From ac6f8778ba9b824897a64972939373515ac49e96 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 7 Apr 2025 21:33:59 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-36p2-3xmm-mxrv.json | 2 +- .../GHSA-4wpp-22r3-jr8g.json | 6 +- .../GHSA-6fwq-c2cr-jg74.json | 6 +- .../GHSA-6wqq-m34g-chqp.json | 14 ++++- .../GHSA-p28r-f42x-qmm2.json | 6 +- .../GHSA-pmh6-cq54-943m.json | 6 +- .../GHSA-q9vj-6cqq-wmgg.json | 2 +- .../GHSA-3qv4-3prp-9cv5.json | 4 +- .../GHSA-7w57-r874-fx7f.json | 4 +- .../GHSA-8wgh-w2f4-v692.json | 4 +- .../GHSA-c5j5-pffr-9wgm.json | 1 + .../GHSA-mcp4-w22q-6q4h.json | 4 +- .../GHSA-pfj6-pxh2-f24m.json | 4 +- .../GHSA-phx3-79h9-xhvq.json | 4 +- .../GHSA-5244-qm9f-xx43.json | 15 +++-- .../GHSA-3g3j-w5cc-fqpr.json | 3 +- .../GHSA-f2hp-vf26-j2rg.json | 3 +- .../GHSA-2f35-gvj8-wv7h.json | 3 +- .../GHSA-378w-m5r6-wj6p.json | 6 +- .../GHSA-4qcq-c33q-9hm3.json | 3 +- .../GHSA-f624-74px-f7hv.json | 3 +- .../GHSA-w277-7jfc-fqc3.json | 3 +- .../GHSA-23rf-wq7x-gvq7.json | 11 +++- .../GHSA-2cp9-r2rg-qvgg.json | 6 +- .../GHSA-3ch3-mpx2-hj74.json | 29 ++++++++++ .../GHSA-3qpv-2q49-9qj8.json | 29 ++++++++++ .../GHSA-3wrm-64r6-6q6c.json | 15 +++-- .../GHSA-43jx-m6w2-jq4p.json | 29 ++++++++++ .../GHSA-57cc-74xg-cqvg.json | 29 ++++++++++ .../GHSA-5mvf-2v8v-7668.json | 52 +++++++++++++++++ .../GHSA-6j35-rq42-fv6v.json | 29 ++++++++++ .../GHSA-8h3v-hh74-r7p2.json | 15 +++-- .../GHSA-928q-p6rr-68q8.json | 29 ++++++++++ .../GHSA-9j5c-g9c4-jwqv.json | 11 +++- .../GHSA-cc3m-w7mm-948m.json | 15 +++-- .../GHSA-ch4m-2996-7xpv.json | 11 +++- .../GHSA-fphf-v8m4-xjvx.json | 11 +++- .../GHSA-g6v4-qjhj-pxw5.json | 52 +++++++++++++++++ .../GHSA-gfj4-2p4p-m25j.json | 11 +++- .../GHSA-gh2f-rgj7-f8jm.json | 52 +++++++++++++++++ .../GHSA-h49w-g4vp-f472.json | 11 +++- .../GHSA-hp4v-q7qc-45wr.json | 11 +++- .../GHSA-hx6m-xfx3-6p5x.json | 11 +++- .../GHSA-j87v-9jp4-gw6c.json | 15 +++-- .../GHSA-p53h-9vwh-rvvp.json | 15 +++-- .../GHSA-p7jp-69j5-crrv.json | 29 ++++++++++ .../GHSA-pfr4-hcrh-5w35.json | 52 +++++++++++++++++ .../GHSA-q732-48vr-36f4.json | 15 +++-- .../GHSA-q844-h75g-f78q.json | 15 +++-- .../GHSA-qcwf-jj36-gr7m.json | 11 +++- .../GHSA-qg7f-449v-85xg.json | 15 +++-- .../GHSA-r75x-m5pq-2c5m.json | 56 +++++++++++++++++++ .../GHSA-rmr8-rg92-5f98.json | 15 +++-- .../GHSA-wp3g-9m76-xj95.json | 56 +++++++++++++++++++ .../GHSA-xw8c-3xf4-r67j.json | 33 +++++++++++ 55 files changed, 813 insertions(+), 89 deletions(-) create mode 100644 advisories/unreviewed/2025/04/GHSA-3ch3-mpx2-hj74/GHSA-3ch3-mpx2-hj74.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3qpv-2q49-9qj8/GHSA-3qpv-2q49-9qj8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-43jx-m6w2-jq4p/GHSA-43jx-m6w2-jq4p.json create mode 100644 advisories/unreviewed/2025/04/GHSA-57cc-74xg-cqvg/GHSA-57cc-74xg-cqvg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5mvf-2v8v-7668/GHSA-5mvf-2v8v-7668.json create mode 100644 advisories/unreviewed/2025/04/GHSA-6j35-rq42-fv6v/GHSA-6j35-rq42-fv6v.json create mode 100644 advisories/unreviewed/2025/04/GHSA-928q-p6rr-68q8/GHSA-928q-p6rr-68q8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-g6v4-qjhj-pxw5/GHSA-g6v4-qjhj-pxw5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-gh2f-rgj7-f8jm/GHSA-gh2f-rgj7-f8jm.json create mode 100644 advisories/unreviewed/2025/04/GHSA-p7jp-69j5-crrv/GHSA-p7jp-69j5-crrv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-pfr4-hcrh-5w35/GHSA-pfr4-hcrh-5w35.json create mode 100644 advisories/unreviewed/2025/04/GHSA-r75x-m5pq-2c5m/GHSA-r75x-m5pq-2c5m.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wp3g-9m76-xj95/GHSA-wp3g-9m76-xj95.json create mode 100644 advisories/unreviewed/2025/04/GHSA-xw8c-3xf4-r67j/GHSA-xw8c-3xf4-r67j.json diff --git a/advisories/unreviewed/2023/01/GHSA-36p2-3xmm-mxrv/GHSA-36p2-3xmm-mxrv.json b/advisories/unreviewed/2023/01/GHSA-36p2-3xmm-mxrv/GHSA-36p2-3xmm-mxrv.json index cc19884bcd4..8163cbf3ff6 100644 --- a/advisories/unreviewed/2023/01/GHSA-36p2-3xmm-mxrv/GHSA-36p2-3xmm-mxrv.json +++ b/advisories/unreviewed/2023/01/GHSA-36p2-3xmm-mxrv/GHSA-36p2-3xmm-mxrv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-36p2-3xmm-mxrv", - "modified": "2023-01-18T21:30:21Z", + "modified": "2025-04-07T21:31:40Z", "published": "2023-01-11T06:30:21Z", "aliases": [ "CVE-2023-22959" diff --git a/advisories/unreviewed/2023/01/GHSA-4wpp-22r3-jr8g/GHSA-4wpp-22r3-jr8g.json b/advisories/unreviewed/2023/01/GHSA-4wpp-22r3-jr8g/GHSA-4wpp-22r3-jr8g.json index 7f6cfce499f..c507441d9e7 100644 --- a/advisories/unreviewed/2023/01/GHSA-4wpp-22r3-jr8g/GHSA-4wpp-22r3-jr8g.json +++ b/advisories/unreviewed/2023/01/GHSA-4wpp-22r3-jr8g/GHSA-4wpp-22r3-jr8g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4wpp-22r3-jr8g", - "modified": "2023-01-13T09:30:27Z", + "modified": "2025-04-07T21:31:39Z", "published": "2023-01-10T09:30:24Z", "aliases": [ "CVE-2023-22909" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22909" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AP65YEN762IBNQPOYGUVLTQIDLM5XD2A" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AP65YEN762IBNQPOYGUVLTQIDLM5XD2A" diff --git a/advisories/unreviewed/2023/01/GHSA-6fwq-c2cr-jg74/GHSA-6fwq-c2cr-jg74.json b/advisories/unreviewed/2023/01/GHSA-6fwq-c2cr-jg74/GHSA-6fwq-c2cr-jg74.json index b7b220d2a5c..81ae12a383c 100644 --- a/advisories/unreviewed/2023/01/GHSA-6fwq-c2cr-jg74/GHSA-6fwq-c2cr-jg74.json +++ b/advisories/unreviewed/2023/01/GHSA-6fwq-c2cr-jg74/GHSA-6fwq-c2cr-jg74.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6fwq-c2cr-jg74", - "modified": "2023-01-13T09:30:26Z", + "modified": "2025-04-07T21:31:39Z", "published": "2023-01-10T09:30:24Z", "aliases": [ "CVE-2023-22911" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22911" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AP65YEN762IBNQPOYGUVLTQIDLM5XD2A" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AP65YEN762IBNQPOYGUVLTQIDLM5XD2A" diff --git a/advisories/unreviewed/2023/01/GHSA-6wqq-m34g-chqp/GHSA-6wqq-m34g-chqp.json b/advisories/unreviewed/2023/01/GHSA-6wqq-m34g-chqp/GHSA-6wqq-m34g-chqp.json index 3079ebecb03..9cebd20dae6 100644 --- a/advisories/unreviewed/2023/01/GHSA-6wqq-m34g-chqp/GHSA-6wqq-m34g-chqp.json +++ b/advisories/unreviewed/2023/01/GHSA-6wqq-m34g-chqp/GHSA-6wqq-m34g-chqp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6wqq-m34g-chqp", - "modified": "2023-01-25T00:30:38Z", + "modified": "2025-04-07T21:31:48Z", "published": "2023-01-14T03:30:22Z", "aliases": [ "CVE-2023-23589" @@ -35,6 +35,14 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/01/msg00026.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IYOLTP6HQO2HPXUYKOR7P5YYYN7CINQQ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZMY4FWXYKP3MDXTZ3EJ7XJVGBCKBK2XL" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IYOLTP6HQO2HPXUYKOR7P5YYYN7CINQQ" @@ -53,7 +61,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-693" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-p28r-f42x-qmm2/GHSA-p28r-f42x-qmm2.json b/advisories/unreviewed/2023/01/GHSA-p28r-f42x-qmm2/GHSA-p28r-f42x-qmm2.json index c7f879eb622..ff512daaa7a 100644 --- a/advisories/unreviewed/2023/01/GHSA-p28r-f42x-qmm2/GHSA-p28r-f42x-qmm2.json +++ b/advisories/unreviewed/2023/01/GHSA-p28r-f42x-qmm2/GHSA-p28r-f42x-qmm2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p28r-f42x-qmm2", - "modified": "2023-01-19T00:30:31Z", + "modified": "2025-04-07T21:31:40Z", "published": "2023-01-11T03:30:20Z", "aliases": [ "CVE-2023-22945" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://gerrit.wikimedia.org/r/q/Id1b83fcd58eccb8b2dfea44a3ab2f72314860d88" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AP65YEN762IBNQPOYGUVLTQIDLM5XD2A" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AP65YEN762IBNQPOYGUVLTQIDLM5XD2A" diff --git a/advisories/unreviewed/2023/01/GHSA-pmh6-cq54-943m/GHSA-pmh6-cq54-943m.json b/advisories/unreviewed/2023/01/GHSA-pmh6-cq54-943m/GHSA-pmh6-cq54-943m.json index b29048ff1c5..52cbdd51c04 100644 --- a/advisories/unreviewed/2023/01/GHSA-pmh6-cq54-943m/GHSA-pmh6-cq54-943m.json +++ b/advisories/unreviewed/2023/01/GHSA-pmh6-cq54-943m/GHSA-pmh6-cq54-943m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pmh6-cq54-943m", - "modified": "2023-01-11T18:30:32Z", + "modified": "2025-04-07T21:31:37Z", "published": "2023-01-05T03:30:36Z", "aliases": [ "CVE-2023-22622" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://github.com/WordPress/WordPress/blob/dca7b5204b5fea54e6d1774689777b359a9222ab/wp-cron.php#L5-L8" }, + { + "type": "WEB", + "url": "https://medium.com/%40thecpanelguy/the-nightmare-that-is-wpcron-php-ae31c1d3ae30" + }, { "type": "WEB", "url": "https://medium.com/@thecpanelguy/the-nightmare-that-is-wpcron-php-ae31c1d3ae30" diff --git a/advisories/unreviewed/2023/01/GHSA-q9vj-6cqq-wmgg/GHSA-q9vj-6cqq-wmgg.json b/advisories/unreviewed/2023/01/GHSA-q9vj-6cqq-wmgg/GHSA-q9vj-6cqq-wmgg.json index bb2e2fc9cab..159918bfa1e 100644 --- a/advisories/unreviewed/2023/01/GHSA-q9vj-6cqq-wmgg/GHSA-q9vj-6cqq-wmgg.json +++ b/advisories/unreviewed/2023/01/GHSA-q9vj-6cqq-wmgg/GHSA-q9vj-6cqq-wmgg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q9vj-6cqq-wmgg", - "modified": "2023-01-13T18:30:20Z", + "modified": "2025-04-07T21:31:38Z", "published": "2023-01-10T06:30:25Z", "aliases": [ "CVE-2023-22320" diff --git a/advisories/unreviewed/2024/05/GHSA-3qv4-3prp-9cv5/GHSA-3qv4-3prp-9cv5.json b/advisories/unreviewed/2024/05/GHSA-3qv4-3prp-9cv5/GHSA-3qv4-3prp-9cv5.json index 5dd7f13929e..7a0faf8997d 100644 --- a/advisories/unreviewed/2024/05/GHSA-3qv4-3prp-9cv5/GHSA-3qv4-3prp-9cv5.json +++ b/advisories/unreviewed/2024/05/GHSA-3qv4-3prp-9cv5/GHSA-3qv4-3prp-9cv5.json @@ -61,7 +61,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-362" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-7w57-r874-fx7f/GHSA-7w57-r874-fx7f.json b/advisories/unreviewed/2024/05/GHSA-7w57-r874-fx7f/GHSA-7w57-r874-fx7f.json index 3d5f643a6c3..bf3d50a4a38 100644 --- a/advisories/unreviewed/2024/05/GHSA-7w57-r874-fx7f/GHSA-7w57-r874-fx7f.json +++ b/advisories/unreviewed/2024/05/GHSA-7w57-r874-fx7f/GHSA-7w57-r874-fx7f.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-416" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-8wgh-w2f4-v692/GHSA-8wgh-w2f4-v692.json b/advisories/unreviewed/2024/05/GHSA-8wgh-w2f4-v692/GHSA-8wgh-w2f4-v692.json index fb2565f8229..65bde4b105f 100644 --- a/advisories/unreviewed/2024/05/GHSA-8wgh-w2f4-v692/GHSA-8wgh-w2f4-v692.json +++ b/advisories/unreviewed/2024/05/GHSA-8wgh-w2f4-v692/GHSA-8wgh-w2f4-v692.json @@ -61,7 +61,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-415" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-c5j5-pffr-9wgm/GHSA-c5j5-pffr-9wgm.json b/advisories/unreviewed/2024/05/GHSA-c5j5-pffr-9wgm/GHSA-c5j5-pffr-9wgm.json index a1caa1e9f06..562e945c63c 100644 --- a/advisories/unreviewed/2024/05/GHSA-c5j5-pffr-9wgm/GHSA-c5j5-pffr-9wgm.json +++ b/advisories/unreviewed/2024/05/GHSA-c5j5-pffr-9wgm/GHSA-c5j5-pffr-9wgm.json @@ -54,6 +54,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-401", "CWE-416" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/05/GHSA-mcp4-w22q-6q4h/GHSA-mcp4-w22q-6q4h.json b/advisories/unreviewed/2024/05/GHSA-mcp4-w22q-6q4h/GHSA-mcp4-w22q-6q4h.json index b3aaa0b2a18..324675c4949 100644 --- a/advisories/unreviewed/2024/05/GHSA-mcp4-w22q-6q4h/GHSA-mcp4-w22q-6q4h.json +++ b/advisories/unreviewed/2024/05/GHSA-mcp4-w22q-6q4h/GHSA-mcp4-w22q-6q4h.json @@ -61,7 +61,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-908" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-pfj6-pxh2-f24m/GHSA-pfj6-pxh2-f24m.json b/advisories/unreviewed/2024/05/GHSA-pfj6-pxh2-f24m/GHSA-pfj6-pxh2-f24m.json index 5f7730e1c12..06e931d0bf4 100644 --- a/advisories/unreviewed/2024/05/GHSA-pfj6-pxh2-f24m/GHSA-pfj6-pxh2-f24m.json +++ b/advisories/unreviewed/2024/05/GHSA-pfj6-pxh2-f24m/GHSA-pfj6-pxh2-f24m.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-401" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-phx3-79h9-xhvq/GHSA-phx3-79h9-xhvq.json b/advisories/unreviewed/2024/05/GHSA-phx3-79h9-xhvq/GHSA-phx3-79h9-xhvq.json index 7fda271c07a..bc83fab3346 100644 --- a/advisories/unreviewed/2024/05/GHSA-phx3-79h9-xhvq/GHSA-phx3-79h9-xhvq.json +++ b/advisories/unreviewed/2024/05/GHSA-phx3-79h9-xhvq/GHSA-phx3-79h9-xhvq.json @@ -53,7 +53,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-401" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-5244-qm9f-xx43/GHSA-5244-qm9f-xx43.json b/advisories/unreviewed/2024/12/GHSA-5244-qm9f-xx43/GHSA-5244-qm9f-xx43.json index b74465a4e44..2c42233cdbb 100644 --- a/advisories/unreviewed/2024/12/GHSA-5244-qm9f-xx43/GHSA-5244-qm9f-xx43.json +++ b/advisories/unreviewed/2024/12/GHSA-5244-qm9f-xx43/GHSA-5244-qm9f-xx43.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5244-qm9f-xx43", - "modified": "2024-12-27T15:31:51Z", + "modified": "2025-04-07T21:31:55Z", "published": "2024-12-27T15:31:51Z", "aliases": [ "CVE-2024-53197" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices\n\nA bogus device can provide a bNumConfigurations value that exceeds the\ninitial value used in usb_get_configuration for allocating dev->config.\n\nThis can lead to out-of-bounds accesses later, e.g. in\nusb_destroy_configuration.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -52,8 +57,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T14:15:27Z" diff --git a/advisories/unreviewed/2025/01/GHSA-3g3j-w5cc-fqpr/GHSA-3g3j-w5cc-fqpr.json b/advisories/unreviewed/2025/01/GHSA-3g3j-w5cc-fqpr/GHSA-3g3j-w5cc-fqpr.json index 4009ffa6a71..f4d13242b53 100644 --- a/advisories/unreviewed/2025/01/GHSA-3g3j-w5cc-fqpr/GHSA-3g3j-w5cc-fqpr.json +++ b/advisories/unreviewed/2025/01/GHSA-3g3j-w5cc-fqpr/GHSA-3g3j-w5cc-fqpr.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-f2hp-vf26-j2rg/GHSA-f2hp-vf26-j2rg.json b/advisories/unreviewed/2025/01/GHSA-f2hp-vf26-j2rg/GHSA-f2hp-vf26-j2rg.json index d1dbba26e37..c12f04a85d6 100644 --- a/advisories/unreviewed/2025/01/GHSA-f2hp-vf26-j2rg/GHSA-f2hp-vf26-j2rg.json +++ b/advisories/unreviewed/2025/01/GHSA-f2hp-vf26-j2rg/GHSA-f2hp-vf26-j2rg.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-2f35-gvj8-wv7h/GHSA-2f35-gvj8-wv7h.json b/advisories/unreviewed/2025/03/GHSA-2f35-gvj8-wv7h/GHSA-2f35-gvj8-wv7h.json index 38a582f4bd5..b899fe6548e 100644 --- a/advisories/unreviewed/2025/03/GHSA-2f35-gvj8-wv7h/GHSA-2f35-gvj8-wv7h.json +++ b/advisories/unreviewed/2025/03/GHSA-2f35-gvj8-wv7h/GHSA-2f35-gvj8-wv7h.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-378w-m5r6-wj6p/GHSA-378w-m5r6-wj6p.json b/advisories/unreviewed/2025/03/GHSA-378w-m5r6-wj6p/GHSA-378w-m5r6-wj6p.json index 5be5eaf4ab1..ed0c70a599a 100644 --- a/advisories/unreviewed/2025/03/GHSA-378w-m5r6-wj6p/GHSA-378w-m5r6-wj6p.json +++ b/advisories/unreviewed/2025/03/GHSA-378w-m5r6-wj6p/GHSA-378w-m5r6-wj6p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-378w-m5r6-wj6p", - "modified": "2025-03-29T09:30:31Z", + "modified": "2025-04-07T21:32:03Z", "published": "2025-03-29T09:30:31Z", "aliases": [ "CVE-2025-2006" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://plugins.trac.wordpress.org/browser/image-upload-for-bbpress/tags/1.1.19/bbp-image-upload.php#L136" }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3264738%40image-upload-for-bbpress&new=3264738%40image-upload-for-bbpress&sfp_email=&sfph_mail=" + }, { "type": "WEB", "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/df09af41-399a-4878-8420-721f1198d895?source=cve" diff --git a/advisories/unreviewed/2025/03/GHSA-4qcq-c33q-9hm3/GHSA-4qcq-c33q-9hm3.json b/advisories/unreviewed/2025/03/GHSA-4qcq-c33q-9hm3/GHSA-4qcq-c33q-9hm3.json index 9be5f34c7fb..0e1c1774915 100644 --- a/advisories/unreviewed/2025/03/GHSA-4qcq-c33q-9hm3/GHSA-4qcq-c33q-9hm3.json +++ b/advisories/unreviewed/2025/03/GHSA-4qcq-c33q-9hm3/GHSA-4qcq-c33q-9hm3.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-f624-74px-f7hv/GHSA-f624-74px-f7hv.json b/advisories/unreviewed/2025/03/GHSA-f624-74px-f7hv/GHSA-f624-74px-f7hv.json index eb9b09364d4..9d4f064141b 100644 --- a/advisories/unreviewed/2025/03/GHSA-f624-74px-f7hv/GHSA-f624-74px-f7hv.json +++ b/advisories/unreviewed/2025/03/GHSA-f624-74px-f7hv/GHSA-f624-74px-f7hv.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-w277-7jfc-fqc3/GHSA-w277-7jfc-fqc3.json b/advisories/unreviewed/2025/03/GHSA-w277-7jfc-fqc3/GHSA-w277-7jfc-fqc3.json index 4f7667e31a3..cae8be0629e 100644 --- a/advisories/unreviewed/2025/03/GHSA-w277-7jfc-fqc3/GHSA-w277-7jfc-fqc3.json +++ b/advisories/unreviewed/2025/03/GHSA-w277-7jfc-fqc3/GHSA-w277-7jfc-fqc3.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-23rf-wq7x-gvq7/GHSA-23rf-wq7x-gvq7.json b/advisories/unreviewed/2025/04/GHSA-23rf-wq7x-gvq7/GHSA-23rf-wq7x-gvq7.json index 5e5922a85b4..51ab4b118e5 100644 --- a/advisories/unreviewed/2025/04/GHSA-23rf-wq7x-gvq7/GHSA-23rf-wq7x-gvq7.json +++ b/advisories/unreviewed/2025/04/GHSA-23rf-wq7x-gvq7/GHSA-23rf-wq7x-gvq7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-23rf-wq7x-gvq7", - "modified": "2025-04-07T15:31:12Z", + "modified": "2025-04-07T21:32:07Z", "published": "2025-04-07T15:31:11Z", "aliases": [ "CVE-2024-52322" ], "details": "WebService::Xero 0.11 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions.\n\nSpecifically WebService::Xero uses the Data::Random library which specifically states that it is \"Useful mostly for test programs\". Data::Random uses the rand() function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -47,7 +52,7 @@ "cwe_ids": [ "CWE-338" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-05T17:15:39Z" diff --git a/advisories/unreviewed/2025/04/GHSA-2cp9-r2rg-qvgg/GHSA-2cp9-r2rg-qvgg.json b/advisories/unreviewed/2025/04/GHSA-2cp9-r2rg-qvgg/GHSA-2cp9-r2rg-qvgg.json index b4cd5afbe47..b568ed412a9 100644 --- a/advisories/unreviewed/2025/04/GHSA-2cp9-r2rg-qvgg/GHSA-2cp9-r2rg-qvgg.json +++ b/advisories/unreviewed/2025/04/GHSA-2cp9-r2rg-qvgg/GHSA-2cp9-r2rg-qvgg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2cp9-r2rg-qvgg", - "modified": "2025-04-01T06:30:44Z", + "modified": "2025-04-07T21:32:03Z", "published": "2025-04-01T06:30:44Z", "aliases": [ "CVE-2025-1534" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://docs.payara.fish/enterprise/docs/Release%20Notes/Release%20Notes%206.24.0.html" + }, + { + "type": "WEB", + "url": "https://www.gruppotim.it/it/footer/red-team.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/04/GHSA-3ch3-mpx2-hj74/GHSA-3ch3-mpx2-hj74.json b/advisories/unreviewed/2025/04/GHSA-3ch3-mpx2-hj74/GHSA-3ch3-mpx2-hj74.json new file mode 100644 index 00000000000..9b1b037b769 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3ch3-mpx2-hj74/GHSA-3ch3-mpx2-hj74.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3ch3-mpx2-hj74", + "modified": "2025-04-07T21:32:08Z", + "published": "2025-04-07T21:32:08Z", + "aliases": [ + "CVE-2025-29481" + ], + "details": "Buffer Overflow vulnerability in libbpf 1.5.0 allows a local attacker to execute arbitrary code via the bpf_object__init_prog` function of libbpf.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29481" + }, + { + "type": "WEB", + "url": "https://github.com/lmarch2/poc/blob/main/libbpf/libbpf.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T20:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3qpv-2q49-9qj8/GHSA-3qpv-2q49-9qj8.json b/advisories/unreviewed/2025/04/GHSA-3qpv-2q49-9qj8/GHSA-3qpv-2q49-9qj8.json new file mode 100644 index 00000000000..b561df03d67 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3qpv-2q49-9qj8/GHSA-3qpv-2q49-9qj8.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qpv-2q49-9qj8", + "modified": "2025-04-07T21:32:08Z", + "published": "2025-04-07T21:32:08Z", + "aliases": [ + "CVE-2024-46494" + ], + "details": "A cross-site scripting (XSS) vulnerability in Typecho v1.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into Name parameter under a comment for an Article.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46494" + }, + { + "type": "WEB", + "url": "https://h40vv3n.github.io/2024/09/05/typecho-xss" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T20:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3wrm-64r6-6q6c/GHSA-3wrm-64r6-6q6c.json b/advisories/unreviewed/2025/04/GHSA-3wrm-64r6-6q6c/GHSA-3wrm-64r6-6q6c.json index 335e8ac66d4..13229d70bf4 100644 --- a/advisories/unreviewed/2025/04/GHSA-3wrm-64r6-6q6c/GHSA-3wrm-64r6-6q6c.json +++ b/advisories/unreviewed/2025/04/GHSA-3wrm-64r6-6q6c/GHSA-3wrm-64r6-6q6c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3wrm-64r6-6q6c", - "modified": "2025-04-03T21:33:00Z", + "modified": "2025-04-07T21:32:04Z", "published": "2025-04-03T21:33:00Z", "aliases": [ "CVE-2024-47215" ], "details": "An issue was discovered in Snowbridge setups sending data to Google Tag Manager Server Side. It involves attaching an invalid GTM SS preview header to events, causing them to be retried indefinitely. As a result, the performance of forwarding events to GTM SS overall can be affected (latency, throughput).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-703" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-03T21:15:38Z" diff --git a/advisories/unreviewed/2025/04/GHSA-43jx-m6w2-jq4p/GHSA-43jx-m6w2-jq4p.json b/advisories/unreviewed/2025/04/GHSA-43jx-m6w2-jq4p/GHSA-43jx-m6w2-jq4p.json new file mode 100644 index 00000000000..0e8678af171 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-43jx-m6w2-jq4p/GHSA-43jx-m6w2-jq4p.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-43jx-m6w2-jq4p", + "modified": "2025-04-07T21:32:08Z", + "published": "2025-04-07T21:32:08Z", + "aliases": [ + "CVE-2025-29482" + ], + "details": "Buffer Overflow vulnerability in libheif 1.19.7 allows a local attacker to execute arbitrary code via the SAO (Sample Adaptive Offset) processing of libde265.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29482" + }, + { + "type": "WEB", + "url": "https://github.com/lmarch2/poc/blob/main/libheif/libheif.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T20:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-57cc-74xg-cqvg/GHSA-57cc-74xg-cqvg.json b/advisories/unreviewed/2025/04/GHSA-57cc-74xg-cqvg/GHSA-57cc-74xg-cqvg.json new file mode 100644 index 00000000000..c86abab81ac --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-57cc-74xg-cqvg/GHSA-57cc-74xg-cqvg.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-57cc-74xg-cqvg", + "modified": "2025-04-07T21:32:08Z", + "published": "2025-04-07T21:32:08Z", + "aliases": [ + "CVE-2025-29478" + ], + "details": "An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the cfl_list_size in cfl_list.h:165.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29478" + }, + { + "type": "WEB", + "url": "https://github.com/lmarch2/poc/blob/main/fluent-bit/fluent-bit.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T20:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5mvf-2v8v-7668/GHSA-5mvf-2v8v-7668.json b/advisories/unreviewed/2025/04/GHSA-5mvf-2v8v-7668/GHSA-5mvf-2v8v-7668.json new file mode 100644 index 00000000000..7f286ab57da --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5mvf-2v8v-7668/GHSA-5mvf-2v8v-7668.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5mvf-2v8v-7668", + "modified": "2025-04-07T21:32:08Z", + "published": "2025-04-07T21:32:08Z", + "aliases": [ + "CVE-2025-3380" + ], + "details": "A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. Affected by this issue is some unknown functionality of the component FEAT Command Handler. The manipulation leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3380" + }, + { + "type": "WEB", + "url": "https://fitoxs.com/exploit/exploit-c926c69a41d2fce207cf3a3b789b7a79.txt" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303626" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303626" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.552342" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T19:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6j35-rq42-fv6v/GHSA-6j35-rq42-fv6v.json b/advisories/unreviewed/2025/04/GHSA-6j35-rq42-fv6v/GHSA-6j35-rq42-fv6v.json new file mode 100644 index 00000000000..a88b7efe6f3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6j35-rq42-fv6v/GHSA-6j35-rq42-fv6v.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6j35-rq42-fv6v", + "modified": "2025-04-07T21:32:08Z", + "published": "2025-04-07T21:32:08Z", + "aliases": [ + "CVE-2025-29087" + ], + "details": "Sqlite 3.49.0 is susceptible to integer overflow through the concat function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29087" + }, + { + "type": "WEB", + "url": "https://gist.github.com/ylwango613/a44a29f1ef074fa783e29f04a0afd62a" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T20:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8h3v-hh74-r7p2/GHSA-8h3v-hh74-r7p2.json b/advisories/unreviewed/2025/04/GHSA-8h3v-hh74-r7p2/GHSA-8h3v-hh74-r7p2.json index d0973f03885..6b6e4e855d5 100644 --- a/advisories/unreviewed/2025/04/GHSA-8h3v-hh74-r7p2/GHSA-8h3v-hh74-r7p2.json +++ b/advisories/unreviewed/2025/04/GHSA-8h3v-hh74-r7p2/GHSA-8h3v-hh74-r7p2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8h3v-hh74-r7p2", - "modified": "2025-04-04T18:31:07Z", + "modified": "2025-04-07T21:32:06Z", "published": "2025-04-04T18:31:07Z", "aliases": [ "CVE-2025-29477" ], "details": "An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the function consume_event.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-04T18:15:48Z" diff --git a/advisories/unreviewed/2025/04/GHSA-928q-p6rr-68q8/GHSA-928q-p6rr-68q8.json b/advisories/unreviewed/2025/04/GHSA-928q-p6rr-68q8/GHSA-928q-p6rr-68q8.json new file mode 100644 index 00000000000..adb4436dc27 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-928q-p6rr-68q8/GHSA-928q-p6rr-68q8.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-928q-p6rr-68q8", + "modified": "2025-04-07T21:32:08Z", + "published": "2025-04-07T21:32:08Z", + "aliases": [ + "CVE-2025-29479" + ], + "details": "Buffer Overflow in hiredis 1.2.0 allows a local attacker to cause a denial of service via the sdscatlen function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29479" + }, + { + "type": "WEB", + "url": "https://github.com/lmarch2/poc/blob/main/hiredis/hiredis.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T20:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9j5c-g9c4-jwqv/GHSA-9j5c-g9c4-jwqv.json b/advisories/unreviewed/2025/04/GHSA-9j5c-g9c4-jwqv/GHSA-9j5c-g9c4-jwqv.json index 9490b837c27..e93245530e7 100644 --- a/advisories/unreviewed/2025/04/GHSA-9j5c-g9c4-jwqv/GHSA-9j5c-g9c4-jwqv.json +++ b/advisories/unreviewed/2025/04/GHSA-9j5c-g9c4-jwqv/GHSA-9j5c-g9c4-jwqv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9j5c-g9c4-jwqv", - "modified": "2025-04-07T06:30:27Z", + "modified": "2025-04-07T21:32:07Z", "published": "2025-04-07T06:30:27Z", "aliases": [ "CVE-2025-20658" ], "details": "In DA, there is a possible permission bypass due to a logic error. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09474894; Issue ID: MSV-2597.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-07T04:15:19Z" diff --git a/advisories/unreviewed/2025/04/GHSA-cc3m-w7mm-948m/GHSA-cc3m-w7mm-948m.json b/advisories/unreviewed/2025/04/GHSA-cc3m-w7mm-948m/GHSA-cc3m-w7mm-948m.json index c9f9623a3aa..91dca7f3e95 100644 --- a/advisories/unreviewed/2025/04/GHSA-cc3m-w7mm-948m/GHSA-cc3m-w7mm-948m.json +++ b/advisories/unreviewed/2025/04/GHSA-cc3m-w7mm-948m/GHSA-cc3m-w7mm-948m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cc3m-w7mm-948m", - "modified": "2025-04-07T18:30:46Z", + "modified": "2025-04-07T21:32:07Z", "published": "2025-04-07T18:30:46Z", "aliases": [ "CVE-2025-28400" ], "details": "An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the postID parameter in the edit method", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-269" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-07T16:15:24Z" diff --git a/advisories/unreviewed/2025/04/GHSA-ch4m-2996-7xpv/GHSA-ch4m-2996-7xpv.json b/advisories/unreviewed/2025/04/GHSA-ch4m-2996-7xpv/GHSA-ch4m-2996-7xpv.json index 80649bbb3ae..90387ee4df8 100644 --- a/advisories/unreviewed/2025/04/GHSA-ch4m-2996-7xpv/GHSA-ch4m-2996-7xpv.json +++ b/advisories/unreviewed/2025/04/GHSA-ch4m-2996-7xpv/GHSA-ch4m-2996-7xpv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-ch4m-2996-7xpv", - "modified": "2025-04-07T15:31:10Z", + "modified": "2025-04-07T21:32:06Z", "published": "2025-04-07T15:31:10Z", "aliases": [ "CVE-2024-57835" ], "details": "Amon2::Auth::Site::LINE uses the String::Random module to generate nonce values. \n\nString::Random defaults to Perl's built-in predictable random number generator, the rand() function, which is not cryptographically secure", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -35,7 +40,7 @@ "cwe_ids": [ "CWE-338" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-05T16:15:32Z" diff --git a/advisories/unreviewed/2025/04/GHSA-fphf-v8m4-xjvx/GHSA-fphf-v8m4-xjvx.json b/advisories/unreviewed/2025/04/GHSA-fphf-v8m4-xjvx/GHSA-fphf-v8m4-xjvx.json index bb428928b52..3404b99f479 100644 --- a/advisories/unreviewed/2025/04/GHSA-fphf-v8m4-xjvx/GHSA-fphf-v8m4-xjvx.json +++ b/advisories/unreviewed/2025/04/GHSA-fphf-v8m4-xjvx/GHSA-fphf-v8m4-xjvx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fphf-v8m4-xjvx", - "modified": "2025-04-03T21:33:00Z", + "modified": "2025-04-07T21:32:04Z", "published": "2025-04-03T21:33:00Z", "aliases": [ "CVE-2024-47217" ], "details": "An issue was discovered in Iglu Server 0.13.0 and below. It is similar to CVE-2024-47214, but involves an authenticated endpoint. It can render Iglu Server completely unresponsive. If the operation of Iglu Server is not restored, event processing in the pipeline would eventually halt.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-03T21:15:38Z" diff --git a/advisories/unreviewed/2025/04/GHSA-g6v4-qjhj-pxw5/GHSA-g6v4-qjhj-pxw5.json b/advisories/unreviewed/2025/04/GHSA-g6v4-qjhj-pxw5/GHSA-g6v4-qjhj-pxw5.json new file mode 100644 index 00000000000..6fe9499893e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g6v4-qjhj-pxw5/GHSA-g6v4-qjhj-pxw5.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g6v4-qjhj-pxw5", + "modified": "2025-04-07T21:32:09Z", + "published": "2025-04-07T21:32:09Z", + "aliases": [ + "CVE-2025-3381" + ], + "details": "A vulnerability, which was classified as critical, was found in zhangyanbo2007 youkefu 4.2.0. This affects an unknown part of the file WebIMController.java of the component File Upload. The manipulation of the argument ID leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3381" + }, + { + "type": "WEB", + "url": "https://github.com/mapl3miss/uckefuVul/blob/main/uckefu-upload.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303627" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303627" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.552369" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T20:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gfj4-2p4p-m25j/GHSA-gfj4-2p4p-m25j.json b/advisories/unreviewed/2025/04/GHSA-gfj4-2p4p-m25j/GHSA-gfj4-2p4p-m25j.json index 701dfaf9dd0..be8a3c0d5b4 100644 --- a/advisories/unreviewed/2025/04/GHSA-gfj4-2p4p-m25j/GHSA-gfj4-2p4p-m25j.json +++ b/advisories/unreviewed/2025/04/GHSA-gfj4-2p4p-m25j/GHSA-gfj4-2p4p-m25j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gfj4-2p4p-m25j", - "modified": "2025-04-07T15:31:11Z", + "modified": "2025-04-07T21:32:07Z", "published": "2025-04-07T15:31:10Z", "aliases": [ "CVE-2024-57868" ], "details": "Web::API 2.8 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions.\n\nSpecifically Web::API uses the Data::Random library which specifically states that it is \"Useful mostly for test programs\". Data::Random uses the rand() function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -39,7 +44,7 @@ "cwe_ids": [ "CWE-338" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-05T16:15:33Z" diff --git a/advisories/unreviewed/2025/04/GHSA-gh2f-rgj7-f8jm/GHSA-gh2f-rgj7-f8jm.json b/advisories/unreviewed/2025/04/GHSA-gh2f-rgj7-f8jm/GHSA-gh2f-rgj7-f8jm.json new file mode 100644 index 00000000000..977e3631e6b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gh2f-rgj7-f8jm/GHSA-gh2f-rgj7-f8jm.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gh2f-rgj7-f8jm", + "modified": "2025-04-07T21:32:08Z", + "published": "2025-04-07T21:32:08Z", + "aliases": [ + "CVE-2025-3379" + ], + "details": "A vulnerability classified as critical was found in PCMan FTP Server 2.0.7. Affected by this vulnerability is an unknown functionality of the component EPSV Command Handler. The manipulation leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3379" + }, + { + "type": "WEB", + "url": "https://fitoxs.com/exploit/exploit-bb0f6aa46681315f8c62a944a52a3f4e.txt" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303625" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303625" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.552341" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T19:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h49w-g4vp-f472/GHSA-h49w-g4vp-f472.json b/advisories/unreviewed/2025/04/GHSA-h49w-g4vp-f472/GHSA-h49w-g4vp-f472.json index f4735781432..d9768bde2f6 100644 --- a/advisories/unreviewed/2025/04/GHSA-h49w-g4vp-f472/GHSA-h49w-g4vp-f472.json +++ b/advisories/unreviewed/2025/04/GHSA-h49w-g4vp-f472/GHSA-h49w-g4vp-f472.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h49w-g4vp-f472", - "modified": "2025-04-07T06:30:27Z", + "modified": "2025-04-07T21:32:07Z", "published": "2025-04-07T06:30:27Z", "aliases": [ "CVE-2025-20655" ], "details": "In keymaster, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: DTV04427687; Issue ID: MSV-3183.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-07T04:15:19Z" diff --git a/advisories/unreviewed/2025/04/GHSA-hp4v-q7qc-45wr/GHSA-hp4v-q7qc-45wr.json b/advisories/unreviewed/2025/04/GHSA-hp4v-q7qc-45wr/GHSA-hp4v-q7qc-45wr.json index 5f90a43cdf6..c2e4edfd561 100644 --- a/advisories/unreviewed/2025/04/GHSA-hp4v-q7qc-45wr/GHSA-hp4v-q7qc-45wr.json +++ b/advisories/unreviewed/2025/04/GHSA-hp4v-q7qc-45wr/GHSA-hp4v-q7qc-45wr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hp4v-q7qc-45wr", - "modified": "2025-04-07T15:31:10Z", + "modified": "2025-04-07T21:32:06Z", "published": "2025-04-07T15:31:10Z", "aliases": [ "CVE-2025-30401" ], "details": "A spoofing issue in WhatsApp for Windows prior to version 2.2450.6 displayed attachments according to their MIME type but selected the file opening handler based on the attachment’s filename extension. A maliciously crafted mismatch could have caused the recipient to inadvertently execute arbitrary code rather than view the attachment when manually opening the attachment inside WhatsApp.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-05T12:15:14Z" diff --git a/advisories/unreviewed/2025/04/GHSA-hx6m-xfx3-6p5x/GHSA-hx6m-xfx3-6p5x.json b/advisories/unreviewed/2025/04/GHSA-hx6m-xfx3-6p5x/GHSA-hx6m-xfx3-6p5x.json index 71ec3d2eba9..04342adab68 100644 --- a/advisories/unreviewed/2025/04/GHSA-hx6m-xfx3-6p5x/GHSA-hx6m-xfx3-6p5x.json +++ b/advisories/unreviewed/2025/04/GHSA-hx6m-xfx3-6p5x/GHSA-hx6m-xfx3-6p5x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hx6m-xfx3-6p5x", - "modified": "2025-04-07T15:31:11Z", + "modified": "2025-04-07T21:32:07Z", "published": "2025-04-07T15:31:11Z", "aliases": [ "CVE-2024-58036" ], "details": "Net::Dropbox::API 1.9 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions.\n\nSpecifically Net::Dropbox::API uses the Data::Random library which specifically states that it is \"Useful mostly for test programs\". Data::Random uses the rand() function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -39,7 +44,7 @@ "cwe_ids": [ "CWE-338" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-05T16:15:33Z" diff --git a/advisories/unreviewed/2025/04/GHSA-j87v-9jp4-gw6c/GHSA-j87v-9jp4-gw6c.json b/advisories/unreviewed/2025/04/GHSA-j87v-9jp4-gw6c/GHSA-j87v-9jp4-gw6c.json index f39f7ea5e1a..742a7fee118 100644 --- a/advisories/unreviewed/2025/04/GHSA-j87v-9jp4-gw6c/GHSA-j87v-9jp4-gw6c.json +++ b/advisories/unreviewed/2025/04/GHSA-j87v-9jp4-gw6c/GHSA-j87v-9jp4-gw6c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j87v-9jp4-gw6c", - "modified": "2025-04-01T00:30:44Z", + "modified": "2025-04-07T21:32:03Z", "published": "2025-04-01T00:30:44Z", "aliases": [ "CVE-2025-31188" ], "details": "A race condition was addressed with additional validation. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to bypass Privacy preferences.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-362" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:29Z" diff --git a/advisories/unreviewed/2025/04/GHSA-p53h-9vwh-rvvp/GHSA-p53h-9vwh-rvvp.json b/advisories/unreviewed/2025/04/GHSA-p53h-9vwh-rvvp/GHSA-p53h-9vwh-rvvp.json index 293e5023490..ca5e323c345 100644 --- a/advisories/unreviewed/2025/04/GHSA-p53h-9vwh-rvvp/GHSA-p53h-9vwh-rvvp.json +++ b/advisories/unreviewed/2025/04/GHSA-p53h-9vwh-rvvp/GHSA-p53h-9vwh-rvvp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p53h-9vwh-rvvp", - "modified": "2025-04-04T18:31:07Z", + "modified": "2025-04-07T21:32:05Z", "published": "2025-04-04T18:31:07Z", "aliases": [ "CVE-2025-29476" ], "details": "Buffer Overflow vulnerability in compress_chunk_fuzzer with oss-fuzz on commit 16450518afddcb3139de627157208e49bfef6987 in c-blosc2 v.2.17.0 and before.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-04T18:15:48Z" diff --git a/advisories/unreviewed/2025/04/GHSA-p7jp-69j5-crrv/GHSA-p7jp-69j5-crrv.json b/advisories/unreviewed/2025/04/GHSA-p7jp-69j5-crrv/GHSA-p7jp-69j5-crrv.json new file mode 100644 index 00000000000..3f85b97529e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p7jp-69j5-crrv/GHSA-p7jp-69j5-crrv.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p7jp-69j5-crrv", + "modified": "2025-04-07T21:32:08Z", + "published": "2025-04-07T21:32:08Z", + "aliases": [ + "CVE-2025-29480" + ], + "details": "Buffer Overflow vulnerability in gdal 3.10.2 allows a local attacker to cause a denial of service via the OGRSpatialReference::Release function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29480" + }, + { + "type": "WEB", + "url": "https://github.com/lmarch2/poc/blob/main/gdal/gdal.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T20:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pfr4-hcrh-5w35/GHSA-pfr4-hcrh-5w35.json b/advisories/unreviewed/2025/04/GHSA-pfr4-hcrh-5w35/GHSA-pfr4-hcrh-5w35.json new file mode 100644 index 00000000000..ea643b7735c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pfr4-hcrh-5w35/GHSA-pfr4-hcrh-5w35.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pfr4-hcrh-5w35", + "modified": "2025-04-07T21:32:08Z", + "published": "2025-04-07T21:32:08Z", + "aliases": [ + "CVE-2025-3382" + ], + "details": "A vulnerability has been found in joey-zhou xiaozhi-esp32-server-java up to a14fe8115842ee42ab5c7a51706b8a85db5200b7 and classified as critical. This vulnerability affects the function update of the file /api/user/update. The manipulation of the argument state leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3382" + }, + { + "type": "WEB", + "url": "https://github.com/exp3n5ive/Vul/blob/main/xiaozhi-sqli/xiaozhi-sqli.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303628" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303628" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.552387" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T20:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-q732-48vr-36f4/GHSA-q732-48vr-36f4.json b/advisories/unreviewed/2025/04/GHSA-q732-48vr-36f4/GHSA-q732-48vr-36f4.json index d3b556852df..a81f2d452d4 100644 --- a/advisories/unreviewed/2025/04/GHSA-q732-48vr-36f4/GHSA-q732-48vr-36f4.json +++ b/advisories/unreviewed/2025/04/GHSA-q732-48vr-36f4/GHSA-q732-48vr-36f4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q732-48vr-36f4", - "modified": "2025-04-07T18:30:46Z", + "modified": "2025-04-07T21:32:07Z", "published": "2025-04-07T18:30:46Z", "aliases": [ "CVE-2025-28401" ], "details": "An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the menuId parameter", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-269" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-07T16:15:24Z" diff --git a/advisories/unreviewed/2025/04/GHSA-q844-h75g-f78q/GHSA-q844-h75g-f78q.json b/advisories/unreviewed/2025/04/GHSA-q844-h75g-f78q/GHSA-q844-h75g-f78q.json index 45aaf6b8569..5bdcb6ae819 100644 --- a/advisories/unreviewed/2025/04/GHSA-q844-h75g-f78q/GHSA-q844-h75g-f78q.json +++ b/advisories/unreviewed/2025/04/GHSA-q844-h75g-f78q/GHSA-q844-h75g-f78q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q844-h75g-f78q", - "modified": "2025-04-01T00:30:44Z", + "modified": "2025-04-07T21:32:03Z", "published": "2025-04-01T00:30:44Z", "aliases": [ "CVE-2025-31184" ], "details": "This issue was addressed with improved permissions checking. This issue is fixed in Safari 18.4, visionOS 2.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may gain unauthorized access to Local Network.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-281" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:28Z" diff --git a/advisories/unreviewed/2025/04/GHSA-qcwf-jj36-gr7m/GHSA-qcwf-jj36-gr7m.json b/advisories/unreviewed/2025/04/GHSA-qcwf-jj36-gr7m/GHSA-qcwf-jj36-gr7m.json index 6a4dde09a5b..a48c1a39b8b 100644 --- a/advisories/unreviewed/2025/04/GHSA-qcwf-jj36-gr7m/GHSA-qcwf-jj36-gr7m.json +++ b/advisories/unreviewed/2025/04/GHSA-qcwf-jj36-gr7m/GHSA-qcwf-jj36-gr7m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qcwf-jj36-gr7m", - "modified": "2025-04-03T21:33:00Z", + "modified": "2025-04-07T21:32:04Z", "published": "2025-04-03T21:33:00Z", "aliases": [ "CVE-2024-47214" ], "details": "An issue was discovered in Iglu Server 0.13.0 and below. It is similar to CVE-2024-47212, but involves a different kind of malicious payload. As above, it can render Iglu Server completely unresponsive. If the operation of Iglu Server is not restored, event processing in the pipeline would eventually halt.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-03T21:15:38Z" diff --git a/advisories/unreviewed/2025/04/GHSA-qg7f-449v-85xg/GHSA-qg7f-449v-85xg.json b/advisories/unreviewed/2025/04/GHSA-qg7f-449v-85xg/GHSA-qg7f-449v-85xg.json index ffcb4de4ca5..5edc3754e67 100644 --- a/advisories/unreviewed/2025/04/GHSA-qg7f-449v-85xg/GHSA-qg7f-449v-85xg.json +++ b/advisories/unreviewed/2025/04/GHSA-qg7f-449v-85xg/GHSA-qg7f-449v-85xg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qg7f-449v-85xg", - "modified": "2025-04-03T21:33:00Z", + "modified": "2025-04-07T21:32:05Z", "published": "2025-04-03T21:33:00Z", "aliases": [ "CVE-2024-56528" ], "details": "This vulnerability affects Snowplow Collector 3.x before 3.3.0 (unless it’s set up behind a reverse proxy that establishes payload limits). It involves sending very large payloads to the Collector and can render it unresponsive to the rest of the requests. As a result, data would not enter the pipeline and would be potentially lost.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-03T21:15:39Z" diff --git a/advisories/unreviewed/2025/04/GHSA-r75x-m5pq-2c5m/GHSA-r75x-m5pq-2c5m.json b/advisories/unreviewed/2025/04/GHSA-r75x-m5pq-2c5m/GHSA-r75x-m5pq-2c5m.json new file mode 100644 index 00000000000..6bd17332ba7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-r75x-m5pq-2c5m/GHSA-r75x-m5pq-2c5m.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r75x-m5pq-2c5m", + "modified": "2025-04-07T21:32:09Z", + "published": "2025-04-07T21:32:09Z", + "aliases": [ + "CVE-2025-3383" + ], + "details": "A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /search/search_sales.php. The manipulation of the argument Name leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3383" + }, + { + "type": "WEB", + "url": "https://github.com/Colorado-all/cve/blob/main/Web-based%20Pharmacy%20Product%20Management%20System/SQL-1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303629" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303629" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.552388" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T21:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rmr8-rg92-5f98/GHSA-rmr8-rg92-5f98.json b/advisories/unreviewed/2025/04/GHSA-rmr8-rg92-5f98/GHSA-rmr8-rg92-5f98.json index 0403a558902..9c0211ab17a 100644 --- a/advisories/unreviewed/2025/04/GHSA-rmr8-rg92-5f98/GHSA-rmr8-rg92-5f98.json +++ b/advisories/unreviewed/2025/04/GHSA-rmr8-rg92-5f98/GHSA-rmr8-rg92-5f98.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rmr8-rg92-5f98", - "modified": "2025-04-03T21:32:59Z", + "modified": "2025-04-07T21:32:03Z", "published": "2025-04-03T21:32:59Z", "aliases": [ "CVE-2025-29064" ], "details": "An issue in TOTOLINK x18 v.9.1.0cu.2024_B20220329 allows a remote attacker to execute arbitrary code via the sub_410E54 function of the cstecgi.cgi.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-03T20:15:24Z" diff --git a/advisories/unreviewed/2025/04/GHSA-wp3g-9m76-xj95/GHSA-wp3g-9m76-xj95.json b/advisories/unreviewed/2025/04/GHSA-wp3g-9m76-xj95/GHSA-wp3g-9m76-xj95.json new file mode 100644 index 00000000000..8b3bf314481 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wp3g-9m76-xj95/GHSA-wp3g-9m76-xj95.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wp3g-9m76-xj95", + "modified": "2025-04-07T21:32:09Z", + "published": "2025-04-07T21:32:09Z", + "aliases": [ + "CVE-2025-3384" + ], + "details": "A vulnerability was found in 1000 Projects Human Resource Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /controller/employee.php. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3384" + }, + { + "type": "WEB", + "url": "https://github.com/onupset/CVE/issues/7" + }, + { + "type": "WEB", + "url": "https://1000projects.org" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303630" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303630" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.552447" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T21:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xw8c-3xf4-r67j/GHSA-xw8c-3xf4-r67j.json b/advisories/unreviewed/2025/04/GHSA-xw8c-3xf4-r67j/GHSA-xw8c-3xf4-r67j.json new file mode 100644 index 00000000000..e5726a54b19 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xw8c-3xf4-r67j/GHSA-xw8c-3xf4-r67j.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xw8c-3xf4-r67j", + "modified": "2025-04-07T21:32:08Z", + "published": "2025-04-07T21:32:08Z", + "aliases": [ + "CVE-2025-29594" + ], + "details": "A vulnerability exists in the errorpage.php file of the CS2-WeaponPaints-Website v2.1.7 where user-controlled input is not adequately validated before being processed. Specifically, the $_GET['errorcode'] parameter can be manipulated to access unauthorized error codes, leading to Cross-Site Scripting (XSS) attacks and information disclosure.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29594" + }, + { + "type": "WEB", + "url": "https://github.com/J4cky1028/vulnerability-research/tree/main/CVE-2025-29594" + }, + { + "type": "WEB", + "url": "https://github.com/LielXD/CS2-WeaponPaints-Website/blob/b1d8364c1cbcab6981a564d8abe43b1cc26a2503/errorpage.php#L41" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T20:15:20Z" + } +} \ No newline at end of file