diff --git a/advisories/unreviewed/2025/05/GHSA-96gf-3rqf-c8m9/GHSA-96gf-3rqf-c8m9.json b/advisories/unreviewed/2025/05/GHSA-96gf-3rqf-c8m9/GHSA-96gf-3rqf-c8m9.json new file mode 100644 index 00000000000..ba79fbaedc0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-96gf-3rqf-c8m9/GHSA-96gf-3rqf-c8m9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-96gf-3rqf-c8m9", + "modified": "2025-05-22T00:34:03Z", + "published": "2025-05-22T00:34:03Z", + "aliases": [ + "CVE-2025-34027" + ], + "details": "The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The Spack upload endpoint can be leveraged for a Time-of-Check to Time-of-Use (TOCTOU) write in combination with a race condition to achieve remote code execution via path loading manipulation, allowing an unauthenticated actor to achieve remote code execution (RCE).This issue is known to affect Concerto from 12.1.2 through 12.2.0. Additional versions may be vulnerable.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-34027" + }, + { + "type": "WEB", + "url": "https://projectdiscovery.io/blog/versa-concerto-authentication-bypass-rce" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T22:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h2mm-jj4p-hm2p/GHSA-h2mm-jj4p-hm2p.json b/advisories/unreviewed/2025/05/GHSA-h2mm-jj4p-hm2p/GHSA-h2mm-jj4p-hm2p.json new file mode 100644 index 00000000000..64ec150d2f4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h2mm-jj4p-hm2p/GHSA-h2mm-jj4p-hm2p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h2mm-jj4p-hm2p", + "modified": "2025-05-22T00:34:03Z", + "published": "2025-05-22T00:34:03Z", + "aliases": [ + "CVE-2025-34026" + ], + "details": "The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal Actuator endpoint can be leveraged for access to heap dumps and trace logs.This issue is known to affect Concerto from 12.1.2 through 12.2.0. Additional versions may be vulnerable.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-34026" + }, + { + "type": "WEB", + "url": "https://projectdiscovery.io/blog/versa-concerto-authentication-bypass-rce" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T22:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-m89j-9v2x-qhqj/GHSA-m89j-9v2x-qhqj.json b/advisories/unreviewed/2025/05/GHSA-m89j-9v2x-qhqj/GHSA-m89j-9v2x-qhqj.json new file mode 100644 index 00000000000..608c4e3c3dc --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-m89j-9v2x-qhqj/GHSA-m89j-9v2x-qhqj.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m89j-9v2x-qhqj", + "modified": "2025-05-22T00:34:04Z", + "published": "2025-05-22T00:34:04Z", + "aliases": [ + "CVE-2025-5059" + ], + "details": "A vulnerability classified as critical has been found in Campcodes Online Shopping Portal 1.0. This affects an unknown part of the file /admin/edit-subcategory.php. The manipulation of the argument productimage1/productimage2/productimage3 leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5059" + }, + { + "type": "WEB", + "url": "https://github.com/snkercyber/CVE/issues/3" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309879" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309879" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.581391" + }, + { + "type": "WEB", + "url": "https://www.campcodes.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T23:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vr5w-fmp9-m564/GHSA-vr5w-fmp9-m564.json b/advisories/unreviewed/2025/05/GHSA-vr5w-fmp9-m564/GHSA-vr5w-fmp9-m564.json index 8e82afbea6e..7ffb2b95513 100644 --- a/advisories/unreviewed/2025/05/GHSA-vr5w-fmp9-m564/GHSA-vr5w-fmp9-m564.json +++ b/advisories/unreviewed/2025/05/GHSA-vr5w-fmp9-m564/GHSA-vr5w-fmp9-m564.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vr5w-fmp9-m564", - "modified": "2025-05-21T21:31:37Z", + "modified": "2025-05-22T00:34:02Z", "published": "2025-05-21T21:31:36Z", "aliases": [ "CVE-2025-4094" ], "details": "The DIGITS: WordPress Mobile Number Signup and Login WordPress plugin before 8.4.6.1 does not rate limit OTP validation attempts, making it straightforward for attackers to bruteforce them.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-21T06:16:28Z" diff --git a/advisories/unreviewed/2025/05/GHSA-x2qf-7fp6-459x/GHSA-x2qf-7fp6-459x.json b/advisories/unreviewed/2025/05/GHSA-x2qf-7fp6-459x/GHSA-x2qf-7fp6-459x.json new file mode 100644 index 00000000000..da34e817f31 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-x2qf-7fp6-459x/GHSA-x2qf-7fp6-459x.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x2qf-7fp6-459x", + "modified": "2025-05-22T00:34:03Z", + "published": "2025-05-22T00:34:03Z", + "aliases": [ + "CVE-2025-5057" + ], + "details": "A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/insert-product.php. The manipulation of the argument Category leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5057" + }, + { + "type": "WEB", + "url": "https://github.com/Jacob-z691/CVE/issues/2" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309878" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309878" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.581374" + }, + { + "type": "WEB", + "url": "https://www.campcodes.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T22:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-x3hf-596g-m5vx/GHSA-x3hf-596g-m5vx.json b/advisories/unreviewed/2025/05/GHSA-x3hf-596g-m5vx/GHSA-x3hf-596g-m5vx.json new file mode 100644 index 00000000000..af2203f473a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-x3hf-596g-m5vx/GHSA-x3hf-596g-m5vx.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x3hf-596g-m5vx", + "modified": "2025-05-22T00:34:03Z", + "published": "2025-05-22T00:34:03Z", + "aliases": [ + "CVE-2025-5056" + ], + "details": "A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/edit-products.php. The manipulation of the argument Category leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5056" + }, + { + "type": "WEB", + "url": "https://github.com/Jacob-z691/CVE/issues/1" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309877" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309877" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.581373" + }, + { + "type": "WEB", + "url": "https://www.campcodes.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T22:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-x5xg-rmf4-2q22/GHSA-x5xg-rmf4-2q22.json b/advisories/unreviewed/2025/05/GHSA-x5xg-rmf4-2q22/GHSA-x5xg-rmf4-2q22.json new file mode 100644 index 00000000000..14986e1d6c6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-x5xg-rmf4-2q22/GHSA-x5xg-rmf4-2q22.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x5xg-rmf4-2q22", + "modified": "2025-05-22T00:34:03Z", + "published": "2025-05-22T00:34:03Z", + "aliases": [ + "CVE-2025-34025" + ], + "details": "The Versa Concerto SD-WAN orchestration platform is vulnerable to an privileges escalation and container escape vulnerability caused by unsafe default mounting of host binary paths that allow the container to modify host paths. The escape can be used to trigger remote code execution or direct host access depending on the host operating system configuration.This issue is known to affect Concerto from 12.1.2 through 12.2.0. Additional versions may be vulnerable.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-34025" + }, + { + "type": "WEB", + "url": "https://projectdiscovery.io/blog/versa-concerto-authentication-bypass-rce" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T23:15:54Z" + } +} \ No newline at end of file