From ae5dc603e2b60cb91ad2b0bea105e33e6ecaaf33 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 22 Apr 2025 15:32:02 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-76hq-7c4p-7vcg.json | 9 +++- .../GHSA-qhv8-qr2f-xwvq.json | 9 +++- .../GHSA-2hvq-vmfm-c497.json | 4 +- .../GHSA-9h2x-cq23-hmx7.json | 4 +- .../GHSA-g3fw-7m9c-g9m8.json | 4 +- .../GHSA-hhjc-j2mm-6qxp.json | 4 +- .../GHSA-j38m-4q67-m9hm.json | 4 +- .../GHSA-qmjc-q235-3hw5.json | 4 +- .../GHSA-4rc3-56q2-qpp2.json | 2 +- .../GHSA-57q3-v3hf-grgw.json | 2 +- .../GHSA-5xfh-4pqx-pm43.json | 4 +- .../GHSA-68xf-4w7r-p3v5.json | 1 + .../GHSA-6q7p-h646-hjmp.json | 3 +- .../GHSA-873m-q6f6-cfqx.json | 2 +- .../GHSA-f4qr-m466-5qpf.json | 4 +- .../GHSA-h97p-r383-p42m.json | 1 + .../GHSA-j5rg-4wj9-7v6m.json | 2 +- .../GHSA-m257-4mgj-cg83.json | 1 + .../GHSA-pg72-vgx7-799x.json | 4 +- .../GHSA-qggh-6fch-vxcc.json | 3 +- .../GHSA-r84c-983f-q52v.json | 4 +- .../GHSA-rh6c-rgq8-jq7m.json | 4 +- .../GHSA-vv55-64q4-h5fj.json | 2 +- .../GHSA-vvgj-jgpv-mjh7.json | 4 +- .../GHSA-wpr6-p2f8-xgcj.json | 3 +- .../GHSA-cc49-h52c-hm2r.json | 3 +- .../GHSA-w9p5-xqxf-xvx7.json | 3 +- .../GHSA-6cmw-42pp-vrv8.json | 3 +- .../GHSA-2x7x-7j2m-xw86.json | 3 +- .../GHSA-v8pv-7728-56fc.json | 3 +- .../GHSA-2vpw-mvv7-vfx4.json | 15 +++++-- .../GHSA-388j-24wv-pfqq.json | 36 +++++++++++++++ .../GHSA-3c6p-c4v9-m5mw.json | 15 +++++-- .../GHSA-4528-h42g-x3c7.json | 15 +++++-- .../GHSA-485p-gmh5-r688.json | 15 +++++-- .../GHSA-4qhj-jmx7-8mr8.json | 41 +++++++++++++++++ .../GHSA-69cv-j485-xjf7.json | 15 +++++-- .../GHSA-6mcv-x7cp-3q3f.json | 36 +++++++++++++++ .../GHSA-7jpf-hrrg-gcj2.json | 15 +++++-- .../GHSA-c785-qf3f-59ww.json | 33 ++++++++++++++ .../GHSA-c7rc-cfrf-3v4q.json | 15 +++++-- .../GHSA-c839-wqcr-r3p3.json | 15 +++++-- .../GHSA-chhj-m9v4-rx7m.json | 36 +++++++++++++++ .../GHSA-chm5-6f56-6fwp.json | 15 +++++-- .../GHSA-chx3-h6vh-h2pv.json | 15 +++++-- .../GHSA-fpqq-44hc-vvx2.json | 15 +++++-- .../GHSA-h3qf-q3hj-98c2.json | 11 +++-- .../GHSA-hfrv-r3rc-g4p6.json | 15 +++++-- .../GHSA-hj8g-f5gh-vqmq.json | 44 +++++++++++++++++++ .../GHSA-hmpr-r93w-5j44.json | 11 +++-- .../GHSA-jhcm-4gfm-2q7g.json | 15 +++++-- .../GHSA-m728-3vq8-cxvv.json | 15 +++++-- .../GHSA-mp63-mm73-jhgm.json | 29 ++++++++++++ .../GHSA-p2gm-m8q4-6r5q.json | 29 ++++++++++++ .../GHSA-p688-g48x-vg8h.json | 15 +++++-- .../GHSA-pfpp-vwh2-g27w.json | 15 +++++-- .../GHSA-pw67-xjhq-389w.json | 15 +++++-- .../GHSA-q8pq-pv68-q9cm.json | 29 ++++++++++++ .../GHSA-qcvj-mcp5-pjg8.json | 36 +++++++++++++++ .../GHSA-rw43-mgp5-rf2m.json | 33 ++++++++++++++ .../GHSA-rw8h-4h76-h2mx.json | 15 +++++-- .../GHSA-v8vm-8h6v-g2gc.json | 15 +++++-- .../GHSA-wgwq-2crv-c4jj.json | 15 +++++-- .../GHSA-wm23-hcgv-w4x3.json | 15 +++++-- 64 files changed, 703 insertions(+), 119 deletions(-) create mode 100644 advisories/unreviewed/2025/04/GHSA-388j-24wv-pfqq/GHSA-388j-24wv-pfqq.json create mode 100644 advisories/unreviewed/2025/04/GHSA-4qhj-jmx7-8mr8/GHSA-4qhj-jmx7-8mr8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-6mcv-x7cp-3q3f/GHSA-6mcv-x7cp-3q3f.json create mode 100644 advisories/unreviewed/2025/04/GHSA-c785-qf3f-59ww/GHSA-c785-qf3f-59ww.json create mode 100644 advisories/unreviewed/2025/04/GHSA-chhj-m9v4-rx7m/GHSA-chhj-m9v4-rx7m.json create mode 100644 advisories/unreviewed/2025/04/GHSA-hj8g-f5gh-vqmq/GHSA-hj8g-f5gh-vqmq.json create mode 100644 advisories/unreviewed/2025/04/GHSA-mp63-mm73-jhgm/GHSA-mp63-mm73-jhgm.json create mode 100644 advisories/unreviewed/2025/04/GHSA-p2gm-m8q4-6r5q/GHSA-p2gm-m8q4-6r5q.json create mode 100644 advisories/unreviewed/2025/04/GHSA-q8pq-pv68-q9cm/GHSA-q8pq-pv68-q9cm.json create mode 100644 advisories/unreviewed/2025/04/GHSA-qcvj-mcp5-pjg8/GHSA-qcvj-mcp5-pjg8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-rw43-mgp5-rf2m/GHSA-rw43-mgp5-rf2m.json diff --git a/advisories/unreviewed/2022/01/GHSA-76hq-7c4p-7vcg/GHSA-76hq-7c4p-7vcg.json b/advisories/unreviewed/2022/01/GHSA-76hq-7c4p-7vcg/GHSA-76hq-7c4p-7vcg.json index be2473d3d6f..8981b789856 100644 --- a/advisories/unreviewed/2022/01/GHSA-76hq-7c4p-7vcg/GHSA-76hq-7c4p-7vcg.json +++ b/advisories/unreviewed/2022/01/GHSA-76hq-7c4p-7vcg/GHSA-76hq-7c4p-7vcg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-76hq-7c4p-7vcg", - "modified": "2022-01-26T00:02:13Z", + "modified": "2025-04-22T15:30:23Z", "published": "2022-01-21T00:00:54Z", "aliases": [ "CVE-2021-46027" ], "details": "mysiteforme, as of 19-12-2022, has a CSRF vulnerability in the background blog management. The attacker constructs a CSRF load. Once the administrator clicks a malicious link, a blog tag will be added", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-qhv8-qr2f-xwvq/GHSA-qhv8-qr2f-xwvq.json b/advisories/unreviewed/2022/05/GHSA-qhv8-qr2f-xwvq/GHSA-qhv8-qr2f-xwvq.json index b89d905ead1..1d0005fb0d3 100644 --- a/advisories/unreviewed/2022/05/GHSA-qhv8-qr2f-xwvq/GHSA-qhv8-qr2f-xwvq.json +++ b/advisories/unreviewed/2022/05/GHSA-qhv8-qr2f-xwvq/GHSA-qhv8-qr2f-xwvq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qhv8-qr2f-xwvq", - "modified": "2022-05-24T17:26:14Z", + "modified": "2025-04-22T15:30:23Z", "published": "2022-05-24T17:26:14Z", "aliases": [ "CVE-2020-23935" ], "details": "Kabir Alhasan Student Management System 1.0 is vulnerable to Authentication Bypass via \"Username: admin'# && Password: (Write Something)\".", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/11/GHSA-2hvq-vmfm-c497/GHSA-2hvq-vmfm-c497.json b/advisories/unreviewed/2022/11/GHSA-2hvq-vmfm-c497/GHSA-2hvq-vmfm-c497.json index fee022effbd..ff4b002a0c0 100644 --- a/advisories/unreviewed/2022/11/GHSA-2hvq-vmfm-c497/GHSA-2hvq-vmfm-c497.json +++ b/advisories/unreviewed/2022/11/GHSA-2hvq-vmfm-c497/GHSA-2hvq-vmfm-c497.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-9h2x-cq23-hmx7/GHSA-9h2x-cq23-hmx7.json b/advisories/unreviewed/2022/11/GHSA-9h2x-cq23-hmx7/GHSA-9h2x-cq23-hmx7.json index 9a3003d5e62..736b2882f14 100644 --- a/advisories/unreviewed/2022/11/GHSA-9h2x-cq23-hmx7/GHSA-9h2x-cq23-hmx7.json +++ b/advisories/unreviewed/2022/11/GHSA-9h2x-cq23-hmx7/GHSA-9h2x-cq23-hmx7.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-g3fw-7m9c-g9m8/GHSA-g3fw-7m9c-g9m8.json b/advisories/unreviewed/2022/11/GHSA-g3fw-7m9c-g9m8/GHSA-g3fw-7m9c-g9m8.json index 1cdffdfe966..58595524417 100644 --- a/advisories/unreviewed/2022/11/GHSA-g3fw-7m9c-g9m8/GHSA-g3fw-7m9c-g9m8.json +++ b/advisories/unreviewed/2022/11/GHSA-g3fw-7m9c-g9m8/GHSA-g3fw-7m9c-g9m8.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-hhjc-j2mm-6qxp/GHSA-hhjc-j2mm-6qxp.json b/advisories/unreviewed/2022/11/GHSA-hhjc-j2mm-6qxp/GHSA-hhjc-j2mm-6qxp.json index 53b4aa48e49..e9573091f85 100644 --- a/advisories/unreviewed/2022/11/GHSA-hhjc-j2mm-6qxp/GHSA-hhjc-j2mm-6qxp.json +++ b/advisories/unreviewed/2022/11/GHSA-hhjc-j2mm-6qxp/GHSA-hhjc-j2mm-6qxp.json @@ -49,7 +49,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-693" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-j38m-4q67-m9hm/GHSA-j38m-4q67-m9hm.json b/advisories/unreviewed/2022/11/GHSA-j38m-4q67-m9hm/GHSA-j38m-4q67-m9hm.json index 2a3e373c7d4..39cce0583e5 100644 --- a/advisories/unreviewed/2022/11/GHSA-j38m-4q67-m9hm/GHSA-j38m-4q67-m9hm.json +++ b/advisories/unreviewed/2022/11/GHSA-j38m-4q67-m9hm/GHSA-j38m-4q67-m9hm.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-119" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-qmjc-q235-3hw5/GHSA-qmjc-q235-3hw5.json b/advisories/unreviewed/2022/11/GHSA-qmjc-q235-3hw5/GHSA-qmjc-q235-3hw5.json index e9dfbf760bb..6b99e379253 100644 --- a/advisories/unreviewed/2022/11/GHSA-qmjc-q235-3hw5/GHSA-qmjc-q235-3hw5.json +++ b/advisories/unreviewed/2022/11/GHSA-qmjc-q235-3hw5/GHSA-qmjc-q235-3hw5.json @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-20" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-4rc3-56q2-qpp2/GHSA-4rc3-56q2-qpp2.json b/advisories/unreviewed/2022/12/GHSA-4rc3-56q2-qpp2/GHSA-4rc3-56q2-qpp2.json index f1d74f92f8d..66e8041f9e2 100644 --- a/advisories/unreviewed/2022/12/GHSA-4rc3-56q2-qpp2/GHSA-4rc3-56q2-qpp2.json +++ b/advisories/unreviewed/2022/12/GHSA-4rc3-56q2-qpp2/GHSA-4rc3-56q2-qpp2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4rc3-56q2-qpp2", - "modified": "2022-12-16T21:30:44Z", + "modified": "2025-04-22T15:30:33Z", "published": "2022-12-14T15:30:16Z", "aliases": [ "CVE-2022-44832" diff --git a/advisories/unreviewed/2022/12/GHSA-57q3-v3hf-grgw/GHSA-57q3-v3hf-grgw.json b/advisories/unreviewed/2022/12/GHSA-57q3-v3hf-grgw/GHSA-57q3-v3hf-grgw.json index 40fa1639bc9..516209b6fa3 100644 --- a/advisories/unreviewed/2022/12/GHSA-57q3-v3hf-grgw/GHSA-57q3-v3hf-grgw.json +++ b/advisories/unreviewed/2022/12/GHSA-57q3-v3hf-grgw/GHSA-57q3-v3hf-grgw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-57q3-v3hf-grgw", - "modified": "2022-12-16T21:30:44Z", + "modified": "2025-04-22T15:30:33Z", "published": "2022-12-14T18:30:23Z", "aliases": [ "CVE-2022-46443" diff --git a/advisories/unreviewed/2022/12/GHSA-5xfh-4pqx-pm43/GHSA-5xfh-4pqx-pm43.json b/advisories/unreviewed/2022/12/GHSA-5xfh-4pqx-pm43/GHSA-5xfh-4pqx-pm43.json index a69d73c567a..124ca8f5732 100644 --- a/advisories/unreviewed/2022/12/GHSA-5xfh-4pqx-pm43/GHSA-5xfh-4pqx-pm43.json +++ b/advisories/unreviewed/2022/12/GHSA-5xfh-4pqx-pm43/GHSA-5xfh-4pqx-pm43.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-68xf-4w7r-p3v5/GHSA-68xf-4w7r-p3v5.json b/advisories/unreviewed/2022/12/GHSA-68xf-4w7r-p3v5/GHSA-68xf-4w7r-p3v5.json index 8b552db0489..04dca1079e6 100644 --- a/advisories/unreviewed/2022/12/GHSA-68xf-4w7r-p3v5/GHSA-68xf-4w7r-p3v5.json +++ b/advisories/unreviewed/2022/12/GHSA-68xf-4w7r-p3v5/GHSA-68xf-4w7r-p3v5.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1284", "CWE-400" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/12/GHSA-6q7p-h646-hjmp/GHSA-6q7p-h646-hjmp.json b/advisories/unreviewed/2022/12/GHSA-6q7p-h646-hjmp/GHSA-6q7p-h646-hjmp.json index e38092c1075..02e704b34c5 100644 --- a/advisories/unreviewed/2022/12/GHSA-6q7p-h646-hjmp/GHSA-6q7p-h646-hjmp.json +++ b/advisories/unreviewed/2022/12/GHSA-6q7p-h646-hjmp/GHSA-6q7p-h646-hjmp.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-770" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-873m-q6f6-cfqx/GHSA-873m-q6f6-cfqx.json b/advisories/unreviewed/2022/12/GHSA-873m-q6f6-cfqx/GHSA-873m-q6f6-cfqx.json index 1a30db97517..479c0778bf8 100644 --- a/advisories/unreviewed/2022/12/GHSA-873m-q6f6-cfqx/GHSA-873m-q6f6-cfqx.json +++ b/advisories/unreviewed/2022/12/GHSA-873m-q6f6-cfqx/GHSA-873m-q6f6-cfqx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-873m-q6f6-cfqx", - "modified": "2022-12-16T21:30:44Z", + "modified": "2025-04-22T15:30:33Z", "published": "2022-12-14T15:30:16Z", "aliases": [ "CVE-2022-44898" diff --git a/advisories/unreviewed/2022/12/GHSA-f4qr-m466-5qpf/GHSA-f4qr-m466-5qpf.json b/advisories/unreviewed/2022/12/GHSA-f4qr-m466-5qpf/GHSA-f4qr-m466-5qpf.json index f1a5ee0a457..18e09e61dd9 100644 --- a/advisories/unreviewed/2022/12/GHSA-f4qr-m466-5qpf/GHSA-f4qr-m466-5qpf.json +++ b/advisories/unreviewed/2022/12/GHSA-f4qr-m466-5qpf/GHSA-f4qr-m466-5qpf.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-h97p-r383-p42m/GHSA-h97p-r383-p42m.json b/advisories/unreviewed/2022/12/GHSA-h97p-r383-p42m/GHSA-h97p-r383-p42m.json index 0a2e24fd5c4..5297e8f8c08 100644 --- a/advisories/unreviewed/2022/12/GHSA-h97p-r383-p42m/GHSA-h97p-r383-p42m.json +++ b/advisories/unreviewed/2022/12/GHSA-h97p-r383-p42m/GHSA-h97p-r383-p42m.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1284", "CWE-400" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/12/GHSA-j5rg-4wj9-7v6m/GHSA-j5rg-4wj9-7v6m.json b/advisories/unreviewed/2022/12/GHSA-j5rg-4wj9-7v6m/GHSA-j5rg-4wj9-7v6m.json index b7e6f01f9cf..01e19b722ba 100644 --- a/advisories/unreviewed/2022/12/GHSA-j5rg-4wj9-7v6m/GHSA-j5rg-4wj9-7v6m.json +++ b/advisories/unreviewed/2022/12/GHSA-j5rg-4wj9-7v6m/GHSA-j5rg-4wj9-7v6m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j5rg-4wj9-7v6m", - "modified": "2022-12-16T21:30:44Z", + "modified": "2025-04-22T15:30:33Z", "published": "2022-12-14T15:30:16Z", "aliases": [ "CVE-2022-46609" diff --git a/advisories/unreviewed/2022/12/GHSA-m257-4mgj-cg83/GHSA-m257-4mgj-cg83.json b/advisories/unreviewed/2022/12/GHSA-m257-4mgj-cg83/GHSA-m257-4mgj-cg83.json index 0258eeab447..0d457f24300 100644 --- a/advisories/unreviewed/2022/12/GHSA-m257-4mgj-cg83/GHSA-m257-4mgj-cg83.json +++ b/advisories/unreviewed/2022/12/GHSA-m257-4mgj-cg83/GHSA-m257-4mgj-cg83.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1284", "CWE-400" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/12/GHSA-pg72-vgx7-799x/GHSA-pg72-vgx7-799x.json b/advisories/unreviewed/2022/12/GHSA-pg72-vgx7-799x/GHSA-pg72-vgx7-799x.json index 78a9b3e8777..0b4a7d282aa 100644 --- a/advisories/unreviewed/2022/12/GHSA-pg72-vgx7-799x/GHSA-pg72-vgx7-799x.json +++ b/advisories/unreviewed/2022/12/GHSA-pg72-vgx7-799x/GHSA-pg72-vgx7-799x.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-qggh-6fch-vxcc/GHSA-qggh-6fch-vxcc.json b/advisories/unreviewed/2022/12/GHSA-qggh-6fch-vxcc/GHSA-qggh-6fch-vxcc.json index b0d996140e6..d12e4189808 100644 --- a/advisories/unreviewed/2022/12/GHSA-qggh-6fch-vxcc/GHSA-qggh-6fch-vxcc.json +++ b/advisories/unreviewed/2022/12/GHSA-qggh-6fch-vxcc/GHSA-qggh-6fch-vxcc.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-770" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-r84c-983f-q52v/GHSA-r84c-983f-q52v.json b/advisories/unreviewed/2022/12/GHSA-r84c-983f-q52v/GHSA-r84c-983f-q52v.json index 09ecb3b3dd1..201e7412fca 100644 --- a/advisories/unreviewed/2022/12/GHSA-r84c-983f-q52v/GHSA-r84c-983f-q52v.json +++ b/advisories/unreviewed/2022/12/GHSA-r84c-983f-q52v/GHSA-r84c-983f-q52v.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-rh6c-rgq8-jq7m/GHSA-rh6c-rgq8-jq7m.json b/advisories/unreviewed/2022/12/GHSA-rh6c-rgq8-jq7m/GHSA-rh6c-rgq8-jq7m.json index dbf30748021..a64aadd11ab 100644 --- a/advisories/unreviewed/2022/12/GHSA-rh6c-rgq8-jq7m/GHSA-rh6c-rgq8-jq7m.json +++ b/advisories/unreviewed/2022/12/GHSA-rh6c-rgq8-jq7m/GHSA-rh6c-rgq8-jq7m.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-20" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-vv55-64q4-h5fj/GHSA-vv55-64q4-h5fj.json b/advisories/unreviewed/2022/12/GHSA-vv55-64q4-h5fj/GHSA-vv55-64q4-h5fj.json index e7f760e4afe..cdd0f79293f 100644 --- a/advisories/unreviewed/2022/12/GHSA-vv55-64q4-h5fj/GHSA-vv55-64q4-h5fj.json +++ b/advisories/unreviewed/2022/12/GHSA-vv55-64q4-h5fj/GHSA-vv55-64q4-h5fj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vv55-64q4-h5fj", - "modified": "2022-12-15T00:30:16Z", + "modified": "2025-04-22T15:30:26Z", "published": "2022-12-12T18:30:27Z", "aliases": [ "CVE-2022-3925" diff --git a/advisories/unreviewed/2022/12/GHSA-vvgj-jgpv-mjh7/GHSA-vvgj-jgpv-mjh7.json b/advisories/unreviewed/2022/12/GHSA-vvgj-jgpv-mjh7/GHSA-vvgj-jgpv-mjh7.json index 21e8fa452e0..9f163a9db99 100644 --- a/advisories/unreviewed/2022/12/GHSA-vvgj-jgpv-mjh7/GHSA-vvgj-jgpv-mjh7.json +++ b/advisories/unreviewed/2022/12/GHSA-vvgj-jgpv-mjh7/GHSA-vvgj-jgpv-mjh7.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-wpr6-p2f8-xgcj/GHSA-wpr6-p2f8-xgcj.json b/advisories/unreviewed/2022/12/GHSA-wpr6-p2f8-xgcj/GHSA-wpr6-p2f8-xgcj.json index cf530ce162c..e118a937263 100644 --- a/advisories/unreviewed/2022/12/GHSA-wpr6-p2f8-xgcj/GHSA-wpr6-p2f8-xgcj.json +++ b/advisories/unreviewed/2022/12/GHSA-wpr6-p2f8-xgcj/GHSA-wpr6-p2f8-xgcj.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-754" + "CWE-754", + "CWE-755" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-cc49-h52c-hm2r/GHSA-cc49-h52c-hm2r.json b/advisories/unreviewed/2024/11/GHSA-cc49-h52c-hm2r/GHSA-cc49-h52c-hm2r.json index 27d8b920dd8..1e6af07836c 100644 --- a/advisories/unreviewed/2024/11/GHSA-cc49-h52c-hm2r/GHSA-cc49-h52c-hm2r.json +++ b/advisories/unreviewed/2024/11/GHSA-cc49-h52c-hm2r/GHSA-cc49-h52c-hm2r.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-123" + "CWE-123", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-w9p5-xqxf-xvx7/GHSA-w9p5-xqxf-xvx7.json b/advisories/unreviewed/2024/11/GHSA-w9p5-xqxf-xvx7/GHSA-w9p5-xqxf-xvx7.json index 51476c37aa6..f076d67130b 100644 --- a/advisories/unreviewed/2024/11/GHSA-w9p5-xqxf-xvx7/GHSA-w9p5-xqxf-xvx7.json +++ b/advisories/unreviewed/2024/11/GHSA-w9p5-xqxf-xvx7/GHSA-w9p5-xqxf-xvx7.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-123" + "CWE-123", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-6cmw-42pp-vrv8/GHSA-6cmw-42pp-vrv8.json b/advisories/unreviewed/2024/12/GHSA-6cmw-42pp-vrv8/GHSA-6cmw-42pp-vrv8.json index 9ddd70b8ddd..49c43150790 100644 --- a/advisories/unreviewed/2024/12/GHSA-6cmw-42pp-vrv8/GHSA-6cmw-42pp-vrv8.json +++ b/advisories/unreviewed/2024/12/GHSA-6cmw-42pp-vrv8/GHSA-6cmw-42pp-vrv8.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-2x7x-7j2m-xw86/GHSA-2x7x-7j2m-xw86.json b/advisories/unreviewed/2025/02/GHSA-2x7x-7j2m-xw86/GHSA-2x7x-7j2m-xw86.json index dab098a72b6..1d73d900b13 100644 --- a/advisories/unreviewed/2025/02/GHSA-2x7x-7j2m-xw86/GHSA-2x7x-7j2m-xw86.json +++ b/advisories/unreviewed/2025/02/GHSA-2x7x-7j2m-xw86/GHSA-2x7x-7j2m-xw86.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-v8pv-7728-56fc/GHSA-v8pv-7728-56fc.json b/advisories/unreviewed/2025/02/GHSA-v8pv-7728-56fc/GHSA-v8pv-7728-56fc.json index ab5a84c7e5b..089fd674434 100644 --- a/advisories/unreviewed/2025/02/GHSA-v8pv-7728-56fc/GHSA-v8pv-7728-56fc.json +++ b/advisories/unreviewed/2025/02/GHSA-v8pv-7728-56fc/GHSA-v8pv-7728-56fc.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-2vpw-mvv7-vfx4/GHSA-2vpw-mvv7-vfx4.json b/advisories/unreviewed/2025/04/GHSA-2vpw-mvv7-vfx4/GHSA-2vpw-mvv7-vfx4.json index 266ac9c4e8e..c27fed8de25 100644 --- a/advisories/unreviewed/2025/04/GHSA-2vpw-mvv7-vfx4/GHSA-2vpw-mvv7-vfx4.json +++ b/advisories/unreviewed/2025/04/GHSA-2vpw-mvv7-vfx4/GHSA-2vpw-mvv7-vfx4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2vpw-mvv7-vfx4", - "modified": "2025-04-16T18:31:53Z", + "modified": "2025-04-22T15:30:50Z", "published": "2025-04-16T18:31:53Z", "aliases": [ "CVE-2024-40071" ], "details": "Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_generator/classes/SystemSettings.php?f=update_settings. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T17:15:48Z" diff --git a/advisories/unreviewed/2025/04/GHSA-388j-24wv-pfqq/GHSA-388j-24wv-pfqq.json b/advisories/unreviewed/2025/04/GHSA-388j-24wv-pfqq/GHSA-388j-24wv-pfqq.json new file mode 100644 index 00000000000..963d0e02248 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-388j-24wv-pfqq/GHSA-388j-24wv-pfqq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-388j-24wv-pfqq", + "modified": "2025-04-22T15:30:53Z", + "published": "2025-04-22T15:30:53Z", + "aliases": [ + "CVE-2025-23176" + ], + "details": "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23176" + }, + { + "type": "WEB", + "url": "https://www.gov.il/en/departments/dynamiccollectors/cve_advisories_listing?skip=0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T15:16:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3c6p-c4v9-m5mw/GHSA-3c6p-c4v9-m5mw.json b/advisories/unreviewed/2025/04/GHSA-3c6p-c4v9-m5mw/GHSA-3c6p-c4v9-m5mw.json index fbc226663c5..d6b66e69b57 100644 --- a/advisories/unreviewed/2025/04/GHSA-3c6p-c4v9-m5mw/GHSA-3c6p-c4v9-m5mw.json +++ b/advisories/unreviewed/2025/04/GHSA-3c6p-c4v9-m5mw/GHSA-3c6p-c4v9-m5mw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3c6p-c4v9-m5mw", - "modified": "2025-04-18T21:31:20Z", + "modified": "2025-04-22T15:30:52Z", "published": "2025-04-18T21:31:20Z", "aliases": [ "CVE-2024-57493" ], "details": "An issue in redoxOS relibc before commit 98aa4ea5 allows a local attacker to cause a denial of service via the setsockopt function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-404" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-18T20:15:15Z" diff --git a/advisories/unreviewed/2025/04/GHSA-4528-h42g-x3c7/GHSA-4528-h42g-x3c7.json b/advisories/unreviewed/2025/04/GHSA-4528-h42g-x3c7/GHSA-4528-h42g-x3c7.json index 498531120bd..e871370cab4 100644 --- a/advisories/unreviewed/2025/04/GHSA-4528-h42g-x3c7/GHSA-4528-h42g-x3c7.json +++ b/advisories/unreviewed/2025/04/GHSA-4528-h42g-x3c7/GHSA-4528-h42g-x3c7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4528-h42g-x3c7", - "modified": "2025-04-21T18:32:09Z", + "modified": "2025-04-22T15:30:52Z", "published": "2025-04-21T18:32:09Z", "aliases": [ "CVE-2025-27086" ], "details": "Vulnerability in Hewlett Packard Enterprise HPE Performance Cluster Manager (HPCM).This issue affects HPE Performance Cluster Manager (HPCM): through 1.12.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-287" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-21T18:15:21Z" diff --git a/advisories/unreviewed/2025/04/GHSA-485p-gmh5-r688/GHSA-485p-gmh5-r688.json b/advisories/unreviewed/2025/04/GHSA-485p-gmh5-r688/GHSA-485p-gmh5-r688.json index 13768191c3c..5127e49ee7f 100644 --- a/advisories/unreviewed/2025/04/GHSA-485p-gmh5-r688/GHSA-485p-gmh5-r688.json +++ b/advisories/unreviewed/2025/04/GHSA-485p-gmh5-r688/GHSA-485p-gmh5-r688.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-485p-gmh5-r688", - "modified": "2025-04-18T18:31:24Z", + "modified": "2025-04-22T15:30:51Z", "published": "2025-04-18T18:31:24Z", "aliases": [ "CVE-2025-28236" ], "details": "Nautel VX Series transmitters VX SW v6.4.0 and below was discovered to contain a remote code execution (RCE) vulnerability in the firmware update process. This vulnerability allows attackers to execute arbitrary code via supplying a crafted update package to the /#/software/upgrades endpoint.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-494" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-18T18:15:46Z" diff --git a/advisories/unreviewed/2025/04/GHSA-4qhj-jmx7-8mr8/GHSA-4qhj-jmx7-8mr8.json b/advisories/unreviewed/2025/04/GHSA-4qhj-jmx7-8mr8/GHSA-4qhj-jmx7-8mr8.json new file mode 100644 index 00000000000..c563afcfe37 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4qhj-jmx7-8mr8/GHSA-4qhj-jmx7-8mr8.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4qhj-jmx7-8mr8", + "modified": "2025-04-22T15:30:52Z", + "published": "2025-04-22T15:30:52Z", + "aliases": [ + "CVE-2024-40445" + ], + "details": "Directory Traversal vulnerability in forkosh Mime Tex before v.1.77 allows an attacker to execute arbitrary code via a crafted file upload", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40445" + }, + { + "type": "WEB", + "url": "https://github.com/Oefenweb/mimetex/blob/master/mimetex.c#L12414-L12423" + }, + { + "type": "WEB", + "url": "https://github.com/TaiYou-TW/CVE-2024-40445_CVE-2024-40446" + }, + { + "type": "WEB", + "url": "https://youtu.be/OII16TteaJw" + }, + { + "type": "WEB", + "url": "https://youtu.be/W2KPHFNfgrg" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T14:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-69cv-j485-xjf7/GHSA-69cv-j485-xjf7.json b/advisories/unreviewed/2025/04/GHSA-69cv-j485-xjf7/GHSA-69cv-j485-xjf7.json index 4d8db250d37..912c86748c0 100644 --- a/advisories/unreviewed/2025/04/GHSA-69cv-j485-xjf7/GHSA-69cv-j485-xjf7.json +++ b/advisories/unreviewed/2025/04/GHSA-69cv-j485-xjf7/GHSA-69cv-j485-xjf7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-69cv-j485-xjf7", - "modified": "2025-04-21T15:31:21Z", + "modified": "2025-04-22T15:30:51Z", "published": "2025-04-21T15:31:21Z", "aliases": [ "CVE-2025-28230" ], "details": "Incorrect access control in JMBroadcast JMB0150 Firmware v1.0 allows attackers to access hardcoded administrator credentials.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-798" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-18T15:15:58Z" diff --git a/advisories/unreviewed/2025/04/GHSA-6mcv-x7cp-3q3f/GHSA-6mcv-x7cp-3q3f.json b/advisories/unreviewed/2025/04/GHSA-6mcv-x7cp-3q3f/GHSA-6mcv-x7cp-3q3f.json new file mode 100644 index 00000000000..dc7b5247572 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6mcv-x7cp-3q3f/GHSA-6mcv-x7cp-3q3f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6mcv-x7cp-3q3f", + "modified": "2025-04-22T15:30:53Z", + "published": "2025-04-22T15:30:53Z", + "aliases": [ + "CVE-2025-1951" + ], + "details": "IBM Hardware Management Console - Power Systems V10.2.1030.0 and V10.3.1050.0 could allow a local user to execute commands as a privileged user due to execution of commands with unnecessary privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1951" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7231389" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-250" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T15:16:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7jpf-hrrg-gcj2/GHSA-7jpf-hrrg-gcj2.json b/advisories/unreviewed/2025/04/GHSA-7jpf-hrrg-gcj2/GHSA-7jpf-hrrg-gcj2.json index b41a4aa569c..7b3f561d574 100644 --- a/advisories/unreviewed/2025/04/GHSA-7jpf-hrrg-gcj2/GHSA-7jpf-hrrg-gcj2.json +++ b/advisories/unreviewed/2025/04/GHSA-7jpf-hrrg-gcj2/GHSA-7jpf-hrrg-gcj2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7jpf-hrrg-gcj2", - "modified": "2025-04-18T18:31:24Z", + "modified": "2025-04-22T15:30:51Z", "published": "2025-04-18T18:31:24Z", "aliases": [ "CVE-2025-28233" ], "details": "Incorrect access control in BW Broadcast TX600 (14980), TX300 (32990) (31448), TX150, TX1000, TX30, and TX50 Hardware Version: 2, Software Version: 1.6.0, Control Version: 1.0, AIO Firmware Version: 1.7 allows attackers to access log files and extract session identifiers to execute a session hijacking attack.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-18T18:15:45Z" diff --git a/advisories/unreviewed/2025/04/GHSA-c785-qf3f-59ww/GHSA-c785-qf3f-59ww.json b/advisories/unreviewed/2025/04/GHSA-c785-qf3f-59ww/GHSA-c785-qf3f-59ww.json new file mode 100644 index 00000000000..67b28007f72 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c785-qf3f-59ww/GHSA-c785-qf3f-59ww.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c785-qf3f-59ww", + "modified": "2025-04-22T15:30:53Z", + "published": "2025-04-22T15:30:53Z", + "aliases": [ + "CVE-2025-29547" + ], + "details": "In Rollback Rx Professional 12.8.0.0, the driver file shieldm.sys allows local users to cause a denial of service because of a null pointer dereference from IOCtl 0x96202000.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29547" + }, + { + "type": "WEB", + "url": "https://horizondatasys.com/rollback-rx-time-machine/rollback-rx-professional" + }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/190491" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T15:16:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c7rc-cfrf-3v4q/GHSA-c7rc-cfrf-3v4q.json b/advisories/unreviewed/2025/04/GHSA-c7rc-cfrf-3v4q/GHSA-c7rc-cfrf-3v4q.json index b05c1645f21..c8f15509257 100644 --- a/advisories/unreviewed/2025/04/GHSA-c7rc-cfrf-3v4q/GHSA-c7rc-cfrf-3v4q.json +++ b/advisories/unreviewed/2025/04/GHSA-c7rc-cfrf-3v4q/GHSA-c7rc-cfrf-3v4q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c7rc-cfrf-3v4q", - "modified": "2025-04-18T18:31:24Z", + "modified": "2025-04-22T15:30:52Z", "published": "2025-04-18T18:31:24Z", "aliases": [ "CVE-2025-28237" ], "details": "An issue in WorldCast Systems ECRESO FM/DAB/TV Transmitter v1.10.1 allows authenticated attackers to escalate privileges via a crafted JSON payload.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-18T18:15:46Z" diff --git a/advisories/unreviewed/2025/04/GHSA-c839-wqcr-r3p3/GHSA-c839-wqcr-r3p3.json b/advisories/unreviewed/2025/04/GHSA-c839-wqcr-r3p3/GHSA-c839-wqcr-r3p3.json index 0997c48bb3b..cb933aa6f6f 100644 --- a/advisories/unreviewed/2025/04/GHSA-c839-wqcr-r3p3/GHSA-c839-wqcr-r3p3.json +++ b/advisories/unreviewed/2025/04/GHSA-c839-wqcr-r3p3/GHSA-c839-wqcr-r3p3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c839-wqcr-r3p3", - "modified": "2025-04-16T18:31:53Z", + "modified": "2025-04-22T15:30:50Z", "published": "2025-04-16T18:31:53Z", "aliases": [ "CVE-2024-40072" ], "details": "Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at id_generator/admin/?page=generate/index&id=1.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T17:15:49Z" diff --git a/advisories/unreviewed/2025/04/GHSA-chhj-m9v4-rx7m/GHSA-chhj-m9v4-rx7m.json b/advisories/unreviewed/2025/04/GHSA-chhj-m9v4-rx7m/GHSA-chhj-m9v4-rx7m.json new file mode 100644 index 00000000000..1affc113c32 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-chhj-m9v4-rx7m/GHSA-chhj-m9v4-rx7m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-chhj-m9v4-rx7m", + "modified": "2025-04-22T15:30:52Z", + "published": "2025-04-22T15:30:52Z", + "aliases": [ + "CVE-2025-23175" + ], + "details": "Multiple XSS (CWE-79)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23175" + }, + { + "type": "WEB", + "url": "https://www.gov.il/en/departments/dynamiccollectors/cve_advisories_listing?skip=0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T13:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-chm5-6f56-6fwp/GHSA-chm5-6f56-6fwp.json b/advisories/unreviewed/2025/04/GHSA-chm5-6f56-6fwp/GHSA-chm5-6f56-6fwp.json index c7f6ad3d6e6..26d33c323d6 100644 --- a/advisories/unreviewed/2025/04/GHSA-chm5-6f56-6fwp/GHSA-chm5-6f56-6fwp.json +++ b/advisories/unreviewed/2025/04/GHSA-chm5-6f56-6fwp/GHSA-chm5-6f56-6fwp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-chm5-6f56-6fwp", - "modified": "2025-04-18T18:31:24Z", + "modified": "2025-04-22T15:30:51Z", "published": "2025-04-18T18:31:24Z", "aliases": [ "CVE-2025-28231" ], "details": "Incorrect access control in Itel Electronics IP Stream v1.7.0.6 allows unauthorized attackers to execute arbitrary commands with Administrator privileges.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-18T18:15:44Z" diff --git a/advisories/unreviewed/2025/04/GHSA-chx3-h6vh-h2pv/GHSA-chx3-h6vh-h2pv.json b/advisories/unreviewed/2025/04/GHSA-chx3-h6vh-h2pv/GHSA-chx3-h6vh-h2pv.json index e8de42c00d5..c7d0a32d1c2 100644 --- a/advisories/unreviewed/2025/04/GHSA-chx3-h6vh-h2pv/GHSA-chx3-h6vh-h2pv.json +++ b/advisories/unreviewed/2025/04/GHSA-chx3-h6vh-h2pv/GHSA-chx3-h6vh-h2pv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-chx3-h6vh-h2pv", - "modified": "2025-04-21T15:31:21Z", + "modified": "2025-04-22T15:30:51Z", "published": "2025-04-21T15:31:21Z", "aliases": [ "CVE-2025-28232" ], "details": "Incorrect access control in the HOME.php endpoint of JMBroadcast JMB0150 Firmware v1.0 allows attackers to access the Admin panel without authentication.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-18T15:15:58Z" diff --git a/advisories/unreviewed/2025/04/GHSA-fpqq-44hc-vvx2/GHSA-fpqq-44hc-vvx2.json b/advisories/unreviewed/2025/04/GHSA-fpqq-44hc-vvx2/GHSA-fpqq-44hc-vvx2.json index 358604b8d5b..7bc139785c1 100644 --- a/advisories/unreviewed/2025/04/GHSA-fpqq-44hc-vvx2/GHSA-fpqq-44hc-vvx2.json +++ b/advisories/unreviewed/2025/04/GHSA-fpqq-44hc-vvx2/GHSA-fpqq-44hc-vvx2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fpqq-44hc-vvx2", - "modified": "2025-04-18T18:31:24Z", + "modified": "2025-04-22T15:30:52Z", "published": "2025-04-18T18:31:24Z", "aliases": [ "CVE-2025-28238" ], "details": "Improper session management in Elber REBLE310 Firmware v5.5.1.R , Equipment Model: REBLE310/RX10/4ASI allows attackers to execute a session hijacking attack.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-384" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-18T18:15:46Z" diff --git a/advisories/unreviewed/2025/04/GHSA-h3qf-q3hj-98c2/GHSA-h3qf-q3hj-98c2.json b/advisories/unreviewed/2025/04/GHSA-h3qf-q3hj-98c2/GHSA-h3qf-q3hj-98c2.json index 8972febda4c..8a159c99852 100644 --- a/advisories/unreviewed/2025/04/GHSA-h3qf-q3hj-98c2/GHSA-h3qf-q3hj-98c2.json +++ b/advisories/unreviewed/2025/04/GHSA-h3qf-q3hj-98c2/GHSA-h3qf-q3hj-98c2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h3qf-q3hj-98c2", - "modified": "2025-04-22T06:30:29Z", + "modified": "2025-04-22T15:30:52Z", "published": "2025-04-22T06:30:29Z", "aliases": [ "CVE-2024-13569" ], "details": "The Front End Users WordPress plugin through 3.2.32 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-22T06:15:44Z" diff --git a/advisories/unreviewed/2025/04/GHSA-hfrv-r3rc-g4p6/GHSA-hfrv-r3rc-g4p6.json b/advisories/unreviewed/2025/04/GHSA-hfrv-r3rc-g4p6/GHSA-hfrv-r3rc-g4p6.json index 4a89646ef14..b191c7c3bae 100644 --- a/advisories/unreviewed/2025/04/GHSA-hfrv-r3rc-g4p6/GHSA-hfrv-r3rc-g4p6.json +++ b/advisories/unreviewed/2025/04/GHSA-hfrv-r3rc-g4p6/GHSA-hfrv-r3rc-g4p6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hfrv-r3rc-g4p6", - "modified": "2025-04-18T18:31:24Z", + "modified": "2025-04-22T15:30:52Z", "published": "2025-04-18T18:31:24Z", "aliases": [ "CVE-2025-28242" ], "details": "Improper session management in the /login_ok.htm endpoint of DAEnetIP4 METO v1.25 allows attackers to execute a session hijacking attack.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-384" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-18T18:15:47Z" diff --git a/advisories/unreviewed/2025/04/GHSA-hj8g-f5gh-vqmq/GHSA-hj8g-f5gh-vqmq.json b/advisories/unreviewed/2025/04/GHSA-hj8g-f5gh-vqmq/GHSA-hj8g-f5gh-vqmq.json new file mode 100644 index 00000000000..0fdd61910ff --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hj8g-f5gh-vqmq/GHSA-hj8g-f5gh-vqmq.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hj8g-f5gh-vqmq", + "modified": "2025-04-22T15:30:52Z", + "published": "2025-04-22T15:30:52Z", + "aliases": [ + "CVE-2024-46546" + ], + "details": "NEXTU FLETA AX1500 WIFI6 Router v1.0.3 was discovered to contain a stack overflow via the url parameter at /boafrm/formFilter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46546" + }, + { + "type": "WEB", + "url": "https://ez-net.co.kr/new_2012/customer/download_view.php?cid=&sid=&goods=&cate=&q=&seq=233" + }, + { + "type": "WEB", + "url": "https://ez-net.co.kr/new_2012/product/view.php?cid=461&sid=467&q=%C7%C3%B7%B9%C5%B8&seq=3479&page=" + }, + { + "type": "WEB", + "url": "https://gist.github.com/laskdjlaskdj12/5b29b8b68f8a2279c9294708f080496b" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T14:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hmpr-r93w-5j44/GHSA-hmpr-r93w-5j44.json b/advisories/unreviewed/2025/04/GHSA-hmpr-r93w-5j44/GHSA-hmpr-r93w-5j44.json index 32072ceed01..0fe9468619b 100644 --- a/advisories/unreviewed/2025/04/GHSA-hmpr-r93w-5j44/GHSA-hmpr-r93w-5j44.json +++ b/advisories/unreviewed/2025/04/GHSA-hmpr-r93w-5j44/GHSA-hmpr-r93w-5j44.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hmpr-r93w-5j44", - "modified": "2025-04-22T06:30:29Z", + "modified": "2025-04-22T15:30:52Z", "published": "2025-04-22T06:30:29Z", "aliases": [ "CVE-2025-2594" ], "details": "The User Registration & Membership WordPress plugin before 4.1.3 does not properly validate data in an AJAX action when the Membership Addon is enabled, allowing attackers to authenticate as any user, including administrators, by simply using the target account's user ID.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-22T06:15:44Z" diff --git a/advisories/unreviewed/2025/04/GHSA-jhcm-4gfm-2q7g/GHSA-jhcm-4gfm-2q7g.json b/advisories/unreviewed/2025/04/GHSA-jhcm-4gfm-2q7g/GHSA-jhcm-4gfm-2q7g.json index 4e6c3d01442..4048280391b 100644 --- a/advisories/unreviewed/2025/04/GHSA-jhcm-4gfm-2q7g/GHSA-jhcm-4gfm-2q7g.json +++ b/advisories/unreviewed/2025/04/GHSA-jhcm-4gfm-2q7g/GHSA-jhcm-4gfm-2q7g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jhcm-4gfm-2q7g", - "modified": "2025-04-21T15:31:19Z", + "modified": "2025-04-22T15:30:51Z", "published": "2025-04-21T15:31:19Z", "aliases": [ "CVE-2025-28229" ], "details": "Incorrect access control in Orban OPTIMOD 5950 Firmware v1.0.0.2 and System v2.2.15 allows attackers to bypass authentication and gain Administrator privileges.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-18T15:15:58Z" diff --git a/advisories/unreviewed/2025/04/GHSA-m728-3vq8-cxvv/GHSA-m728-3vq8-cxvv.json b/advisories/unreviewed/2025/04/GHSA-m728-3vq8-cxvv/GHSA-m728-3vq8-cxvv.json index a61e0d50b0b..6373070477a 100644 --- a/advisories/unreviewed/2025/04/GHSA-m728-3vq8-cxvv/GHSA-m728-3vq8-cxvv.json +++ b/advisories/unreviewed/2025/04/GHSA-m728-3vq8-cxvv/GHSA-m728-3vq8-cxvv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m728-3vq8-cxvv", - "modified": "2025-04-18T18:31:24Z", + "modified": "2025-04-22T15:30:51Z", "published": "2025-04-18T18:31:24Z", "aliases": [ "CVE-2025-28235" ], "details": "An information disclosure vulnerability in the component /socket.io/1/websocket/ of Soundcraft Ui Series Model(s) Ui12 and Ui16 Firmware v1.0.7x and v1.0.5x allows attackers to access Administrator credentials in plaintext.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-18T18:15:45Z" diff --git a/advisories/unreviewed/2025/04/GHSA-mp63-mm73-jhgm/GHSA-mp63-mm73-jhgm.json b/advisories/unreviewed/2025/04/GHSA-mp63-mm73-jhgm/GHSA-mp63-mm73-jhgm.json new file mode 100644 index 00000000000..2089f5e7d28 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mp63-mm73-jhgm/GHSA-mp63-mm73-jhgm.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mp63-mm73-jhgm", + "modified": "2025-04-22T15:30:52Z", + "published": "2025-04-22T15:30:52Z", + "aliases": [ + "CVE-2025-28033" + ], + "details": "TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a pre-auth buffer overflow vulnerability in the setNoticeCfg function through the IpTo parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28033" + }, + { + "type": "WEB", + "url": "https://locrian-lightning-dc7.notion.site/BufferOverflow7-1a98e5e2b1a280708d6ec6155ce88d8c" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T14:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p2gm-m8q4-6r5q/GHSA-p2gm-m8q4-6r5q.json b/advisories/unreviewed/2025/04/GHSA-p2gm-m8q4-6r5q/GHSA-p2gm-m8q4-6r5q.json new file mode 100644 index 00000000000..4e0b7a5bc59 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p2gm-m8q4-6r5q/GHSA-p2gm-m8q4-6r5q.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p2gm-m8q4-6r5q", + "modified": "2025-04-22T15:30:52Z", + "published": "2025-04-22T15:30:52Z", + "aliases": [ + "CVE-2025-28034" + ], + "details": "TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a pre-auth remote command execution vulnerability in the NTPSyncWithHost function through the hostTime parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28034" + }, + { + "type": "WEB", + "url": "https://locrian-lightning-dc7.notion.site/RCE2-1a98e5e2b1a280bebf53d868f1b1a711?pvs=74" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T14:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p688-g48x-vg8h/GHSA-p688-g48x-vg8h.json b/advisories/unreviewed/2025/04/GHSA-p688-g48x-vg8h/GHSA-p688-g48x-vg8h.json index 24f242bbf8e..193626385f3 100644 --- a/advisories/unreviewed/2025/04/GHSA-p688-g48x-vg8h/GHSA-p688-g48x-vg8h.json +++ b/advisories/unreviewed/2025/04/GHSA-p688-g48x-vg8h/GHSA-p688-g48x-vg8h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p688-g48x-vg8h", - "modified": "2025-04-21T15:31:21Z", + "modified": "2025-04-22T15:30:51Z", "published": "2025-04-21T15:31:21Z", "aliases": [ "CVE-2025-29209" ], "details": "TOTOLINK X18 v9.1.0cu.2024_B20220329 has an unauthorized arbitrary command execution in the enable parameter' of the sub_41105C function of cstecgi .cgi.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-18T15:15:58Z" diff --git a/advisories/unreviewed/2025/04/GHSA-pfpp-vwh2-g27w/GHSA-pfpp-vwh2-g27w.json b/advisories/unreviewed/2025/04/GHSA-pfpp-vwh2-g27w/GHSA-pfpp-vwh2-g27w.json index 4fb258ddd94..079599f5837 100644 --- a/advisories/unreviewed/2025/04/GHSA-pfpp-vwh2-g27w/GHSA-pfpp-vwh2-g27w.json +++ b/advisories/unreviewed/2025/04/GHSA-pfpp-vwh2-g27w/GHSA-pfpp-vwh2-g27w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pfpp-vwh2-g27w", - "modified": "2025-04-16T18:31:53Z", + "modified": "2025-04-22T15:30:50Z", "published": "2025-04-16T18:31:53Z", "aliases": [ "CVE-2024-40073" ], "details": "Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the template parameter at id_generator/admin/?page=generate&template=4.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T17:15:49Z" diff --git a/advisories/unreviewed/2025/04/GHSA-pw67-xjhq-389w/GHSA-pw67-xjhq-389w.json b/advisories/unreviewed/2025/04/GHSA-pw67-xjhq-389w/GHSA-pw67-xjhq-389w.json index f9df0e93ceb..69ea5e0435d 100644 --- a/advisories/unreviewed/2025/04/GHSA-pw67-xjhq-389w/GHSA-pw67-xjhq-389w.json +++ b/advisories/unreviewed/2025/04/GHSA-pw67-xjhq-389w/GHSA-pw67-xjhq-389w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pw67-xjhq-389w", - "modified": "2025-04-17T18:31:23Z", + "modified": "2025-04-22T15:30:51Z", "published": "2025-04-17T18:31:23Z", "aliases": [ "CVE-2024-53924" ], "details": "Pycel through 1.0b30, when operating on an untrusted spreadsheet, allows code execution via a crafted formula in a cell, such as one beginning with the =IF(A1=200, eval(\"__import__('os').system( substring.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-17T18:15:47Z" diff --git a/advisories/unreviewed/2025/04/GHSA-q8pq-pv68-q9cm/GHSA-q8pq-pv68-q9cm.json b/advisories/unreviewed/2025/04/GHSA-q8pq-pv68-q9cm/GHSA-q8pq-pv68-q9cm.json new file mode 100644 index 00000000000..98963dd7287 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-q8pq-pv68-q9cm/GHSA-q8pq-pv68-q9cm.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q8pq-pv68-q9cm", + "modified": "2025-04-22T15:30:52Z", + "published": "2025-04-22T15:30:52Z", + "aliases": [ + "CVE-2025-28032" + ], + "details": "TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 contain a pre-auth buffer overflow vulnerability in the setNoticeCfg function through the IpForm parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28032" + }, + { + "type": "WEB", + "url": "https://locrian-lightning-dc7.notion.site/BufferOverflow6-19f8e5e2b1a28052bda1f6ede9db341d" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T14:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qcvj-mcp5-pjg8/GHSA-qcvj-mcp5-pjg8.json b/advisories/unreviewed/2025/04/GHSA-qcvj-mcp5-pjg8/GHSA-qcvj-mcp5-pjg8.json new file mode 100644 index 00000000000..a10ce92dfb5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qcvj-mcp5-pjg8/GHSA-qcvj-mcp5-pjg8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qcvj-mcp5-pjg8", + "modified": "2025-04-22T15:30:52Z", + "published": "2025-04-22T15:30:52Z", + "aliases": [ + "CVE-2025-1950" + ], + "details": "IBM Hardware Management Console - Power Systems V10.2.1030.0 and V10.3.1050.0 could allow a local user to execute commands locally due to improper validation of libraries of an untrusted source.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1950" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7231507" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-114" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T15:16:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rw43-mgp5-rf2m/GHSA-rw43-mgp5-rf2m.json b/advisories/unreviewed/2025/04/GHSA-rw43-mgp5-rf2m/GHSA-rw43-mgp5-rf2m.json new file mode 100644 index 00000000000..5a331e9caf4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rw43-mgp5-rf2m/GHSA-rw43-mgp5-rf2m.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rw43-mgp5-rf2m", + "modified": "2025-04-22T15:30:52Z", + "published": "2025-04-22T15:30:52Z", + "aliases": [ + "CVE-2024-40446" + ], + "details": "An issue in forkosh Mime Tex before v.1.77 allows an attacker to execute arbitrary code via a crafted script", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40446" + }, + { + "type": "WEB", + "url": "https://github.com/TaiYou-TW/CVE-2024-40445_CVE-2024-40446" + }, + { + "type": "WEB", + "url": "https://youtu.be/S3cmZkWIi6o" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T14:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rw8h-4h76-h2mx/GHSA-rw8h-4h76-h2mx.json b/advisories/unreviewed/2025/04/GHSA-rw8h-4h76-h2mx/GHSA-rw8h-4h76-h2mx.json index b3bc775cd42..67c9b698aa7 100644 --- a/advisories/unreviewed/2025/04/GHSA-rw8h-4h76-h2mx/GHSA-rw8h-4h76-h2mx.json +++ b/advisories/unreviewed/2025/04/GHSA-rw8h-4h76-h2mx/GHSA-rw8h-4h76-h2mx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rw8h-4h76-h2mx", - "modified": "2025-04-18T18:31:24Z", + "modified": "2025-04-22T15:30:51Z", "published": "2025-04-18T18:31:24Z", "aliases": [ "CVE-2025-28059" ], "details": "An access control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows deleted users to retain access to system resources due to improper session invalidation and stale token handling. When an administrator deletes a user account, the backend fails to terminate active sessions and revoke associated API tokens, enabling unauthorized access to restricted functions.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-613" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-18T17:15:34Z" diff --git a/advisories/unreviewed/2025/04/GHSA-v8vm-8h6v-g2gc/GHSA-v8vm-8h6v-g2gc.json b/advisories/unreviewed/2025/04/GHSA-v8vm-8h6v-g2gc/GHSA-v8vm-8h6v-g2gc.json index 2bee43c0b17..0e2d4415362 100644 --- a/advisories/unreviewed/2025/04/GHSA-v8vm-8h6v-g2gc/GHSA-v8vm-8h6v-g2gc.json +++ b/advisories/unreviewed/2025/04/GHSA-v8vm-8h6v-g2gc/GHSA-v8vm-8h6v-g2gc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v8vm-8h6v-g2gc", - "modified": "2025-04-17T18:31:12Z", + "modified": "2025-04-22T15:30:50Z", "published": "2025-04-17T18:31:12Z", "aliases": [ "CVE-2024-56518" ], "details": "Hazelcast Management Center through 6.0 allows remote code execution via a JndiLoginModule user.provider.url in a hazelcast-client XML document (aka a client configuration file), which can be uploaded at the /cluster-connections URI.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-17T16:15:27Z" diff --git a/advisories/unreviewed/2025/04/GHSA-wgwq-2crv-c4jj/GHSA-wgwq-2crv-c4jj.json b/advisories/unreviewed/2025/04/GHSA-wgwq-2crv-c4jj/GHSA-wgwq-2crv-c4jj.json index 7a4c05ed8e4..72249c03272 100644 --- a/advisories/unreviewed/2025/04/GHSA-wgwq-2crv-c4jj/GHSA-wgwq-2crv-c4jj.json +++ b/advisories/unreviewed/2025/04/GHSA-wgwq-2crv-c4jj/GHSA-wgwq-2crv-c4jj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wgwq-2crv-c4jj", - "modified": "2025-04-17T21:31:05Z", + "modified": "2025-04-22T15:30:51Z", "published": "2025-04-17T21:31:04Z", "aliases": [ "CVE-2025-29316" ], "details": "An issue in DataPatrol Screenshot watermark, printing watermark agent v.3.5.2.0 allows a physically proximate attacker to obtain sensitive information", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-17T19:16:08Z" diff --git a/advisories/unreviewed/2025/04/GHSA-wm23-hcgv-w4x3/GHSA-wm23-hcgv-w4x3.json b/advisories/unreviewed/2025/04/GHSA-wm23-hcgv-w4x3/GHSA-wm23-hcgv-w4x3.json index f99f93767b6..e8dc06938c9 100644 --- a/advisories/unreviewed/2025/04/GHSA-wm23-hcgv-w4x3/GHSA-wm23-hcgv-w4x3.json +++ b/advisories/unreviewed/2025/04/GHSA-wm23-hcgv-w4x3/GHSA-wm23-hcgv-w4x3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wm23-hcgv-w4x3", - "modified": "2025-04-21T15:31:19Z", + "modified": "2025-04-22T15:30:51Z", "published": "2025-04-21T15:31:19Z", "aliases": [ "CVE-2025-28228" ], "details": "A credential exposure vulnerability in Electrolink 500W, 1kW, 2kW Medium DAB Transmitter Web v01.09, v01.08, v01.07, and Display v1.4, v1.2 allows unauthorized attackers to access credentials in plaintext.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-522" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-18T15:15:58Z"