diff --git a/advisories/github-reviewed/2024/04/GHSA-2v42-xp3j-47m4/GHSA-2v42-xp3j-47m4.json b/advisories/github-reviewed/2024/04/GHSA-2v42-xp3j-47m4/GHSA-2v42-xp3j-47m4.json index e5121ce6f26..e1aff4aa32c 100644 --- a/advisories/github-reviewed/2024/04/GHSA-2v42-xp3j-47m4/GHSA-2v42-xp3j-47m4.json +++ b/advisories/github-reviewed/2024/04/GHSA-2v42-xp3j-47m4/GHSA-2v42-xp3j-47m4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2v42-xp3j-47m4", - "modified": "2024-04-08T15:42:15Z", + "modified": "2025-05-23T18:32:28Z", "published": "2024-04-06T12:30:56Z", "aliases": [ "CVE-2024-3366" @@ -44,6 +44,10 @@ "type": "WEB", "url": "https://github.com/xuxueli/xxl-job/issues/3391" }, + { + "type": "WEB", + "url": "https://github.com/xuxueli/xxl-job/commit/e3b2e1234614195390f46e26c15cd4881bd4dbe3" + }, { "type": "PACKAGE", "url": "https://github.com/xuxueli/xxl-job" diff --git a/advisories/unreviewed/2022/10/GHSA-86wj-xg3c-r8gx/GHSA-86wj-xg3c-r8gx.json b/advisories/unreviewed/2022/10/GHSA-86wj-xg3c-r8gx/GHSA-86wj-xg3c-r8gx.json index 32135f9041f..8aa0ca6719b 100644 --- a/advisories/unreviewed/2022/10/GHSA-86wj-xg3c-r8gx/GHSA-86wj-xg3c-r8gx.json +++ b/advisories/unreviewed/2022/10/GHSA-86wj-xg3c-r8gx/GHSA-86wj-xg3c-r8gx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-86wj-xg3c-r8gx", - "modified": "2022-10-20T19:00:36Z", + "modified": "2025-05-23T18:31:51Z", "published": "2022-10-17T19:00:24Z", "aliases": [ "CVE-2022-3559" @@ -27,6 +27,18 @@ "type": "WEB", "url": "https://git.exim.org/exim.git/commit/4e9ed49f8f12eb331b29bd5b6dc3693c520fddc2" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EIH4W5R7SHTUEQFWWKB4TUO5YFZX64KV" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TMQ6OCKPNPBPSD37YR4FOWV2R54M2UEP" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WFHLZVHNNO2GWYP5EA4TZQZ5O4GVPARR" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EIH4W5R7SHTUEQFWWKB4TUO5YFZX64KV" @@ -46,7 +58,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-416" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/10/GHSA-jcq6-47h7-2c66/GHSA-jcq6-47h7-2c66.json b/advisories/unreviewed/2022/10/GHSA-jcq6-47h7-2c66/GHSA-jcq6-47h7-2c66.json index d61f8b375bc..e8654fd494d 100644 --- a/advisories/unreviewed/2022/10/GHSA-jcq6-47h7-2c66/GHSA-jcq6-47h7-2c66.json +++ b/advisories/unreviewed/2022/10/GHSA-jcq6-47h7-2c66/GHSA-jcq6-47h7-2c66.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jcq6-47h7-2c66", - "modified": "2022-10-24T19:00:22Z", + "modified": "2025-05-23T18:31:52Z", "published": "2022-10-21T12:00:17Z", "aliases": [ "CVE-2022-3620" @@ -23,6 +23,18 @@ "type": "WEB", "url": "https://git.exim.org/exim.git/commit/12fb3842f81bcbd4a4519d5728f2d7e0e3ca1445" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/667V3ADXQ2MHUJMSXA3VZZEWLVSCIBEU" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EIH4W5R7SHTUEQFWWKB4TUO5YFZX64KV" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XV2K2AWF62FSJ64B5CUZPFT4COK7P5PM" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/667V3ADXQ2MHUJMSXA3VZZEWLVSCIBEU" diff --git a/advisories/unreviewed/2024/02/GHSA-35g3-5r8c-ffwf/GHSA-35g3-5r8c-ffwf.json b/advisories/unreviewed/2024/02/GHSA-35g3-5r8c-ffwf/GHSA-35g3-5r8c-ffwf.json index 1472f0e0310..0fa71970b22 100644 --- a/advisories/unreviewed/2024/02/GHSA-35g3-5r8c-ffwf/GHSA-35g3-5r8c-ffwf.json +++ b/advisories/unreviewed/2024/02/GHSA-35g3-5r8c-ffwf/GHSA-35g3-5r8c-ffwf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-35g3-5r8c-ffwf", - "modified": "2024-02-27T18:31:02Z", + "modified": "2025-05-23T18:31:52Z", "published": "2024-02-27T18:31:02Z", "aliases": [ "CVE-2024-25841" ], "details": "In the module \"So Flexibilite\" (soflexibilite) from Common-Services for PrestaShop < 4.1.26, a guest (authenticated customer) can perform Cross Site Scripting (XSS) injection.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T17:15:12Z" diff --git a/advisories/unreviewed/2024/02/GHSA-qp5h-mm28-4jq3/GHSA-qp5h-mm28-4jq3.json b/advisories/unreviewed/2024/02/GHSA-qp5h-mm28-4jq3/GHSA-qp5h-mm28-4jq3.json index 3c60c6f1858..11515cabd52 100644 --- a/advisories/unreviewed/2024/02/GHSA-qp5h-mm28-4jq3/GHSA-qp5h-mm28-4jq3.json +++ b/advisories/unreviewed/2024/02/GHSA-qp5h-mm28-4jq3/GHSA-qp5h-mm28-4jq3.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-401" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-238q-xvw6-rfhf/GHSA-238q-xvw6-rfhf.json b/advisories/unreviewed/2025/01/GHSA-238q-xvw6-rfhf/GHSA-238q-xvw6-rfhf.json index 29500aae858..5285ad6851e 100644 --- a/advisories/unreviewed/2025/01/GHSA-238q-xvw6-rfhf/GHSA-238q-xvw6-rfhf.json +++ b/advisories/unreviewed/2025/01/GHSA-238q-xvw6-rfhf/GHSA-238q-xvw6-rfhf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-238q-xvw6-rfhf", - "modified": "2025-01-31T18:31:05Z", + "modified": "2025-05-23T18:31:52Z", "published": "2025-01-31T06:30:53Z", "aliases": [ "CVE-2024-12872" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-5mrr-3jvw-jc5j/GHSA-5mrr-3jvw-jc5j.json b/advisories/unreviewed/2025/01/GHSA-5mrr-3jvw-jc5j/GHSA-5mrr-3jvw-jc5j.json index 67c56924ed0..3dca7c353e1 100644 --- a/advisories/unreviewed/2025/01/GHSA-5mrr-3jvw-jc5j/GHSA-5mrr-3jvw-jc5j.json +++ b/advisories/unreviewed/2025/01/GHSA-5mrr-3jvw-jc5j/GHSA-5mrr-3jvw-jc5j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5mrr-3jvw-jc5j", - "modified": "2025-01-31T06:30:52Z", + "modified": "2025-05-23T18:31:52Z", "published": "2025-01-31T06:30:52Z", "aliases": [ "CVE-2025-0470" diff --git a/advisories/unreviewed/2025/01/GHSA-rj7j-qmvg-v343/GHSA-rj7j-qmvg-v343.json b/advisories/unreviewed/2025/01/GHSA-rj7j-qmvg-v343/GHSA-rj7j-qmvg-v343.json index 179a8ece676..64542354d18 100644 --- a/advisories/unreviewed/2025/01/GHSA-rj7j-qmvg-v343/GHSA-rj7j-qmvg-v343.json +++ b/advisories/unreviewed/2025/01/GHSA-rj7j-qmvg-v343/GHSA-rj7j-qmvg-v343.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-2fqx-9j9h-4f77/GHSA-2fqx-9j9h-4f77.json b/advisories/unreviewed/2025/02/GHSA-2fqx-9j9h-4f77/GHSA-2fqx-9j9h-4f77.json index 2eadca5fb80..e2597ba4024 100644 --- a/advisories/unreviewed/2025/02/GHSA-2fqx-9j9h-4f77/GHSA-2fqx-9j9h-4f77.json +++ b/advisories/unreviewed/2025/02/GHSA-2fqx-9j9h-4f77/GHSA-2fqx-9j9h-4f77.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2fqx-9j9h-4f77", - "modified": "2025-02-17T00:31:39Z", + "modified": "2025-05-23T18:31:54Z", "published": "2025-02-17T00:31:39Z", "aliases": [ "CVE-2025-22289" diff --git a/advisories/unreviewed/2025/02/GHSA-38p7-5mvh-wf3m/GHSA-38p7-5mvh-wf3m.json b/advisories/unreviewed/2025/02/GHSA-38p7-5mvh-wf3m/GHSA-38p7-5mvh-wf3m.json index 68b2cf91327..f9b1caae0e4 100644 --- a/advisories/unreviewed/2025/02/GHSA-38p7-5mvh-wf3m/GHSA-38p7-5mvh-wf3m.json +++ b/advisories/unreviewed/2025/02/GHSA-38p7-5mvh-wf3m/GHSA-38p7-5mvh-wf3m.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-3wcm-m2wj-fj25/GHSA-3wcm-m2wj-fj25.json b/advisories/unreviewed/2025/02/GHSA-3wcm-m2wj-fj25/GHSA-3wcm-m2wj-fj25.json index d3856132d09..2f8e205b8aa 100644 --- a/advisories/unreviewed/2025/02/GHSA-3wcm-m2wj-fj25/GHSA-3wcm-m2wj-fj25.json +++ b/advisories/unreviewed/2025/02/GHSA-3wcm-m2wj-fj25/GHSA-3wcm-m2wj-fj25.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-4rqp-q2jf-gm6h/GHSA-4rqp-q2jf-gm6h.json b/advisories/unreviewed/2025/02/GHSA-4rqp-q2jf-gm6h/GHSA-4rqp-q2jf-gm6h.json index 661abfa3ee5..376a5fb4452 100644 --- a/advisories/unreviewed/2025/02/GHSA-4rqp-q2jf-gm6h/GHSA-4rqp-q2jf-gm6h.json +++ b/advisories/unreviewed/2025/02/GHSA-4rqp-q2jf-gm6h/GHSA-4rqp-q2jf-gm6h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4rqp-q2jf-gm6h", - "modified": "2025-02-17T00:31:40Z", + "modified": "2025-05-23T18:31:54Z", "published": "2025-02-17T00:31:40Z", "aliases": [ "CVE-2025-26767" diff --git a/advisories/unreviewed/2025/02/GHSA-cwqv-628v-v6fj/GHSA-cwqv-628v-v6fj.json b/advisories/unreviewed/2025/02/GHSA-cwqv-628v-v6fj/GHSA-cwqv-628v-v6fj.json index b4774bdcbaa..04f9d6b55aa 100644 --- a/advisories/unreviewed/2025/02/GHSA-cwqv-628v-v6fj/GHSA-cwqv-628v-v6fj.json +++ b/advisories/unreviewed/2025/02/GHSA-cwqv-628v-v6fj/GHSA-cwqv-628v-v6fj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cwqv-628v-v6fj", - "modified": "2025-02-04T12:30:58Z", + "modified": "2025-05-23T18:31:53Z", "published": "2025-02-04T12:30:58Z", "aliases": [ "CVE-2024-13733" diff --git a/advisories/unreviewed/2025/02/GHSA-gqj7-345q-xx3j/GHSA-gqj7-345q-xx3j.json b/advisories/unreviewed/2025/02/GHSA-gqj7-345q-xx3j/GHSA-gqj7-345q-xx3j.json index 0282c9d1e0d..0ae4d403abd 100644 --- a/advisories/unreviewed/2025/02/GHSA-gqj7-345q-xx3j/GHSA-gqj7-345q-xx3j.json +++ b/advisories/unreviewed/2025/02/GHSA-gqj7-345q-xx3j/GHSA-gqj7-345q-xx3j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gqj7-345q-xx3j", - "modified": "2025-02-17T06:30:39Z", + "modified": "2025-05-23T18:31:54Z", "published": "2025-02-17T06:30:39Z", "aliases": [ "CVE-2025-0924" diff --git a/advisories/unreviewed/2025/02/GHSA-pm4j-w673-3p6x/GHSA-pm4j-w673-3p6x.json b/advisories/unreviewed/2025/02/GHSA-pm4j-w673-3p6x/GHSA-pm4j-w673-3p6x.json index 1e23e2e86fc..08d3ebcfe59 100644 --- a/advisories/unreviewed/2025/02/GHSA-pm4j-w673-3p6x/GHSA-pm4j-w673-3p6x.json +++ b/advisories/unreviewed/2025/02/GHSA-pm4j-w673-3p6x/GHSA-pm4j-w673-3p6x.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-352", "CWE-79" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/02/GHSA-qwvj-rw68-g43j/GHSA-qwvj-rw68-g43j.json b/advisories/unreviewed/2025/02/GHSA-qwvj-rw68-g43j/GHSA-qwvj-rw68-g43j.json index 69683640315..1809ebeb90d 100644 --- a/advisories/unreviewed/2025/02/GHSA-qwvj-rw68-g43j/GHSA-qwvj-rw68-g43j.json +++ b/advisories/unreviewed/2025/02/GHSA-qwvj-rw68-g43j/GHSA-qwvj-rw68-g43j.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-rwgq-769w-9jq7/GHSA-rwgq-769w-9jq7.json b/advisories/unreviewed/2025/02/GHSA-rwgq-769w-9jq7/GHSA-rwgq-769w-9jq7.json index 97bba72fddf..99cd1ea9fba 100644 --- a/advisories/unreviewed/2025/02/GHSA-rwgq-769w-9jq7/GHSA-rwgq-769w-9jq7.json +++ b/advisories/unreviewed/2025/02/GHSA-rwgq-769w-9jq7/GHSA-rwgq-769w-9jq7.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-wv32-c2xr-97ch/GHSA-wv32-c2xr-97ch.json b/advisories/unreviewed/2025/02/GHSA-wv32-c2xr-97ch/GHSA-wv32-c2xr-97ch.json index bd00a8ba2fb..6954bd1595d 100644 --- a/advisories/unreviewed/2025/02/GHSA-wv32-c2xr-97ch/GHSA-wv32-c2xr-97ch.json +++ b/advisories/unreviewed/2025/02/GHSA-wv32-c2xr-97ch/GHSA-wv32-c2xr-97ch.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wv32-c2xr-97ch", - "modified": "2025-02-17T00:31:39Z", + "modified": "2025-05-23T18:31:54Z", "published": "2025-02-17T00:31:39Z", "aliases": [ "CVE-2025-22284" diff --git a/advisories/unreviewed/2025/05/GHSA-2h3c-3h32-6j65/GHSA-2h3c-3h32-6j65.json b/advisories/unreviewed/2025/05/GHSA-2h3c-3h32-6j65/GHSA-2h3c-3h32-6j65.json new file mode 100644 index 00000000000..20649e4ef57 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2h3c-3h32-6j65/GHSA-2h3c-3h32-6j65.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2h3c-3h32-6j65", + "modified": "2025-05-23T18:32:12Z", + "published": "2025-05-23T18:32:12Z", + "aliases": [ + "CVE-2024-48704" + ], + "details": "Phpgurukul Medical Card Generation System v1.0 is vulnerable to HTML Injection in admin/contactus.php via the parameter pagedes.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48704" + }, + { + "type": "WEB", + "url": "https://github.com/0xBhushan/Writeups/blob/main/CVE/phpGurukul/Medical%20Card%20Generation%20System/HTML%20Injection%28pagedes%29.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2mx4-jrqf-62cp/GHSA-2mx4-jrqf-62cp.json b/advisories/unreviewed/2025/05/GHSA-2mx4-jrqf-62cp/GHSA-2mx4-jrqf-62cp.json new file mode 100644 index 00000000000..d7427f8ad41 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2mx4-jrqf-62cp/GHSA-2mx4-jrqf-62cp.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2mx4-jrqf-62cp", + "modified": "2025-05-23T18:32:12Z", + "published": "2025-05-23T18:32:12Z", + "aliases": [ + "CVE-2024-51099" + ], + "details": "A reflected cross-site scripting (XSS) vulnerability in the component mcgs/download-medical-cards.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the searchdata parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51099" + }, + { + "type": "WEB", + "url": "https://github.com/0xBhushan/Writeups/blob/main/CVE/phpGurukul/Medical%20Card%20Generation%20System/Reflected%20Cross-Site%20Scripting%20%28XSS%29-medical%20card%20details%20search.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2qg7-wwhv-wp5v/GHSA-2qg7-wwhv-wp5v.json b/advisories/unreviewed/2025/05/GHSA-2qg7-wwhv-wp5v/GHSA-2qg7-wwhv-wp5v.json index b6806c99db7..55ff5cbf303 100644 --- a/advisories/unreviewed/2025/05/GHSA-2qg7-wwhv-wp5v/GHSA-2qg7-wwhv-wp5v.json +++ b/advisories/unreviewed/2025/05/GHSA-2qg7-wwhv-wp5v/GHSA-2qg7-wwhv-wp5v.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-3264-h8mv-qcrp/GHSA-3264-h8mv-qcrp.json b/advisories/unreviewed/2025/05/GHSA-3264-h8mv-qcrp/GHSA-3264-h8mv-qcrp.json index 0992e8198e9..9d7722421e1 100644 --- a/advisories/unreviewed/2025/05/GHSA-3264-h8mv-qcrp/GHSA-3264-h8mv-qcrp.json +++ b/advisories/unreviewed/2025/05/GHSA-3264-h8mv-qcrp/GHSA-3264-h8mv-qcrp.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-477r-5m44-x37w/GHSA-477r-5m44-x37w.json b/advisories/unreviewed/2025/05/GHSA-477r-5m44-x37w/GHSA-477r-5m44-x37w.json new file mode 100644 index 00000000000..b82e6b43b12 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-477r-5m44-x37w/GHSA-477r-5m44-x37w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-477r-5m44-x37w", + "modified": "2025-05-23T18:32:12Z", + "published": "2025-05-23T18:32:12Z", + "aliases": [ + "CVE-2024-51103" + ], + "details": "PHPGURUKUL Student Management System using PHP and MySQL v1 was discovered to contain multiple SQL injection vulnerabilities at /studentrecordms/password-recovery.php via the emailid and id parameters.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51103" + }, + { + "type": "WEB", + "url": "https://github.com/0xBhushan/Writeups/blob/main/CVE/phpGurukul/Student%20Management%20System/SQL%20Injection-Password-Recovery.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4cmr-35q3-c969/GHSA-4cmr-35q3-c969.json b/advisories/unreviewed/2025/05/GHSA-4cmr-35q3-c969/GHSA-4cmr-35q3-c969.json index 68a9d167b1a..3bfc2423066 100644 --- a/advisories/unreviewed/2025/05/GHSA-4cmr-35q3-c969/GHSA-4cmr-35q3-c969.json +++ b/advisories/unreviewed/2025/05/GHSA-4cmr-35q3-c969/GHSA-4cmr-35q3-c969.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-59h9-45h4-4xj9/GHSA-59h9-45h4-4xj9.json b/advisories/unreviewed/2025/05/GHSA-59h9-45h4-4xj9/GHSA-59h9-45h4-4xj9.json index 9eb414f22a6..e4640798130 100644 --- a/advisories/unreviewed/2025/05/GHSA-59h9-45h4-4xj9/GHSA-59h9-45h4-4xj9.json +++ b/advisories/unreviewed/2025/05/GHSA-59h9-45h4-4xj9/GHSA-59h9-45h4-4xj9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-59h9-45h4-4xj9", - "modified": "2025-05-22T21:30:47Z", + "modified": "2025-05-23T18:32:03Z", "published": "2025-05-22T21:30:47Z", "aliases": [ "CVE-2024-40461" ], "details": "An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the STOCKORDERENTRY.EXE component", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-22T19:15:40Z" diff --git a/advisories/unreviewed/2025/05/GHSA-5m7h-3422-q57v/GHSA-5m7h-3422-q57v.json b/advisories/unreviewed/2025/05/GHSA-5m7h-3422-q57v/GHSA-5m7h-3422-q57v.json index d9b3688d94f..949b5006627 100644 --- a/advisories/unreviewed/2025/05/GHSA-5m7h-3422-q57v/GHSA-5m7h-3422-q57v.json +++ b/advisories/unreviewed/2025/05/GHSA-5m7h-3422-q57v/GHSA-5m7h-3422-q57v.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-5w6r-h2m8-3mxg/GHSA-5w6r-h2m8-3mxg.json b/advisories/unreviewed/2025/05/GHSA-5w6r-h2m8-3mxg/GHSA-5w6r-h2m8-3mxg.json index c8e1b7a75bd..dd49b3c2c13 100644 --- a/advisories/unreviewed/2025/05/GHSA-5w6r-h2m8-3mxg/GHSA-5w6r-h2m8-3mxg.json +++ b/advisories/unreviewed/2025/05/GHSA-5w6r-h2m8-3mxg/GHSA-5w6r-h2m8-3mxg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5w6r-h2m8-3mxg", - "modified": "2025-05-11T18:30:25Z", + "modified": "2025-05-23T18:31:54Z", "published": "2025-05-11T18:30:25Z", "aliases": [ "CVE-2025-4540" @@ -23,6 +23,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4540" }, + { + "type": "WEB", + "url": "https://0nightsedge0.github.io/2025/05/14/CVE-2025-4540-C-Lodop" + }, { "type": "WEB", "url": "https://mega.nz/folder/A5lQQKpL#AF3WPzST3X1Ot6B6fs3bow" diff --git a/advisories/unreviewed/2025/05/GHSA-8h4w-44qv-79mq/GHSA-8h4w-44qv-79mq.json b/advisories/unreviewed/2025/05/GHSA-8h4w-44qv-79mq/GHSA-8h4w-44qv-79mq.json new file mode 100644 index 00000000000..ca246118334 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8h4w-44qv-79mq/GHSA-8h4w-44qv-79mq.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8h4w-44qv-79mq", + "modified": "2025-05-23T18:32:12Z", + "published": "2025-05-23T18:32:12Z", + "aliases": [ + "CVE-2023-53154" + ], + "details": "parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {\"1\":1, with no trailing newline if cJSON_ParseWithLength is called.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-53154" + }, + { + "type": "WEB", + "url": "https://github.com/DaveGamble/cJSON/issues/800" + }, + { + "type": "WEB", + "url": "https://github.com/DaveGamble/cJSON/compare/v1.7.17...v1.7.18" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T16:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9cwm-pw9v-q42q/GHSA-9cwm-pw9v-q42q.json b/advisories/unreviewed/2025/05/GHSA-9cwm-pw9v-q42q/GHSA-9cwm-pw9v-q42q.json new file mode 100644 index 00000000000..3cd67be7ee5 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9cwm-pw9v-q42q/GHSA-9cwm-pw9v-q42q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9cwm-pw9v-q42q", + "modified": "2025-05-23T18:32:12Z", + "published": "2025-05-23T18:32:12Z", + "aliases": [ + "CVE-2025-24917" + ], + "details": "In Tenable Network Monitor versions prior to 6.5.1 on a Windows host, it was found that a non-administrative user could stage files in a local directory to run arbitrary code with SYSTEM privileges, potentially leading to local privilege escalation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24917" + }, + { + "type": "WEB", + "url": "https://www.tenable.com/security/tns-2025-10" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9wpx-f5qr-7rcr/GHSA-9wpx-f5qr-7rcr.json b/advisories/unreviewed/2025/05/GHSA-9wpx-f5qr-7rcr/GHSA-9wpx-f5qr-7rcr.json new file mode 100644 index 00000000000..1b8f80d3272 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9wpx-f5qr-7rcr/GHSA-9wpx-f5qr-7rcr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9wpx-f5qr-7rcr", + "modified": "2025-05-23T18:32:13Z", + "published": "2025-05-23T18:32:12Z", + "aliases": [ + "CVE-2025-24916" + ], + "details": "When installing Tenable Network Monitor to a non-default location on a Windows host, Tenable Network Monitor versions prior to 6.5.1 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24916" + }, + { + "type": "WEB", + "url": "https://www.tenable.com/security/tns-2025-10" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-cq5p-gh3j-rmpx/GHSA-cq5p-gh3j-rmpx.json b/advisories/unreviewed/2025/05/GHSA-cq5p-gh3j-rmpx/GHSA-cq5p-gh3j-rmpx.json index 2aaa67abf1a..d13235d1fdf 100644 --- a/advisories/unreviewed/2025/05/GHSA-cq5p-gh3j-rmpx/GHSA-cq5p-gh3j-rmpx.json +++ b/advisories/unreviewed/2025/05/GHSA-cq5p-gh3j-rmpx/GHSA-cq5p-gh3j-rmpx.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-ffqf-972q-qhhv/GHSA-ffqf-972q-qhhv.json b/advisories/unreviewed/2025/05/GHSA-ffqf-972q-qhhv/GHSA-ffqf-972q-qhhv.json index a949fcd12dd..d44a503f437 100644 --- a/advisories/unreviewed/2025/05/GHSA-ffqf-972q-qhhv/GHSA-ffqf-972q-qhhv.json +++ b/advisories/unreviewed/2025/05/GHSA-ffqf-972q-qhhv/GHSA-ffqf-972q-qhhv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-ffqf-972q-qhhv", - "modified": "2025-05-22T18:31:16Z", + "modified": "2025-05-23T18:32:01Z", "published": "2025-05-22T18:31:16Z", "aliases": [ "CVE-2024-52874" ], "details": "In Infoblox NETMRI before 7.6.1, authenticated users can perform SQL injection attacks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-22T18:15:40Z" diff --git a/advisories/unreviewed/2025/05/GHSA-fg6v-mffr-f5c5/GHSA-fg6v-mffr-f5c5.json b/advisories/unreviewed/2025/05/GHSA-fg6v-mffr-f5c5/GHSA-fg6v-mffr-f5c5.json index 872031e5d5e..1015dda4ac6 100644 --- a/advisories/unreviewed/2025/05/GHSA-fg6v-mffr-f5c5/GHSA-fg6v-mffr-f5c5.json +++ b/advisories/unreviewed/2025/05/GHSA-fg6v-mffr-f5c5/GHSA-fg6v-mffr-f5c5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fg6v-mffr-f5c5", - "modified": "2025-05-23T03:32:38Z", + "modified": "2025-05-23T18:32:04Z", "published": "2025-05-23T03:32:38Z", "aliases": [ "CVE-2025-5098" ], "details": "PrinterShare Android application allows the capture of Gmail authentication tokens that can be reused to access a user's Gmail account without proper authorization.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-200" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-23T02:15:21Z" diff --git a/advisories/unreviewed/2025/05/GHSA-fmqv-vc53-6mwm/GHSA-fmqv-vc53-6mwm.json b/advisories/unreviewed/2025/05/GHSA-fmqv-vc53-6mwm/GHSA-fmqv-vc53-6mwm.json index 749559e7953..89074433a02 100644 --- a/advisories/unreviewed/2025/05/GHSA-fmqv-vc53-6mwm/GHSA-fmqv-vc53-6mwm.json +++ b/advisories/unreviewed/2025/05/GHSA-fmqv-vc53-6mwm/GHSA-fmqv-vc53-6mwm.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-g26h-jcgf-xc83/GHSA-g26h-jcgf-xc83.json b/advisories/unreviewed/2025/05/GHSA-g26h-jcgf-xc83/GHSA-g26h-jcgf-xc83.json index 57b84e62484..b52eaf3c695 100644 --- a/advisories/unreviewed/2025/05/GHSA-g26h-jcgf-xc83/GHSA-g26h-jcgf-xc83.json +++ b/advisories/unreviewed/2025/05/GHSA-g26h-jcgf-xc83/GHSA-g26h-jcgf-xc83.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-gx7g-663f-fvr2/GHSA-gx7g-663f-fvr2.json b/advisories/unreviewed/2025/05/GHSA-gx7g-663f-fvr2/GHSA-gx7g-663f-fvr2.json index 731480d2190..e5b7264aa33 100644 --- a/advisories/unreviewed/2025/05/GHSA-gx7g-663f-fvr2/GHSA-gx7g-663f-fvr2.json +++ b/advisories/unreviewed/2025/05/GHSA-gx7g-663f-fvr2/GHSA-gx7g-663f-fvr2.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-h93j-5g7q-3xgg/GHSA-h93j-5g7q-3xgg.json b/advisories/unreviewed/2025/05/GHSA-h93j-5g7q-3xgg/GHSA-h93j-5g7q-3xgg.json index 59545e2b5ae..b9d6ea2d3c9 100644 --- a/advisories/unreviewed/2025/05/GHSA-h93j-5g7q-3xgg/GHSA-h93j-5g7q-3xgg.json +++ b/advisories/unreviewed/2025/05/GHSA-h93j-5g7q-3xgg/GHSA-h93j-5g7q-3xgg.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-h9vw-8pf3-5j78/GHSA-h9vw-8pf3-5j78.json b/advisories/unreviewed/2025/05/GHSA-h9vw-8pf3-5j78/GHSA-h9vw-8pf3-5j78.json index cc519ad63b2..f5e0cfca94c 100644 --- a/advisories/unreviewed/2025/05/GHSA-h9vw-8pf3-5j78/GHSA-h9vw-8pf3-5j78.json +++ b/advisories/unreviewed/2025/05/GHSA-h9vw-8pf3-5j78/GHSA-h9vw-8pf3-5j78.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-j55x-w58q-g339/GHSA-j55x-w58q-g339.json b/advisories/unreviewed/2025/05/GHSA-j55x-w58q-g339/GHSA-j55x-w58q-g339.json index 88e0fde6e9a..a8fbddff1c9 100644 --- a/advisories/unreviewed/2025/05/GHSA-j55x-w58q-g339/GHSA-j55x-w58q-g339.json +++ b/advisories/unreviewed/2025/05/GHSA-j55x-w58q-g339/GHSA-j55x-w58q-g339.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j55x-w58q-g339", - "modified": "2025-05-22T21:30:47Z", + "modified": "2025-05-23T18:32:03Z", "published": "2025-05-22T21:30:47Z", "aliases": [ "CVE-2024-40462" ], "details": "An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the SETTINGSVATIGATOR.EXE component", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-22T19:15:41Z" diff --git a/advisories/unreviewed/2025/05/GHSA-jw4h-4rg7-p2p2/GHSA-jw4h-4rg7-p2p2.json b/advisories/unreviewed/2025/05/GHSA-jw4h-4rg7-p2p2/GHSA-jw4h-4rg7-p2p2.json index 5ad84388d54..500448cc9e5 100644 --- a/advisories/unreviewed/2025/05/GHSA-jw4h-4rg7-p2p2/GHSA-jw4h-4rg7-p2p2.json +++ b/advisories/unreviewed/2025/05/GHSA-jw4h-4rg7-p2p2/GHSA-jw4h-4rg7-p2p2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jw4h-4rg7-p2p2", - "modified": "2025-05-22T21:30:47Z", + "modified": "2025-05-23T18:32:04Z", "published": "2025-05-22T21:30:47Z", "aliases": [ "CVE-2024-41197" ], "details": "An issue in Ocuco Innovation - INVCLIENT.EXE v2.10.24.5 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-287" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-22T19:15:41Z" diff --git a/advisories/unreviewed/2025/05/GHSA-mhfp-2wg5-h75r/GHSA-mhfp-2wg5-h75r.json b/advisories/unreviewed/2025/05/GHSA-mhfp-2wg5-h75r/GHSA-mhfp-2wg5-h75r.json index 1e2a106c923..c0ef038e910 100644 --- a/advisories/unreviewed/2025/05/GHSA-mhfp-2wg5-h75r/GHSA-mhfp-2wg5-h75r.json +++ b/advisories/unreviewed/2025/05/GHSA-mhfp-2wg5-h75r/GHSA-mhfp-2wg5-h75r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mhfp-2wg5-h75r", - "modified": "2025-05-22T21:30:48Z", + "modified": "2025-05-23T18:32:04Z", "published": "2025-05-22T21:30:47Z", "aliases": [ "CVE-2024-41196" ], "details": "An issue in Ocuco Innovation - REPORTSERVER.EXE v2.10.24.13 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-287" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-22T19:15:41Z" diff --git a/advisories/unreviewed/2025/05/GHSA-q84q-fh2m-2w47/GHSA-q84q-fh2m-2w47.json b/advisories/unreviewed/2025/05/GHSA-q84q-fh2m-2w47/GHSA-q84q-fh2m-2w47.json new file mode 100644 index 00000000000..c6d2ee15cd5 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q84q-fh2m-2w47/GHSA-q84q-fh2m-2w47.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q84q-fh2m-2w47", + "modified": "2025-05-23T18:32:13Z", + "published": "2025-05-23T18:32:13Z", + "aliases": [ + "CVE-2023-34873" + ], + "details": "On MOBOTIX P3 cameras before MX-V4.7.2.18 and Mx6 cameras before MX-V5.2.0.61, the tcpdump feature does not properly validate input, which allows authenticated users to execute code.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34873" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-235-03" + }, + { + "type": "WEB", + "url": "https://www.mobotix.com/en/node/13391" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T18:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qgvv-277q-3rpm/GHSA-qgvv-277q-3rpm.json b/advisories/unreviewed/2025/05/GHSA-qgvv-277q-3rpm/GHSA-qgvv-277q-3rpm.json index f9a1a66d98c..3128c772b98 100644 --- a/advisories/unreviewed/2025/05/GHSA-qgvv-277q-3rpm/GHSA-qgvv-277q-3rpm.json +++ b/advisories/unreviewed/2025/05/GHSA-qgvv-277q-3rpm/GHSA-qgvv-277q-3rpm.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-qxxx-9ww2-f3qj/GHSA-qxxx-9ww2-f3qj.json b/advisories/unreviewed/2025/05/GHSA-qxxx-9ww2-f3qj/GHSA-qxxx-9ww2-f3qj.json index 403d753be98..b35faaafdcb 100644 --- a/advisories/unreviewed/2025/05/GHSA-qxxx-9ww2-f3qj/GHSA-qxxx-9ww2-f3qj.json +++ b/advisories/unreviewed/2025/05/GHSA-qxxx-9ww2-f3qj/GHSA-qxxx-9ww2-f3qj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qxxx-9ww2-f3qj", - "modified": "2025-05-23T03:32:38Z", + "modified": "2025-05-23T18:32:04Z", "published": "2025-05-23T03:32:38Z", "aliases": [ "CVE-2025-5099" ], "details": "An Out of Bounds Write occurs when the native library attempts PDF rendering, which can be exploited to achieve memory corruption and potentially arbitrary code execution.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-119" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-23T02:15:22Z" diff --git a/advisories/unreviewed/2025/05/GHSA-rfmc-2hwr-mm4p/GHSA-rfmc-2hwr-mm4p.json b/advisories/unreviewed/2025/05/GHSA-rfmc-2hwr-mm4p/GHSA-rfmc-2hwr-mm4p.json new file mode 100644 index 00000000000..7d749c9657e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rfmc-2hwr-mm4p/GHSA-rfmc-2hwr-mm4p.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rfmc-2hwr-mm4p", + "modified": "2025-05-23T18:32:13Z", + "published": "2025-05-23T18:32:13Z", + "aliases": [ + "CVE-2024-51102" + ], + "details": "PHPGURUKUL Student Management System using PHP and MySQL v1 was discovered to contain multiple SQL injection vulnerabilities at /studentrecordms/login.php via the username and password parameters.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51102" + }, + { + "type": "WEB", + "url": "https://github.com/0xBhushan/Writeups/blob/main/CVE/phpGurukul/Student%20Management%20System/SQL%20Injection%20-%20admin%20login.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T18:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rx9g-4vxh-vcv6/GHSA-rx9g-4vxh-vcv6.json b/advisories/unreviewed/2025/05/GHSA-rx9g-4vxh-vcv6/GHSA-rx9g-4vxh-vcv6.json index dbf9bdbf8cf..5d5f0f23ab2 100644 --- a/advisories/unreviewed/2025/05/GHSA-rx9g-4vxh-vcv6/GHSA-rx9g-4vxh-vcv6.json +++ b/advisories/unreviewed/2025/05/GHSA-rx9g-4vxh-vcv6/GHSA-rx9g-4vxh-vcv6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rx9g-4vxh-vcv6", - "modified": "2025-05-22T21:30:47Z", + "modified": "2025-05-23T18:32:04Z", "published": "2025-05-22T21:30:47Z", "aliases": [ "CVE-2024-41198" ], "details": "An issue in Ocuco Innovation - REPORTS.EXE v2.10.24.13 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-287" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-22T19:15:41Z" diff --git a/advisories/unreviewed/2025/05/GHSA-vp4m-3qw3-rfpq/GHSA-vp4m-3qw3-rfpq.json b/advisories/unreviewed/2025/05/GHSA-vp4m-3qw3-rfpq/GHSA-vp4m-3qw3-rfpq.json index a944d18aaaa..abd0c7d45b0 100644 --- a/advisories/unreviewed/2025/05/GHSA-vp4m-3qw3-rfpq/GHSA-vp4m-3qw3-rfpq.json +++ b/advisories/unreviewed/2025/05/GHSA-vp4m-3qw3-rfpq/GHSA-vp4m-3qw3-rfpq.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-wfm4-cvqx-m7rj/GHSA-wfm4-cvqx-m7rj.json b/advisories/unreviewed/2025/05/GHSA-wfm4-cvqx-m7rj/GHSA-wfm4-cvqx-m7rj.json index a9a6e055ce8..9cfca91c464 100644 --- a/advisories/unreviewed/2025/05/GHSA-wfm4-cvqx-m7rj/GHSA-wfm4-cvqx-m7rj.json +++ b/advisories/unreviewed/2025/05/GHSA-wfm4-cvqx-m7rj/GHSA-wfm4-cvqx-m7rj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wfm4-cvqx-m7rj", - "modified": "2025-05-22T21:30:47Z", + "modified": "2025-05-23T18:32:04Z", "published": "2025-05-22T21:30:47Z", "aliases": [ "CVE-2024-41195" ], "details": "An issue in Ocuco Innovation - INNOVASERVICEINTF.EXE v2.10.24.17 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-287" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-22T19:15:41Z" diff --git a/advisories/unreviewed/2025/05/GHSA-x9g7-j8rx-fcjc/GHSA-x9g7-j8rx-fcjc.json b/advisories/unreviewed/2025/05/GHSA-x9g7-j8rx-fcjc/GHSA-x9g7-j8rx-fcjc.json index 8d860518ed2..9e64b1ed1c4 100644 --- a/advisories/unreviewed/2025/05/GHSA-x9g7-j8rx-fcjc/GHSA-x9g7-j8rx-fcjc.json +++ b/advisories/unreviewed/2025/05/GHSA-x9g7-j8rx-fcjc/GHSA-x9g7-j8rx-fcjc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x9g7-j8rx-fcjc", - "modified": "2025-05-22T18:31:16Z", + "modified": "2025-05-23T18:32:01Z", "published": "2025-05-22T18:31:16Z", "aliases": [ "CVE-2025-45472" ], "details": "Insecure permissions in autodeploy-layer v1.2.0 allows attackers to escalate privileges and compromise the customer cloud account.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-732" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-22T17:15:24Z"