From b1fd56beb69aabc00493709ec13b19e82ae0b203 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 30 Apr 2025 18:33:14 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-4qcm-h32c-8xq3.json | 1 + .../GHSA-vgg5-g88f-mq8p.json | 9 ++- .../GHSA-7jfg-qpxp-6grc.json | 2 +- .../GHSA-7jhg-5532-mghv.json | 6 +- .../GHSA-f6j2-5hv7-j68q.json | 2 +- .../GHSA-fw87-542j-77hx.json | 2 +- .../GHSA-gx89-fjwq-4vh9.json | 2 +- .../GHSA-mjxc-g8h2-2g9g.json | 6 +- .../GHSA-wr5x-h3hw-v3xg.json | 4 +- .../GHSA-7p9m-p78c-278w.json | 4 +- .../GHSA-hp23-vcj5-cjvv.json | 4 +- .../GHSA-r84c-86vg-4c66.json | 3 +- .../GHSA-f834-hvgh-g5v9.json | 4 +- .../GHSA-xpv6-mc85-j28m.json | 4 +- .../GHSA-2ffg-57j4-xqr7.json | 15 +++-- .../GHSA-2qvw-44pq-38xj.json | 4 +- .../GHSA-2wq7-hx2p-5748.json | 36 ++++++++++++ .../GHSA-37cp-q8j3-ccqw.json | 36 ++++++++++++ .../GHSA-3h8x-jv2f-mmvp.json | 3 +- .../GHSA-3hgc-5x5v-4fp3.json | 2 +- .../GHSA-3wvv-8p7v-4mj2.json | 25 +++++++++ .../GHSA-4jh7-c2vv-7qf2.json | 33 +++++++++++ .../GHSA-4p64-hxgr-8p2m.json | 4 +- .../GHSA-59pp-9hh9-qj7w.json | 29 ++++++++++ .../GHSA-72pc-mw67-6f3f.json | 1 + .../GHSA-86pf-577r-267c.json | 3 +- .../GHSA-8rhw-vhcc-f87c.json | 25 +++++++++ .../GHSA-9fw4-p66g-p3hh.json | 4 +- .../GHSA-c257-vc93-2rj8.json | 56 +++++++++++++++++++ .../GHSA-cv46-v88f-9qx8.json | 15 +++-- .../GHSA-f27c-q8cq-2ffp.json | 15 +++-- .../GHSA-f8rv-5fvx-grrj.json | 3 +- .../GHSA-fqm9-qqwf-gq9r.json | 2 +- .../GHSA-fv83-m6v9-qw8v.json | 37 ++++++++++++ .../GHSA-h35h-mv3v-626v.json | 36 ++++++++++++ .../GHSA-h5h2-cvc7-hm6x.json | 2 +- .../GHSA-hf49-wfhj-98g5.json | 29 ++++++++++ .../GHSA-hq76-qh6p-g7m6.json | 3 +- .../GHSA-j8hf-p5v4-xpj9.json | 3 +- .../GHSA-m48h-73h7-3chf.json | 36 ++++++++++++ .../GHSA-m76m-45c7-gvr3.json | 36 ++++++++++++ .../GHSA-mpc5-8rvq-8qfx.json | 36 ++++++++++++ .../GHSA-ppf8-hgp4-7rvj.json | 11 +++- .../GHSA-pwgp-427f-j92g.json | 36 ++++++++++++ .../GHSA-px62-fqwr-9g32.json | 29 ++++++++++ .../GHSA-qh62-99w2-xfq5.json | 15 +++-- .../GHSA-qmf3-4g6f-3fjv.json | 33 +++++++++++ .../GHSA-rm5g-c65x-vjvv.json | 36 ++++++++++++ .../GHSA-vhj2-4h8c-jc8m.json | 3 +- .../GHSA-vv86-jpff-556f.json | 2 +- .../GHSA-w583-vcj4-hhr9.json | 3 +- 51 files changed, 703 insertions(+), 47 deletions(-) create mode 100644 advisories/unreviewed/2025/04/GHSA-2wq7-hx2p-5748/GHSA-2wq7-hx2p-5748.json create mode 100644 advisories/unreviewed/2025/04/GHSA-37cp-q8j3-ccqw/GHSA-37cp-q8j3-ccqw.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3wvv-8p7v-4mj2/GHSA-3wvv-8p7v-4mj2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-4jh7-c2vv-7qf2/GHSA-4jh7-c2vv-7qf2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-59pp-9hh9-qj7w/GHSA-59pp-9hh9-qj7w.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8rhw-vhcc-f87c/GHSA-8rhw-vhcc-f87c.json create mode 100644 advisories/unreviewed/2025/04/GHSA-c257-vc93-2rj8/GHSA-c257-vc93-2rj8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-fv83-m6v9-qw8v/GHSA-fv83-m6v9-qw8v.json create mode 100644 advisories/unreviewed/2025/04/GHSA-h35h-mv3v-626v/GHSA-h35h-mv3v-626v.json create mode 100644 advisories/unreviewed/2025/04/GHSA-hf49-wfhj-98g5/GHSA-hf49-wfhj-98g5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-m48h-73h7-3chf/GHSA-m48h-73h7-3chf.json create mode 100644 advisories/unreviewed/2025/04/GHSA-m76m-45c7-gvr3/GHSA-m76m-45c7-gvr3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-mpc5-8rvq-8qfx/GHSA-mpc5-8rvq-8qfx.json create mode 100644 advisories/unreviewed/2025/04/GHSA-pwgp-427f-j92g/GHSA-pwgp-427f-j92g.json create mode 100644 advisories/unreviewed/2025/04/GHSA-px62-fqwr-9g32/GHSA-px62-fqwr-9g32.json create mode 100644 advisories/unreviewed/2025/04/GHSA-qmf3-4g6f-3fjv/GHSA-qmf3-4g6f-3fjv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-rm5g-c65x-vjvv/GHSA-rm5g-c65x-vjvv.json diff --git a/advisories/unreviewed/2022/05/GHSA-4qcm-h32c-8xq3/GHSA-4qcm-h32c-8xq3.json b/advisories/unreviewed/2022/05/GHSA-4qcm-h32c-8xq3/GHSA-4qcm-h32c-8xq3.json index 06833afe26b..0bca9d41407 100644 --- a/advisories/unreviewed/2022/05/GHSA-4qcm-h32c-8xq3/GHSA-4qcm-h32c-8xq3.json +++ b/advisories/unreviewed/2022/05/GHSA-4qcm-h32c-8xq3/GHSA-4qcm-h32c-8xq3.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-178", "CWE-863" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/05/GHSA-vgg5-g88f-mq8p/GHSA-vgg5-g88f-mq8p.json b/advisories/unreviewed/2022/05/GHSA-vgg5-g88f-mq8p/GHSA-vgg5-g88f-mq8p.json index 0e7c8055c09..66e70f22fcc 100644 --- a/advisories/unreviewed/2022/05/GHSA-vgg5-g88f-mq8p/GHSA-vgg5-g88f-mq8p.json +++ b/advisories/unreviewed/2022/05/GHSA-vgg5-g88f-mq8p/GHSA-vgg5-g88f-mq8p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vgg5-g88f-mq8p", - "modified": "2022-05-24T17:45:01Z", + "modified": "2025-04-30T18:31:37Z", "published": "2022-05-24T17:45:01Z", "aliases": [ "CVE-2021-25921" ], "details": "In OpenEMR, versions 2.7.3-rc1 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly in the `Allergies` section. An attacker could lure an admin to enter a malicious payload and by that initiate the exploit.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/11/GHSA-7jfg-qpxp-6grc/GHSA-7jfg-qpxp-6grc.json b/advisories/unreviewed/2022/11/GHSA-7jfg-qpxp-6grc/GHSA-7jfg-qpxp-6grc.json index 8e99787011a..9780dac7621 100644 --- a/advisories/unreviewed/2022/11/GHSA-7jfg-qpxp-6grc/GHSA-7jfg-qpxp-6grc.json +++ b/advisories/unreviewed/2022/11/GHSA-7jfg-qpxp-6grc/GHSA-7jfg-qpxp-6grc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7jfg-qpxp-6grc", - "modified": "2022-11-18T06:30:35Z", + "modified": "2025-04-30T18:31:40Z", "published": "2022-11-16T19:00:31Z", "aliases": [ "CVE-2022-43264" diff --git a/advisories/unreviewed/2022/11/GHSA-7jhg-5532-mghv/GHSA-7jhg-5532-mghv.json b/advisories/unreviewed/2022/11/GHSA-7jhg-5532-mghv/GHSA-7jhg-5532-mghv.json index 2d8f350a4c2..f052c09028e 100644 --- a/advisories/unreviewed/2022/11/GHSA-7jhg-5532-mghv/GHSA-7jhg-5532-mghv.json +++ b/advisories/unreviewed/2022/11/GHSA-7jhg-5532-mghv/GHSA-7jhg-5532-mghv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7jhg-5532-mghv", - "modified": "2022-11-17T06:30:19Z", + "modified": "2025-04-30T18:31:40Z", "published": "2022-11-16T12:00:20Z", "aliases": [ "CVE-2022-30769" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://github.com/ZoneMinder/zoneminder/releases" }, + { + "type": "WEB", + "url": "https://medium.com/%40dk50u1/session-fixation-in-zoneminder-up-to-v1-36-12-3c850b1fbbf3" + }, { "type": "WEB", "url": "https://medium.com/@dk50u1/session-fixation-in-zoneminder-up-to-v1-36-12-3c850b1fbbf3" diff --git a/advisories/unreviewed/2022/11/GHSA-f6j2-5hv7-j68q/GHSA-f6j2-5hv7-j68q.json b/advisories/unreviewed/2022/11/GHSA-f6j2-5hv7-j68q/GHSA-f6j2-5hv7-j68q.json index 95a795685c4..9878e75d20a 100644 --- a/advisories/unreviewed/2022/11/GHSA-f6j2-5hv7-j68q/GHSA-f6j2-5hv7-j68q.json +++ b/advisories/unreviewed/2022/11/GHSA-f6j2-5hv7-j68q/GHSA-f6j2-5hv7-j68q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f6j2-5hv7-j68q", - "modified": "2022-11-21T18:30:36Z", + "modified": "2025-04-30T18:31:42Z", "published": "2022-11-17T03:30:49Z", "aliases": [ "CVE-2022-42960" diff --git a/advisories/unreviewed/2022/11/GHSA-fw87-542j-77hx/GHSA-fw87-542j-77hx.json b/advisories/unreviewed/2022/11/GHSA-fw87-542j-77hx/GHSA-fw87-542j-77hx.json index e07566bc5c2..7bfcd2807ad 100644 --- a/advisories/unreviewed/2022/11/GHSA-fw87-542j-77hx/GHSA-fw87-542j-77hx.json +++ b/advisories/unreviewed/2022/11/GHSA-fw87-542j-77hx/GHSA-fw87-542j-77hx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fw87-542j-77hx", - "modified": "2022-11-17T03:30:52Z", + "modified": "2025-04-30T18:31:40Z", "published": "2022-11-16T19:00:31Z", "aliases": [ "CVE-2022-43263" diff --git a/advisories/unreviewed/2022/11/GHSA-gx89-fjwq-4vh9/GHSA-gx89-fjwq-4vh9.json b/advisories/unreviewed/2022/11/GHSA-gx89-fjwq-4vh9/GHSA-gx89-fjwq-4vh9.json index d4ce82e45ce..48b18ece44e 100644 --- a/advisories/unreviewed/2022/11/GHSA-gx89-fjwq-4vh9/GHSA-gx89-fjwq-4vh9.json +++ b/advisories/unreviewed/2022/11/GHSA-gx89-fjwq-4vh9/GHSA-gx89-fjwq-4vh9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gx89-fjwq-4vh9", - "modified": "2022-11-17T03:30:51Z", + "modified": "2025-04-30T18:31:38Z", "published": "2022-11-14T19:00:19Z", "aliases": [ "CVE-2022-43342" diff --git a/advisories/unreviewed/2022/11/GHSA-mjxc-g8h2-2g9g/GHSA-mjxc-g8h2-2g9g.json b/advisories/unreviewed/2022/11/GHSA-mjxc-g8h2-2g9g/GHSA-mjxc-g8h2-2g9g.json index f35decf959c..1101429e25d 100644 --- a/advisories/unreviewed/2022/11/GHSA-mjxc-g8h2-2g9g/GHSA-mjxc-g8h2-2g9g.json +++ b/advisories/unreviewed/2022/11/GHSA-mjxc-g8h2-2g9g/GHSA-mjxc-g8h2-2g9g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mjxc-g8h2-2g9g", - "modified": "2022-11-18T06:30:35Z", + "modified": "2025-04-30T18:31:40Z", "published": "2022-11-16T12:00:20Z", "aliases": [ "CVE-2022-30768" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://github.com/ZoneMinder/zoneminder/releases" }, + { + "type": "WEB", + "url": "https://medium.com/%40dk50u1/stored-xss-in-zoneminder-up-to-v1-36-12-f26b4bb68c31" + }, { "type": "WEB", "url": "https://medium.com/@dk50u1/stored-xss-in-zoneminder-up-to-v1-36-12-f26b4bb68c31" diff --git a/advisories/unreviewed/2022/11/GHSA-wr5x-h3hw-v3xg/GHSA-wr5x-h3hw-v3xg.json b/advisories/unreviewed/2022/11/GHSA-wr5x-h3hw-v3xg/GHSA-wr5x-h3hw-v3xg.json index ea5f6a7b8df..18356224355 100644 --- a/advisories/unreviewed/2022/11/GHSA-wr5x-h3hw-v3xg/GHSA-wr5x-h3hw-v3xg.json +++ b/advisories/unreviewed/2022/11/GHSA-wr5x-h3hw-v3xg/GHSA-wr5x-h3hw-v3xg.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-693" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-7p9m-p78c-278w/GHSA-7p9m-p78c-278w.json b/advisories/unreviewed/2022/12/GHSA-7p9m-p78c-278w/GHSA-7p9m-p78c-278w.json index dce25018dcb..dbb4ae7cdb5 100644 --- a/advisories/unreviewed/2022/12/GHSA-7p9m-p78c-278w/GHSA-7p9m-p78c-278w.json +++ b/advisories/unreviewed/2022/12/GHSA-7p9m-p78c-278w/GHSA-7p9m-p78c-278w.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/10/GHSA-hp23-vcj5-cjvv/GHSA-hp23-vcj5-cjvv.json b/advisories/unreviewed/2023/10/GHSA-hp23-vcj5-cjvv/GHSA-hp23-vcj5-cjvv.json index d4fa6560b9b..e8498b1554f 100644 --- a/advisories/unreviewed/2023/10/GHSA-hp23-vcj5-cjvv/GHSA-hp23-vcj5-cjvv.json +++ b/advisories/unreviewed/2023/10/GHSA-hp23-vcj5-cjvv/GHSA-hp23-vcj5-cjvv.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-295" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-r84c-86vg-4c66/GHSA-r84c-86vg-4c66.json b/advisories/unreviewed/2024/03/GHSA-r84c-86vg-4c66/GHSA-r84c-86vg-4c66.json index 73cb3eab114..0014fd196d5 100644 --- a/advisories/unreviewed/2024/03/GHSA-r84c-86vg-4c66/GHSA-r84c-86vg-4c66.json +++ b/advisories/unreviewed/2024/03/GHSA-r84c-86vg-4c66/GHSA-r84c-86vg-4c66.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-312" + "CWE-312", + "CWE-89" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-f834-hvgh-g5v9/GHSA-f834-hvgh-g5v9.json b/advisories/unreviewed/2024/04/GHSA-f834-hvgh-g5v9/GHSA-f834-hvgh-g5v9.json index 638370e69fe..7eb613876e3 100644 --- a/advisories/unreviewed/2024/04/GHSA-f834-hvgh-g5v9/GHSA-f834-hvgh-g5v9.json +++ b/advisories/unreviewed/2024/04/GHSA-f834-hvgh-g5v9/GHSA-f834-hvgh-g5v9.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-667" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-xpv6-mc85-j28m/GHSA-xpv6-mc85-j28m.json b/advisories/unreviewed/2025/03/GHSA-xpv6-mc85-j28m/GHSA-xpv6-mc85-j28m.json index 58857a02f2f..ac2cd3fc410 100644 --- a/advisories/unreviewed/2025/03/GHSA-xpv6-mc85-j28m/GHSA-xpv6-mc85-j28m.json +++ b/advisories/unreviewed/2025/03/GHSA-xpv6-mc85-j28m/GHSA-xpv6-mc85-j28m.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-2ffg-57j4-xqr7/GHSA-2ffg-57j4-xqr7.json b/advisories/unreviewed/2025/04/GHSA-2ffg-57j4-xqr7/GHSA-2ffg-57j4-xqr7.json index 94449923de3..a813f9eae5f 100644 --- a/advisories/unreviewed/2025/04/GHSA-2ffg-57j4-xqr7/GHSA-2ffg-57j4-xqr7.json +++ b/advisories/unreviewed/2025/04/GHSA-2ffg-57j4-xqr7/GHSA-2ffg-57j4-xqr7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2ffg-57j4-xqr7", - "modified": "2025-04-30T15:30:49Z", + "modified": "2025-04-30T18:31:54Z", "published": "2025-04-30T15:30:49Z", "aliases": [ "CVE-2025-45009" ], "details": "A HTML Injection vulnerability was discovered in the normal-search.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary code via the searchdata parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-30T14:15:28Z" diff --git a/advisories/unreviewed/2025/04/GHSA-2qvw-44pq-38xj/GHSA-2qvw-44pq-38xj.json b/advisories/unreviewed/2025/04/GHSA-2qvw-44pq-38xj/GHSA-2qvw-44pq-38xj.json index 45501e4621e..a69964c5da4 100644 --- a/advisories/unreviewed/2025/04/GHSA-2qvw-44pq-38xj/GHSA-2qvw-44pq-38xj.json +++ b/advisories/unreviewed/2025/04/GHSA-2qvw-44pq-38xj/GHSA-2qvw-44pq-38xj.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-2wq7-hx2p-5748/GHSA-2wq7-hx2p-5748.json b/advisories/unreviewed/2025/04/GHSA-2wq7-hx2p-5748/GHSA-2wq7-hx2p-5748.json new file mode 100644 index 00000000000..98715fd30f8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2wq7-hx2p-5748/GHSA-2wq7-hx2p-5748.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2wq7-hx2p-5748", + "modified": "2025-04-30T18:31:55Z", + "published": "2025-04-30T18:31:55Z", + "aliases": [ + "CVE-2025-30389" + ], + "details": "Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30389" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-30389" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-30T18:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-37cp-q8j3-ccqw/GHSA-37cp-q8j3-ccqw.json b/advisories/unreviewed/2025/04/GHSA-37cp-q8j3-ccqw/GHSA-37cp-q8j3-ccqw.json new file mode 100644 index 00000000000..eefa32dd9a1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-37cp-q8j3-ccqw/GHSA-37cp-q8j3-ccqw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-37cp-q8j3-ccqw", + "modified": "2025-04-30T18:31:55Z", + "published": "2025-04-30T18:31:55Z", + "aliases": [ + "CVE-2025-30391" + ], + "details": "Improper input validation in Microsoft Dynamics allows an unauthorized attacker to disclose information over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30391" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-30391" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-30T18:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3h8x-jv2f-mmvp/GHSA-3h8x-jv2f-mmvp.json b/advisories/unreviewed/2025/04/GHSA-3h8x-jv2f-mmvp/GHSA-3h8x-jv2f-mmvp.json index 6a295cf8f6b..1b5ff87c6cf 100644 --- a/advisories/unreviewed/2025/04/GHSA-3h8x-jv2f-mmvp/GHSA-3h8x-jv2f-mmvp.json +++ b/advisories/unreviewed/2025/04/GHSA-3h8x-jv2f-mmvp/GHSA-3h8x-jv2f-mmvp.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-3hgc-5x5v-4fp3/GHSA-3hgc-5x5v-4fp3.json b/advisories/unreviewed/2025/04/GHSA-3hgc-5x5v-4fp3/GHSA-3hgc-5x5v-4fp3.json index 1a325c6e266..f0cc8c345af 100644 --- a/advisories/unreviewed/2025/04/GHSA-3hgc-5x5v-4fp3/GHSA-3hgc-5x5v-4fp3.json +++ b/advisories/unreviewed/2025/04/GHSA-3hgc-5x5v-4fp3/GHSA-3hgc-5x5v-4fp3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3hgc-5x5v-4fp3", - "modified": "2025-04-22T12:31:23Z", + "modified": "2025-04-30T18:31:54Z", "published": "2025-04-22T12:31:23Z", "aliases": [ "CVE-2025-46235" diff --git a/advisories/unreviewed/2025/04/GHSA-3wvv-8p7v-4mj2/GHSA-3wvv-8p7v-4mj2.json b/advisories/unreviewed/2025/04/GHSA-3wvv-8p7v-4mj2/GHSA-3wvv-8p7v-4mj2.json new file mode 100644 index 00000000000..6d9fdbe84af --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3wvv-8p7v-4mj2/GHSA-3wvv-8p7v-4mj2.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3wvv-8p7v-4mj2", + "modified": "2025-04-30T18:31:55Z", + "published": "2025-04-30T18:31:55Z", + "aliases": [ + "CVE-2025-3269" + ], + "details": "Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3269" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-30T18:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4jh7-c2vv-7qf2/GHSA-4jh7-c2vv-7qf2.json b/advisories/unreviewed/2025/04/GHSA-4jh7-c2vv-7qf2/GHSA-4jh7-c2vv-7qf2.json new file mode 100644 index 00000000000..7384bdaa791 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4jh7-c2vv-7qf2/GHSA-4jh7-c2vv-7qf2.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4jh7-c2vv-7qf2", + "modified": "2025-04-30T18:31:55Z", + "published": "2025-04-30T18:31:55Z", + "aliases": [ + "CVE-2025-3859" + ], + "details": "Websites directing users to long URLs that caused eliding to occur in the location view could leverage the truncating behavior to potentially trick users into thinking they were on a different webpage This vulnerability affects Focus < 138.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3859" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1951533" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-33" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-30T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4p64-hxgr-8p2m/GHSA-4p64-hxgr-8p2m.json b/advisories/unreviewed/2025/04/GHSA-4p64-hxgr-8p2m/GHSA-4p64-hxgr-8p2m.json index e7f6284ce47..2350de24379 100644 --- a/advisories/unreviewed/2025/04/GHSA-4p64-hxgr-8p2m/GHSA-4p64-hxgr-8p2m.json +++ b/advisories/unreviewed/2025/04/GHSA-4p64-hxgr-8p2m/GHSA-4p64-hxgr-8p2m.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-59pp-9hh9-qj7w/GHSA-59pp-9hh9-qj7w.json b/advisories/unreviewed/2025/04/GHSA-59pp-9hh9-qj7w/GHSA-59pp-9hh9-qj7w.json new file mode 100644 index 00000000000..3a18ea5ad35 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-59pp-9hh9-qj7w/GHSA-59pp-9hh9-qj7w.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-59pp-9hh9-qj7w", + "modified": "2025-04-30T18:31:55Z", + "published": "2025-04-30T18:31:55Z", + "aliases": [ + "CVE-2025-44192" + ], + "details": "SourceCodester Simple Barangay Management System v1.0 has a SQL injection vulnerability in /barangay_management/admin/?page=view_clearance.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44192" + }, + { + "type": "WEB", + "url": "https://github.com/red-team00/bug_report/blob/main/simple-barangay-management-system/SQLi-1.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-30T18:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-72pc-mw67-6f3f/GHSA-72pc-mw67-6f3f.json b/advisories/unreviewed/2025/04/GHSA-72pc-mw67-6f3f/GHSA-72pc-mw67-6f3f.json index 495f7604aea..aeb0fca066c 100644 --- a/advisories/unreviewed/2025/04/GHSA-72pc-mw67-6f3f/GHSA-72pc-mw67-6f3f.json +++ b/advisories/unreviewed/2025/04/GHSA-72pc-mw67-6f3f/GHSA-72pc-mw67-6f3f.json @@ -50,6 +50,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-306", "CWE-862" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/04/GHSA-86pf-577r-267c/GHSA-86pf-577r-267c.json b/advisories/unreviewed/2025/04/GHSA-86pf-577r-267c/GHSA-86pf-577r-267c.json index c6dc6623240..37ca0a7f5b4 100644 --- a/advisories/unreviewed/2025/04/GHSA-86pf-577r-267c/GHSA-86pf-577r-267c.json +++ b/advisories/unreviewed/2025/04/GHSA-86pf-577r-267c/GHSA-86pf-577r-267c.json @@ -50,7 +50,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-416" + "CWE-416", + "CWE-476" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-8rhw-vhcc-f87c/GHSA-8rhw-vhcc-f87c.json b/advisories/unreviewed/2025/04/GHSA-8rhw-vhcc-f87c/GHSA-8rhw-vhcc-f87c.json new file mode 100644 index 00000000000..11ad1151121 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8rhw-vhcc-f87c/GHSA-8rhw-vhcc-f87c.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8rhw-vhcc-f87c", + "modified": "2025-04-30T18:31:55Z", + "published": "2025-04-30T18:31:55Z", + "aliases": [ + "CVE-2025-2156" + ], + "details": "Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2156" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-30T18:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9fw4-p66g-p3hh/GHSA-9fw4-p66g-p3hh.json b/advisories/unreviewed/2025/04/GHSA-9fw4-p66g-p3hh/GHSA-9fw4-p66g-p3hh.json index c61751bf35c..d53c3ef21ec 100644 --- a/advisories/unreviewed/2025/04/GHSA-9fw4-p66g-p3hh/GHSA-9fw4-p66g-p3hh.json +++ b/advisories/unreviewed/2025/04/GHSA-9fw4-p66g-p3hh/GHSA-9fw4-p66g-p3hh.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-c257-vc93-2rj8/GHSA-c257-vc93-2rj8.json b/advisories/unreviewed/2025/04/GHSA-c257-vc93-2rj8/GHSA-c257-vc93-2rj8.json new file mode 100644 index 00000000000..b6638fc02d9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c257-vc93-2rj8/GHSA-c257-vc93-2rj8.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c257-vc93-2rj8", + "modified": "2025-04-30T18:31:56Z", + "published": "2025-04-30T18:31:56Z", + "aliases": [ + "CVE-2025-4135" + ], + "details": "A vulnerability was found in Netgear WG302v2 up to 5.2.9 and classified as critical. Affected by this issue is the function ui_get_input_value. The manipulation of the argument host leads to command injection. The attack may be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4135" + }, + { + "type": "WEB", + "url": "https://github.com/jylsec/vuldb/blob/main/Netgear/netgear_WG302v2/Command_injection-basic_settings_handler-static-ip-update/README.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.306626" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.306626" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.560779" + }, + { + "type": "WEB", + "url": "https://www.netgear.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-30T18:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cv46-v88f-9qx8/GHSA-cv46-v88f-9qx8.json b/advisories/unreviewed/2025/04/GHSA-cv46-v88f-9qx8/GHSA-cv46-v88f-9qx8.json index 6227123cbde..b4d20121fd6 100644 --- a/advisories/unreviewed/2025/04/GHSA-cv46-v88f-9qx8/GHSA-cv46-v88f-9qx8.json +++ b/advisories/unreviewed/2025/04/GHSA-cv46-v88f-9qx8/GHSA-cv46-v88f-9qx8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cv46-v88f-9qx8", - "modified": "2025-04-30T15:30:49Z", + "modified": "2025-04-30T18:31:54Z", "published": "2025-04-30T15:30:49Z", "aliases": [ "CVE-2025-45011" ], "details": "A HTML Injection vulnerability was discovered in the foreigner-search.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary code via the searchdata POST request parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-30T14:15:29Z" diff --git a/advisories/unreviewed/2025/04/GHSA-f27c-q8cq-2ffp/GHSA-f27c-q8cq-2ffp.json b/advisories/unreviewed/2025/04/GHSA-f27c-q8cq-2ffp/GHSA-f27c-q8cq-2ffp.json index 405af36a706..3108a33f9e1 100644 --- a/advisories/unreviewed/2025/04/GHSA-f27c-q8cq-2ffp/GHSA-f27c-q8cq-2ffp.json +++ b/advisories/unreviewed/2025/04/GHSA-f27c-q8cq-2ffp/GHSA-f27c-q8cq-2ffp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f27c-q8cq-2ffp", - "modified": "2025-04-30T15:30:49Z", + "modified": "2025-04-30T18:31:54Z", "published": "2025-04-30T15:30:49Z", "aliases": [ "CVE-2025-45010" ], "details": "A HTML Injection vulnerability was discovered in the normal-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary code via the fromdate and todate POST request parameters.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-30T14:15:29Z" diff --git a/advisories/unreviewed/2025/04/GHSA-f8rv-5fvx-grrj/GHSA-f8rv-5fvx-grrj.json b/advisories/unreviewed/2025/04/GHSA-f8rv-5fvx-grrj/GHSA-f8rv-5fvx-grrj.json index 190ae88eb7f..8f6631313a6 100644 --- a/advisories/unreviewed/2025/04/GHSA-f8rv-5fvx-grrj/GHSA-f8rv-5fvx-grrj.json +++ b/advisories/unreviewed/2025/04/GHSA-f8rv-5fvx-grrj/GHSA-f8rv-5fvx-grrj.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-434" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-fqm9-qqwf-gq9r/GHSA-fqm9-qqwf-gq9r.json b/advisories/unreviewed/2025/04/GHSA-fqm9-qqwf-gq9r/GHSA-fqm9-qqwf-gq9r.json index dc399c5265f..ab89c00f3ed 100644 --- a/advisories/unreviewed/2025/04/GHSA-fqm9-qqwf-gq9r/GHSA-fqm9-qqwf-gq9r.json +++ b/advisories/unreviewed/2025/04/GHSA-fqm9-qqwf-gq9r/GHSA-fqm9-qqwf-gq9r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fqm9-qqwf-gq9r", - "modified": "2025-04-23T21:30:36Z", + "modified": "2025-04-30T18:31:54Z", "published": "2025-04-23T21:30:36Z", "aliases": [ "CVE-2025-46397" diff --git a/advisories/unreviewed/2025/04/GHSA-fv83-m6v9-qw8v/GHSA-fv83-m6v9-qw8v.json b/advisories/unreviewed/2025/04/GHSA-fv83-m6v9-qw8v/GHSA-fv83-m6v9-qw8v.json new file mode 100644 index 00000000000..40cd26e44ee --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fv83-m6v9-qw8v/GHSA-fv83-m6v9-qw8v.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fv83-m6v9-qw8v", + "modified": "2025-04-30T18:31:56Z", + "published": "2025-04-30T18:31:56Z", + "aliases": [ + "CVE-2025-46619" + ], + "details": "A security issue has been discovered in Couchbase Server before 7.6.4 and fixed in v.7.6.4 and v.7.2.7 for Windows that could allow unauthorized access to sensitive files. Depending on the level of privileges, this vulnerability may grant access to files such as /etc/passwd or /etc/shadow.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46619" + }, + { + "type": "WEB", + "url": "https://docs.couchbase.com/server/current/release-notes/relnotes.html" + }, + { + "type": "WEB", + "url": "https://forums.couchbase.com/tags/security" + }, + { + "type": "WEB", + "url": "https://www.couchbase.com/alerts" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-30T18:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h35h-mv3v-626v/GHSA-h35h-mv3v-626v.json b/advisories/unreviewed/2025/04/GHSA-h35h-mv3v-626v/GHSA-h35h-mv3v-626v.json new file mode 100644 index 00000000000..932661dad0f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-h35h-mv3v-626v/GHSA-h35h-mv3v-626v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h35h-mv3v-626v", + "modified": "2025-04-30T18:31:55Z", + "published": "2025-04-30T18:31:55Z", + "aliases": [ + "CVE-2025-21416" + ], + "details": "Missing authorization in Azure Virtual Desktop allows an authorized attacker to elevate privileges over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21416" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21416" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-30T18:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h5h2-cvc7-hm6x/GHSA-h5h2-cvc7-hm6x.json b/advisories/unreviewed/2025/04/GHSA-h5h2-cvc7-hm6x/GHSA-h5h2-cvc7-hm6x.json index e32a35a44cb..254ee64836d 100644 --- a/advisories/unreviewed/2025/04/GHSA-h5h2-cvc7-hm6x/GHSA-h5h2-cvc7-hm6x.json +++ b/advisories/unreviewed/2025/04/GHSA-h5h2-cvc7-hm6x/GHSA-h5h2-cvc7-hm6x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h5h2-cvc7-hm6x", - "modified": "2025-04-23T21:30:36Z", + "modified": "2025-04-30T18:31:54Z", "published": "2025-04-23T21:30:36Z", "aliases": [ "CVE-2025-46399" diff --git a/advisories/unreviewed/2025/04/GHSA-hf49-wfhj-98g5/GHSA-hf49-wfhj-98g5.json b/advisories/unreviewed/2025/04/GHSA-hf49-wfhj-98g5/GHSA-hf49-wfhj-98g5.json new file mode 100644 index 00000000000..309bcaa3c4e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hf49-wfhj-98g5/GHSA-hf49-wfhj-98g5.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hf49-wfhj-98g5", + "modified": "2025-04-30T18:31:56Z", + "published": "2025-04-30T18:31:55Z", + "aliases": [ + "CVE-2025-44194" + ], + "details": "SourceCodester Simple Barangay Management System v1.0 has a SQL injection vulnerability in /barangay_management/admin/?page=view_household.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44194" + }, + { + "type": "WEB", + "url": "https://github.com/red-team00/bug_report/blob/main/simple-barangay-management-system/SQLi-3.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-30T18:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hq76-qh6p-g7m6/GHSA-hq76-qh6p-g7m6.json b/advisories/unreviewed/2025/04/GHSA-hq76-qh6p-g7m6/GHSA-hq76-qh6p-g7m6.json index 3dbb09c33c5..8a481ea6c41 100644 --- a/advisories/unreviewed/2025/04/GHSA-hq76-qh6p-g7m6/GHSA-hq76-qh6p-g7m6.json +++ b/advisories/unreviewed/2025/04/GHSA-hq76-qh6p-g7m6/GHSA-hq76-qh6p-g7m6.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-j8hf-p5v4-xpj9/GHSA-j8hf-p5v4-xpj9.json b/advisories/unreviewed/2025/04/GHSA-j8hf-p5v4-xpj9/GHSA-j8hf-p5v4-xpj9.json index 704d7b5a5e5..c4665cb0643 100644 --- a/advisories/unreviewed/2025/04/GHSA-j8hf-p5v4-xpj9/GHSA-j8hf-p5v4-xpj9.json +++ b/advisories/unreviewed/2025/04/GHSA-j8hf-p5v4-xpj9/GHSA-j8hf-p5v4-xpj9.json @@ -50,7 +50,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-416" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-m48h-73h7-3chf/GHSA-m48h-73h7-3chf.json b/advisories/unreviewed/2025/04/GHSA-m48h-73h7-3chf/GHSA-m48h-73h7-3chf.json new file mode 100644 index 00000000000..1384462019f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m48h-73h7-3chf/GHSA-m48h-73h7-3chf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m48h-73h7-3chf", + "modified": "2025-04-30T18:31:55Z", + "published": "2025-04-30T18:31:55Z", + "aliases": [ + "CVE-2025-33074" + ], + "details": "Improper verification of cryptographic signature in Microsoft Azure Functions allows an authorized attacker to execute code over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33074" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-33074" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-347" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-30T18:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m76m-45c7-gvr3/GHSA-m76m-45c7-gvr3.json b/advisories/unreviewed/2025/04/GHSA-m76m-45c7-gvr3/GHSA-m76m-45c7-gvr3.json new file mode 100644 index 00000000000..edc32cceede --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m76m-45c7-gvr3/GHSA-m76m-45c7-gvr3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m76m-45c7-gvr3", + "modified": "2025-04-30T18:31:55Z", + "published": "2025-04-30T18:31:55Z", + "aliases": [ + "CVE-2025-3599" + ], + "details": "Symantec Endpoint Protection Windows Agent, running an ERASER Engine prior to 119.1.7.8, may be susceptible to an Elevation of Privilege vulnerability, which may allow an attacker to delete resources that are normally protected from an application or user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3599" + }, + { + "type": "WEB", + "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25659" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-30T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mpc5-8rvq-8qfx/GHSA-mpc5-8rvq-8qfx.json b/advisories/unreviewed/2025/04/GHSA-mpc5-8rvq-8qfx/GHSA-mpc5-8rvq-8qfx.json new file mode 100644 index 00000000000..84c31078d30 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mpc5-8rvq-8qfx/GHSA-mpc5-8rvq-8qfx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mpc5-8rvq-8qfx", + "modified": "2025-04-30T18:31:55Z", + "published": "2025-04-30T18:31:55Z", + "aliases": [ + "CVE-2025-39413" + ], + "details": "Missing Authorization vulnerability in David Gwyer Simple Sitemap – Create a Responsive HTML Sitemap.This issue affects Simple Sitemap – Create a Responsive HTML Sitemap: from n/a through 3.5.14.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39413" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simple-sitemap/vulnerability/wordpress-simple-sitemap-create-a-responsive-html-sitemap-plugin-3-5-14-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-30T18:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-ppf8-hgp4-7rvj/GHSA-ppf8-hgp4-7rvj.json b/advisories/unreviewed/2025/04/GHSA-ppf8-hgp4-7rvj/GHSA-ppf8-hgp4-7rvj.json index df9902062b7..895b089d1bd 100644 --- a/advisories/unreviewed/2025/04/GHSA-ppf8-hgp4-7rvj/GHSA-ppf8-hgp4-7rvj.json +++ b/advisories/unreviewed/2025/04/GHSA-ppf8-hgp4-7rvj/GHSA-ppf8-hgp4-7rvj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-ppf8-hgp4-7rvj", - "modified": "2025-04-30T06:30:21Z", + "modified": "2025-04-30T18:31:54Z", "published": "2025-04-30T06:30:21Z", "aliases": [ "CVE-2025-3471" ], "details": "The SureForms WordPress plugin before 1.4.4 does not have proper authorisation check when updating its settings via the REST API, which could allow Contributor and above roles to perform such action", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-30T06:15:53Z" diff --git a/advisories/unreviewed/2025/04/GHSA-pwgp-427f-j92g/GHSA-pwgp-427f-j92g.json b/advisories/unreviewed/2025/04/GHSA-pwgp-427f-j92g/GHSA-pwgp-427f-j92g.json new file mode 100644 index 00000000000..1bde3972a7c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pwgp-427f-j92g/GHSA-pwgp-427f-j92g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pwgp-427f-j92g", + "modified": "2025-04-30T18:31:56Z", + "published": "2025-04-30T18:31:55Z", + "aliases": [ + "CVE-2025-30390" + ], + "details": "Improper authorization in Azure allows an authorized attacker to elevate privileges over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30390" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-30390" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-30T18:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-px62-fqwr-9g32/GHSA-px62-fqwr-9g32.json b/advisories/unreviewed/2025/04/GHSA-px62-fqwr-9g32/GHSA-px62-fqwr-9g32.json new file mode 100644 index 00000000000..8f05da2aac9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-px62-fqwr-9g32/GHSA-px62-fqwr-9g32.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-px62-fqwr-9g32", + "modified": "2025-04-30T18:31:55Z", + "published": "2025-04-30T18:31:55Z", + "aliases": [ + "CVE-2025-44193" + ], + "details": "SourceCodester Simple Barangay Management System v1.0 has a SQL injection vulnerability in /barangay_management/admin/?page=view_complaint.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44193" + }, + { + "type": "WEB", + "url": "https://github.com/red-team00/bug_report/blob/main/simple-barangay-management-system/SQLi-2.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-30T18:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qh62-99w2-xfq5/GHSA-qh62-99w2-xfq5.json b/advisories/unreviewed/2025/04/GHSA-qh62-99w2-xfq5/GHSA-qh62-99w2-xfq5.json index 17be0403488..5cc5677a7ac 100644 --- a/advisories/unreviewed/2025/04/GHSA-qh62-99w2-xfq5/GHSA-qh62-99w2-xfq5.json +++ b/advisories/unreviewed/2025/04/GHSA-qh62-99w2-xfq5/GHSA-qh62-99w2-xfq5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qh62-99w2-xfq5", - "modified": "2025-04-30T15:30:49Z", + "modified": "2025-04-30T18:31:54Z", "published": "2025-04-30T15:30:49Z", "aliases": [ "CVE-2025-45021" ], "details": "A SQL Injection vulnerability was identified in the admin/edit-directory.php file of the PHPGurukul Directory Management System v2.0. Attackers can exploit this vulnerability via the email parameter in a POST request to execute arbitrary SQL commands.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-30T14:15:29Z" diff --git a/advisories/unreviewed/2025/04/GHSA-qmf3-4g6f-3fjv/GHSA-qmf3-4g6f-3fjv.json b/advisories/unreviewed/2025/04/GHSA-qmf3-4g6f-3fjv/GHSA-qmf3-4g6f-3fjv.json new file mode 100644 index 00000000000..b8ac617b74b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qmf3-4g6f-3fjv/GHSA-qmf3-4g6f-3fjv.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qmf3-4g6f-3fjv", + "modified": "2025-04-30T18:31:55Z", + "published": "2025-04-30T18:31:55Z", + "aliases": [ + "CVE-2025-24091" + ], + "details": "An app could impersonate system notifications. Sensitive notifications now require restricted entitlements. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.3. An app may be able to cause a denial-of-service.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24091" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121838" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122066" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-30T18:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rm5g-c65x-vjvv/GHSA-rm5g-c65x-vjvv.json b/advisories/unreviewed/2025/04/GHSA-rm5g-c65x-vjvv/GHSA-rm5g-c65x-vjvv.json new file mode 100644 index 00000000000..3fe91c91721 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rm5g-c65x-vjvv/GHSA-rm5g-c65x-vjvv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rm5g-c65x-vjvv", + "modified": "2025-04-30T18:31:55Z", + "published": "2025-04-30T18:31:55Z", + "aliases": [ + "CVE-2025-30392" + ], + "details": "Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30392" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-30392" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-30T18:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vhj2-4h8c-jc8m/GHSA-vhj2-4h8c-jc8m.json b/advisories/unreviewed/2025/04/GHSA-vhj2-4h8c-jc8m/GHSA-vhj2-4h8c-jc8m.json index 8f5c953969d..d389eb2d3ee 100644 --- a/advisories/unreviewed/2025/04/GHSA-vhj2-4h8c-jc8m/GHSA-vhj2-4h8c-jc8m.json +++ b/advisories/unreviewed/2025/04/GHSA-vhj2-4h8c-jc8m/GHSA-vhj2-4h8c-jc8m.json @@ -54,7 +54,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-476" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-vv86-jpff-556f/GHSA-vv86-jpff-556f.json b/advisories/unreviewed/2025/04/GHSA-vv86-jpff-556f/GHSA-vv86-jpff-556f.json index a07785947b2..70530f231cc 100644 --- a/advisories/unreviewed/2025/04/GHSA-vv86-jpff-556f/GHSA-vv86-jpff-556f.json +++ b/advisories/unreviewed/2025/04/GHSA-vv86-jpff-556f/GHSA-vv86-jpff-556f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vv86-jpff-556f", - "modified": "2025-04-23T21:30:36Z", + "modified": "2025-04-30T18:31:54Z", "published": "2025-04-23T21:30:36Z", "aliases": [ "CVE-2025-46398" diff --git a/advisories/unreviewed/2025/04/GHSA-w583-vcj4-hhr9/GHSA-w583-vcj4-hhr9.json b/advisories/unreviewed/2025/04/GHSA-w583-vcj4-hhr9/GHSA-w583-vcj4-hhr9.json index b185edb7280..75e8da6919d 100644 --- a/advisories/unreviewed/2025/04/GHSA-w583-vcj4-hhr9/GHSA-w583-vcj4-hhr9.json +++ b/advisories/unreviewed/2025/04/GHSA-w583-vcj4-hhr9/GHSA-w583-vcj4-hhr9.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false,