From 9c69b750d179cbe2e0973fd36015aa75c391213e Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 23 Apr 2025 15:31:52 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-2wj7-33c2-h45r.json | 2 +- .../GHSA-3r66-jfjh-6x67.json | 4 +- .../GHSA-3rjw-7wv2-m7wv.json | 4 +- .../GHSA-5rqp-847g-v4f2.json | 2 +- .../GHSA-62xx-9h8p-6hm3.json | 4 +- .../GHSA-6q9w-5qvx-ggjm.json | 2 +- .../GHSA-743q-wpgm-76xq.json | 2 +- .../GHSA-c6jj-hc2x-m9jc.json | 1 + .../GHSA-gfcg-5w9f-h7j7.json | 3 +- .../GHSA-jfv6-7jf3-3v86.json | 5 ++- .../GHSA-pfw9-5vx2-rm8m.json | 3 +- .../GHSA-qv3c-3mgw-hqqj.json | 4 +- .../GHSA-xg52-54c7-pvc7.json | 2 +- .../GHSA-xvm4-qw2r-9jf6.json | 10 ++++- .../GHSA-9hvr-9q8w-mmmp.json | 3 +- .../GHSA-q79q-mvw6-5crr.json | 3 +- .../GHSA-qvq9-g9g9-hm4j.json | 6 ++- .../GHSA-23p7-2cxv-3gpw.json | 3 +- .../GHSA-24j3-w3xq-4r3w.json | 6 ++- .../GHSA-27ww-388c-hfhf.json | 6 ++- .../GHSA-286f-m35x-h7r5.json | 19 +++++++-- .../GHSA-2m4j-5h27-9q77.json | 19 +++++++-- .../GHSA-2qhw-4vw3-x335.json | 6 ++- .../GHSA-32gj-564x-3982.json | 36 +++++++++++++++++ .../GHSA-3996-4m5r-mmwf.json | 6 ++- .../GHSA-4v4v-wmpc-5vh5.json | 3 +- .../GHSA-5qr3-hm6r-fwx9.json | 40 +++++++++++++++++++ .../GHSA-6qxc-wcv9-954v.json | 15 +++++-- .../GHSA-743m-763q-grgv.json | 15 +++++-- .../GHSA-7gr5-w4q5-hvw3.json | 15 +++++-- .../GHSA-869x-7923-5x6q.json | 15 +++++-- .../GHSA-8hhf-mvxr-j339.json | 3 +- .../GHSA-92h7-q9m9-98h8.json | 40 +++++++++++++++++++ .../GHSA-92w5-fx6f-j3pw.json | 15 +++++-- .../GHSA-cm5r-mjj2-pxp4.json | 19 +++++++-- .../GHSA-f57x-prr8-55vv.json | 40 +++++++++++++++++++ .../GHSA-fc67-q532-m8q4.json | 29 ++++++++++++++ .../GHSA-fg9r-f95c-6rgw.json | 19 +++++++-- .../GHSA-fjxj-774q-fh4q.json | 15 +++++-- .../GHSA-gg8q-wm6m-x7w3.json | 19 +++++++-- .../GHSA-gwvg-5xhp-rp5q.json | 15 +++++-- .../GHSA-h65q-2g3v-qm4r.json | 15 +++++-- .../GHSA-j2xc-53c4-c8p4.json | 3 +- .../GHSA-jqqv-g9pc-97qc.json | 29 ++++++++++++++ .../GHSA-mp63-mm73-jhgm.json | 19 +++++++-- .../GHSA-mwgr-p983-v4m9.json | 15 +++++-- .../GHSA-p2gm-m8q4-6r5q.json | 19 +++++++-- .../GHSA-q8pq-pv68-q9cm.json | 15 +++++-- .../GHSA-qch9-x3vr-h45w.json | 15 +++++-- .../GHSA-qrqw-4g4q-63h8.json | 15 +++++-- .../GHSA-r24q-j79w-9jww.json | 15 +++++-- .../GHSA-rgcr-wg7p-29p2.json | 15 +++++-- .../GHSA-rpcc-c8w6-wwj6.json | 15 +++++-- .../GHSA-rw43-mgp5-rf2m.json | 15 +++++-- .../GHSA-v7m9-pm9f-frqg.json | 15 +++++-- .../GHSA-vwgx-54x2-gc6m.json | 15 +++++-- .../GHSA-x8cw-f5xw-fwh2.json | 36 +++++++++++++++++ 57 files changed, 624 insertions(+), 125 deletions(-) create mode 100644 advisories/unreviewed/2025/04/GHSA-32gj-564x-3982/GHSA-32gj-564x-3982.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5qr3-hm6r-fwx9/GHSA-5qr3-hm6r-fwx9.json create mode 100644 advisories/unreviewed/2025/04/GHSA-92h7-q9m9-98h8/GHSA-92h7-q9m9-98h8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-f57x-prr8-55vv/GHSA-f57x-prr8-55vv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-fc67-q532-m8q4/GHSA-fc67-q532-m8q4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-jqqv-g9pc-97qc/GHSA-jqqv-g9pc-97qc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-x8cw-f5xw-fwh2/GHSA-x8cw-f5xw-fwh2.json diff --git a/advisories/unreviewed/2022/12/GHSA-2wj7-33c2-h45r/GHSA-2wj7-33c2-h45r.json b/advisories/unreviewed/2022/12/GHSA-2wj7-33c2-h45r/GHSA-2wj7-33c2-h45r.json index 8a9564bd9de..02e9bee07e8 100644 --- a/advisories/unreviewed/2022/12/GHSA-2wj7-33c2-h45r/GHSA-2wj7-33c2-h45r.json +++ b/advisories/unreviewed/2022/12/GHSA-2wj7-33c2-h45r/GHSA-2wj7-33c2-h45r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2wj7-33c2-h45r", - "modified": "2022-12-08T15:30:24Z", + "modified": "2025-04-23T15:30:35Z", "published": "2022-12-05T21:30:41Z", "aliases": [ "CVE-2022-45479" diff --git a/advisories/unreviewed/2022/12/GHSA-3r66-jfjh-6x67/GHSA-3r66-jfjh-6x67.json b/advisories/unreviewed/2022/12/GHSA-3r66-jfjh-6x67/GHSA-3r66-jfjh-6x67.json index 02e2012d35d..a9c7807039d 100644 --- a/advisories/unreviewed/2022/12/GHSA-3r66-jfjh-6x67/GHSA-3r66-jfjh-6x67.json +++ b/advisories/unreviewed/2022/12/GHSA-3r66-jfjh-6x67/GHSA-3r66-jfjh-6x67.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-78" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-3rjw-7wv2-m7wv/GHSA-3rjw-7wv2-m7wv.json b/advisories/unreviewed/2022/12/GHSA-3rjw-7wv2-m7wv/GHSA-3rjw-7wv2-m7wv.json index e00881f1a2f..00564a98cfc 100644 --- a/advisories/unreviewed/2022/12/GHSA-3rjw-7wv2-m7wv/GHSA-3rjw-7wv2-m7wv.json +++ b/advisories/unreviewed/2022/12/GHSA-3rjw-7wv2-m7wv/GHSA-3rjw-7wv2-m7wv.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-306" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-5rqp-847g-v4f2/GHSA-5rqp-847g-v4f2.json b/advisories/unreviewed/2022/12/GHSA-5rqp-847g-v4f2/GHSA-5rqp-847g-v4f2.json index d2034ceb077..b3ab63eedfc 100644 --- a/advisories/unreviewed/2022/12/GHSA-5rqp-847g-v4f2/GHSA-5rqp-847g-v4f2.json +++ b/advisories/unreviewed/2022/12/GHSA-5rqp-847g-v4f2/GHSA-5rqp-847g-v4f2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5rqp-847g-v4f2", - "modified": "2022-12-13T15:30:27Z", + "modified": "2025-04-23T15:30:41Z", "published": "2022-12-12T03:31:04Z", "aliases": [ "CVE-2022-45227" diff --git a/advisories/unreviewed/2022/12/GHSA-62xx-9h8p-6hm3/GHSA-62xx-9h8p-6hm3.json b/advisories/unreviewed/2022/12/GHSA-62xx-9h8p-6hm3/GHSA-62xx-9h8p-6hm3.json index 3d553589c63..9bec555788a 100644 --- a/advisories/unreviewed/2022/12/GHSA-62xx-9h8p-6hm3/GHSA-62xx-9h8p-6hm3.json +++ b/advisories/unreviewed/2022/12/GHSA-62xx-9h8p-6hm3/GHSA-62xx-9h8p-6hm3.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-306" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-6q9w-5qvx-ggjm/GHSA-6q9w-5qvx-ggjm.json b/advisories/unreviewed/2022/12/GHSA-6q9w-5qvx-ggjm/GHSA-6q9w-5qvx-ggjm.json index b478f646c32..ab7e1f41e59 100644 --- a/advisories/unreviewed/2022/12/GHSA-6q9w-5qvx-ggjm/GHSA-6q9w-5qvx-ggjm.json +++ b/advisories/unreviewed/2022/12/GHSA-6q9w-5qvx-ggjm/GHSA-6q9w-5qvx-ggjm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6q9w-5qvx-ggjm", - "modified": "2022-12-07T21:30:30Z", + "modified": "2025-04-23T15:30:36Z", "published": "2022-12-06T15:30:28Z", "aliases": [ "CVE-2020-6627" diff --git a/advisories/unreviewed/2022/12/GHSA-743q-wpgm-76xq/GHSA-743q-wpgm-76xq.json b/advisories/unreviewed/2022/12/GHSA-743q-wpgm-76xq/GHSA-743q-wpgm-76xq.json index 9cb39963aaa..8cbaee4ab3f 100644 --- a/advisories/unreviewed/2022/12/GHSA-743q-wpgm-76xq/GHSA-743q-wpgm-76xq.json +++ b/advisories/unreviewed/2022/12/GHSA-743q-wpgm-76xq/GHSA-743q-wpgm-76xq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-743q-wpgm-76xq", - "modified": "2022-12-13T15:30:28Z", + "modified": "2025-04-23T15:30:41Z", "published": "2022-12-12T03:31:04Z", "aliases": [ "CVE-2022-45228" diff --git a/advisories/unreviewed/2022/12/GHSA-c6jj-hc2x-m9jc/GHSA-c6jj-hc2x-m9jc.json b/advisories/unreviewed/2022/12/GHSA-c6jj-hc2x-m9jc/GHSA-c6jj-hc2x-m9jc.json index f2ac646f1a1..7962113926f 100644 --- a/advisories/unreviewed/2022/12/GHSA-c6jj-hc2x-m9jc/GHSA-c6jj-hc2x-m9jc.json +++ b/advisories/unreviewed/2022/12/GHSA-c6jj-hc2x-m9jc/GHSA-c6jj-hc2x-m9jc.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-287", "CWE-306" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2022/12/GHSA-gfcg-5w9f-h7j7/GHSA-gfcg-5w9f-h7j7.json b/advisories/unreviewed/2022/12/GHSA-gfcg-5w9f-h7j7/GHSA-gfcg-5w9f-h7j7.json index 03a68b31248..0e954efa5bb 100644 --- a/advisories/unreviewed/2022/12/GHSA-gfcg-5w9f-h7j7/GHSA-gfcg-5w9f-h7j7.json +++ b/advisories/unreviewed/2022/12/GHSA-gfcg-5w9f-h7j7/GHSA-gfcg-5w9f-h7j7.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-jfv6-7jf3-3v86/GHSA-jfv6-7jf3-3v86.json b/advisories/unreviewed/2022/12/GHSA-jfv6-7jf3-3v86/GHSA-jfv6-7jf3-3v86.json index c72334dc4c6..275ad7b514f 100644 --- a/advisories/unreviewed/2022/12/GHSA-jfv6-7jf3-3v86/GHSA-jfv6-7jf3-3v86.json +++ b/advisories/unreviewed/2022/12/GHSA-jfv6-7jf3-3v86/GHSA-jfv6-7jf3-3v86.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jfv6-7jf3-3v86", - "modified": "2022-12-10T03:30:43Z", + "modified": "2025-04-23T15:30:38Z", "published": "2022-12-08T06:30:29Z", "aliases": [ "CVE-2022-46792" @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-732" + "CWE-732", + "CWE-863" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-pfw9-5vx2-rm8m/GHSA-pfw9-5vx2-rm8m.json b/advisories/unreviewed/2022/12/GHSA-pfw9-5vx2-rm8m/GHSA-pfw9-5vx2-rm8m.json index 2f25082494d..fa8f9725219 100644 --- a/advisories/unreviewed/2022/12/GHSA-pfw9-5vx2-rm8m/GHSA-pfw9-5vx2-rm8m.json +++ b/advisories/unreviewed/2022/12/GHSA-pfw9-5vx2-rm8m/GHSA-pfw9-5vx2-rm8m.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-qv3c-3mgw-hqqj/GHSA-qv3c-3mgw-hqqj.json b/advisories/unreviewed/2022/12/GHSA-qv3c-3mgw-hqqj/GHSA-qv3c-3mgw-hqqj.json index 697f7f6803c..dd986039ff9 100644 --- a/advisories/unreviewed/2022/12/GHSA-qv3c-3mgw-hqqj/GHSA-qv3c-3mgw-hqqj.json +++ b/advisories/unreviewed/2022/12/GHSA-qv3c-3mgw-hqqj/GHSA-qv3c-3mgw-hqqj.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-xg52-54c7-pvc7/GHSA-xg52-54c7-pvc7.json b/advisories/unreviewed/2022/12/GHSA-xg52-54c7-pvc7/GHSA-xg52-54c7-pvc7.json index 0adaf50526e..58bfde59950 100644 --- a/advisories/unreviewed/2022/12/GHSA-xg52-54c7-pvc7/GHSA-xg52-54c7-pvc7.json +++ b/advisories/unreviewed/2022/12/GHSA-xg52-54c7-pvc7/GHSA-xg52-54c7-pvc7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xg52-54c7-pvc7", - "modified": "2022-12-14T15:30:17Z", + "modified": "2025-04-23T15:30:41Z", "published": "2022-12-09T21:30:46Z", "aliases": [ "CVE-2022-44790" diff --git a/advisories/unreviewed/2022/12/GHSA-xvm4-qw2r-9jf6/GHSA-xvm4-qw2r-9jf6.json b/advisories/unreviewed/2022/12/GHSA-xvm4-qw2r-9jf6/GHSA-xvm4-qw2r-9jf6.json index 625aa8ec3ef..6ae18161c4e 100644 --- a/advisories/unreviewed/2022/12/GHSA-xvm4-qw2r-9jf6/GHSA-xvm4-qw2r-9jf6.json +++ b/advisories/unreviewed/2022/12/GHSA-xvm4-qw2r-9jf6/GHSA-xvm4-qw2r-9jf6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xvm4-qw2r-9jf6", - "modified": "2022-12-13T15:30:27Z", + "modified": "2025-04-23T15:30:41Z", "published": "2022-12-10T18:30:22Z", "aliases": [ "CVE-2022-45145" @@ -19,6 +19,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45145" }, + { + "type": "WEB", + "url": "https://code.call-cc.org/cgi-bin/gitweb.cgi?p=chicken-core.git%3Ba=blobdiff%3Bf=NEWS%3Bh=54888afff09353093453673c407cabfe76a5ce77%3Bhp=a3fd88a892f82c8353267f50509d018bbb1934b9%3Bhb=670478435a982fc4d1f001ea08669f53d35a51cd%3Bhpb=a08f8f548d772ef410c672ba33a27108d8d434f3" + }, + { + "type": "WEB", + "url": "https://code.call-cc.org/cgi-bin/gitweb.cgi?p=chicken-core.git%3Ba=blobdiff%3Bf=egg-compile.scm%3Bh=9ba4568113350ec75204cba55e43e27925e2d6fe%3Bhp=c1f2ceb0fb470f63c2ba2a1cf9d8d40083c2359f%3Bhb=a08f8f548d772ef410c672ba33a27108d8d434f3%3Bhpb=9c6fb001c25de4390f46ffd7c3c94237f4df92a9" + }, { "type": "WEB", "url": "https://code.call-cc.org/cgi-bin/gitweb.cgi?p=chicken-core.git;a=blobdiff;f=NEWS;h=54888afff09353093453673c407cabfe76a5ce77;hp=a3fd88a892f82c8353267f50509d018bbb1934b9;hb=670478435a982fc4d1f001ea08669f53d35a51cd;hpb=a08f8f548d772ef410c672ba33a27108d8d434f3" diff --git a/advisories/unreviewed/2024/07/GHSA-9hvr-9q8w-mmmp/GHSA-9hvr-9q8w-mmmp.json b/advisories/unreviewed/2024/07/GHSA-9hvr-9q8w-mmmp/GHSA-9hvr-9q8w-mmmp.json index 8a6ef3797e7..6feece21774 100644 --- a/advisories/unreviewed/2024/07/GHSA-9hvr-9q8w-mmmp/GHSA-9hvr-9q8w-mmmp.json +++ b/advisories/unreviewed/2024/07/GHSA-9hvr-9q8w-mmmp/GHSA-9hvr-9q8w-mmmp.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-89" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-q79q-mvw6-5crr/GHSA-q79q-mvw6-5crr.json b/advisories/unreviewed/2024/11/GHSA-q79q-mvw6-5crr/GHSA-q79q-mvw6-5crr.json index af8f3ce45f6..f7b2a17ebf6 100644 --- a/advisories/unreviewed/2024/11/GHSA-q79q-mvw6-5crr/GHSA-q79q-mvw6-5crr.json +++ b/advisories/unreviewed/2024/11/GHSA-q79q-mvw6-5crr/GHSA-q79q-mvw6-5crr.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-qvq9-g9g9-hm4j/GHSA-qvq9-g9g9-hm4j.json b/advisories/unreviewed/2024/12/GHSA-qvq9-g9g9-hm4j/GHSA-qvq9-g9g9-hm4j.json index 96af34f7039..41d0b86c5ea 100644 --- a/advisories/unreviewed/2024/12/GHSA-qvq9-g9g9-hm4j/GHSA-qvq9-g9g9-hm4j.json +++ b/advisories/unreviewed/2024/12/GHSA-qvq9-g9g9-hm4j/GHSA-qvq9-g9g9-hm4j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qvq9-g9g9-hm4j", - "modified": "2024-12-02T15:31:38Z", + "modified": "2025-04-23T15:30:46Z", "published": "2024-12-02T15:31:38Z", "aliases": [ "CVE-2024-52459" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://patchstack.com/database/wordpress/plugin/chameleon-jobs/vulnerability/wordpress-chameleoni-jobs-plugin-2-5-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + }, + { + "type": "WEB", + "url": "https://plugins.svn.wordpress.org/chameleon-jobs/tags/2.5.6/readme.txt" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/04/GHSA-23p7-2cxv-3gpw/GHSA-23p7-2cxv-3gpw.json b/advisories/unreviewed/2025/04/GHSA-23p7-2cxv-3gpw/GHSA-23p7-2cxv-3gpw.json index 04b82ec0fc6..16106e4f59d 100644 --- a/advisories/unreviewed/2025/04/GHSA-23p7-2cxv-3gpw/GHSA-23p7-2cxv-3gpw.json +++ b/advisories/unreviewed/2025/04/GHSA-23p7-2cxv-3gpw/GHSA-23p7-2cxv-3gpw.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-24j3-w3xq-4r3w/GHSA-24j3-w3xq-4r3w.json b/advisories/unreviewed/2025/04/GHSA-24j3-w3xq-4r3w/GHSA-24j3-w3xq-4r3w.json index 03353209c7f..cbe30dde26e 100644 --- a/advisories/unreviewed/2025/04/GHSA-24j3-w3xq-4r3w/GHSA-24j3-w3xq-4r3w.json +++ b/advisories/unreviewed/2025/04/GHSA-24j3-w3xq-4r3w/GHSA-24j3-w3xq-4r3w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-24j3-w3xq-4r3w", - "modified": "2025-04-18T15:31:37Z", + "modified": "2025-04-23T15:30:47Z", "published": "2025-04-18T00:30:43Z", "aliases": [ "CVE-2025-29460" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29460" }, + { + "type": "WEB", + "url": "https://docs.mybb.com/1.8/administration/security/protection/#limit-access-to-private-hosts-and-ip-addresses" + }, { "type": "WEB", "url": "https://www.yuque.com/morysummer/vx41bz/fgg059stiog457ch" diff --git a/advisories/unreviewed/2025/04/GHSA-27ww-388c-hfhf/GHSA-27ww-388c-hfhf.json b/advisories/unreviewed/2025/04/GHSA-27ww-388c-hfhf/GHSA-27ww-388c-hfhf.json index b3859a0bb17..bcebbdb40c2 100644 --- a/advisories/unreviewed/2025/04/GHSA-27ww-388c-hfhf/GHSA-27ww-388c-hfhf.json +++ b/advisories/unreviewed/2025/04/GHSA-27ww-388c-hfhf/GHSA-27ww-388c-hfhf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-27ww-388c-hfhf", - "modified": "2025-04-18T18:31:23Z", + "modified": "2025-04-23T15:30:47Z", "published": "2025-04-18T00:30:43Z", "aliases": [ "CVE-2025-29457" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29457" }, + { + "type": "WEB", + "url": "https://docs.mybb.com/1.8/administration/security/protection/#limit-access-to-private-hosts-and-ip-addresses" + }, { "type": "WEB", "url": "https://www.yuque.com/morysummer/vx41bz/vro4dvxzuiwlg6uv" diff --git a/advisories/unreviewed/2025/04/GHSA-286f-m35x-h7r5/GHSA-286f-m35x-h7r5.json b/advisories/unreviewed/2025/04/GHSA-286f-m35x-h7r5/GHSA-286f-m35x-h7r5.json index 8738e43f721..a478d9c59cb 100644 --- a/advisories/unreviewed/2025/04/GHSA-286f-m35x-h7r5/GHSA-286f-m35x-h7r5.json +++ b/advisories/unreviewed/2025/04/GHSA-286f-m35x-h7r5/GHSA-286f-m35x-h7r5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-286f-m35x-h7r5", - "modified": "2025-04-22T18:32:12Z", + "modified": "2025-04-23T15:30:55Z", "published": "2025-04-22T18:32:12Z", "aliases": [ "CVE-2025-28029" ], "details": "TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a buffer overflow vulnerability in cstecgi.cgi", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -17,11 +22,17 @@ { "type": "WEB", "url": "https://locrian-lightning-dc7.notion.site/BufferOverflow5-1978e5e2b1a28043af78e5ccfc0203a0" + }, + { + "type": "WEB", + "url": "https://locrian-lightning-dc7.notion.site/CVE-2025-28023-CVE-2025-28029-BufferOverflow5-1978e5e2b1a28043af78e5ccfc0203a0" } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-22T18:15:59Z" diff --git a/advisories/unreviewed/2025/04/GHSA-2m4j-5h27-9q77/GHSA-2m4j-5h27-9q77.json b/advisories/unreviewed/2025/04/GHSA-2m4j-5h27-9q77/GHSA-2m4j-5h27-9q77.json index c8a053a9cc2..bbadfbf556e 100644 --- a/advisories/unreviewed/2025/04/GHSA-2m4j-5h27-9q77/GHSA-2m4j-5h27-9q77.json +++ b/advisories/unreviewed/2025/04/GHSA-2m4j-5h27-9q77/GHSA-2m4j-5h27-9q77.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2m4j-5h27-9q77", - "modified": "2025-04-22T18:32:12Z", + "modified": "2025-04-23T15:30:55Z", "published": "2025-04-22T18:32:12Z", "aliases": [ "CVE-2025-28027" ], "details": "TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 was found to contain a buffer overflow vulnerability in downloadFile.cgi.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -17,11 +22,17 @@ { "type": "WEB", "url": "https://locrian-lightning-dc7.notion.site/BufferOverflow2-19e8e5e2b1a2806db38bea19abb4630a?pvs=73" + }, + { + "type": "WEB", + "url": "https://locrian-lightning-dc7.notion.site/CVE-2025-28027-BufferOverflow2-19e8e5e2b1a2806db38bea19abb4630a" } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-22T18:15:58Z" diff --git a/advisories/unreviewed/2025/04/GHSA-2qhw-4vw3-x335/GHSA-2qhw-4vw3-x335.json b/advisories/unreviewed/2025/04/GHSA-2qhw-4vw3-x335/GHSA-2qhw-4vw3-x335.json index 2e9ebcd9723..be631fd65ac 100644 --- a/advisories/unreviewed/2025/04/GHSA-2qhw-4vw3-x335/GHSA-2qhw-4vw3-x335.json +++ b/advisories/unreviewed/2025/04/GHSA-2qhw-4vw3-x335/GHSA-2qhw-4vw3-x335.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2qhw-4vw3-x335", - "modified": "2025-04-18T15:31:37Z", + "modified": "2025-04-23T15:30:47Z", "published": "2025-04-18T00:30:43Z", "aliases": [ "CVE-2025-29459" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29459" }, + { + "type": "WEB", + "url": "https://docs.mybb.com/1.8/administration/security/protection/#limit-access-to-private-hosts-and-ip-addresses" + }, { "type": "WEB", "url": "https://www.yuque.com/morysummer/vx41bz/ggnmg5nnu635kvrc" diff --git a/advisories/unreviewed/2025/04/GHSA-32gj-564x-3982/GHSA-32gj-564x-3982.json b/advisories/unreviewed/2025/04/GHSA-32gj-564x-3982/GHSA-32gj-564x-3982.json new file mode 100644 index 00000000000..3d213106bd4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-32gj-564x-3982/GHSA-32gj-564x-3982.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-32gj-564x-3982", + "modified": "2025-04-23T15:30:47Z", + "published": "2025-04-17T18:31:22Z", + "aliases": [ + "CVE-2025-42921" + ], + "details": "In JetBrains Toolbox App before 2.6 host key verification was missing in SSH plugin", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-42921" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-297" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3996-4m5r-mmwf/GHSA-3996-4m5r-mmwf.json b/advisories/unreviewed/2025/04/GHSA-3996-4m5r-mmwf/GHSA-3996-4m5r-mmwf.json index 93d0f387d1c..c13d488b460 100644 --- a/advisories/unreviewed/2025/04/GHSA-3996-4m5r-mmwf/GHSA-3996-4m5r-mmwf.json +++ b/advisories/unreviewed/2025/04/GHSA-3996-4m5r-mmwf/GHSA-3996-4m5r-mmwf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3996-4m5r-mmwf", - "modified": "2025-04-18T18:31:23Z", + "modified": "2025-04-23T15:30:47Z", "published": "2025-04-18T00:30:43Z", "aliases": [ "CVE-2025-29458" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29458" }, + { + "type": "WEB", + "url": "https://docs.mybb.com/1.8/administration/security/protection/#limit-access-to-private-hosts-and-ip-addresses" + }, { "type": "WEB", "url": "https://www.yuque.com/morysummer/vx41bz/qu7zyyxr84qno64e" diff --git a/advisories/unreviewed/2025/04/GHSA-4v4v-wmpc-5vh5/GHSA-4v4v-wmpc-5vh5.json b/advisories/unreviewed/2025/04/GHSA-4v4v-wmpc-5vh5/GHSA-4v4v-wmpc-5vh5.json index c1ff5a28d6a..e6f3e3e1915 100644 --- a/advisories/unreviewed/2025/04/GHSA-4v4v-wmpc-5vh5/GHSA-4v4v-wmpc-5vh5.json +++ b/advisories/unreviewed/2025/04/GHSA-4v4v-wmpc-5vh5/GHSA-4v4v-wmpc-5vh5.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-94" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-5qr3-hm6r-fwx9/GHSA-5qr3-hm6r-fwx9.json b/advisories/unreviewed/2025/04/GHSA-5qr3-hm6r-fwx9/GHSA-5qr3-hm6r-fwx9.json new file mode 100644 index 00000000000..d902a157288 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5qr3-hm6r-fwx9/GHSA-5qr3-hm6r-fwx9.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5qr3-hm6r-fwx9", + "modified": "2025-04-23T15:30:57Z", + "published": "2025-04-23T15:30:57Z", + "aliases": [ + "CVE-2025-43965" + ], + "details": "In MIFF image processing in ImageMagick before 7.1.1-44, image depth is mishandled after SetQuantumFormat is used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43965" + }, + { + "type": "WEB", + "url": "https://github.com/ImageMagick/ImageMagick/commit/bac413a26073923d3ffb258adaab07fb3fe8fdc9" + }, + { + "type": "WEB", + "url": "https://github.com/ImageMagick/Website/blob/main/ChangeLog.md#711-44---2025-02-22" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-131" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-23T15:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6qxc-wcv9-954v/GHSA-6qxc-wcv9-954v.json b/advisories/unreviewed/2025/04/GHSA-6qxc-wcv9-954v/GHSA-6qxc-wcv9-954v.json index 95e881ee334..7c0ce82f56e 100644 --- a/advisories/unreviewed/2025/04/GHSA-6qxc-wcv9-954v/GHSA-6qxc-wcv9-954v.json +++ b/advisories/unreviewed/2025/04/GHSA-6qxc-wcv9-954v/GHSA-6qxc-wcv9-954v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6qxc-wcv9-954v", - "modified": "2025-04-22T21:30:44Z", + "modified": "2025-04-23T15:30:56Z", "published": "2025-04-22T21:30:44Z", "aliases": [ "CVE-2024-53568" ], "details": "A stored cross-site scripting (XSS) vulnerability in the Image Upload section of Volmarg Personal Management System v1.4.65 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the tag parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-22T19:15:51Z" diff --git a/advisories/unreviewed/2025/04/GHSA-743m-763q-grgv/GHSA-743m-763q-grgv.json b/advisories/unreviewed/2025/04/GHSA-743m-763q-grgv/GHSA-743m-763q-grgv.json index 8492dfff03c..83167940c62 100644 --- a/advisories/unreviewed/2025/04/GHSA-743m-763q-grgv/GHSA-743m-763q-grgv.json +++ b/advisories/unreviewed/2025/04/GHSA-743m-763q-grgv/GHSA-743m-763q-grgv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-743m-763q-grgv", - "modified": "2025-04-22T18:32:13Z", + "modified": "2025-04-23T15:30:56Z", "published": "2025-04-22T18:32:13Z", "aliases": [ "CVE-2025-43951" ], "details": "LabVantage before LV 8.8.0.13 HF6 allows local file inclusion. Authenticated users can retrieve arbitrary files from the environment via the objectname request parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-73" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-22T18:16:01Z" diff --git a/advisories/unreviewed/2025/04/GHSA-7gr5-w4q5-hvw3/GHSA-7gr5-w4q5-hvw3.json b/advisories/unreviewed/2025/04/GHSA-7gr5-w4q5-hvw3/GHSA-7gr5-w4q5-hvw3.json index e54613efaee..2cb659b76c3 100644 --- a/advisories/unreviewed/2025/04/GHSA-7gr5-w4q5-hvw3/GHSA-7gr5-w4q5-hvw3.json +++ b/advisories/unreviewed/2025/04/GHSA-7gr5-w4q5-hvw3/GHSA-7gr5-w4q5-hvw3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7gr5-w4q5-hvw3", - "modified": "2025-04-22T18:32:12Z", + "modified": "2025-04-23T15:30:54Z", "published": "2025-04-22T18:32:12Z", "aliases": [ "CVE-2023-44753" ], "details": "A stored cross-site scripting (XSS) vulnerability fin Student Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email parameter on the profile.php page.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-22T18:15:58Z" diff --git a/advisories/unreviewed/2025/04/GHSA-869x-7923-5x6q/GHSA-869x-7923-5x6q.json b/advisories/unreviewed/2025/04/GHSA-869x-7923-5x6q/GHSA-869x-7923-5x6q.json index ef7afccab3f..ac99c97c637 100644 --- a/advisories/unreviewed/2025/04/GHSA-869x-7923-5x6q/GHSA-869x-7923-5x6q.json +++ b/advisories/unreviewed/2025/04/GHSA-869x-7923-5x6q/GHSA-869x-7923-5x6q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-869x-7923-5x6q", - "modified": "2025-04-22T18:32:13Z", + "modified": "2025-04-23T15:30:55Z", "published": "2025-04-22T18:32:13Z", "aliases": [ "CVE-2025-43946" ], "details": "TCPWave DDI 11.34P1C2 allows Remote Code Execution via Unrestricted File Upload (combined with Path Traversal).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-22T18:16:01Z" diff --git a/advisories/unreviewed/2025/04/GHSA-8hhf-mvxr-j339/GHSA-8hhf-mvxr-j339.json b/advisories/unreviewed/2025/04/GHSA-8hhf-mvxr-j339/GHSA-8hhf-mvxr-j339.json index 5dfaac1a87d..a63b8ed613c 100644 --- a/advisories/unreviewed/2025/04/GHSA-8hhf-mvxr-j339/GHSA-8hhf-mvxr-j339.json +++ b/advisories/unreviewed/2025/04/GHSA-8hhf-mvxr-j339/GHSA-8hhf-mvxr-j339.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-92h7-q9m9-98h8/GHSA-92h7-q9m9-98h8.json b/advisories/unreviewed/2025/04/GHSA-92h7-q9m9-98h8/GHSA-92h7-q9m9-98h8.json new file mode 100644 index 00000000000..ab63333305a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-92h7-q9m9-98h8/GHSA-92h7-q9m9-98h8.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-92h7-q9m9-98h8", + "modified": "2025-04-23T15:30:57Z", + "published": "2025-04-23T15:30:57Z", + "aliases": [ + "CVE-2025-43716" + ], + "details": "A directory traversal vulnerability exists in Ivanti LANDesk Management Gateway through 4.2-1.9. By appending %3F.php to the URI of the /client/index.php endpoint, an attacker can bypass access controls and gain unauthorized access to various endpoints such as /client/index.php%3F.php/gsb/firewall.php within the management web panel, potentially exposing sensitive device information. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43716" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Graphical-overview-of-the-LANDesk-Management-Gateway-Functionality" + }, + { + "type": "WEB", + "url": "https://medium.com/@0xbytehunter/discovery-of-path-traversal-vulnerability-in-landesk-management-gateway-devices-6dba386dd290" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-180" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-23T14:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-92w5-fx6f-j3pw/GHSA-92w5-fx6f-j3pw.json b/advisories/unreviewed/2025/04/GHSA-92w5-fx6f-j3pw/GHSA-92w5-fx6f-j3pw.json index a88321736df..911f88f7cee 100644 --- a/advisories/unreviewed/2025/04/GHSA-92w5-fx6f-j3pw/GHSA-92w5-fx6f-j3pw.json +++ b/advisories/unreviewed/2025/04/GHSA-92w5-fx6f-j3pw/GHSA-92w5-fx6f-j3pw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-92w5-fx6f-j3pw", - "modified": "2025-04-22T18:32:13Z", + "modified": "2025-04-23T15:30:56Z", "published": "2025-04-22T18:32:13Z", "aliases": [ "CVE-2025-43949" ], "details": "MuM (aka Mensch und Maschine) MapEdit (aka mapedit-web) 24.2.3 is vulnerable to SQL Injection that allows an attacker to execute malicious SQL statements that control a web application's database server.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-22T18:16:01Z" diff --git a/advisories/unreviewed/2025/04/GHSA-cm5r-mjj2-pxp4/GHSA-cm5r-mjj2-pxp4.json b/advisories/unreviewed/2025/04/GHSA-cm5r-mjj2-pxp4/GHSA-cm5r-mjj2-pxp4.json index 0492a75551c..c20bcb1518a 100644 --- a/advisories/unreviewed/2025/04/GHSA-cm5r-mjj2-pxp4/GHSA-cm5r-mjj2-pxp4.json +++ b/advisories/unreviewed/2025/04/GHSA-cm5r-mjj2-pxp4/GHSA-cm5r-mjj2-pxp4.json @@ -1,27 +1,38 @@ { "schema_version": "1.4.0", "id": "GHSA-cm5r-mjj2-pxp4", - "modified": "2025-04-22T18:32:12Z", + "modified": "2025-04-23T15:30:55Z", "published": "2025-04-22T18:32:12Z", "aliases": [ "CVE-2025-28036" ], "details": "TOTOLINK A950RG V4.1.2cu.5161_B20200903 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28036" }, + { + "type": "WEB", + "url": "https://locrian-lightning-dc7.notion.site/CVE-2025-28035-CVE-2025-28036-RCE1-1a98e5e2b1a28081880dd817104b3af4" + }, { "type": "WEB", "url": "https://locrian-lightning-dc7.notion.site/RCE1-1a98e5e2b1a28081880dd817104b3af4" } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-22T18:15:59Z" diff --git a/advisories/unreviewed/2025/04/GHSA-f57x-prr8-55vv/GHSA-f57x-prr8-55vv.json b/advisories/unreviewed/2025/04/GHSA-f57x-prr8-55vv/GHSA-f57x-prr8-55vv.json new file mode 100644 index 00000000000..3d180ee452a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f57x-prr8-55vv/GHSA-f57x-prr8-55vv.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f57x-prr8-55vv", + "modified": "2025-04-23T15:30:57Z", + "published": "2025-04-23T15:30:57Z", + "aliases": [ + "CVE-2025-46393" + ], + "details": "In multispectral MIFF image processing in ImageMagick before 7.1.1-44, packet_size is mishandled (related to the rendering of all channels in an arbitrary order).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46393" + }, + { + "type": "WEB", + "url": "https://github.com/ImageMagick/ImageMagick/commit/81ac8a0d2eb21739842ed18c48c7646b7eef65b8" + }, + { + "type": "WEB", + "url": "https://github.com/ImageMagick/Website/blob/main/ChangeLog.md#711-44---2025-02-22" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-131" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-23T15:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fc67-q532-m8q4/GHSA-fc67-q532-m8q4.json b/advisories/unreviewed/2025/04/GHSA-fc67-q532-m8q4/GHSA-fc67-q532-m8q4.json new file mode 100644 index 00000000000..55668b35803 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fc67-q532-m8q4/GHSA-fc67-q532-m8q4.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fc67-q532-m8q4", + "modified": "2025-04-23T15:30:57Z", + "published": "2025-04-23T15:30:57Z", + "aliases": [ + "CVE-2025-45427" + ], + "details": "In Tenda AC9 v1.0 with firmware V15.03.05.14_multi, the security parameter of /goform/WifiBasicSet has a stack overflow vulnerability, which can lead to remote arbitrary code execution.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45427" + }, + { + "type": "WEB", + "url": "https://github.com/shuqi233/loophole/blob/main/Tenda%20AC9/WifiBasicSet-security.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-23T15:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fg9r-f95c-6rgw/GHSA-fg9r-f95c-6rgw.json b/advisories/unreviewed/2025/04/GHSA-fg9r-f95c-6rgw/GHSA-fg9r-f95c-6rgw.json index b97134a8aca..b2b74b93303 100644 --- a/advisories/unreviewed/2025/04/GHSA-fg9r-f95c-6rgw/GHSA-fg9r-f95c-6rgw.json +++ b/advisories/unreviewed/2025/04/GHSA-fg9r-f95c-6rgw/GHSA-fg9r-f95c-6rgw.json @@ -1,27 +1,38 @@ { "schema_version": "1.4.0", "id": "GHSA-fg9r-f95c-6rgw", - "modified": "2025-04-22T18:32:12Z", + "modified": "2025-04-23T15:30:55Z", "published": "2025-04-22T18:32:12Z", "aliases": [ "CVE-2025-28035" ], "details": "TOTOLINK A830R V4.1.2cu.5182_B20201102 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28035" }, + { + "type": "WEB", + "url": "https://locrian-lightning-dc7.notion.site/CVE-2025-28035-CVE-2025-28036-RCE1-1a98e5e2b1a28081880dd817104b3af4" + }, { "type": "WEB", "url": "https://locrian-lightning-dc7.notion.site/RCE1-1a98e5e2b1a28081880dd817104b3af4?pvs=73" } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-22T18:15:59Z" diff --git a/advisories/unreviewed/2025/04/GHSA-fjxj-774q-fh4q/GHSA-fjxj-774q-fh4q.json b/advisories/unreviewed/2025/04/GHSA-fjxj-774q-fh4q/GHSA-fjxj-774q-fh4q.json index 5e50014f7bc..ecbe0c8aff0 100644 --- a/advisories/unreviewed/2025/04/GHSA-fjxj-774q-fh4q/GHSA-fjxj-774q-fh4q.json +++ b/advisories/unreviewed/2025/04/GHSA-fjxj-774q-fh4q/GHSA-fjxj-774q-fh4q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fjxj-774q-fh4q", - "modified": "2025-04-22T18:32:12Z", + "modified": "2025-04-23T15:30:54Z", "published": "2025-04-22T18:32:12Z", "aliases": [ "CVE-2023-44755" ], "details": "Sacco Management system v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /sacco/ajax.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-22T18:15:58Z" diff --git a/advisories/unreviewed/2025/04/GHSA-gg8q-wm6m-x7w3/GHSA-gg8q-wm6m-x7w3.json b/advisories/unreviewed/2025/04/GHSA-gg8q-wm6m-x7w3/GHSA-gg8q-wm6m-x7w3.json index 09b0cdb4ed7..8f9bc5c630c 100644 --- a/advisories/unreviewed/2025/04/GHSA-gg8q-wm6m-x7w3/GHSA-gg8q-wm6m-x7w3.json +++ b/advisories/unreviewed/2025/04/GHSA-gg8q-wm6m-x7w3/GHSA-gg8q-wm6m-x7w3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gg8q-wm6m-x7w3", - "modified": "2025-04-22T18:32:12Z", + "modified": "2025-04-23T15:30:54Z", "published": "2025-04-22T18:32:12Z", "aliases": [ "CVE-2025-28026" ], "details": "TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a buffer overflow vulnerability in downloadFile.cgi.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -17,11 +22,17 @@ { "type": "WEB", "url": "https://locrian-lightning-dc7.notion.site/BufferOverflow3-19e8e5e2b1a28048b8ddd4afdbe18d55" + }, + { + "type": "WEB", + "url": "https://locrian-lightning-dc7.notion.site/CVE-2025-28026-BufferOverflow3-19e8e5e2b1a28048b8ddd4afdbe18d55" } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-22T18:15:58Z" diff --git a/advisories/unreviewed/2025/04/GHSA-gwvg-5xhp-rp5q/GHSA-gwvg-5xhp-rp5q.json b/advisories/unreviewed/2025/04/GHSA-gwvg-5xhp-rp5q/GHSA-gwvg-5xhp-rp5q.json index cbce62ebc56..438baf74f67 100644 --- a/advisories/unreviewed/2025/04/GHSA-gwvg-5xhp-rp5q/GHSA-gwvg-5xhp-rp5q.json +++ b/advisories/unreviewed/2025/04/GHSA-gwvg-5xhp-rp5q/GHSA-gwvg-5xhp-rp5q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gwvg-5xhp-rp5q", - "modified": "2025-04-22T21:30:44Z", + "modified": "2025-04-23T15:30:56Z", "published": "2025-04-22T21:30:44Z", "aliases": [ "CVE-2025-37087" ], "details": "A vulnerability in the cmdb service of the HPE Performance Cluster Manager (HPCM) could allow an attacker to gain access to an arbitrary file on the server host.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-862" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-22T21:15:45Z" diff --git a/advisories/unreviewed/2025/04/GHSA-h65q-2g3v-qm4r/GHSA-h65q-2g3v-qm4r.json b/advisories/unreviewed/2025/04/GHSA-h65q-2g3v-qm4r/GHSA-h65q-2g3v-qm4r.json index cc80b6653e3..b8607e9dfbd 100644 --- a/advisories/unreviewed/2025/04/GHSA-h65q-2g3v-qm4r/GHSA-h65q-2g3v-qm4r.json +++ b/advisories/unreviewed/2025/04/GHSA-h65q-2g3v-qm4r/GHSA-h65q-2g3v-qm4r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h65q-2g3v-qm4r", - "modified": "2025-04-22T18:32:12Z", + "modified": "2025-04-23T15:30:54Z", "published": "2025-04-22T18:32:12Z", "aliases": [ "CVE-2023-43958" ], "details": "An arbitrary file upload vulnerability in the component /jquery-file-upload/server/php/index.php of Hospital Management System v4.0 allows an unauthenticated attacker to upload any file to the server and execute arbitrary code.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-22T18:15:58Z" diff --git a/advisories/unreviewed/2025/04/GHSA-j2xc-53c4-c8p4/GHSA-j2xc-53c4-c8p4.json b/advisories/unreviewed/2025/04/GHSA-j2xc-53c4-c8p4/GHSA-j2xc-53c4-c8p4.json index 8116cc023f5..443655a02b9 100644 --- a/advisories/unreviewed/2025/04/GHSA-j2xc-53c4-c8p4/GHSA-j2xc-53c4-c8p4.json +++ b/advisories/unreviewed/2025/04/GHSA-j2xc-53c4-c8p4/GHSA-j2xc-53c4-c8p4.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-jqqv-g9pc-97qc/GHSA-jqqv-g9pc-97qc.json b/advisories/unreviewed/2025/04/GHSA-jqqv-g9pc-97qc/GHSA-jqqv-g9pc-97qc.json new file mode 100644 index 00000000000..5426c39f3a7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jqqv-g9pc-97qc/GHSA-jqqv-g9pc-97qc.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jqqv-g9pc-97qc", + "modified": "2025-04-23T15:30:57Z", + "published": "2025-04-23T15:30:57Z", + "aliases": [ + "CVE-2025-45428" + ], + "details": "In Tenda ac9 v1.0 with firmware V15.03.05.14_multi, the rebootTime parameter of /goform/SetSysAutoRebbotCfg has a stack overflow vulnerability, which can lead to remote arbitrary code execution.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45428" + }, + { + "type": "WEB", + "url": "https://github.com/shuqi233/loophole/blob/main/Tenda%20AC9/SetSysAutoRebbotCfg-rebootTime.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-23T15:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mp63-mm73-jhgm/GHSA-mp63-mm73-jhgm.json b/advisories/unreviewed/2025/04/GHSA-mp63-mm73-jhgm/GHSA-mp63-mm73-jhgm.json index 2089f5e7d28..faec27ff93d 100644 --- a/advisories/unreviewed/2025/04/GHSA-mp63-mm73-jhgm/GHSA-mp63-mm73-jhgm.json +++ b/advisories/unreviewed/2025/04/GHSA-mp63-mm73-jhgm/GHSA-mp63-mm73-jhgm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mp63-mm73-jhgm", - "modified": "2025-04-22T15:30:52Z", + "modified": "2025-04-23T15:30:52Z", "published": "2025-04-22T15:30:52Z", "aliases": [ "CVE-2025-28033" ], "details": "TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a pre-auth buffer overflow vulnerability in the setNoticeCfg function through the IpTo parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -17,11 +22,17 @@ { "type": "WEB", "url": "https://locrian-lightning-dc7.notion.site/BufferOverflow7-1a98e5e2b1a280708d6ec6155ce88d8c" + }, + { + "type": "WEB", + "url": "https://locrian-lightning-dc7.notion.site/CVE-2025-28033-BufferOverflow7-1a98e5e2b1a280708d6ec6155ce88d8c" } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-22T14:15:25Z" diff --git a/advisories/unreviewed/2025/04/GHSA-mwgr-p983-v4m9/GHSA-mwgr-p983-v4m9.json b/advisories/unreviewed/2025/04/GHSA-mwgr-p983-v4m9/GHSA-mwgr-p983-v4m9.json index 05906adad6d..81fa4405e2b 100644 --- a/advisories/unreviewed/2025/04/GHSA-mwgr-p983-v4m9/GHSA-mwgr-p983-v4m9.json +++ b/advisories/unreviewed/2025/04/GHSA-mwgr-p983-v4m9/GHSA-mwgr-p983-v4m9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mwgr-p983-v4m9", - "modified": "2025-04-23T00:30:37Z", + "modified": "2025-04-23T15:30:56Z", "published": "2025-04-23T00:30:37Z", "aliases": [ "CVE-2025-27087" ], "details": "A vulnerability in the kernel of the Cray Operating System (COS) could allow an attacker to perform a local Denial of Service (DoS) attack.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-22T22:15:17Z" diff --git a/advisories/unreviewed/2025/04/GHSA-p2gm-m8q4-6r5q/GHSA-p2gm-m8q4-6r5q.json b/advisories/unreviewed/2025/04/GHSA-p2gm-m8q4-6r5q/GHSA-p2gm-m8q4-6r5q.json index 4e0b7a5bc59..7fecb633248 100644 --- a/advisories/unreviewed/2025/04/GHSA-p2gm-m8q4-6r5q/GHSA-p2gm-m8q4-6r5q.json +++ b/advisories/unreviewed/2025/04/GHSA-p2gm-m8q4-6r5q/GHSA-p2gm-m8q4-6r5q.json @@ -1,27 +1,38 @@ { "schema_version": "1.4.0", "id": "GHSA-p2gm-m8q4-6r5q", - "modified": "2025-04-22T15:30:52Z", + "modified": "2025-04-23T15:30:52Z", "published": "2025-04-22T15:30:52Z", "aliases": [ "CVE-2025-28034" ], "details": "TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a pre-auth remote command execution vulnerability in the NTPSyncWithHost function through the hostTime parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28034" }, + { + "type": "WEB", + "url": "https://locrian-lightning-dc7.notion.site/CVE-2025-28034-RCE2-1a98e5e2b1a280bebf53d868f1b1a711" + }, { "type": "WEB", "url": "https://locrian-lightning-dc7.notion.site/RCE2-1a98e5e2b1a280bebf53d868f1b1a711?pvs=74" } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-22T14:15:25Z" diff --git a/advisories/unreviewed/2025/04/GHSA-q8pq-pv68-q9cm/GHSA-q8pq-pv68-q9cm.json b/advisories/unreviewed/2025/04/GHSA-q8pq-pv68-q9cm/GHSA-q8pq-pv68-q9cm.json index 98963dd7287..6b34ade19da 100644 --- a/advisories/unreviewed/2025/04/GHSA-q8pq-pv68-q9cm/GHSA-q8pq-pv68-q9cm.json +++ b/advisories/unreviewed/2025/04/GHSA-q8pq-pv68-q9cm/GHSA-q8pq-pv68-q9cm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q8pq-pv68-q9cm", - "modified": "2025-04-22T15:30:52Z", + "modified": "2025-04-23T15:30:52Z", "published": "2025-04-22T15:30:52Z", "aliases": [ "CVE-2025-28032" ], "details": "TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 contain a pre-auth buffer overflow vulnerability in the setNoticeCfg function through the IpForm parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-22T14:15:25Z" diff --git a/advisories/unreviewed/2025/04/GHSA-qch9-x3vr-h45w/GHSA-qch9-x3vr-h45w.json b/advisories/unreviewed/2025/04/GHSA-qch9-x3vr-h45w/GHSA-qch9-x3vr-h45w.json index 215c5bcc121..571cf136ca1 100644 --- a/advisories/unreviewed/2025/04/GHSA-qch9-x3vr-h45w/GHSA-qch9-x3vr-h45w.json +++ b/advisories/unreviewed/2025/04/GHSA-qch9-x3vr-h45w/GHSA-qch9-x3vr-h45w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qch9-x3vr-h45w", - "modified": "2025-04-23T00:30:37Z", + "modified": "2025-04-23T15:30:57Z", "published": "2025-04-23T00:30:37Z", "aliases": [ "CVE-2025-37088" ], "details": "A security vulnerability has been identified in HPE Cray Data Virtualization Service (DVS). Depending on race conditions and configuration, this vulnerability may lead to local/cluster unauthorized access.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-22T22:15:17Z" diff --git a/advisories/unreviewed/2025/04/GHSA-qrqw-4g4q-63h8/GHSA-qrqw-4g4q-63h8.json b/advisories/unreviewed/2025/04/GHSA-qrqw-4g4q-63h8/GHSA-qrqw-4g4q-63h8.json index be9fb1e0e11..9138554ec5d 100644 --- a/advisories/unreviewed/2025/04/GHSA-qrqw-4g4q-63h8/GHSA-qrqw-4g4q-63h8.json +++ b/advisories/unreviewed/2025/04/GHSA-qrqw-4g4q-63h8/GHSA-qrqw-4g4q-63h8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qrqw-4g4q-63h8", - "modified": "2025-04-22T18:32:12Z", + "modified": "2025-04-23T15:30:54Z", "published": "2025-04-22T18:32:12Z", "aliases": [ "CVE-2023-43378" ], "details": "A cross-site scripting (XSS) vulnerability in Hoteldruid v3.0.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the commento1_1 parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-22T18:15:57Z" diff --git a/advisories/unreviewed/2025/04/GHSA-r24q-j79w-9jww/GHSA-r24q-j79w-9jww.json b/advisories/unreviewed/2025/04/GHSA-r24q-j79w-9jww/GHSA-r24q-j79w-9jww.json index 998b56469b6..e498cd5abc4 100644 --- a/advisories/unreviewed/2025/04/GHSA-r24q-j79w-9jww/GHSA-r24q-j79w-9jww.json +++ b/advisories/unreviewed/2025/04/GHSA-r24q-j79w-9jww/GHSA-r24q-j79w-9jww.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r24q-j79w-9jww", - "modified": "2025-04-22T18:32:13Z", + "modified": "2025-04-23T15:30:56Z", "published": "2025-04-22T18:32:13Z", "aliases": [ "CVE-2025-43950" ], "details": "DPMAdirektPro 4.1.5 is vulnerable to DLL Hijacking. It happens by placing a malicious DLL in a directory (in the absence of a legitimate DLL), which is then loaded by the application instead of the legitimate DLL. This causes the malicious DLL to load with the same privileges as the application, thus causing a privilege escalation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-427" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-22T18:16:01Z" diff --git a/advisories/unreviewed/2025/04/GHSA-rgcr-wg7p-29p2/GHSA-rgcr-wg7p-29p2.json b/advisories/unreviewed/2025/04/GHSA-rgcr-wg7p-29p2/GHSA-rgcr-wg7p-29p2.json index bcdfe620213..29d2386ef73 100644 --- a/advisories/unreviewed/2025/04/GHSA-rgcr-wg7p-29p2/GHSA-rgcr-wg7p-29p2.json +++ b/advisories/unreviewed/2025/04/GHSA-rgcr-wg7p-29p2/GHSA-rgcr-wg7p-29p2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rgcr-wg7p-29p2", - "modified": "2025-04-22T18:32:11Z", + "modified": "2025-04-23T15:30:53Z", "published": "2025-04-22T18:32:11Z", "aliases": [ "CVE-2025-28030" ], "details": "TOTOLINK A810R V4.1.2cu.5182_B20201026 was discovered to contain a stack overflow via the startTime and endTime parameters in setParentalRules function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-22T16:15:45Z" diff --git a/advisories/unreviewed/2025/04/GHSA-rpcc-c8w6-wwj6/GHSA-rpcc-c8w6-wwj6.json b/advisories/unreviewed/2025/04/GHSA-rpcc-c8w6-wwj6/GHSA-rpcc-c8w6-wwj6.json index c004d751899..b5d49c9d2e1 100644 --- a/advisories/unreviewed/2025/04/GHSA-rpcc-c8w6-wwj6/GHSA-rpcc-c8w6-wwj6.json +++ b/advisories/unreviewed/2025/04/GHSA-rpcc-c8w6-wwj6/GHSA-rpcc-c8w6-wwj6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rpcc-c8w6-wwj6", - "modified": "2025-04-22T18:32:12Z", + "modified": "2025-04-23T15:30:54Z", "published": "2025-04-22T18:32:12Z", "aliases": [ "CVE-2023-44752" ], "details": "An issue in Student Study Center Desk Management System v1.0 allows attackers to bypass authentication via a crafted GET request to /php-sscdms/admin/login.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-287" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-22T18:15:58Z" diff --git a/advisories/unreviewed/2025/04/GHSA-rw43-mgp5-rf2m/GHSA-rw43-mgp5-rf2m.json b/advisories/unreviewed/2025/04/GHSA-rw43-mgp5-rf2m/GHSA-rw43-mgp5-rf2m.json index 5a331e9caf4..ef5352d3eb7 100644 --- a/advisories/unreviewed/2025/04/GHSA-rw43-mgp5-rf2m/GHSA-rw43-mgp5-rf2m.json +++ b/advisories/unreviewed/2025/04/GHSA-rw43-mgp5-rf2m/GHSA-rw43-mgp5-rf2m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rw43-mgp5-rf2m", - "modified": "2025-04-22T15:30:52Z", + "modified": "2025-04-23T15:30:52Z", "published": "2025-04-22T15:30:52Z", "aliases": [ "CVE-2024-40446" ], "details": "An issue in forkosh Mime Tex before v.1.77 allows an attacker to execute arbitrary code via a crafted script", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-22T14:15:24Z" diff --git a/advisories/unreviewed/2025/04/GHSA-v7m9-pm9f-frqg/GHSA-v7m9-pm9f-frqg.json b/advisories/unreviewed/2025/04/GHSA-v7m9-pm9f-frqg/GHSA-v7m9-pm9f-frqg.json index 0b15bdcd8d5..2e612067cfd 100644 --- a/advisories/unreviewed/2025/04/GHSA-v7m9-pm9f-frqg/GHSA-v7m9-pm9f-frqg.json +++ b/advisories/unreviewed/2025/04/GHSA-v7m9-pm9f-frqg/GHSA-v7m9-pm9f-frqg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v7m9-pm9f-frqg", - "modified": "2025-04-22T18:32:11Z", + "modified": "2025-04-23T15:30:53Z", "published": "2025-04-22T18:32:11Z", "aliases": [ "CVE-2025-29339" ], "details": "An issue in UPF in Open5GS UPF versions up to v2.7.2 results an assertion failure vulnerability in PFCP session parameter validation. When processing a PFCP Session Establishment Request with PDN Type=0, the UPF fails to handle the invalid value propagated from SMF (or via direct attack), triggering a fatal assertion check and causing a daemon crash.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-617" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-22T17:16:46Z" diff --git a/advisories/unreviewed/2025/04/GHSA-vwgx-54x2-gc6m/GHSA-vwgx-54x2-gc6m.json b/advisories/unreviewed/2025/04/GHSA-vwgx-54x2-gc6m/GHSA-vwgx-54x2-gc6m.json index a41fb54e621..cb11f10230d 100644 --- a/advisories/unreviewed/2025/04/GHSA-vwgx-54x2-gc6m/GHSA-vwgx-54x2-gc6m.json +++ b/advisories/unreviewed/2025/04/GHSA-vwgx-54x2-gc6m/GHSA-vwgx-54x2-gc6m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vwgx-54x2-gc6m", - "modified": "2025-04-22T18:32:11Z", + "modified": "2025-04-23T15:30:53Z", "published": "2025-04-22T18:32:11Z", "aliases": [ "CVE-2025-28024" ], "details": "TOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in the cstecgi.cgi", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-22T16:15:44Z" diff --git a/advisories/unreviewed/2025/04/GHSA-x8cw-f5xw-fwh2/GHSA-x8cw-f5xw-fwh2.json b/advisories/unreviewed/2025/04/GHSA-x8cw-f5xw-fwh2/GHSA-x8cw-f5xw-fwh2.json new file mode 100644 index 00000000000..8d3e5c01b86 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-x8cw-f5xw-fwh2/GHSA-x8cw-f5xw-fwh2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x8cw-f5xw-fwh2", + "modified": "2025-04-23T15:30:47Z", + "published": "2025-04-17T18:31:22Z", + "aliases": [ + "CVE-2025-43013" + ], + "details": "In JetBrains Toolbox App before 2.6 unencrypted credential transmission during SSH authentication was possible", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43013" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-319" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:59Z" + } +} \ No newline at end of file