33.json | 44 ++++++++++++++++ .../GHSA-jv2r-79gq-5mh3.json | 36 +++++++++++++ .../GHSA-w6h2-p5q3-p762.json | 36 +++++++++++++ .../GHSA-x9v7-mgg6-wjfr.json | 36 +++++++++++++ 30 files changed, 763 insertions(+), 10 deletions(-) create mode 100644 advisories/unreviewed/2025/06/GHSA-25ww-mhx2-69ff/GHSA-25ww-mhx2-69ff.json create mode 100644 advisories/unreviewed/2025/06/GHSA-3429-h97r-hqqx/GHSA-3429-h97r-hqqx.json create mode 100644 advisories/unreviewed/2025/06/GHSA-3hvp-qhfg-j3vj/GHSA-3hvp-qhfg-j3vj.json create mode 100644 advisories/unreviewed/2025/06/GHSA-3vj2-mww6-fh3x/GHSA-3vj2-mww6-fh3x.json create mode 100644 advisories/unreviewed/2025/06/GHSA-4h25-6mgv-2q43/GHSA-4h25-6mgv-2q43.json create mode 100644 advisories/unreviewed/2025/06/GHSA-55jr-mfpr-5vwv/GHSA-55jr-mfpr-5vwv.json create mode 100644 advisories/unreviewed/2025/06/GHSA-6236-fhhc-64mr/GHSA-6236-fhhc-64mr.json create mode 100644 advisories/unreviewed/2025/06/GHSA-6wvr-wrjw-5g3c/GHSA-6wvr-wrjw-5g3c.json create mode 100644 advisories/unreviewed/2025/06/GHSA-7p84-3xrw-mfhg/GHSA-7p84-3xrw-mfhg.json create mode 100644 advisories/unreviewed/2025/06/GHSA-7wrh-jx7h-gpfr/GHSA-7wrh-jx7h-gpfr.json create mode 100644 advisories/unreviewed/2025/06/GHSA-8g3x-gq5f-v54w/GHSA-8g3x-gq5f-v54w.json create mode 100644 advisories/unreviewed/2025/06/GHSA-8h63-5g4g-f8h5/GHSA-8h63-5g4g-f8h5.json create mode 100644 advisories/unreviewed/2025/06/GHSA-8mwm-vx53-284j/GHSA-8mwm-vx53-284j.json create mode 100644 advisories/unreviewed/2025/06/GHSA-c2wc-64f2-wxpp/GHSA-c2wc-64f2-wxpp.json create mode 100644 advisories/unreviewed/2025/06/GHSA-gqmw-jrgv-446q/GHSA-gqmw-jrgv-446q.json create mode 100644 advisories/unreviewed/2025/06/GHSA-h5mc-fvr9-pr54/GHSA-h5mc-fvr9-pr54.json create mode 100644 advisories/unreviewed/2025/06/GHSA-h8v5-mvp3-hf33/GHSA-h8v5-mvp3-hf33.json create mode 100644 advisories/unreviewed/2025/06/GHSA-jv2r-79gq-5mh3/GHSA-jv2r-79gq-5mh3.json create mode 100644 advisories/unreviewed/2025/06/GHSA-w6h2-p5q3-p762/GHSA-w6h2-p5q3-p762.json create mode 100644 advisories/unreviewed/2025/06/GHSA-x9v7-mgg6-wjfr/GHSA-x9v7-mgg6-wjfr.json diff --git a/advisories/unreviewed/2025/04/GHSA-cjw9-x8qr-5wpf/GHSA-cjw9-x8qr-5wpf.json b/advisories/unreviewed/2025/04/GHSA-cjw9-x8qr-5wpf/GHSA-cjw9-x8qr-5wpf.json index 7377daa46df..6866faa5447 100644 --- a/advisories/unreviewed/2025/04/GHSA-cjw9-x8qr-5wpf/GHSA-cjw9-x8qr-5wpf.json +++ b/advisories/unreviewed/2025/04/GHSA-cjw9-x8qr-5wpf/GHSA-cjw9-x8qr-5wpf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cjw9-x8qr-5wpf", - "modified": "2025-04-16T15:34:45Z", + "modified": "2025-06-10T12:30:17Z", "published": "2025-04-16T15:34:45Z", "aliases": [ "CVE-2025-22122" @@ -14,6 +14,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22122" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0c60158ff14df04c92792dd9b1809372b095040f" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/26064d3e2b4d9a14df1072980e558c636fb023ea" diff --git a/advisories/unreviewed/2025/04/GHSA-fq4p-236v-8g34/GHSA-fq4p-236v-8g34.json b/advisories/unreviewed/2025/04/GHSA-fq4p-236v-8g34/GHSA-fq4p-236v-8g34.json index cafe57e7500..a7ac439e25c 100644 --- a/advisories/unreviewed/2025/04/GHSA-fq4p-236v-8g34/GHSA-fq4p-236v-8g34.json +++ b/advisories/unreviewed/2025/04/GHSA-fq4p-236v-8g34/GHSA-fq4p-236v-8g34.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fq4p-236v-8g34", - "modified": "2025-04-16T15:34:45Z", + "modified": "2025-06-10T12:30:17Z", "published": "2025-04-16T15:34:45Z", "aliases": [ "CVE-2025-22123" @@ -21,6 +21,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/986c50f6bca109c6cf362b4e2babcb85aba958f6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bf49527089ec1ba894c6e587affabbfb2329f52e" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/04/GHSA-p2mq-5mvf-j4j6/GHSA-p2mq-5mvf-j4j6.json b/advisories/unreviewed/2025/04/GHSA-p2mq-5mvf-j4j6/GHSA-p2mq-5mvf-j4j6.json index 7fc5826db3b..0a08e12db70 100644 --- a/advisories/unreviewed/2025/04/GHSA-p2mq-5mvf-j4j6/GHSA-p2mq-5mvf-j4j6.json +++ b/advisories/unreviewed/2025/04/GHSA-p2mq-5mvf-j4j6/GHSA-p2mq-5mvf-j4j6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p2mq-5mvf-j4j6", - "modified": "2025-04-23T12:31:26Z", + "modified": "2025-06-10T12:30:17Z", "published": "2025-04-23T12:31:25Z", "aliases": [ "CVE-2025-2703" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://grafana.com/security/security-advisories/cve-2025-2703" + }, + { + "type": "WEB", + "url": "https://www.sonarsource.com/blog/data-in-danger-detecting-xss-in-grafana-cve-2025-2703" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/05/GHSA-6545-29c2-j2r5/GHSA-6545-29c2-j2r5.json b/advisories/unreviewed/2025/05/GHSA-6545-29c2-j2r5/GHSA-6545-29c2-j2r5.json index 57b5b0afcc0..1d33adedf23 100644 --- a/advisories/unreviewed/2025/05/GHSA-6545-29c2-j2r5/GHSA-6545-29c2-j2r5.json +++ b/advisories/unreviewed/2025/05/GHSA-6545-29c2-j2r5/GHSA-6545-29c2-j2r5.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-89vx-m8mc-p558/GHSA-89vx-m8mc-p558.json b/advisories/unreviewed/2025/05/GHSA-89vx-m8mc-p558/GHSA-89vx-m8mc-p558.json index e4a26ca3bb6..3d5f7802787 100644 --- a/advisories/unreviewed/2025/05/GHSA-89vx-m8mc-p558/GHSA-89vx-m8mc-p558.json +++ b/advisories/unreviewed/2025/05/GHSA-89vx-m8mc-p558/GHSA-89vx-m8mc-p558.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-89vx-m8mc-p558", - "modified": "2025-05-30T18:31:14Z", + "modified": "2025-06-10T12:30:18Z", "published": "2025-05-30T18:31:14Z", "aliases": [ "CVE-2024-13917" diff --git a/advisories/unreviewed/2025/05/GHSA-9fcp-xcwr-cjm9/GHSA-9fcp-xcwr-cjm9.json b/advisories/unreviewed/2025/05/GHSA-9fcp-xcwr-cjm9/GHSA-9fcp-xcwr-cjm9.json index 1aca37fd44e..be05fbdfd48 100644 --- a/advisories/unreviewed/2025/05/GHSA-9fcp-xcwr-cjm9/GHSA-9fcp-xcwr-cjm9.json +++ b/advisories/unreviewed/2025/05/GHSA-9fcp-xcwr-cjm9/GHSA-9fcp-xcwr-cjm9.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-c6wh-53mq-4gr9/GHSA-c6wh-53mq-4gr9.json b/advisories/unreviewed/2025/05/GHSA-c6wh-53mq-4gr9/GHSA-c6wh-53mq-4gr9.json index 47c47846bbd..98869b96fc1 100644 --- a/advisories/unreviewed/2025/05/GHSA-c6wh-53mq-4gr9/GHSA-c6wh-53mq-4gr9.json +++ b/advisories/unreviewed/2025/05/GHSA-c6wh-53mq-4gr9/GHSA-c6wh-53mq-4gr9.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-639" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-fq7q-wgm6-7rqj/GHSA-fq7q-wgm6-7rqj.json b/advisories/unreviewed/2025/05/GHSA-fq7q-wgm6-7rqj/GHSA-fq7q-wgm6-7rqj.json index 9a2392162df..9037c407338 100644 --- a/advisories/unreviewed/2025/05/GHSA-fq7q-wgm6-7rqj/GHSA-fq7q-wgm6-7rqj.json +++ b/advisories/unreviewed/2025/05/GHSA-fq7q-wgm6-7rqj/GHSA-fq7q-wgm6-7rqj.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-pw53-33fx-vf55/GHSA-pw53-33fx-vf55.json b/advisories/unreviewed/2025/05/GHSA-pw53-33fx-vf55/GHSA-pw53-33fx-vf55.json index c28399534c9..624e7349b7c 100644 --- a/advisories/unreviewed/2025/05/GHSA-pw53-33fx-vf55/GHSA-pw53-33fx-vf55.json +++ b/advisories/unreviewed/2025/05/GHSA-pw53-33fx-vf55/GHSA-pw53-33fx-vf55.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pw53-33fx-vf55", - "modified": "2025-05-30T18:31:13Z", + "modified": "2025-06-10T12:30:18Z", "published": "2025-05-30T18:31:13Z", "aliases": [ "CVE-2024-13916" diff --git a/advisories/unreviewed/2025/05/GHSA-r77g-4w8g-2vqq/GHSA-r77g-4w8g-2vqq.json b/advisories/unreviewed/2025/05/GHSA-r77g-4w8g-2vqq/GHSA-r77g-4w8g-2vqq.json index 26aba4d97a8..bfd5ae6488f 100644 --- a/advisories/unreviewed/2025/05/GHSA-r77g-4w8g-2vqq/GHSA-r77g-4w8g-2vqq.json +++ b/advisories/unreviewed/2025/05/GHSA-r77g-4w8g-2vqq/GHSA-r77g-4w8g-2vqq.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/06/GHSA-25ww-mhx2-69ff/GHSA-25ww-mhx2-69ff.json b/advisories/unreviewed/2025/06/GHSA-25ww-mhx2-69ff/GHSA-25ww-mhx2-69ff.json new file mode 100644 index 00000000000..9a74e88c50e --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-25ww-mhx2-69ff/GHSA-25ww-mhx2-69ff.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-25ww-mhx2-69ff", + "modified": "2025-06-10T12:30:18Z", + "published": "2025-06-10T12:30:18Z", + "aliases": [ + "CVE-2025-40659" + ], + "details": "An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option parameter equal to 0, 1 or 2 in /administer/selectionnode/framesSelectionNetworks.asp.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40659" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-dm-corporative-cms-dmacroweb" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T10:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-3429-h97r-hqqx/GHSA-3429-h97r-hqqx.json b/advisories/unreviewed/2025/06/GHSA-3429-h97r-hqqx/GHSA-3429-h97r-hqqx.json new file mode 100644 index 00000000000..de028cd73ec --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-3429-h97r-hqqx/GHSA-3429-h97r-hqqx.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3429-h97r-hqqx", + "modified": "2025-06-10T12:30:19Z", + "published": "2025-06-10T12:30:19Z", + "aliases": [ + "CVE-2025-43701" + ], + "details": "Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows exposure of Custom Settings data. \n\nThis impacts OmniStudio: before version 254.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43701" + }, + { + "type": "WEB", + "url": "https://help.salesforce.com/s/articleView?id=004980323&type=1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-281" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T12:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-3hvp-qhfg-j3vj/GHSA-3hvp-qhfg-j3vj.json b/advisories/unreviewed/2025/06/GHSA-3hvp-qhfg-j3vj/GHSA-3hvp-qhfg-j3vj.json new file mode 100644 index 00000000000..3f61136903b --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-3hvp-qhfg-j3vj/GHSA-3hvp-qhfg-j3vj.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3hvp-qhfg-j3vj", + "modified": "2025-06-10T12:30:19Z", + "published": "2025-06-10T12:30:18Z", + "aliases": [ + "CVE-2025-43699" + ], + "details": "Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows bypass of field level security controls for OmniUICard objects. \n\nThis impacts OmniStudio: before Spring 2025", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43699" + }, + { + "type": "WEB", + "url": "https://help.salesforce.com/s/articleView?id=004980323&type=1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-281" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T12:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-3vj2-mww6-fh3x/GHSA-3vj2-mww6-fh3x.json b/advisories/unreviewed/2025/06/GHSA-3vj2-mww6-fh3x/GHSA-3vj2-mww6-fh3x.json new file mode 100644 index 00000000000..c554056fc0a --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-3vj2-mww6-fh3x/GHSA-3vj2-mww6-fh3x.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3vj2-mww6-fh3x", + "modified": "2025-06-10T12:30:19Z", + "published": "2025-06-10T12:30:19Z", + "aliases": [ + "CVE-2025-4774" + ], + "details": "The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-countdown attribute of Countdown widget in all versions up to, and including, 4.11.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4774" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/premium-addons-for-elementor/tags/4.11.6/assets/frontend/js/jquery-countdown.js#L97" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/024af9de-d4c7-43ec-a602-c45ded3ddad3?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T12:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-4h25-6mgv-2q43/GHSA-4h25-6mgv-2q43.json b/advisories/unreviewed/2025/06/GHSA-4h25-6mgv-2q43/GHSA-4h25-6mgv-2q43.json new file mode 100644 index 00000000000..80a2bab32d7 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-4h25-6mgv-2q43/GHSA-4h25-6mgv-2q43.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4h25-6mgv-2q43", + "modified": "2025-06-10T12:30:18Z", + "published": "2025-06-10T12:30:18Z", + "aliases": [ + "CVE-2025-40662" + ], + "details": "Absolute path disclosure vulnerability in DM Corporative CMS. This vulnerability allows an attacker to view the contents of webroot/file, if navigating to a non-existent file.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40662" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-dm-corporative-cms-dmacroweb" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T10:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-55jr-mfpr-5vwv/GHSA-55jr-mfpr-5vwv.json b/advisories/unreviewed/2025/06/GHSA-55jr-mfpr-5vwv/GHSA-55jr-mfpr-5vwv.json new file mode 100644 index 00000000000..09c856534e3 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-55jr-mfpr-5vwv/GHSA-55jr-mfpr-5vwv.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-55jr-mfpr-5vwv", + "modified": "2025-06-10T12:30:18Z", + "published": "2025-06-10T12:30:18Z", + "aliases": [ + "CVE-2024-13090" + ], + "details": "A privilege escalation vulnerability may enable a service account to elevate its privileges.\n\n\n\nThe sudo rules configured for a local service account were excessively permissive, potentially allowing administrative access if a malicious actor could execute arbitrary commands as that account.\n\nIt is important to note that no such vector has been identified in this instance.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13090" + }, + { + "type": "WEB", + "url": "https://security.nozominetworks.com/NN-2025:2-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-250" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T11:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-6236-fhhc-64mr/GHSA-6236-fhhc-64mr.json b/advisories/unreviewed/2025/06/GHSA-6236-fhhc-64mr/GHSA-6236-fhhc-64mr.json new file mode 100644 index 00000000000..5725752a613 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-6236-fhhc-64mr/GHSA-6236-fhhc-64mr.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6236-fhhc-64mr", + "modified": "2025-06-10T12:30:18Z", + "published": "2025-06-10T12:30:18Z", + "aliases": [ + "CVE-2025-43697" + ], + "details": "Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (DataMapper) allows exposure of encrypted data.\nThis impacts OmniStudio: before Spring 2025", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43697" + }, + { + "type": "WEB", + "url": "https://help.salesforce.com/s/articleView?id=004980323&type=1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-281" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T12:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-6wvr-wrjw-5g3c/GHSA-6wvr-wrjw-5g3c.json b/advisories/unreviewed/2025/06/GHSA-6wvr-wrjw-5g3c/GHSA-6wvr-wrjw-5g3c.json new file mode 100644 index 00000000000..20a7e886375 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-6wvr-wrjw-5g3c/GHSA-6wvr-wrjw-5g3c.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6wvr-wrjw-5g3c", + "modified": "2025-06-10T12:30:19Z", + "published": "2025-06-10T12:30:18Z", + "aliases": [ + "CVE-2025-43700" + ], + "details": "Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows exposure of encrypted data. \n\nThis impacts OmniStudio: before Spring 2025.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43700" + }, + { + "type": "WEB", + "url": "https://help.salesforce.com/s/articleView?id=004980323&type=1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-281" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T12:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-7p84-3xrw-mfhg/GHSA-7p84-3xrw-mfhg.json b/advisories/unreviewed/2025/06/GHSA-7p84-3xrw-mfhg/GHSA-7p84-3xrw-mfhg.json new file mode 100644 index 00000000000..7ac642073b0 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-7p84-3xrw-mfhg/GHSA-7p84-3xrw-mfhg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7p84-3xrw-mfhg", + "modified": "2025-06-10T12:30:18Z", + "published": "2025-06-10T12:30:18Z", + "aliases": [ + "CVE-2025-40657" + ], + "details": "A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, create, update and delete databases through the codform parameter in /modules/forms/collectform.asp.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40657" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-dm-corporative-cms-dmacroweb" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T10:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-7wrh-jx7h-gpfr/GHSA-7wrh-jx7h-gpfr.json b/advisories/unreviewed/2025/06/GHSA-7wrh-jx7h-gpfr/GHSA-7wrh-jx7h-gpfr.json new file mode 100644 index 00000000000..a15ef9949b7 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-7wrh-jx7h-gpfr/GHSA-7wrh-jx7h-gpfr.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7wrh-jx7h-gpfr", + "modified": "2025-06-10T12:30:18Z", + "published": "2025-06-10T12:30:18Z", + "aliases": [ + "CVE-2025-2918" + ], + "details": "The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 3.3.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2918" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/ultimate-blocks/tags/3.2.9/src/blocks/content-filter/block.php#L14" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/ultimate-blocks/tags/3.2.9/src/blocks/content-toggle/block.php#L133" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/ultimate-blocks/tags/3.2.9/src/blocks/how-to/block.php#L335" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/ultimate-blocks/tags/3.2.9/src/blocks/tabbed-content/block.php#L136" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/41b2a4cc-fb23-41eb-b1a4-d793ae924d9a?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T12:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-8g3x-gq5f-v54w/GHSA-8g3x-gq5f-v54w.json b/advisories/unreviewed/2025/06/GHSA-8g3x-gq5f-v54w/GHSA-8g3x-gq5f-v54w.json new file mode 100644 index 00000000000..ec52628e4e5 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-8g3x-gq5f-v54w/GHSA-8g3x-gq5f-v54w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8g3x-gq5f-v54w", + "modified": "2025-06-10T12:30:18Z", + "published": "2025-06-10T12:30:18Z", + "aliases": [ + "CVE-2025-40655" + ], + "details": "A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, create, update and delete databases through the name parameter in /antcatalogue.asp.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40655" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-dm-corporative-cms-dmacroweb" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T10:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-8h63-5g4g-f8h5/GHSA-8h63-5g4g-f8h5.json b/advisories/unreviewed/2025/06/GHSA-8h63-5g4g-f8h5/GHSA-8h63-5g4g-f8h5.json new file mode 100644 index 00000000000..129d5f6ba28 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-8h63-5g4g-f8h5/GHSA-8h63-5g4g-f8h5.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8h63-5g4g-f8h5", + "modified": "2025-06-10T12:30:18Z", + "published": "2025-06-10T12:30:18Z", + "aliases": [ + "CVE-2024-13089" + ], + "details": "An OS command injection vulnerability within the update functionality may allow an authenticated administrator to execute unauthorized arbitrary OS commands.\n\n\n\nUsers with administrative privileges may upload update packages to upgrade the versions of Nozomi Networks Guardian and CMC.\n\nWhile these updates are signed and their signatures are validated prior to installation, an improper signature validation check has been identified.\n\nThis issue could potentially enable users to execute commands remotely on the appliance, thereby impacting confidentiality, integrity, and availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13089" + }, + { + "type": "WEB", + "url": "https://security.nozominetworks.com/NN-2025:1-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T11:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-8mwm-vx53-284j/GHSA-8mwm-vx53-284j.json b/advisories/unreviewed/2025/06/GHSA-8mwm-vx53-284j/GHSA-8mwm-vx53-284j.json new file mode 100644 index 00000000000..6f8f251be09 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-8mwm-vx53-284j/GHSA-8mwm-vx53-284j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8mwm-vx53-284j", + "modified": "2025-06-10T12:30:18Z", + "published": "2025-06-10T12:30:18Z", + "aliases": [ + "CVE-2025-40656" + ], + "details": "A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, create, update and delete databases through the cod parameter in /administer/node-selection/data.asp.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40656" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-dm-corporative-cms-dmacroweb" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T10:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-c2wc-64f2-wxpp/GHSA-c2wc-64f2-wxpp.json b/advisories/unreviewed/2025/06/GHSA-c2wc-64f2-wxpp/GHSA-c2wc-64f2-wxpp.json new file mode 100644 index 00000000000..0317bdca0f2 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-c2wc-64f2-wxpp/GHSA-c2wc-64f2-wxpp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2wc-64f2-wxpp", + "modified": "2025-06-10T12:30:18Z", + "published": "2025-06-10T12:30:18Z", + "aliases": [ + "CVE-2025-40658" + ], + "details": "An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option parameter equal to 0, 1 or 2 in /administer/selectionnode/framesSelection.asp.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40658" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-dm-corporative-cms-dmacroweb" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T10:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-gqmw-jrgv-446q/GHSA-gqmw-jrgv-446q.json b/advisories/unreviewed/2025/06/GHSA-gqmw-jrgv-446q/GHSA-gqmw-jrgv-446q.json new file mode 100644 index 00000000000..bcdc649b38e --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-gqmw-jrgv-446q/GHSA-gqmw-jrgv-446q.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqmw-jrgv-446q", + "modified": "2025-06-10T12:30:19Z", + "published": "2025-06-10T12:30:19Z", + "aliases": [ + "CVE-2025-43698" + ], + "details": "Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows bypass of field level security controls for Salesforce objects. \nThis impacts OmniStudio: before Spring 2025", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43698" + }, + { + "type": "WEB", + "url": "https://help.salesforce.com/s/articleView?id=004980323&type=1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-281" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T12:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-h5mc-fvr9-pr54/GHSA-h5mc-fvr9-pr54.json b/advisories/unreviewed/2025/06/GHSA-h5mc-fvr9-pr54/GHSA-h5mc-fvr9-pr54.json new file mode 100644 index 00000000000..f83e7cd9deb --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-h5mc-fvr9-pr54/GHSA-h5mc-fvr9-pr54.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h5mc-fvr9-pr54", + "modified": "2025-06-10T12:30:18Z", + "published": "2025-06-10T12:30:18Z", + "aliases": [ + "CVE-2025-40661" + ], + "details": "An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option parameter equal to 0, 1 or 2 in /administer/selectionnode/selection.asp.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40661" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-dm-corporative-cms-dmacroweb" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T10:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-h8v5-mvp3-hf33/GHSA-h8v5-mvp3-hf33.json b/advisories/unreviewed/2025/06/GHSA-h8v5-mvp3-hf33/GHSA-h8v5-mvp3-hf33.json new file mode 100644 index 00000000000..76b6b6dd827 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-h8v5-mvp3-hf33/GHSA-h8v5-mvp3-hf33.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h8v5-mvp3-hf33", + "modified": "2025-06-10T12:30:19Z", + "published": "2025-06-10T12:30:19Z", + "aliases": [ + "CVE-2025-4577" + ], + "details": "The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-color attribute in all versions up to, and including, 4.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4577" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/custom-facebook-feed/tags/4.3.0/assets/js/cff-scripts.js#L245" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/custom-facebook-feed/tags/4.3.0/assets/js/cff-scripts.js#L254" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ec3de7e2-4a29-401f-af2c-0ce78d768eae?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T12:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-jv2r-79gq-5mh3/GHSA-jv2r-79gq-5mh3.json b/advisories/unreviewed/2025/06/GHSA-jv2r-79gq-5mh3/GHSA-jv2r-79gq-5mh3.json new file mode 100644 index 00000000000..4304dee46fd --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-jv2r-79gq-5mh3/GHSA-jv2r-79gq-5mh3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jv2r-79gq-5mh3", + "modified": "2025-06-10T12:30:18Z", + "published": "2025-06-10T12:30:18Z", + "aliases": [ + "CVE-2025-40654" + ], + "details": "A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, create, update and delete databases through the name and cod parameters in /antbuspre.asp.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40654" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-dm-corporative-cms-dmacroweb" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T10:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-w6h2-p5q3-p762/GHSA-w6h2-p5q3-p762.json b/advisories/unreviewed/2025/06/GHSA-w6h2-p5q3-p762/GHSA-w6h2-p5q3-p762.json new file mode 100644 index 00000000000..032dfb7ee08 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-w6h2-p5q3-p762/GHSA-w6h2-p5q3-p762.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w6h2-p5q3-p762", + "modified": "2025-06-10T12:30:18Z", + "published": "2025-06-10T12:30:18Z", + "aliases": [ + "CVE-2025-41657" + ], + "details": "Due to an undocumented active bluetooth stack on products delivered within the period 01.01.2024 to 09.05.2025 fingerprinting is possible by an unauthenticated adjacent attacker.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-41657" + }, + { + "type": "WEB", + "url": "https://certvde.com/en/advisories/VDE-2025-047" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-207" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T11:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-x9v7-mgg6-wjfr/GHSA-x9v7-mgg6-wjfr.json b/advisories/unreviewed/2025/06/GHSA-x9v7-mgg6-wjfr/GHSA-x9v7-mgg6-wjfr.json new file mode 100644 index 00000000000..6d18c225a93 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-x9v7-mgg6-wjfr/GHSA-x9v7-mgg6-wjfr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x9v7-mgg6-wjfr", + "modified": "2025-06-10T12:30:18Z", + "published": "2025-06-10T12:30:18Z", + "aliases": [ + "CVE-2025-40660" + ], + "details": "An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option parameter equal to 0, 1 or 2 in /administer/select node/data.asp?mode=catalogue&id1=1&id2=1session=&cod=1&networks=0.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40660" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-dm-corporative-cms-dmacroweb" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T10:15:28Z" + } +} \ No newline at end of file