From ca2335e410a16b0c002fdb4ce6a2da989ce6ef9d Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 17 Apr 2025 15:33:46 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-6vwf-m72q-cw8h.json | 2 +- .../GHSA-242r-mxxc-q586.json | 10 ++++- .../GHSA-2r4f-phw2-gpqp.json | 14 ++++++- .../GHSA-3f9h-xcq9-8jp9.json | 6 ++- .../GHSA-3rxg-cpfg-pf55.json | 4 +- .../GHSA-44mv-gf6j-pvgx.json | 4 +- .../GHSA-4mxg-39wc-hw87.json | 4 +- .../GHSA-6662-6w2g-g564.json | 10 ++++- .../GHSA-6j9p-gpj2-ch2c.json | 4 +- .../GHSA-6w9r-9p3m-qrj9.json | 1 + .../GHSA-79hv-rqqf-c692.json | 10 ++++- .../GHSA-878w-44xc-hm5q.json | 2 +- .../GHSA-8gfh-vhp5-f739.json | 2 +- .../GHSA-ff4v-crmx-qh7v.json | 6 ++- .../GHSA-fjmh-hhjx-7p2m.json | 3 +- .../GHSA-g8ch-8r7r-4wwj.json | 1 + .../GHSA-gffj-35xf-9h4m.json | 4 +- .../GHSA-h3c5-f4fm-gc7h.json | 10 ++++- .../GHSA-j3gx-wf89-g4rx.json | 6 ++- .../GHSA-mccx-hvr6-hc7g.json | 4 +- .../GHSA-pmj2-vwxv-3w98.json | 6 ++- .../GHSA-pvrf-2wf8-jrqv.json | 6 ++- .../GHSA-r8ff-5hff-rprq.json | 2 +- .../GHSA-vqc2-jf89-w6m6.json | 10 ++++- .../GHSA-xfff-jc44-77fg.json | 3 +- .../GHSA-q3rr-g46f-jgqr.json | 6 ++- .../GHSA-475h-5v9w-xfp6.json | 4 +- .../GHSA-69xp-rrpm-qmj5.json | 3 +- .../GHSA-8j53-82pv-32wq.json | 3 +- .../GHSA-fqw7-q4hr-f893.json | 3 +- .../GHSA-j456-qg26-rqx4.json | 3 +- .../GHSA-3x28-h2m6-h5pv.json | 11 +++-- .../GHSA-66qf-7h58-9q6q.json | 15 +++++-- .../GHSA-7c77-7vhg-xpxp.json | 33 +++++++++++++++ .../GHSA-7hqv-m3mr-cv2v.json | 38 ++++++++++++++++++ .../GHSA-8qh5-83cf-f7qw.json | 33 +++++++++++++++ .../GHSA-8x2h-39pf-v8fc.json | 33 +++++++++++++++ .../GHSA-9vh5-xhwh-w9v4.json | 15 +++++-- .../GHSA-cphf-4pm4-j37r.json | 33 +++++++++++++++ .../GHSA-cwh3-jw96-rmr6.json | 36 +++++++++++++++++ .../GHSA-fchw-5m8f-5fmf.json | 40 +++++++++++++++++++ .../GHSA-fq75-mrrq-hvmj.json | 37 +++++++++++++++++ .../GHSA-fqxf-49hh-94mj.json | 15 +++++-- .../GHSA-h4fr-qhv5-6jfq.json | 15 +++++-- .../GHSA-j53w-h88v-2v3x.json | 6 ++- .../GHSA-j9rv-6qvq-mvqj.json | 11 +++-- .../GHSA-jj4c-9qx7-h4pc.json | 15 +++++-- .../GHSA-jpv9-q37j-qv98.json | 15 +++++-- .../GHSA-mc54-4f73-wx8x.json | 15 +++++-- .../GHSA-mhjg-qmr3-w2xc.json | 15 +++++-- .../GHSA-mp2g-3625-m5pp.json | 15 +++++-- .../GHSA-pmgp-fgv4-prx4.json | 15 +++++-- .../GHSA-pv63-22w8-6xj8.json | 15 +++++-- .../GHSA-qg97-xp64-p6pc.json | 11 +++-- .../GHSA-qhp6-vp7c-g7xp.json | 36 +++++++++++++++++ .../GHSA-r734-gfr8-7qj8.json | 40 +++++++++++++++++++ .../GHSA-rm74-9v34-j945.json | 15 +++++-- .../GHSA-vp28-c453-wwjq.json | 15 +++++-- .../GHSA-w8ch-v2qx-54xx.json | 37 +++++++++++++++++ .../GHSA-x2pf-6jgf-xvvw.json | 6 ++- 60 files changed, 693 insertions(+), 99 deletions(-) create mode 100644 advisories/unreviewed/2025/04/GHSA-7c77-7vhg-xpxp/GHSA-7c77-7vhg-xpxp.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7hqv-m3mr-cv2v/GHSA-7hqv-m3mr-cv2v.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8qh5-83cf-f7qw/GHSA-8qh5-83cf-f7qw.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8x2h-39pf-v8fc/GHSA-8x2h-39pf-v8fc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-cphf-4pm4-j37r/GHSA-cphf-4pm4-j37r.json create mode 100644 advisories/unreviewed/2025/04/GHSA-cwh3-jw96-rmr6/GHSA-cwh3-jw96-rmr6.json create mode 100644 advisories/unreviewed/2025/04/GHSA-fchw-5m8f-5fmf/GHSA-fchw-5m8f-5fmf.json create mode 100644 advisories/unreviewed/2025/04/GHSA-fq75-mrrq-hvmj/GHSA-fq75-mrrq-hvmj.json create mode 100644 advisories/unreviewed/2025/04/GHSA-qhp6-vp7c-g7xp/GHSA-qhp6-vp7c-g7xp.json create mode 100644 advisories/unreviewed/2025/04/GHSA-r734-gfr8-7qj8/GHSA-r734-gfr8-7qj8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-w8ch-v2qx-54xx/GHSA-w8ch-v2qx-54xx.json diff --git a/advisories/unreviewed/2022/05/GHSA-6vwf-m72q-cw8h/GHSA-6vwf-m72q-cw8h.json b/advisories/unreviewed/2022/05/GHSA-6vwf-m72q-cw8h/GHSA-6vwf-m72q-cw8h.json index ce0d1625e97..050d076d123 100644 --- a/advisories/unreviewed/2022/05/GHSA-6vwf-m72q-cw8h/GHSA-6vwf-m72q-cw8h.json +++ b/advisories/unreviewed/2022/05/GHSA-6vwf-m72q-cw8h/GHSA-6vwf-m72q-cw8h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6vwf-m72q-cw8h", - "modified": "2022-05-13T01:34:06Z", + "modified": "2025-04-17T15:32:25Z", "published": "2022-05-13T01:34:06Z", "aliases": [ "CVE-2018-16840" diff --git a/advisories/unreviewed/2022/12/GHSA-242r-mxxc-q586/GHSA-242r-mxxc-q586.json b/advisories/unreviewed/2022/12/GHSA-242r-mxxc-q586/GHSA-242r-mxxc-q586.json index 28f59b46ade..afa55d284cd 100644 --- a/advisories/unreviewed/2022/12/GHSA-242r-mxxc-q586/GHSA-242r-mxxc-q586.json +++ b/advisories/unreviewed/2022/12/GHSA-242r-mxxc-q586/GHSA-242r-mxxc-q586.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-242r-mxxc-q586", - "modified": "2022-12-27T18:30:20Z", + "modified": "2025-04-17T15:32:26Z", "published": "2022-12-19T03:30:31Z", "aliases": [ "CVE-2022-43443" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43443" }, + { + "type": "WEB", + "url": "https://jvn.jp/en/vu/JVNVU97099584" + }, { "type": "WEB", "url": "https://jvn.jp/en/vu/JVNVU97099584/index.html" @@ -26,6 +30,10 @@ { "type": "WEB", "url": "https://www.buffalo.jp/news/detail/20221205-01.html" + }, + { + "type": "WEB", + "url": "https://www.buffalo.jp/news/detail/20240131-01.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/12/GHSA-2r4f-phw2-gpqp/GHSA-2r4f-phw2-gpqp.json b/advisories/unreviewed/2022/12/GHSA-2r4f-phw2-gpqp/GHSA-2r4f-phw2-gpqp.json index 3defe3c0193..b65677eacba 100644 --- a/advisories/unreviewed/2022/12/GHSA-2r4f-phw2-gpqp/GHSA-2r4f-phw2-gpqp.json +++ b/advisories/unreviewed/2022/12/GHSA-2r4f-phw2-gpqp/GHSA-2r4f-phw2-gpqp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2r4f-phw2-gpqp", - "modified": "2022-12-27T21:30:21Z", + "modified": "2025-04-17T15:32:26Z", "published": "2022-12-19T03:30:31Z", "aliases": [ "CVE-2022-43486" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43486" }, + { + "type": "WEB", + "url": "https://jvn.jp/en/vu/JVNVU97099584" + }, { "type": "WEB", "url": "https://jvn.jp/en/vu/JVNVU97099584/index.html" @@ -26,10 +30,16 @@ { "type": "WEB", "url": "https://www.buffalo.jp/news/detail/20221205-01.html" + }, + { + "type": "WEB", + "url": "https://www.buffalo.jp/news/detail/20240131-01.html" } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-3f9h-xcq9-8jp9/GHSA-3f9h-xcq9-8jp9.json b/advisories/unreviewed/2022/12/GHSA-3f9h-xcq9-8jp9/GHSA-3f9h-xcq9-8jp9.json index a6b4cd49927..e5b264c53a5 100644 --- a/advisories/unreviewed/2022/12/GHSA-3f9h-xcq9-8jp9/GHSA-3f9h-xcq9-8jp9.json +++ b/advisories/unreviewed/2022/12/GHSA-3f9h-xcq9-8jp9/GHSA-3f9h-xcq9-8jp9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3f9h-xcq9-8jp9", - "modified": "2022-12-24T06:30:25Z", + "modified": "2025-04-17T15:32:32Z", "published": "2022-12-20T21:30:16Z", "aliases": [ "CVE-2022-46327" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-3rxg-cpfg-pf55/GHSA-3rxg-cpfg-pf55.json b/advisories/unreviewed/2022/12/GHSA-3rxg-cpfg-pf55/GHSA-3rxg-cpfg-pf55.json index fc3e59666e7..00237e4af29 100644 --- a/advisories/unreviewed/2022/12/GHSA-3rxg-cpfg-pf55/GHSA-3rxg-cpfg-pf55.json +++ b/advisories/unreviewed/2022/12/GHSA-3rxg-cpfg-pf55/GHSA-3rxg-cpfg-pf55.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-44mv-gf6j-pvgx/GHSA-44mv-gf6j-pvgx.json b/advisories/unreviewed/2022/12/GHSA-44mv-gf6j-pvgx/GHSA-44mv-gf6j-pvgx.json index 5cd94a43756..f8854bb7fca 100644 --- a/advisories/unreviewed/2022/12/GHSA-44mv-gf6j-pvgx/GHSA-44mv-gf6j-pvgx.json +++ b/advisories/unreviewed/2022/12/GHSA-44mv-gf6j-pvgx/GHSA-44mv-gf6j-pvgx.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-170" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-4mxg-39wc-hw87/GHSA-4mxg-39wc-hw87.json b/advisories/unreviewed/2022/12/GHSA-4mxg-39wc-hw87/GHSA-4mxg-39wc-hw87.json index 27ecfdc0ea7..b419e0253c7 100644 --- a/advisories/unreviewed/2022/12/GHSA-4mxg-39wc-hw87/GHSA-4mxg-39wc-hw87.json +++ b/advisories/unreviewed/2022/12/GHSA-4mxg-39wc-hw87/GHSA-4mxg-39wc-hw87.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-404" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-6662-6w2g-g564/GHSA-6662-6w2g-g564.json b/advisories/unreviewed/2022/12/GHSA-6662-6w2g-g564/GHSA-6662-6w2g-g564.json index 970f6bbc091..66d8ff9ee97 100644 --- a/advisories/unreviewed/2022/12/GHSA-6662-6w2g-g564/GHSA-6662-6w2g-g564.json +++ b/advisories/unreviewed/2022/12/GHSA-6662-6w2g-g564/GHSA-6662-6w2g-g564.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6662-6w2g-g564", - "modified": "2022-12-29T18:30:24Z", + "modified": "2025-04-17T15:32:31Z", "published": "2022-12-20T21:30:19Z", "aliases": [ "CVE-2022-46423" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46423" }, + { + "type": "WEB", + "url": "https://hackmd.io/%40slASVrz_SrW7NQCsunofeA/BktKl8ZDo" + }, { "type": "WEB", "url": "https://hackmd.io/@slASVrz_SrW7NQCsunofeA/BktKl8ZDo" @@ -29,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-494" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-6j9p-gpj2-ch2c/GHSA-6j9p-gpj2-ch2c.json b/advisories/unreviewed/2022/12/GHSA-6j9p-gpj2-ch2c/GHSA-6j9p-gpj2-ch2c.json index d0fc989bd99..8706ac86e2e 100644 --- a/advisories/unreviewed/2022/12/GHSA-6j9p-gpj2-ch2c/GHSA-6j9p-gpj2-ch2c.json +++ b/advisories/unreviewed/2022/12/GHSA-6j9p-gpj2-ch2c/GHSA-6j9p-gpj2-ch2c.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-20" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-6w9r-9p3m-qrj9/GHSA-6w9r-9p3m-qrj9.json b/advisories/unreviewed/2022/12/GHSA-6w9r-9p3m-qrj9/GHSA-6w9r-9p3m-qrj9.json index 2646f420c74..365300850ee 100644 --- a/advisories/unreviewed/2022/12/GHSA-6w9r-9p3m-qrj9/GHSA-6w9r-9p3m-qrj9.json +++ b/advisories/unreviewed/2022/12/GHSA-6w9r-9p3m-qrj9/GHSA-6w9r-9p3m-qrj9.json @@ -38,6 +38,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-400", "CWE-863" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/12/GHSA-79hv-rqqf-c692/GHSA-79hv-rqqf-c692.json b/advisories/unreviewed/2022/12/GHSA-79hv-rqqf-c692/GHSA-79hv-rqqf-c692.json index 22ce144f13f..6b209b4540e 100644 --- a/advisories/unreviewed/2022/12/GHSA-79hv-rqqf-c692/GHSA-79hv-rqqf-c692.json +++ b/advisories/unreviewed/2022/12/GHSA-79hv-rqqf-c692/GHSA-79hv-rqqf-c692.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-79hv-rqqf-c692", - "modified": "2022-12-28T18:30:20Z", + "modified": "2025-04-17T15:32:31Z", "published": "2022-12-20T21:30:19Z", "aliases": [ "CVE-2022-46422" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46422" }, + { + "type": "WEB", + "url": "https://hackmd.io/%40slASVrz_SrW7NQCsunofeA/B1bFKBWwi" + }, { "type": "WEB", "url": "https://hackmd.io/@slASVrz_SrW7NQCsunofeA/B1bFKBWwi" @@ -29,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-345" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-878w-44xc-hm5q/GHSA-878w-44xc-hm5q.json b/advisories/unreviewed/2022/12/GHSA-878w-44xc-hm5q/GHSA-878w-44xc-hm5q.json index 9a5b73e3a31..f2798d80412 100644 --- a/advisories/unreviewed/2022/12/GHSA-878w-44xc-hm5q/GHSA-878w-44xc-hm5q.json +++ b/advisories/unreviewed/2022/12/GHSA-878w-44xc-hm5q/GHSA-878w-44xc-hm5q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-878w-44xc-hm5q", - "modified": "2022-12-29T21:30:30Z", + "modified": "2025-04-17T15:32:31Z", "published": "2022-12-20T21:30:18Z", "aliases": [ "CVE-2021-46856" diff --git a/advisories/unreviewed/2022/12/GHSA-8gfh-vhp5-f739/GHSA-8gfh-vhp5-f739.json b/advisories/unreviewed/2022/12/GHSA-8gfh-vhp5-f739/GHSA-8gfh-vhp5-f739.json index d1c4ec4b82b..c7056becc97 100644 --- a/advisories/unreviewed/2022/12/GHSA-8gfh-vhp5-f739/GHSA-8gfh-vhp5-f739.json +++ b/advisories/unreviewed/2022/12/GHSA-8gfh-vhp5-f739/GHSA-8gfh-vhp5-f739.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8gfh-vhp5-f739", - "modified": "2022-12-24T06:30:25Z", + "modified": "2025-04-17T15:32:31Z", "published": "2022-12-20T21:30:16Z", "aliases": [ "CVE-2022-46328" diff --git a/advisories/unreviewed/2022/12/GHSA-ff4v-crmx-qh7v/GHSA-ff4v-crmx-qh7v.json b/advisories/unreviewed/2022/12/GHSA-ff4v-crmx-qh7v/GHSA-ff4v-crmx-qh7v.json index 2059fd73977..bc2fa18b40d 100644 --- a/advisories/unreviewed/2022/12/GHSA-ff4v-crmx-qh7v/GHSA-ff4v-crmx-qh7v.json +++ b/advisories/unreviewed/2022/12/GHSA-ff4v-crmx-qh7v/GHSA-ff4v-crmx-qh7v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ff4v-crmx-qh7v", - "modified": "2022-12-22T15:30:20Z", + "modified": "2025-04-17T15:32:25Z", "published": "2022-12-18T06:31:09Z", "aliases": [ "CVE-2022-47518" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2022/12/msg00031.html" }, + { + "type": "WEB", + "url": "https://lore.kernel.org/r/20221123153543.8568-5-philipturnbull%40github.com" + }, { "type": "WEB", "url": "https://lore.kernel.org/r/20221123153543.8568-5-philipturnbull@github.com" diff --git a/advisories/unreviewed/2022/12/GHSA-fjmh-hhjx-7p2m/GHSA-fjmh-hhjx-7p2m.json b/advisories/unreviewed/2022/12/GHSA-fjmh-hhjx-7p2m/GHSA-fjmh-hhjx-7p2m.json index bf3e055f5dd..d892c913fad 100644 --- a/advisories/unreviewed/2022/12/GHSA-fjmh-hhjx-7p2m/GHSA-fjmh-hhjx-7p2m.json +++ b/advisories/unreviewed/2022/12/GHSA-fjmh-hhjx-7p2m/GHSA-fjmh-hhjx-7p2m.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-125" + "CWE-125", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-g8ch-8r7r-4wwj/GHSA-g8ch-8r7r-4wwj.json b/advisories/unreviewed/2022/12/GHSA-g8ch-8r7r-4wwj/GHSA-g8ch-8r7r-4wwj.json index 56cf5ecc64a..bcdb2340fe8 100644 --- a/advisories/unreviewed/2022/12/GHSA-g8ch-8r7r-4wwj/GHSA-g8ch-8r7r-4wwj.json +++ b/advisories/unreviewed/2022/12/GHSA-g8ch-8r7r-4wwj/GHSA-g8ch-8r7r-4wwj.json @@ -38,6 +38,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-287", "CWE-863" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/12/GHSA-gffj-35xf-9h4m/GHSA-gffj-35xf-9h4m.json b/advisories/unreviewed/2022/12/GHSA-gffj-35xf-9h4m/GHSA-gffj-35xf-9h4m.json index 95a784ba639..f2977a5870e 100644 --- a/advisories/unreviewed/2022/12/GHSA-gffj-35xf-9h4m/GHSA-gffj-35xf-9h4m.json +++ b/advisories/unreviewed/2022/12/GHSA-gffj-35xf-9h4m/GHSA-gffj-35xf-9h4m.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-755" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-h3c5-f4fm-gc7h/GHSA-h3c5-f4fm-gc7h.json b/advisories/unreviewed/2022/12/GHSA-h3c5-f4fm-gc7h/GHSA-h3c5-f4fm-gc7h.json index b3733cf5d6d..5f49ef484ce 100644 --- a/advisories/unreviewed/2022/12/GHSA-h3c5-f4fm-gc7h/GHSA-h3c5-f4fm-gc7h.json +++ b/advisories/unreviewed/2022/12/GHSA-h3c5-f4fm-gc7h/GHSA-h3c5-f4fm-gc7h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h3c5-f4fm-gc7h", - "modified": "2022-12-28T18:30:20Z", + "modified": "2025-04-17T15:32:31Z", "published": "2022-12-20T21:30:19Z", "aliases": [ "CVE-2022-46139" @@ -19,13 +19,19 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46139" }, + { + "type": "WEB", + "url": "https://hackmd.io/%40slASVrz_SrW7NQCsunofeA/HJH7LSZPj" + }, { "type": "WEB", "url": "https://hackmd.io/@slASVrz_SrW7NQCsunofeA/HJH7LSZPj" } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-345" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-j3gx-wf89-g4rx/GHSA-j3gx-wf89-g4rx.json b/advisories/unreviewed/2022/12/GHSA-j3gx-wf89-g4rx/GHSA-j3gx-wf89-g4rx.json index cb13fb52eac..3a529b0318d 100644 --- a/advisories/unreviewed/2022/12/GHSA-j3gx-wf89-g4rx/GHSA-j3gx-wf89-g4rx.json +++ b/advisories/unreviewed/2022/12/GHSA-j3gx-wf89-g4rx/GHSA-j3gx-wf89-g4rx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j3gx-wf89-g4rx", - "modified": "2022-12-29T18:30:24Z", + "modified": "2025-04-17T15:32:31Z", "published": "2022-12-20T21:30:19Z", "aliases": [ "CVE-2022-38873" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-345" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-mccx-hvr6-hc7g/GHSA-mccx-hvr6-hc7g.json b/advisories/unreviewed/2022/12/GHSA-mccx-hvr6-hc7g/GHSA-mccx-hvr6-hc7g.json index 400e16c2cf4..a57a1618a33 100644 --- a/advisories/unreviewed/2022/12/GHSA-mccx-hvr6-hc7g/GHSA-mccx-hvr6-hc7g.json +++ b/advisories/unreviewed/2022/12/GHSA-mccx-hvr6-hc7g/GHSA-mccx-hvr6-hc7g.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-pmj2-vwxv-3w98/GHSA-pmj2-vwxv-3w98.json b/advisories/unreviewed/2022/12/GHSA-pmj2-vwxv-3w98/GHSA-pmj2-vwxv-3w98.json index 6d6d6fb31c0..43e20fd0020 100644 --- a/advisories/unreviewed/2022/12/GHSA-pmj2-vwxv-3w98/GHSA-pmj2-vwxv-3w98.json +++ b/advisories/unreviewed/2022/12/GHSA-pmj2-vwxv-3w98/GHSA-pmj2-vwxv-3w98.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pmj2-vwxv-3w98", - "modified": "2022-12-22T15:30:21Z", + "modified": "2025-04-17T15:32:25Z", "published": "2022-12-18T06:31:09Z", "aliases": [ "CVE-2022-47520" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2022/12/msg00031.html" }, + { + "type": "WEB", + "url": "https://lore.kernel.org/r/20221123153543.8568-2-philipturnbull%40github.com" + }, { "type": "WEB", "url": "https://lore.kernel.org/r/20221123153543.8568-2-philipturnbull@github.com" diff --git a/advisories/unreviewed/2022/12/GHSA-pvrf-2wf8-jrqv/GHSA-pvrf-2wf8-jrqv.json b/advisories/unreviewed/2022/12/GHSA-pvrf-2wf8-jrqv/GHSA-pvrf-2wf8-jrqv.json index 105b14def21..cbd7d5fd569 100644 --- a/advisories/unreviewed/2022/12/GHSA-pvrf-2wf8-jrqv/GHSA-pvrf-2wf8-jrqv.json +++ b/advisories/unreviewed/2022/12/GHSA-pvrf-2wf8-jrqv/GHSA-pvrf-2wf8-jrqv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pvrf-2wf8-jrqv", - "modified": "2022-12-22T15:30:21Z", + "modified": "2025-04-17T15:32:25Z", "published": "2022-12-18T06:31:09Z", "aliases": [ "CVE-2022-47519" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2022/12/msg00031.html" }, + { + "type": "WEB", + "url": "https://lore.kernel.org/r/20221123153543.8568-3-philipturnbull%40github.com" + }, { "type": "WEB", "url": "https://lore.kernel.org/r/20221123153543.8568-3-philipturnbull@github.com" diff --git a/advisories/unreviewed/2022/12/GHSA-r8ff-5hff-rprq/GHSA-r8ff-5hff-rprq.json b/advisories/unreviewed/2022/12/GHSA-r8ff-5hff-rprq/GHSA-r8ff-5hff-rprq.json index aec8b95cf32..d71696961be 100644 --- a/advisories/unreviewed/2022/12/GHSA-r8ff-5hff-rprq/GHSA-r8ff-5hff-rprq.json +++ b/advisories/unreviewed/2022/12/GHSA-r8ff-5hff-rprq/GHSA-r8ff-5hff-rprq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r8ff-5hff-rprq", - "modified": "2022-12-29T18:30:24Z", + "modified": "2025-04-17T15:32:31Z", "published": "2022-12-20T18:30:19Z", "aliases": [ "CVE-2022-46076" diff --git a/advisories/unreviewed/2022/12/GHSA-vqc2-jf89-w6m6/GHSA-vqc2-jf89-w6m6.json b/advisories/unreviewed/2022/12/GHSA-vqc2-jf89-w6m6/GHSA-vqc2-jf89-w6m6.json index ce7711d0383..5490dae222e 100644 --- a/advisories/unreviewed/2022/12/GHSA-vqc2-jf89-w6m6/GHSA-vqc2-jf89-w6m6.json +++ b/advisories/unreviewed/2022/12/GHSA-vqc2-jf89-w6m6/GHSA-vqc2-jf89-w6m6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vqc2-jf89-w6m6", - "modified": "2022-12-27T18:30:20Z", + "modified": "2025-04-17T15:32:26Z", "published": "2022-12-19T03:30:31Z", "aliases": [ "CVE-2022-43466" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43466" }, + { + "type": "WEB", + "url": "https://jvn.jp/en/vu/JVNVU97099584" + }, { "type": "WEB", "url": "https://jvn.jp/en/vu/JVNVU97099584/index.html" @@ -26,6 +30,10 @@ { "type": "WEB", "url": "https://www.buffalo.jp/news/detail/20221205-01.html" + }, + { + "type": "WEB", + "url": "https://www.buffalo.jp/news/detail/20240131-01.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/12/GHSA-xfff-jc44-77fg/GHSA-xfff-jc44-77fg.json b/advisories/unreviewed/2022/12/GHSA-xfff-jc44-77fg/GHSA-xfff-jc44-77fg.json index 2207a18407d..87c3b83f2e4 100644 --- a/advisories/unreviewed/2022/12/GHSA-xfff-jc44-77fg/GHSA-xfff-jc44-77fg.json +++ b/advisories/unreviewed/2022/12/GHSA-xfff-jc44-77fg/GHSA-xfff-jc44-77fg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xfff-jc44-77fg", - "modified": "2022-12-29T18:30:23Z", + "modified": "2025-04-17T15:32:30Z", "published": "2022-12-20T15:30:37Z", "aliases": [ "CVE-2022-45942" @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-78", "CWE-94" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/02/GHSA-q3rr-g46f-jgqr/GHSA-q3rr-g46f-jgqr.json b/advisories/unreviewed/2025/02/GHSA-q3rr-g46f-jgqr/GHSA-q3rr-g46f-jgqr.json index cf8f1b7760b..7e6dee4a426 100644 --- a/advisories/unreviewed/2025/02/GHSA-q3rr-g46f-jgqr/GHSA-q3rr-g46f-jgqr.json +++ b/advisories/unreviewed/2025/02/GHSA-q3rr-g46f-jgqr/GHSA-q3rr-g46f-jgqr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q3rr-g46f-jgqr", - "modified": "2025-04-11T00:31:35Z", + "modified": "2025-04-17T15:32:32Z", "published": "2025-02-19T21:31:38Z", "aliases": [ "CVE-2025-0624" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-0624" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:3780" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:3577" diff --git a/advisories/unreviewed/2025/03/GHSA-475h-5v9w-xfp6/GHSA-475h-5v9w-xfp6.json b/advisories/unreviewed/2025/03/GHSA-475h-5v9w-xfp6/GHSA-475h-5v9w-xfp6.json index 223dae6e67b..ae13d33e821 100644 --- a/advisories/unreviewed/2025/03/GHSA-475h-5v9w-xfp6/GHSA-475h-5v9w-xfp6.json +++ b/advisories/unreviewed/2025/03/GHSA-475h-5v9w-xfp6/GHSA-475h-5v9w-xfp6.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-69xp-rrpm-qmj5/GHSA-69xp-rrpm-qmj5.json b/advisories/unreviewed/2025/03/GHSA-69xp-rrpm-qmj5/GHSA-69xp-rrpm-qmj5.json index a2b2aa3d817..737f4d30d8e 100644 --- a/advisories/unreviewed/2025/03/GHSA-69xp-rrpm-qmj5/GHSA-69xp-rrpm-qmj5.json +++ b/advisories/unreviewed/2025/03/GHSA-69xp-rrpm-qmj5/GHSA-69xp-rrpm-qmj5.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-404" + "CWE-404", + "CWE-476" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-8j53-82pv-32wq/GHSA-8j53-82pv-32wq.json b/advisories/unreviewed/2025/03/GHSA-8j53-82pv-32wq/GHSA-8j53-82pv-32wq.json index 367a88a93a6..2fd65ea8d09 100644 --- a/advisories/unreviewed/2025/03/GHSA-8j53-82pv-32wq/GHSA-8j53-82pv-32wq.json +++ b/advisories/unreviewed/2025/03/GHSA-8j53-82pv-32wq/GHSA-8j53-82pv-32wq.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-415" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-fqw7-q4hr-f893/GHSA-fqw7-q4hr-f893.json b/advisories/unreviewed/2025/03/GHSA-fqw7-q4hr-f893/GHSA-fqw7-q4hr-f893.json index 8c99ef75f74..d9ce386013a 100644 --- a/advisories/unreviewed/2025/03/GHSA-fqw7-q4hr-f893/GHSA-fqw7-q4hr-f893.json +++ b/advisories/unreviewed/2025/03/GHSA-fqw7-q4hr-f893/GHSA-fqw7-q4hr-f893.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-j456-qg26-rqx4/GHSA-j456-qg26-rqx4.json b/advisories/unreviewed/2025/03/GHSA-j456-qg26-rqx4/GHSA-j456-qg26-rqx4.json index 6dafa40fb67..e3af5ce5101 100644 --- a/advisories/unreviewed/2025/03/GHSA-j456-qg26-rqx4/GHSA-j456-qg26-rqx4.json +++ b/advisories/unreviewed/2025/03/GHSA-j456-qg26-rqx4/GHSA-j456-qg26-rqx4.json @@ -54,7 +54,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-125" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-3x28-h2m6-h5pv/GHSA-3x28-h2m6-h5pv.json b/advisories/unreviewed/2025/04/GHSA-3x28-h2m6-h5pv/GHSA-3x28-h2m6-h5pv.json index e7508086ea9..5e15fac5aa9 100644 --- a/advisories/unreviewed/2025/04/GHSA-3x28-h2m6-h5pv/GHSA-3x28-h2m6-h5pv.json +++ b/advisories/unreviewed/2025/04/GHSA-3x28-h2m6-h5pv/GHSA-3x28-h2m6-h5pv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3x28-h2m6-h5pv", - "modified": "2025-04-16T06:31:01Z", + "modified": "2025-04-17T15:32:33Z", "published": "2025-04-16T06:31:01Z", "aliases": [ "CVE-2024-10680" ], "details": "The Form Maker by 10Web WordPress plugin before 1.15.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T06:15:42Z" diff --git a/advisories/unreviewed/2025/04/GHSA-66qf-7h58-9q6q/GHSA-66qf-7h58-9q6q.json b/advisories/unreviewed/2025/04/GHSA-66qf-7h58-9q6q/GHSA-66qf-7h58-9q6q.json index 6703225bf7f..5e4b9447820 100644 --- a/advisories/unreviewed/2025/04/GHSA-66qf-7h58-9q6q/GHSA-66qf-7h58-9q6q.json +++ b/advisories/unreviewed/2025/04/GHSA-66qf-7h58-9q6q/GHSA-66qf-7h58-9q6q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-66qf-7h58-9q6q", - "modified": "2025-04-16T18:31:54Z", + "modified": "2025-04-17T15:32:33Z", "published": "2025-04-16T18:31:54Z", "aliases": [ "CVE-2024-53303" ], "details": "A remote code execution (RCE) vulnerability in the upload_file function of LRQA Nettitude PoshC2 after commit 123db87 allows authenticated attackers to execute arbitrary code via a crafted POST request.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T18:16:03Z" diff --git a/advisories/unreviewed/2025/04/GHSA-7c77-7vhg-xpxp/GHSA-7c77-7vhg-xpxp.json b/advisories/unreviewed/2025/04/GHSA-7c77-7vhg-xpxp/GHSA-7c77-7vhg-xpxp.json new file mode 100644 index 00000000000..9a9bb8583ab --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7c77-7vhg-xpxp/GHSA-7c77-7vhg-xpxp.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7c77-7vhg-xpxp", + "modified": "2025-04-17T15:32:36Z", + "published": "2025-04-17T15:32:36Z", + "aliases": [ + "CVE-2025-29044" + ], + "details": "Buffer Overflow vulnerability in Netgear- R61 router V1.0.1.28 allows a remote attacker to execute arbitrary code via the QUERY_STRING key value", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29044" + }, + { + "type": "WEB", + "url": "https://gist.github.com/xyqer1/09fe6488a6655776c8c5d33e630a0f2a" + }, + { + "type": "WEB", + "url": "https://github.com/xyqer1/Netgear-R6100-cgiMain-QUERY_STRING-StackOverflow?tab=readme-ov-file" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T15:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7hqv-m3mr-cv2v/GHSA-7hqv-m3mr-cv2v.json b/advisories/unreviewed/2025/04/GHSA-7hqv-m3mr-cv2v/GHSA-7hqv-m3mr-cv2v.json new file mode 100644 index 00000000000..ea4b479e97c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7hqv-m3mr-cv2v/GHSA-7hqv-m3mr-cv2v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7hqv-m3mr-cv2v", + "modified": "2025-04-17T15:32:36Z", + "published": "2025-04-17T15:32:36Z", + "aliases": [ + "CVE-2025-25234" + ], + "details": "Omnissa UAG contains a Cross-Origin Resource Sharing (CORS) bypass vulnerability. A malicious actor with network access to UAG may be able to bypass administrator-configured CORS restrictions to gain access to sensitive networks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25234" + }, + { + "type": "WEB", + "url": "https://static.omnissa.com/sites/default/files/OMSA-2025-0002.pdf" + }, + { + "type": "WEB", + "url": "https://www.omnissa.com/omnissa-security-response" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T15:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8qh5-83cf-f7qw/GHSA-8qh5-83cf-f7qw.json b/advisories/unreviewed/2025/04/GHSA-8qh5-83cf-f7qw/GHSA-8qh5-83cf-f7qw.json new file mode 100644 index 00000000000..72c5a727c88 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8qh5-83cf-f7qw/GHSA-8qh5-83cf-f7qw.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8qh5-83cf-f7qw", + "modified": "2025-04-17T15:32:37Z", + "published": "2025-04-17T15:32:37Z", + "aliases": [ + "CVE-2025-29047" + ], + "details": "Buffer Overflow vulnerability inALFA WiFi CampPro router ALFA_CAMPRO-co-2.29 allows a remote attacker to execute arbitrary code via the hiddenIndex in the function StorageEditUser", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29047" + }, + { + "type": "WEB", + "url": "https://gist.github.com/xyqer1/74adbc0249eeacf762fb4d33cf93a0f5" + }, + { + "type": "WEB", + "url": "https://github.com/xyqer1/ALFA-WiFi-CampPro-StorageEditUser-hiddenIndex" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T15:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8x2h-39pf-v8fc/GHSA-8x2h-39pf-v8fc.json b/advisories/unreviewed/2025/04/GHSA-8x2h-39pf-v8fc/GHSA-8x2h-39pf-v8fc.json new file mode 100644 index 00000000000..c0e12573602 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8x2h-39pf-v8fc/GHSA-8x2h-39pf-v8fc.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8x2h-39pf-v8fc", + "modified": "2025-04-17T15:32:37Z", + "published": "2025-04-17T15:32:37Z", + "aliases": [ + "CVE-2025-29046" + ], + "details": "Buffer Overflow vulnerability inALFA WiFi CampPro router ALFA_CAMPRO-co-2.29 allows a remote attacker to execute arbitrary code via the GAPSMinute3 key value", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29046" + }, + { + "type": "WEB", + "url": "https://gist.github.com/xyqer1/7f9970240aec0af412caee79271a5be5" + }, + { + "type": "WEB", + "url": "https://github.com/xyqer1/ALFA-WiFi-CampPro-GreenAP-GAPSMinute3" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T15:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9vh5-xhwh-w9v4/GHSA-9vh5-xhwh-w9v4.json b/advisories/unreviewed/2025/04/GHSA-9vh5-xhwh-w9v4/GHSA-9vh5-xhwh-w9v4.json index 174c3120099..2c22872add0 100644 --- a/advisories/unreviewed/2025/04/GHSA-9vh5-xhwh-w9v4/GHSA-9vh5-xhwh-w9v4.json +++ b/advisories/unreviewed/2025/04/GHSA-9vh5-xhwh-w9v4/GHSA-9vh5-xhwh-w9v4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9vh5-xhwh-w9v4", - "modified": "2025-04-16T21:30:59Z", + "modified": "2025-04-17T15:32:35Z", "published": "2025-04-16T21:30:59Z", "aliases": [ "CVE-2025-29709" ], "details": "SourceCodester Company Website CMS 1.0 has a File upload vulnerability via the \"Create portfolio\" file /dashboard/portfolio.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-73" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T21:15:47Z" diff --git a/advisories/unreviewed/2025/04/GHSA-cphf-4pm4-j37r/GHSA-cphf-4pm4-j37r.json b/advisories/unreviewed/2025/04/GHSA-cphf-4pm4-j37r/GHSA-cphf-4pm4-j37r.json new file mode 100644 index 00000000000..0ebb8f1acba --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cphf-4pm4-j37r/GHSA-cphf-4pm4-j37r.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cphf-4pm4-j37r", + "modified": "2025-04-17T15:32:37Z", + "published": "2025-04-17T15:32:37Z", + "aliases": [ + "CVE-2025-29045" + ], + "details": "Buffer Overflow vulnerability in ALFA_CAMPRO-co-2.29 allows a remote attacker to execute arbitrary code via the newap_text_0 key value", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29045" + }, + { + "type": "WEB", + "url": "https://gist.github.com/xyqer1/16f6b44ef062374bc32c12952c7b81f8" + }, + { + "type": "WEB", + "url": "https://github.com/xyqer1/ALFA-WiFi-CampPro-APSecurity-newap_text_0" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T15:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cwh3-jw96-rmr6/GHSA-cwh3-jw96-rmr6.json b/advisories/unreviewed/2025/04/GHSA-cwh3-jw96-rmr6/GHSA-cwh3-jw96-rmr6.json new file mode 100644 index 00000000000..d1ce3d0a9d3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cwh3-jw96-rmr6/GHSA-cwh3-jw96-rmr6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cwh3-jw96-rmr6", + "modified": "2025-04-17T15:32:37Z", + "published": "2025-04-17T15:32:37Z", + "aliases": [ + "CVE-2025-3651" + ], + "details": "Improper Verification of Source of a Communication Channel in Work Desktop for Mac versions below 10.8.2.33 allows attackers to execute arbitrary commands via unauthorized access to the Agent service.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3651" + }, + { + "type": "WEB", + "url": "https://docs.imanage.com/security/CVE-2025-3651.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-346" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T15:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fchw-5m8f-5fmf/GHSA-fchw-5m8f-5fmf.json b/advisories/unreviewed/2025/04/GHSA-fchw-5m8f-5fmf/GHSA-fchw-5m8f-5fmf.json new file mode 100644 index 00000000000..1965f5b1fef --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fchw-5m8f-5fmf/GHSA-fchw-5m8f-5fmf.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fchw-5m8f-5fmf", + "modified": "2025-04-17T15:32:36Z", + "published": "2025-04-17T15:32:35Z", + "aliases": [ + "CVE-2025-29015" + ], + "details": "Code Astro Internet Banking System 2.0.0 is vulnerable to Cross Site Scripting (XSS) via the name parameter in /admin/pages_account.php.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29015" + }, + { + "type": "WEB", + "url": "https://github.com/b1tm4r/CVE-2025-29015" + }, + { + "type": "WEB", + "url": "https://www.cvedetails.com/vulnerability-list/opxss-1/cross-site-scripting.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T14:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fq75-mrrq-hvmj/GHSA-fq75-mrrq-hvmj.json b/advisories/unreviewed/2025/04/GHSA-fq75-mrrq-hvmj/GHSA-fq75-mrrq-hvmj.json new file mode 100644 index 00000000000..ac1ce53b404 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fq75-mrrq-hvmj/GHSA-fq75-mrrq-hvmj.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fq75-mrrq-hvmj", + "modified": "2025-04-17T15:32:36Z", + "published": "2025-04-17T15:32:36Z", + "aliases": [ + "CVE-2025-29041" + ], + "details": "An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and the function 0x41710c", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29041" + }, + { + "type": "WEB", + "url": "https://gist.github.com/xyqer1/101b7308bdf8618d8be30bd1d09ddd38" + }, + { + "type": "WEB", + "url": "https://github.com/xyqer1/Dlink-dir-823x-diag_nslookup-target_addr-CommandInjection" + }, + { + "type": "WEB", + "url": "https://www.dlink.com/en/security-bulletin" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T15:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fqxf-49hh-94mj/GHSA-fqxf-49hh-94mj.json b/advisories/unreviewed/2025/04/GHSA-fqxf-49hh-94mj/GHSA-fqxf-49hh-94mj.json index 5205c85e780..43fe4ee0754 100644 --- a/advisories/unreviewed/2025/04/GHSA-fqxf-49hh-94mj/GHSA-fqxf-49hh-94mj.json +++ b/advisories/unreviewed/2025/04/GHSA-fqxf-49hh-94mj/GHSA-fqxf-49hh-94mj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fqxf-49hh-94mj", - "modified": "2025-04-16T21:30:58Z", + "modified": "2025-04-17T15:32:34Z", "published": "2025-04-16T21:30:58Z", "aliases": [ "CVE-2024-55372" ], "details": "Wallos <=2.38.2 has a file upload vulnerability in the restore database function, which allows unauthenticated users to restore database by uploading a ZIP file. The contents of the ZIP file are extracted on the server. This functionality enables an unauthenticated attacker to upload malicious files to the server. Once a web shell is installed, the attacker gains the ability to execute arbitrary commands.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-73" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T21:15:45Z" diff --git a/advisories/unreviewed/2025/04/GHSA-h4fr-qhv5-6jfq/GHSA-h4fr-qhv5-6jfq.json b/advisories/unreviewed/2025/04/GHSA-h4fr-qhv5-6jfq/GHSA-h4fr-qhv5-6jfq.json index 4c8ed4e2334..6f2e998eae6 100644 --- a/advisories/unreviewed/2025/04/GHSA-h4fr-qhv5-6jfq/GHSA-h4fr-qhv5-6jfq.json +++ b/advisories/unreviewed/2025/04/GHSA-h4fr-qhv5-6jfq/GHSA-h4fr-qhv5-6jfq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h4fr-qhv5-6jfq", - "modified": "2025-04-17T00:30:26Z", + "modified": "2025-04-17T15:32:35Z", "published": "2025-04-17T00:30:26Z", "aliases": [ "CVE-2025-1568" ], "details": "Access Control Vulnerability in Gerrit chromiumos project configuration in Google ChromeOS 131.0.6778.268 allows an attacker with a registered Gerrit account to inject malicious code into ChromeOS projects and potentially achieve Remote Code Execution and Denial of Service via editing trusted pipelines by insufficient access controls and misconfigurations in Gerrit's project.config.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T23:15:44Z" diff --git a/advisories/unreviewed/2025/04/GHSA-j53w-h88v-2v3x/GHSA-j53w-h88v-2v3x.json b/advisories/unreviewed/2025/04/GHSA-j53w-h88v-2v3x/GHSA-j53w-h88v-2v3x.json index 305f456bd1e..9b3b78c7fc6 100644 --- a/advisories/unreviewed/2025/04/GHSA-j53w-h88v-2v3x/GHSA-j53w-h88v-2v3x.json +++ b/advisories/unreviewed/2025/04/GHSA-j53w-h88v-2v3x/GHSA-j53w-h88v-2v3x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j53w-h88v-2v3x", - "modified": "2025-04-16T03:30:24Z", + "modified": "2025-04-17T15:32:33Z", "published": "2025-04-16T03:30:24Z", "aliases": [ "CVE-2025-3665" @@ -23,6 +23,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3665" }, + { + "type": "WEB", + "url": "https://lavender-bicycle-a5a.notion.site/TOTOLINK-A3700R-setSmartQosCfg-1cb53a41781f80ce9b7aca2c6ff9bea4" + }, { "type": "WEB", "url": "https://lavender-bicycle-a5a.notion.site/TOTOLINK-A3700R-setSmartQosCfg-1cb53a41781f80ce9b7aca2c6ff9bea4?pvs=4" diff --git a/advisories/unreviewed/2025/04/GHSA-j9rv-6qvq-mvqj/GHSA-j9rv-6qvq-mvqj.json b/advisories/unreviewed/2025/04/GHSA-j9rv-6qvq-mvqj/GHSA-j9rv-6qvq-mvqj.json index 7b45229fb42..337817168b8 100644 --- a/advisories/unreviewed/2025/04/GHSA-j9rv-6qvq-mvqj/GHSA-j9rv-6qvq-mvqj.json +++ b/advisories/unreviewed/2025/04/GHSA-j9rv-6qvq-mvqj/GHSA-j9rv-6qvq-mvqj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j9rv-6qvq-mvqj", - "modified": "2025-04-16T21:30:59Z", + "modified": "2025-04-17T15:32:35Z", "published": "2025-04-16T21:30:59Z", "aliases": [ "CVE-2025-3620" ], "details": "Use after free in USB in Google Chrome prior to 135.0.7049.95 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T21:15:48Z" diff --git a/advisories/unreviewed/2025/04/GHSA-jj4c-9qx7-h4pc/GHSA-jj4c-9qx7-h4pc.json b/advisories/unreviewed/2025/04/GHSA-jj4c-9qx7-h4pc/GHSA-jj4c-9qx7-h4pc.json index b2081d28156..b2f4b6b0398 100644 --- a/advisories/unreviewed/2025/04/GHSA-jj4c-9qx7-h4pc/GHSA-jj4c-9qx7-h4pc.json +++ b/advisories/unreviewed/2025/04/GHSA-jj4c-9qx7-h4pc/GHSA-jj4c-9qx7-h4pc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jj4c-9qx7-h4pc", - "modified": "2025-04-16T21:30:59Z", + "modified": "2025-04-17T15:32:34Z", "published": "2025-04-16T21:30:59Z", "aliases": [ "CVE-2025-29708" ], "details": "SourceCodester Company Website CMS 1.0 contains a file upload vulnerability via the \"Create Services\" file /dashboard/Services.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-73" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T21:15:47Z" diff --git a/advisories/unreviewed/2025/04/GHSA-jpv9-q37j-qv98/GHSA-jpv9-q37j-qv98.json b/advisories/unreviewed/2025/04/GHSA-jpv9-q37j-qv98/GHSA-jpv9-q37j-qv98.json index 1e559edb048..ea35a255f3b 100644 --- a/advisories/unreviewed/2025/04/GHSA-jpv9-q37j-qv98/GHSA-jpv9-q37j-qv98.json +++ b/advisories/unreviewed/2025/04/GHSA-jpv9-q37j-qv98/GHSA-jpv9-q37j-qv98.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jpv9-q37j-qv98", - "modified": "2025-04-16T21:30:57Z", + "modified": "2025-04-17T15:32:33Z", "published": "2025-04-16T21:30:57Z", "aliases": [ "CVE-2025-29651" ], "details": "SQL Injection vulnerability exists in the TP-Link M7650 4G LTE Mobile Wi-Fi Router Firmware Version: 1.0.7 Build 170623 Rel.1022n, allowing an unauthenticated attacker to inject malicious SQL statements via the username and password fields.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T20:15:17Z" diff --git a/advisories/unreviewed/2025/04/GHSA-mc54-4f73-wx8x/GHSA-mc54-4f73-wx8x.json b/advisories/unreviewed/2025/04/GHSA-mc54-4f73-wx8x/GHSA-mc54-4f73-wx8x.json index ee88668337e..c7645b4f965 100644 --- a/advisories/unreviewed/2025/04/GHSA-mc54-4f73-wx8x/GHSA-mc54-4f73-wx8x.json +++ b/advisories/unreviewed/2025/04/GHSA-mc54-4f73-wx8x/GHSA-mc54-4f73-wx8x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mc54-4f73-wx8x", - "modified": "2025-04-16T21:30:59Z", + "modified": "2025-04-17T15:32:34Z", "published": "2025-04-16T21:30:59Z", "aliases": [ "CVE-2025-28072" ], "details": "PHPGurukul Pre-School Enrollment System is vulnerable to Directory Traversal in manage-teachers.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T21:15:46Z" diff --git a/advisories/unreviewed/2025/04/GHSA-mhjg-qmr3-w2xc/GHSA-mhjg-qmr3-w2xc.json b/advisories/unreviewed/2025/04/GHSA-mhjg-qmr3-w2xc/GHSA-mhjg-qmr3-w2xc.json index f110a1486c9..3291d047cd8 100644 --- a/advisories/unreviewed/2025/04/GHSA-mhjg-qmr3-w2xc/GHSA-mhjg-qmr3-w2xc.json +++ b/advisories/unreviewed/2025/04/GHSA-mhjg-qmr3-w2xc/GHSA-mhjg-qmr3-w2xc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mhjg-qmr3-w2xc", - "modified": "2025-04-17T00:30:26Z", + "modified": "2025-04-17T15:32:35Z", "published": "2025-04-17T00:30:26Z", "aliases": [ "CVE-2025-1704" ], "details": "ComponentInstaller Modification in ComponentInstaller in Google ChromeOS 124.0.6367.34 on Chromebooks allows enrolled users with local access to unenroll devices \nand intercept device management requests via loading components from the unencrypted stateful partition.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T23:15:44Z" diff --git a/advisories/unreviewed/2025/04/GHSA-mp2g-3625-m5pp/GHSA-mp2g-3625-m5pp.json b/advisories/unreviewed/2025/04/GHSA-mp2g-3625-m5pp/GHSA-mp2g-3625-m5pp.json index bae20aa60ad..8a8980c3be5 100644 --- a/advisories/unreviewed/2025/04/GHSA-mp2g-3625-m5pp/GHSA-mp2g-3625-m5pp.json +++ b/advisories/unreviewed/2025/04/GHSA-mp2g-3625-m5pp/GHSA-mp2g-3625-m5pp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mp2g-3625-m5pp", - "modified": "2025-04-16T21:30:58Z", + "modified": "2025-04-17T15:32:34Z", "published": "2025-04-16T21:30:58Z", "aliases": [ "CVE-2024-55371" ], "details": "Wallos <= 2.38.2 has a file upload vulnerability in the restore backup function, which allows authenticated users to restore backups by uploading a ZIP file. The contents of the ZIP file are extracted on the server. This functionality enables an authenticated attacker (being an administrator is not required) to upload malicious files to the server. Once a web shell is installed, the attacker gains the ability to execute arbitrary commands.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-73" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T21:15:45Z" diff --git a/advisories/unreviewed/2025/04/GHSA-pmgp-fgv4-prx4/GHSA-pmgp-fgv4-prx4.json b/advisories/unreviewed/2025/04/GHSA-pmgp-fgv4-prx4/GHSA-pmgp-fgv4-prx4.json index df89213ec74..a85fc0c076f 100644 --- a/advisories/unreviewed/2025/04/GHSA-pmgp-fgv4-prx4/GHSA-pmgp-fgv4-prx4.json +++ b/advisories/unreviewed/2025/04/GHSA-pmgp-fgv4-prx4/GHSA-pmgp-fgv4-prx4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pmgp-fgv4-prx4", - "modified": "2025-04-16T21:30:57Z", + "modified": "2025-04-17T15:32:33Z", "published": "2025-04-16T21:30:57Z", "aliases": [ "CVE-2025-29652" ], "details": "SQL Injection vulnerability exists in the TP-Link M7000 4G LTE Mobile Wi-Fi Router Firmware Version: 1.0.7 Build 180127 Rel.55998n, allowing an unauthenticated attacker to inject malicious SQL statements via the username and password fields", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T20:15:17Z" diff --git a/advisories/unreviewed/2025/04/GHSA-pv63-22w8-6xj8/GHSA-pv63-22w8-6xj8.json b/advisories/unreviewed/2025/04/GHSA-pv63-22w8-6xj8/GHSA-pv63-22w8-6xj8.json index e36afc2c5f8..bc43abfab04 100644 --- a/advisories/unreviewed/2025/04/GHSA-pv63-22w8-6xj8/GHSA-pv63-22w8-6xj8.json +++ b/advisories/unreviewed/2025/04/GHSA-pv63-22w8-6xj8/GHSA-pv63-22w8-6xj8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pv63-22w8-6xj8", - "modified": "2025-04-17T00:30:26Z", + "modified": "2025-04-17T15:32:35Z", "published": "2025-04-17T00:30:26Z", "aliases": [ "CVE-2025-2073" ], "details": "Out-of-Bounds Read in ip_set_bitmap_ip.c in Google ChromeOS Kernel Versions 6.1, 5.15, 5.10, 5.4, 4.19. on All devices where Termina is used allows an attacker with CAP_NET_ADMIN privileges to cause memory corruption and potentially escalate privileges via crafted ipset commands.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T23:15:45Z" diff --git a/advisories/unreviewed/2025/04/GHSA-qg97-xp64-p6pc/GHSA-qg97-xp64-p6pc.json b/advisories/unreviewed/2025/04/GHSA-qg97-xp64-p6pc/GHSA-qg97-xp64-p6pc.json index 69f7e44cc38..02ada937e32 100644 --- a/advisories/unreviewed/2025/04/GHSA-qg97-xp64-p6pc/GHSA-qg97-xp64-p6pc.json +++ b/advisories/unreviewed/2025/04/GHSA-qg97-xp64-p6pc/GHSA-qg97-xp64-p6pc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qg97-xp64-p6pc", - "modified": "2025-04-16T21:30:59Z", + "modified": "2025-04-17T15:32:35Z", "published": "2025-04-16T21:30:59Z", "aliases": [ "CVE-2025-3619" ], "details": "Heap buffer overflow in Codecs in Google Chrome on Windows prior to 135.0.7049.95 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-122" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T21:15:47Z" diff --git a/advisories/unreviewed/2025/04/GHSA-qhp6-vp7c-g7xp/GHSA-qhp6-vp7c-g7xp.json b/advisories/unreviewed/2025/04/GHSA-qhp6-vp7c-g7xp/GHSA-qhp6-vp7c-g7xp.json new file mode 100644 index 00000000000..e56ddecfca5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qhp6-vp7c-g7xp/GHSA-qhp6-vp7c-g7xp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qhp6-vp7c-g7xp", + "modified": "2025-04-17T15:32:35Z", + "published": "2025-04-17T15:32:35Z", + "aliases": [ + "CVE-2025-3760" + ], + "details": "A stored cross-site scripting (XSS) vulnerability exists with radio button type custom fields in Liferay Portal 7.2.0 through 7.4.3.129, and Liferay DXP 2024.Q4.1 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.9, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, 7.3 GA through update 36, and 7.2 GA through fix pack 20 allows remote authenticated attackers to inject malicious JavaScript into a page.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3760" + }, + { + "type": "WEB", + "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2025-3760" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T13:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-r734-gfr8-7qj8/GHSA-r734-gfr8-7qj8.json b/advisories/unreviewed/2025/04/GHSA-r734-gfr8-7qj8/GHSA-r734-gfr8-7qj8.json new file mode 100644 index 00000000000..54f0151435d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-r734-gfr8-7qj8/GHSA-r734-gfr8-7qj8.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r734-gfr8-7qj8", + "modified": "2025-04-17T15:32:36Z", + "published": "2025-04-17T15:32:35Z", + "aliases": [ + "CVE-2022-26323" + ], + "details": "Incorrect Use of Privileged APIs vulnerability in OpenText™ Operations Bridge Manager, OpenText™ Operations Bridge Suite (Containerized), OpenText™ UCMDB ( Classic and Containerized) allows Privilege Escalation. \n\nThe vulnerability could allow authenticated attackers to elevate user privileges. This issue affects Operations Bridge Manager: through 2021.05; Operations Bridge Suite (Containerized): through 2021.05; UCMDB ( Classic and Containerized): through 2021.05.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:C/RE:M/U:Amber" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-26323" + }, + { + "type": "WEB", + "url": "https://portal.microfocus.com/s/article/KM000039040?language=en_US" + }, + { + "type": "WEB", + "url": "https://portal.microfocus.com/s/article/KM000039044?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-648" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T15:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rm74-9v34-j945/GHSA-rm74-9v34-j945.json b/advisories/unreviewed/2025/04/GHSA-rm74-9v34-j945/GHSA-rm74-9v34-j945.json index 336cadb743d..415b0947650 100644 --- a/advisories/unreviewed/2025/04/GHSA-rm74-9v34-j945/GHSA-rm74-9v34-j945.json +++ b/advisories/unreviewed/2025/04/GHSA-rm74-9v34-j945/GHSA-rm74-9v34-j945.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rm74-9v34-j945", - "modified": "2025-04-17T03:30:30Z", + "modified": "2025-04-17T15:32:35Z", "published": "2025-04-17T03:30:30Z", "aliases": [ "CVE-2025-1290" ], "details": "A race condition Use-After-Free vulnerability exists in the virtio_transport_space_update function within the Kernel 5.4 on ChromeOS. Concurrent allocation and freeing of the virtio_vsock_sock structure \nduring an AF_VSOCK connect syscall can occur before a worker thread accesses it resulting in a dangling pointer and potential kernel code execution.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-17T01:15:46Z" diff --git a/advisories/unreviewed/2025/04/GHSA-vp28-c453-wwjq/GHSA-vp28-c453-wwjq.json b/advisories/unreviewed/2025/04/GHSA-vp28-c453-wwjq/GHSA-vp28-c453-wwjq.json index c4f3581e14a..02264e1a6b6 100644 --- a/advisories/unreviewed/2025/04/GHSA-vp28-c453-wwjq/GHSA-vp28-c453-wwjq.json +++ b/advisories/unreviewed/2025/04/GHSA-vp28-c453-wwjq/GHSA-vp28-c453-wwjq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vp28-c453-wwjq", - "modified": "2025-04-16T21:30:57Z", + "modified": "2025-04-17T15:32:33Z", "published": "2025-04-16T21:30:57Z", "aliases": [ "CVE-2025-29653" ], "details": "SQL Injection vulnerability exists in the TP-Link M7450 4G LTE Mobile Wi-Fi Router Firmware Version: 1.0.2 Build 170306 Rel.1015n, allowing an unauthenticated attacker to inject malicious SQL statements via the username and password fields.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T20:15:17Z" diff --git a/advisories/unreviewed/2025/04/GHSA-w8ch-v2qx-54xx/GHSA-w8ch-v2qx-54xx.json b/advisories/unreviewed/2025/04/GHSA-w8ch-v2qx-54xx/GHSA-w8ch-v2qx-54xx.json new file mode 100644 index 00000000000..c35c21717f2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-w8ch-v2qx-54xx/GHSA-w8ch-v2qx-54xx.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w8ch-v2qx-54xx", + "modified": "2025-04-17T15:32:36Z", + "published": "2025-04-17T15:32:36Z", + "aliases": [ + "CVE-2025-29040" + ], + "details": "An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and the function 0x41737c", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29040" + }, + { + "type": "WEB", + "url": "https://gist.github.com/xyqer1/b3bebe4967a3093951273738f0be45ce" + }, + { + "type": "WEB", + "url": "https://github.com/xyqer1/Dlink-dir-823x-diag_ping-target_addr-CommandInjection" + }, + { + "type": "WEB", + "url": "https://www.dlink.com/en/security-bulletin" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T15:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-x2pf-6jgf-xvvw/GHSA-x2pf-6jgf-xvvw.json b/advisories/unreviewed/2025/04/GHSA-x2pf-6jgf-xvvw/GHSA-x2pf-6jgf-xvvw.json index 4b653ad28f6..935c9c9aaa5 100644 --- a/advisories/unreviewed/2025/04/GHSA-x2pf-6jgf-xvvw/GHSA-x2pf-6jgf-xvvw.json +++ b/advisories/unreviewed/2025/04/GHSA-x2pf-6jgf-xvvw/GHSA-x2pf-6jgf-xvvw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x2pf-6jgf-xvvw", - "modified": "2025-04-17T00:30:25Z", + "modified": "2025-04-17T15:32:35Z", "published": "2025-04-17T00:30:25Z", "aliases": [ "CVE-2025-25230" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null,