Publish Advisories

GHSA-cc77-xm2j-7rm6
GHSA-g7v8-vw35-p6rp
GHSA-5g4q-39w7-g8vv
GHSA-87p5-fx92-387x
GHSA-9563-qrch-r2xp
GHSA-978f-3hph-xcgf
GHSA-9pph-j6v9-q8xv
GHSA-fqr8-q3mh-59gh
GHSA-fwv7-rrjm-6m82
GHSA-gjf5-5c3r-89f6
GHSA-j48h-86ph-5xjx
GHSA-m8hc-hmrj-mf93
GHSA-pw2f-j76p-vrqv
GHSA-qj3j-gr5j-56r7
GHSA-x5gg-v967-8wc4
GHSA-x8w2-qrcv-wgc3
GHSA-7x63-6wwc-qg67
GHSA-mcm6-cpvx-gpc6
GHSA-q22v-8f6w-43w8
GHSA-q55x-cgc8-49xh
GHSA-vqh7-q5w4-vwr6
This commit is contained in:
advisory-database[bot]
2025-05-26 03:32:00 +00:00
parent 3d59db9d4f
commit c081edfbb8
21 changed files with 297 additions and 16 deletions
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-79"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -42,7 +42,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
"CWE-74",
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-87p5-fx92-387x",
"modified": "2025-03-05T12:31:10Z",
"modified": "2025-05-26T03:30:25Z",
"published": "2025-03-05T12:31:10Z",
"aliases": [
"CVE-2024-13757"
@@ -42,7 +42,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-284"
"CWE-284",
"CWE-434"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-978f-3hph-xcgf",
"modified": "2025-03-05T12:31:09Z",
"modified": "2025-05-26T03:30:25Z",
"published": "2025-03-05T12:31:09Z",
"aliases": [
"CVE-2024-11731"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9pph-j6v9-q8xv",
"modified": "2025-03-01T09:30:29Z",
"modified": "2025-05-26T03:30:24Z",
"published": "2025-03-01T09:30:29Z",
"aliases": [
"CVE-2024-13697"
@@ -46,7 +46,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-284"
"CWE-284",
"CWE-434"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -42,7 +42,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
"CWE-74",
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -46,7 +46,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
"CWE-74",
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -42,7 +42,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
"CWE-74",
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m8hc-hmrj-mf93",
"modified": "2025-03-11T09:30:30Z",
"modified": "2025-05-26T03:30:25Z",
"published": "2025-03-11T09:30:30Z",
"aliases": [
"CVE-2024-13228"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pw2f-j76p-vrqv",
"modified": "2025-03-05T09:30:52Z",
"modified": "2025-05-26T03:30:25Z",
"published": "2025-03-05T09:30:52Z",
"aliases": [
"CVE-2024-13350"
@@ -42,7 +42,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
"CWE-74",
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x5gg-v967-8wc4",
"modified": "2025-03-01T06:30:53Z",
"modified": "2025-05-26T03:30:24Z",
"published": "2025-03-01T06:30:53Z",
"aliases": [
"CVE-2024-13901"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x8w2-qrcv-wgc3",
"modified": "2025-03-13T06:30:34Z",
"modified": "2025-05-26T03:30:25Z",
"published": "2025-03-13T06:30:34Z",
"aliases": [
"CVE-2025-1561"
@@ -0,0 +1,52 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7x63-6wwc-qg67",
"modified": "2025-05-26T03:30:25Z",
"published": "2025-05-26T03:30:25Z",
"aliases": [
"CVE-2025-5163"
],
"details": "A vulnerability, which was classified as problematic, was found in yangshare 技术杨工 warehouseManager 仓库管理系统 1.0. This affects an unknown part. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5163"
},
{
"type": "WEB",
"url": "https://github.com/sumingwjl/cve/issues/1"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.310251"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.310251"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.576315"
}
],
"database_specific": {
"cwe_ids": [
"CWE-266"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-26T02:15:18Z"
}
}
@@ -0,0 +1,52 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mcm6-cpvx-gpc6",
"modified": "2025-05-26T03:30:25Z",
"published": "2025-05-26T03:30:25Z",
"aliases": [
"CVE-2025-5161"
],
"details": "A vulnerability classified as problematic was found in H3C SecCenter SMP-E1114P02 up to 20250513. Affected by this vulnerability is the function operationDailyOut of the file /safeEvent/download. The manipulation of the argument filename leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5161"
},
{
"type": "WEB",
"url": "https://flowus.cn/share/d78abd42-5de8-45f1-a941-a11a2581be0c?code=G8A6P3"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.310249"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.310249"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.578678"
}
],
"database_specific": {
"cwe_ids": [
"CWE-22"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-26T01:15:20Z"
}
}
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q22v-8f6w-43w8",
"modified": "2025-05-26T03:30:26Z",
"published": "2025-05-26T03:30:25Z",
"aliases": [
"CVE-2025-5164"
],
"details": "A vulnerability has been found in PerfreeBlog 4.0.11 and classified as problematic. This vulnerability affects the function JwtUtil of the component JWT Handler. The manipulation leads to use of hard-coded cryptographic key\n . The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5164"
},
{
"type": "WEB",
"url": "https://github.com/147536951/Qiany1/blob/main/Perfreeblog_3.pdf"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.310252"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.310252"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.576433"
}
],
"database_specific": {
"cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-26T03:15:35Z"
}
}
@@ -0,0 +1,60 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q55x-cgc8-49xh",
"modified": "2025-05-26T03:30:25Z",
"published": "2025-05-26T03:30:25Z",
"aliases": [
"CVE-2025-5165"
],
"details": "A vulnerability was found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This issue affects the function MDCImporter::ValidateSurfaceHeader of the file assimp/code/AssetLib/MDC/MDCLoader.cpp. The manipulation of the argument pcSurface2 leads to out-of-bounds read. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5165"
},
{
"type": "WEB",
"url": "https://github.com/assimp/assimp/issues/6128"
},
{
"type": "WEB",
"url": "https://github.com/assimp/assimp/issues/6167"
},
{
"type": "WEB",
"url": "https://github.com/user-attachments/files/20204942/reproducer.zip"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.310253"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.310253"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.578000"
}
],
"database_specific": {
"cwe_ids": [
"CWE-119"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-26T03:15:36Z"
}
}

Some files were not shown because too many files have changed in this diff Show More