diff --git a/advisories/unreviewed/2022/08/GHSA-f326-p7mm-52h2/GHSA-f326-p7mm-52h2.json b/advisories/unreviewed/2022/08/GHSA-f326-p7mm-52h2/GHSA-f326-p7mm-52h2.json index a57ceee30a2..af94a3526ae 100644 --- a/advisories/unreviewed/2022/08/GHSA-f326-p7mm-52h2/GHSA-f326-p7mm-52h2.json +++ b/advisories/unreviewed/2022/08/GHSA-f326-p7mm-52h2/GHSA-f326-p7mm-52h2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f326-p7mm-52h2", - "modified": "2022-08-14T00:00:22Z", + "modified": "2025-04-02T21:30:41Z", "published": "2022-08-11T00:00:15Z", "aliases": [ "CVE-2021-33644" @@ -19,6 +19,26 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33644" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4S4PJRCJLEAWN2EKXGLSOBTL7O57V7NC" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5YSHZY753R7XW6CIKJVAWI373WW3YRRJ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7Q26QDNOJDOFYWMJWEIK5XR62M2FF6IJ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WX5YE66CT7Y5C2HTHXSFDKQWYWYWJ2T" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OD4HEBSTI22FNYKOKK7W3X6ZQE6FV3XC" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4S4PJRCJLEAWN2EKXGLSOBTL7O57V7NC" diff --git a/advisories/unreviewed/2022/08/GHSA-j7g9-fcw9-wxcf/GHSA-j7g9-fcw9-wxcf.json b/advisories/unreviewed/2022/08/GHSA-j7g9-fcw9-wxcf/GHSA-j7g9-fcw9-wxcf.json index aaf0d67daf9..2538430dc76 100644 --- a/advisories/unreviewed/2022/08/GHSA-j7g9-fcw9-wxcf/GHSA-j7g9-fcw9-wxcf.json +++ b/advisories/unreviewed/2022/08/GHSA-j7g9-fcw9-wxcf/GHSA-j7g9-fcw9-wxcf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j7g9-fcw9-wxcf", - "modified": "2022-08-14T00:00:22Z", + "modified": "2025-04-02T21:30:41Z", "published": "2022-08-11T00:00:15Z", "aliases": [ "CVE-2021-33643" @@ -19,6 +19,26 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33643" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4S4PJRCJLEAWN2EKXGLSOBTL7O57V7NC" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5YSHZY753R7XW6CIKJVAWI373WW3YRRJ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7Q26QDNOJDOFYWMJWEIK5XR62M2FF6IJ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WX5YE66CT7Y5C2HTHXSFDKQWYWYWJ2T" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OD4HEBSTI22FNYKOKK7W3X6ZQE6FV3XC" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4S4PJRCJLEAWN2EKXGLSOBTL7O57V7NC" diff --git a/advisories/unreviewed/2022/08/GHSA-j8q5-rwmr-9hg8/GHSA-j8q5-rwmr-9hg8.json b/advisories/unreviewed/2022/08/GHSA-j8q5-rwmr-9hg8/GHSA-j8q5-rwmr-9hg8.json index f3977a0ac4d..0c31f38e9d4 100644 --- a/advisories/unreviewed/2022/08/GHSA-j8q5-rwmr-9hg8/GHSA-j8q5-rwmr-9hg8.json +++ b/advisories/unreviewed/2022/08/GHSA-j8q5-rwmr-9hg8/GHSA-j8q5-rwmr-9hg8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j8q5-rwmr-9hg8", - "modified": "2022-12-28T06:30:18Z", + "modified": "2025-04-02T21:30:41Z", "published": "2022-08-11T00:00:15Z", "aliases": [ "CVE-2021-33645" @@ -19,6 +19,26 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33645" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4S4PJRCJLEAWN2EKXGLSOBTL7O57V7NC" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5YSHZY753R7XW6CIKJVAWI373WW3YRRJ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7Q26QDNOJDOFYWMJWEIK5XR62M2FF6IJ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WX5YE66CT7Y5C2HTHXSFDKQWYWYWJ2T" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OD4HEBSTI22FNYKOKK7W3X6ZQE6FV3XC" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4S4PJRCJLEAWN2EKXGLSOBTL7O57V7NC" diff --git a/advisories/unreviewed/2022/08/GHSA-x27v-rjqh-f4xc/GHSA-x27v-rjqh-f4xc.json b/advisories/unreviewed/2022/08/GHSA-x27v-rjqh-f4xc/GHSA-x27v-rjqh-f4xc.json index 7a04b72f3fc..cc827cf03d5 100644 --- a/advisories/unreviewed/2022/08/GHSA-x27v-rjqh-f4xc/GHSA-x27v-rjqh-f4xc.json +++ b/advisories/unreviewed/2022/08/GHSA-x27v-rjqh-f4xc/GHSA-x27v-rjqh-f4xc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x27v-rjqh-f4xc", - "modified": "2022-12-28T06:30:18Z", + "modified": "2025-04-02T21:30:42Z", "published": "2022-08-11T00:00:15Z", "aliases": [ "CVE-2021-33646" @@ -19,6 +19,26 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33646" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4S4PJRCJLEAWN2EKXGLSOBTL7O57V7NC" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5YSHZY753R7XW6CIKJVAWI373WW3YRRJ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7Q26QDNOJDOFYWMJWEIK5XR62M2FF6IJ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WX5YE66CT7Y5C2HTHXSFDKQWYWYWJ2T" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OD4HEBSTI22FNYKOKK7W3X6ZQE6FV3XC" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4S4PJRCJLEAWN2EKXGLSOBTL7O57V7NC" diff --git a/advisories/unreviewed/2022/12/GHSA-pjrv-5vw3-5frj/GHSA-pjrv-5vw3-5frj.json b/advisories/unreviewed/2022/12/GHSA-pjrv-5vw3-5frj/GHSA-pjrv-5vw3-5frj.json index 5d32a650caa..b91f454b53c 100644 --- a/advisories/unreviewed/2022/12/GHSA-pjrv-5vw3-5frj/GHSA-pjrv-5vw3-5frj.json +++ b/advisories/unreviewed/2022/12/GHSA-pjrv-5vw3-5frj/GHSA-pjrv-5vw3-5frj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pjrv-5vw3-5frj", - "modified": "2022-12-29T21:30:30Z", + "modified": "2025-04-02T21:30:42Z", "published": "2022-12-19T18:30:25Z", "aliases": [ "CVE-2021-33640" @@ -19,6 +19,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33640" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4S4PJRCJLEAWN2EKXGLSOBTL7O57V7NC" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WX5YE66CT7Y5C2HTHXSFDKQWYWYWJ2T" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4S4PJRCJLEAWN2EKXGLSOBTL7O57V7NC" diff --git a/advisories/unreviewed/2024/02/GHSA-frwq-jm7h-q2q2/GHSA-frwq-jm7h-q2q2.json b/advisories/unreviewed/2024/02/GHSA-frwq-jm7h-q2q2/GHSA-frwq-jm7h-q2q2.json index 61ffebc7d53..0496e730e2f 100644 --- a/advisories/unreviewed/2024/02/GHSA-frwq-jm7h-q2q2/GHSA-frwq-jm7h-q2q2.json +++ b/advisories/unreviewed/2024/02/GHSA-frwq-jm7h-q2q2/GHSA-frwq-jm7h-q2q2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-frwq-jm7h-q2q2", - "modified": "2024-08-01T15:31:26Z", + "modified": "2025-04-02T21:30:44Z", "published": "2024-02-20T09:30:32Z", "aliases": [ "CVE-2024-25974" @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-57qm-97m4-7q67/GHSA-57qm-97m4-7q67.json b/advisories/unreviewed/2025/02/GHSA-57qm-97m4-7q67/GHSA-57qm-97m4-7q67.json index 55d7feb0dec..c71d9b22b5a 100644 --- a/advisories/unreviewed/2025/02/GHSA-57qm-97m4-7q67/GHSA-57qm-97m4-7q67.json +++ b/advisories/unreviewed/2025/02/GHSA-57qm-97m4-7q67/GHSA-57qm-97m4-7q67.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-5hfg-864g-w62r/GHSA-5hfg-864g-w62r.json b/advisories/unreviewed/2025/02/GHSA-5hfg-864g-w62r/GHSA-5hfg-864g-w62r.json index 728e4efb0dc..fd063b91ef1 100644 --- a/advisories/unreviewed/2025/02/GHSA-5hfg-864g-w62r/GHSA-5hfg-864g-w62r.json +++ b/advisories/unreviewed/2025/02/GHSA-5hfg-864g-w62r/GHSA-5hfg-864g-w62r.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-g533-46g7-g2f9/GHSA-g533-46g7-g2f9.json b/advisories/unreviewed/2025/03/GHSA-g533-46g7-g2f9/GHSA-g533-46g7-g2f9.json index a759abeb10b..e9d85e99a89 100644 --- a/advisories/unreviewed/2025/03/GHSA-g533-46g7-g2f9/GHSA-g533-46g7-g2f9.json +++ b/advisories/unreviewed/2025/03/GHSA-g533-46g7-g2f9/GHSA-g533-46g7-g2f9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g533-46g7-g2f9", - "modified": "2025-04-01T21:30:46Z", + "modified": "2025-04-02T21:30:49Z", "published": "2025-03-26T18:30:50Z", "aliases": [ "CVE-2025-2825" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://attackerkb.com/topics/k0EgiL9Psz/cve-2025-2825/rapid7-analysis" }, + { + "type": "WEB", + "url": "https://outpost24.com/blog/crushftp-auth-bypass-vulnerability" + }, { "type": "WEB", "url": "https://projectdiscovery.io/blog/crushftp-authentication-bypass" diff --git a/advisories/unreviewed/2025/03/GHSA-rmf5-rhfv-3qrp/GHSA-rmf5-rhfv-3qrp.json b/advisories/unreviewed/2025/03/GHSA-rmf5-rhfv-3qrp/GHSA-rmf5-rhfv-3qrp.json index ddb9c2d4b40..a6367054a76 100644 --- a/advisories/unreviewed/2025/03/GHSA-rmf5-rhfv-3qrp/GHSA-rmf5-rhfv-3qrp.json +++ b/advisories/unreviewed/2025/03/GHSA-rmf5-rhfv-3qrp/GHSA-rmf5-rhfv-3qrp.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-39p5-3m6f-c8xp/GHSA-39p5-3m6f-c8xp.json b/advisories/unreviewed/2025/04/GHSA-39p5-3m6f-c8xp/GHSA-39p5-3m6f-c8xp.json new file mode 100644 index 00000000000..98ab2fb7e60 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-39p5-3m6f-c8xp/GHSA-39p5-3m6f-c8xp.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-39p5-3m6f-c8xp", + "modified": "2025-04-02T21:30:51Z", + "published": "2025-04-02T21:30:51Z", + "aliases": [ + "CVE-2025-29063" + ], + "details": "An issue in BL-AC2100 V1.0.4 and before allows a remote attacker to execute arbitrary code via the enable parameter passed to /goform/set_hidessid_cfg is not handled properly.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29063" + }, + { + "type": "WEB", + "url": "https://www.yuque.com/jichujiliangdanwei/vwbq9e/grfgkm2kvk6btwbp" + }, + { + "type": "WEB", + "url": "https://www.yuque.com/jichujiliangdanwei/vwbq9e/ux1426h170rhgfn7" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-02T21:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-49v8-p6mm-3pfj/GHSA-49v8-p6mm-3pfj.json b/advisories/unreviewed/2025/04/GHSA-49v8-p6mm-3pfj/GHSA-49v8-p6mm-3pfj.json new file mode 100644 index 00000000000..2f7c5928b2e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-49v8-p6mm-3pfj/GHSA-49v8-p6mm-3pfj.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-49v8-p6mm-3pfj", + "modified": "2025-04-02T21:30:51Z", + "published": "2025-04-02T21:30:51Z", + "aliases": [ + "CVE-2025-29085" + ], + "details": "SQL injection vulnerability in vipshop Saturn v.3.5.1 and before allows a remote attacker to execute arbitrary code via /console/dashboard/executorCount?zkClusterKey component.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29085" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Cafe-Tea/bcef0d7a2bdb5ec8e0d69de852fdc900" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-02T21:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5gwv-2q72-gxrm/GHSA-5gwv-2q72-gxrm.json b/advisories/unreviewed/2025/04/GHSA-5gwv-2q72-gxrm/GHSA-5gwv-2q72-gxrm.json new file mode 100644 index 00000000000..40304733fb0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5gwv-2q72-gxrm/GHSA-5gwv-2q72-gxrm.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5gwv-2q72-gxrm", + "modified": "2025-04-02T21:30:51Z", + "published": "2025-04-02T21:30:51Z", + "aliases": [ + "CVE-2025-2704" + ], + "details": "OpenVPN version 2.6.1 through 2.6.13 in server mode using TLS-crypt-v2 allows remote attackers to trigger a denial of service by corrupting and replaying network packets in the early handshake phase", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2704" + }, + { + "type": "WEB", + "url": "https://community.openvpn.net/openvpn/wiki/CVE-2025-2704" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-754" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-02T21:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5prh-r43c-x8ww/GHSA-5prh-r43c-x8ww.json b/advisories/unreviewed/2025/04/GHSA-5prh-r43c-x8ww/GHSA-5prh-r43c-x8ww.json new file mode 100644 index 00000000000..3518801e5a9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5prh-r43c-x8ww/GHSA-5prh-r43c-x8ww.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5prh-r43c-x8ww", + "modified": "2025-04-02T21:30:50Z", + "published": "2025-04-02T21:30:50Z", + "aliases": [ + "CVE-2025-22923" + ], + "details": "An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal and delete files by sending a crafted POST request to /Modules.php?modname=users/Staff.php&removefile.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22923" + }, + { + "type": "WEB", + "url": "https://github.com/OS4ED/openSIS-Classic" + }, + { + "type": "WEB", + "url": "https://github.com/esusalla/vulnerability-research/tree/main/CVE-2025-22923" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-02T21:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-72xp-5wmc-q74j/GHSA-72xp-5wmc-q74j.json b/advisories/unreviewed/2025/04/GHSA-72xp-5wmc-q74j/GHSA-72xp-5wmc-q74j.json new file mode 100644 index 00000000000..d87c276c505 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-72xp-5wmc-q74j/GHSA-72xp-5wmc-q74j.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-72xp-5wmc-q74j", + "modified": "2025-04-02T21:30:51Z", + "published": "2025-04-02T21:30:51Z", + "aliases": [ + "CVE-2025-22925" + ], + "details": "OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the table parameter at /attendance/AttendanceCodes.php. The remote, authenticated attacker requires the admin role to successfully exploit this vulnerability.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22925" + }, + { + "type": "WEB", + "url": "https://github.com/OS4ED/openSIS-Classic" + }, + { + "type": "WEB", + "url": "https://github.com/esusalla/vulnerability-research/tree/main/CVE-2025-22925" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-02T21:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8h3c-wm8x-wcrq/GHSA-8h3c-wm8x-wcrq.json b/advisories/unreviewed/2025/04/GHSA-8h3c-wm8x-wcrq/GHSA-8h3c-wm8x-wcrq.json new file mode 100644 index 00000000000..5f09e6478a6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8h3c-wm8x-wcrq/GHSA-8h3c-wm8x-wcrq.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8h3c-wm8x-wcrq", + "modified": "2025-04-02T21:30:49Z", + "published": "2025-04-02T21:30:49Z", + "aliases": [ + "CVE-2024-38392" + ], + "details": "Pexip Infinity Connect before 1.13.0 lacks sufficient authenticity checks during the loading of resources, and thus remote attackers can cause the application to run untrusted code.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38392" + }, + { + "type": "WEB", + "url": "https://docs.pexip.com/admin/security_bulletins.htm" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-02T21:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8w5r-w84g-hvww/GHSA-8w5r-w84g-hvww.json b/advisories/unreviewed/2025/04/GHSA-8w5r-w84g-hvww/GHSA-8w5r-w84g-hvww.json new file mode 100644 index 00000000000..22f0fbaee15 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8w5r-w84g-hvww/GHSA-8w5r-w84g-hvww.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8w5r-w84g-hvww", + "modified": "2025-04-02T21:30:51Z", + "published": "2025-04-02T21:30:51Z", + "aliases": [ + "CVE-2025-3118" + ], + "details": "A vulnerability was found in SourceCodester Online Tutor Portal 1.0. It has been classified as critical. This affects an unknown part of the file /tutor/courses/view_course.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3118" + }, + { + "type": "WEB", + "url": "https://github.com/byxs0x0/SQL/blob/main/SQL3.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303009" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303009" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.524985" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-02T21:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9pv7-g3rx-xpqw/GHSA-9pv7-g3rx-xpqw.json b/advisories/unreviewed/2025/04/GHSA-9pv7-g3rx-xpqw/GHSA-9pv7-g3rx-xpqw.json new file mode 100644 index 00000000000..1423fb23f55 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9pv7-g3rx-xpqw/GHSA-9pv7-g3rx-xpqw.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9pv7-g3rx-xpqw", + "modified": "2025-04-02T21:30:51Z", + "published": "2025-04-02T21:30:51Z", + "aliases": [ + "CVE-2025-30080" + ], + "details": "Signalling in Pexip Infinity 29 through 36.2 before 37.0 has improper input validation that allows remote attackers to trigger a temporary denial of service (software abort).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30080" + }, + { + "type": "WEB", + "url": "https://docs.pexip.com/admin/security_bulletins.htm" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-02T21:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-frqg-qr33-mvr2/GHSA-frqg-qr33-mvr2.json b/advisories/unreviewed/2025/04/GHSA-frqg-qr33-mvr2/GHSA-frqg-qr33-mvr2.json new file mode 100644 index 00000000000..8bf60e1229b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-frqg-qr33-mvr2/GHSA-frqg-qr33-mvr2.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-frqg-qr33-mvr2", + "modified": "2025-04-02T21:30:51Z", + "published": "2025-04-02T21:30:51Z", + "aliases": [ + "CVE-2025-29719" + ], + "details": "SourceCodester (rems) Employee Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in add_employee.php via the First Name and Address text fields.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29719" + }, + { + "type": "WEB", + "url": "https://github.com/sw8y/vulnerability_research/blob/main/CVE-2025-29719/CVE-2025-29719.md" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com/php/17847/employee-management-system-using-php-and-mysql-source-code.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-02T21:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mrfj-vv5j-9gw5/GHSA-mrfj-vv5j-9gw5.json b/advisories/unreviewed/2025/04/GHSA-mrfj-vv5j-9gw5/GHSA-mrfj-vv5j-9gw5.json new file mode 100644 index 00000000000..142b04892cd --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mrfj-vv5j-9gw5/GHSA-mrfj-vv5j-9gw5.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mrfj-vv5j-9gw5", + "modified": "2025-04-02T21:30:50Z", + "published": "2025-04-02T21:30:50Z", + "aliases": [ + "CVE-2025-22924" + ], + "details": "OS4ED openSIS v7.0 through v9.1 contains a SQL injection vulnerability via the stu_id parameter at /modules/students/Student.php.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22924" + }, + { + "type": "WEB", + "url": "https://github.com/OS4ED/openSIS-Classic" + }, + { + "type": "WEB", + "url": "https://github.com/esusalla/vulnerability-research/tree/main/CVE-2025-22924" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-02T21:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rpvv-rj3m-qqgx/GHSA-rpvv-rj3m-qqgx.json b/advisories/unreviewed/2025/04/GHSA-rpvv-rj3m-qqgx/GHSA-rpvv-rj3m-qqgx.json new file mode 100644 index 00000000000..5df96cb079a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rpvv-rj3m-qqgx/GHSA-rpvv-rj3m-qqgx.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rpvv-rj3m-qqgx", + "modified": "2025-04-02T21:30:51Z", + "published": "2025-04-02T21:30:51Z", + "aliases": [ + "CVE-2025-29062" + ], + "details": "An issue in BL-AC2100 <=V1.0.4 allows a remote attacker to execute arbitrary code via the time1 and time2 parameters in the set_LimitClient_cfg of the goahead webservice.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29062" + }, + { + "type": "WEB", + "url": "https://www.yuque.com/jichujiliangdanwei/vwbq9e/grfgkm2kvk6btwbp" + }, + { + "type": "WEB", + "url": "https://www.yuque.com/jichujiliangdanwei/vwbq9e/ux1426h170rhgfn7" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-02T21:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-w73q-37g7-jp37/GHSA-w73q-37g7-jp37.json b/advisories/unreviewed/2025/04/GHSA-w73q-37g7-jp37/GHSA-w73q-37g7-jp37.json new file mode 100644 index 00000000000..1c0bbeadaf2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-w73q-37g7-jp37/GHSA-w73q-37g7-jp37.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w73q-37g7-jp37", + "modified": "2025-04-02T21:30:49Z", + "published": "2025-04-02T21:30:49Z", + "aliases": [ + "CVE-2024-37917" + ], + "details": "Pexip Infinity before 35.0 has improper input validation that allows remote attackers to trigger a denial of service (software abort) via a crafted signalling message.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37917" + }, + { + "type": "WEB", + "url": "https://docs.pexip.com/admin/security_bulletins.htm" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-02T21:15:30Z" + } +} \ No newline at end of file