From d81637fad03616eb7fb520732a1ed40df1fd46ac Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 25 Apr 2025 18:33:00 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-r6j6-xp6q-c876.json | 2 +- .../GHSA-292h-xrr4-85pg.json | 4 +- .../GHSA-3vg4-f6rw-v3x2.json | 2 +- .../GHSA-c4w8-pfrf-hc8p.json | 2 +- .../GHSA-c9xc-qcg9-c8hr.json | 10 ++++- .../GHSA-fp36-pmr8-vj9p.json | 2 +- .../GHSA-hgwc-78jr-63c3.json | 2 +- .../GHSA-pffr-gxw6-r2q7.json | 2 +- .../GHSA-v773-rxxh-3x8r.json | 1 + .../GHSA-wxc6-2xqr-q2pg.json | 2 +- .../GHSA-2x7c-w8p7-47f7.json | 6 ++- .../GHSA-8xp8-gmmj-xc8w.json | 6 ++- .../GHSA-2q5p-jwm7-4gq8.json | 25 ++++++++++++ .../GHSA-2ww5-c4rg-76jh.json | 40 +++++++++++++++++++ .../GHSA-58xr-825m-v3pq.json | 40 +++++++++++++++++++ .../GHSA-6mpj-6mgp-p7v6.json | 40 +++++++++++++++++++ .../GHSA-7885-whv3-46f6.json | 40 +++++++++++++++++++ .../GHSA-794f-v4rm-x7r5.json | 6 ++- .../GHSA-7g9q-ww3r-j77g.json | 36 +++++++++++++++++ .../GHSA-99q6-5j8j-4wv8.json | 15 +++++-- .../GHSA-9m3r-h728-px2f.json | 15 +++++-- .../GHSA-qhx4-9cx2-q4rc.json | 15 +++++-- .../GHSA-rgw7-rhh8-mgf9.json | 15 +++++-- .../GHSA-wqxv-v2vg-q37x.json | 38 ++++++++++++++++++ .../GHSA-xrq2-2h92-m6m8.json | 1 + .../GHSA-xv35-w389-wr74.json | 36 +++++++++++++++++ 26 files changed, 375 insertions(+), 28 deletions(-) create mode 100644 advisories/unreviewed/2025/04/GHSA-2q5p-jwm7-4gq8/GHSA-2q5p-jwm7-4gq8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-2ww5-c4rg-76jh/GHSA-2ww5-c4rg-76jh.json create mode 100644 advisories/unreviewed/2025/04/GHSA-58xr-825m-v3pq/GHSA-58xr-825m-v3pq.json create mode 100644 advisories/unreviewed/2025/04/GHSA-6mpj-6mgp-p7v6/GHSA-6mpj-6mgp-p7v6.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7885-whv3-46f6/GHSA-7885-whv3-46f6.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7g9q-ww3r-j77g/GHSA-7g9q-ww3r-j77g.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wqxv-v2vg-q37x/GHSA-wqxv-v2vg-q37x.json create mode 100644 advisories/unreviewed/2025/04/GHSA-xv35-w389-wr74/GHSA-xv35-w389-wr74.json diff --git a/advisories/unreviewed/2022/02/GHSA-r6j6-xp6q-c876/GHSA-r6j6-xp6q-c876.json b/advisories/unreviewed/2022/02/GHSA-r6j6-xp6q-c876/GHSA-r6j6-xp6q-c876.json index 0ca8d8a718e..a4d48722480 100644 --- a/advisories/unreviewed/2022/02/GHSA-r6j6-xp6q-c876/GHSA-r6j6-xp6q-c876.json +++ b/advisories/unreviewed/2022/02/GHSA-r6j6-xp6q-c876/GHSA-r6j6-xp6q-c876.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r6j6-xp6q-c876", - "modified": "2022-04-13T00:01:07Z", + "modified": "2025-04-25T18:31:01Z", "published": "2022-02-22T00:00:22Z", "aliases": [ "CVE-2022-0564" diff --git a/advisories/unreviewed/2022/11/GHSA-292h-xrr4-85pg/GHSA-292h-xrr4-85pg.json b/advisories/unreviewed/2022/11/GHSA-292h-xrr4-85pg/GHSA-292h-xrr4-85pg.json index a0f83b826c2..04c1ff9ea1b 100644 --- a/advisories/unreviewed/2022/11/GHSA-292h-xrr4-85pg/GHSA-292h-xrr4-85pg.json +++ b/advisories/unreviewed/2022/11/GHSA-292h-xrr4-85pg/GHSA-292h-xrr4-85pg.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-3vg4-f6rw-v3x2/GHSA-3vg4-f6rw-v3x2.json b/advisories/unreviewed/2022/11/GHSA-3vg4-f6rw-v3x2/GHSA-3vg4-f6rw-v3x2.json index be878f918d0..45289b174b5 100644 --- a/advisories/unreviewed/2022/11/GHSA-3vg4-f6rw-v3x2/GHSA-3vg4-f6rw-v3x2.json +++ b/advisories/unreviewed/2022/11/GHSA-3vg4-f6rw-v3x2/GHSA-3vg4-f6rw-v3x2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3vg4-f6rw-v3x2", - "modified": "2022-11-30T21:30:22Z", + "modified": "2025-04-25T18:31:01Z", "published": "2022-11-25T18:30:25Z", "aliases": [ "CVE-2022-23044" diff --git a/advisories/unreviewed/2022/11/GHSA-c4w8-pfrf-hc8p/GHSA-c4w8-pfrf-hc8p.json b/advisories/unreviewed/2022/11/GHSA-c4w8-pfrf-hc8p/GHSA-c4w8-pfrf-hc8p.json index 726eef60476..8dc3c43e741 100644 --- a/advisories/unreviewed/2022/11/GHSA-c4w8-pfrf-hc8p/GHSA-c4w8-pfrf-hc8p.json +++ b/advisories/unreviewed/2022/11/GHSA-c4w8-pfrf-hc8p/GHSA-c4w8-pfrf-hc8p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c4w8-pfrf-hc8p", - "modified": "2022-11-30T21:30:22Z", + "modified": "2025-04-25T18:31:01Z", "published": "2022-11-25T06:30:22Z", "aliases": [ "CVE-2022-36133" diff --git a/advisories/unreviewed/2022/11/GHSA-c9xc-qcg9-c8hr/GHSA-c9xc-qcg9-c8hr.json b/advisories/unreviewed/2022/11/GHSA-c9xc-qcg9-c8hr/GHSA-c9xc-qcg9-c8hr.json index 2a0ee9a06c8..cac64ae3627 100644 --- a/advisories/unreviewed/2022/11/GHSA-c9xc-qcg9-c8hr/GHSA-c9xc-qcg9-c8hr.json +++ b/advisories/unreviewed/2022/11/GHSA-c9xc-qcg9-c8hr/GHSA-c9xc-qcg9-c8hr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c9xc-qcg9-c8hr", - "modified": "2022-11-30T06:30:26Z", + "modified": "2025-04-25T18:31:04Z", "published": "2022-11-29T06:30:19Z", "aliases": [ "CVE-2022-42109" @@ -23,6 +23,14 @@ "type": "WEB", "url": "https://github.com/PuneethReddyHC/online-shopping-system-advanced" }, + { + "type": "WEB", + "url": "https://grimthereaperteam.medium.com/online-shopping-system-advanced-sql-injection-at-product-php-c55c435c35c2" + }, + { + "type": "WEB", + "url": "https://medium.com/%40grimthereaperteam/online-shopping-system-advanced-sql-injection-at-product-php-c55c435c35c2" + }, { "type": "WEB", "url": "https://medium.com/@grimthereaperteam/online-shopping-system-advanced-sql-injection-at-product-php-c55c435c35c2" diff --git a/advisories/unreviewed/2022/11/GHSA-fp36-pmr8-vj9p/GHSA-fp36-pmr8-vj9p.json b/advisories/unreviewed/2022/11/GHSA-fp36-pmr8-vj9p/GHSA-fp36-pmr8-vj9p.json index 85897a2a4ca..b70d6aec253 100644 --- a/advisories/unreviewed/2022/11/GHSA-fp36-pmr8-vj9p/GHSA-fp36-pmr8-vj9p.json +++ b/advisories/unreviewed/2022/11/GHSA-fp36-pmr8-vj9p/GHSA-fp36-pmr8-vj9p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fp36-pmr8-vj9p", - "modified": "2022-11-30T06:30:27Z", + "modified": "2025-04-25T18:31:03Z", "published": "2022-11-28T15:30:24Z", "aliases": [ "CVE-2022-3848" diff --git a/advisories/unreviewed/2022/11/GHSA-hgwc-78jr-63c3/GHSA-hgwc-78jr-63c3.json b/advisories/unreviewed/2022/11/GHSA-hgwc-78jr-63c3/GHSA-hgwc-78jr-63c3.json index 66951fdc1ab..04bc2879415 100644 --- a/advisories/unreviewed/2022/11/GHSA-hgwc-78jr-63c3/GHSA-hgwc-78jr-63c3.json +++ b/advisories/unreviewed/2022/11/GHSA-hgwc-78jr-63c3/GHSA-hgwc-78jr-63c3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hgwc-78jr-63c3", - "modified": "2022-11-30T06:30:27Z", + "modified": "2025-04-25T18:31:02Z", "published": "2022-11-28T15:30:24Z", "aliases": [ "CVE-2022-3768" diff --git a/advisories/unreviewed/2022/11/GHSA-pffr-gxw6-r2q7/GHSA-pffr-gxw6-r2q7.json b/advisories/unreviewed/2022/11/GHSA-pffr-gxw6-r2q7/GHSA-pffr-gxw6-r2q7.json index 03b3d892d98..bf10070f5f5 100644 --- a/advisories/unreviewed/2022/11/GHSA-pffr-gxw6-r2q7/GHSA-pffr-gxw6-r2q7.json +++ b/advisories/unreviewed/2022/11/GHSA-pffr-gxw6-r2q7/GHSA-pffr-gxw6-r2q7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pffr-gxw6-r2q7", - "modified": "2022-11-30T00:30:37Z", + "modified": "2025-04-25T18:31:02Z", "published": "2022-11-25T18:30:26Z", "aliases": [ "CVE-2022-37720" diff --git a/advisories/unreviewed/2022/11/GHSA-v773-rxxh-3x8r/GHSA-v773-rxxh-3x8r.json b/advisories/unreviewed/2022/11/GHSA-v773-rxxh-3x8r/GHSA-v773-rxxh-3x8r.json index d1898a5ff3a..bb1055f0047 100644 --- a/advisories/unreviewed/2022/11/GHSA-v773-rxxh-3x8r/GHSA-v773-rxxh-3x8r.json +++ b/advisories/unreviewed/2022/11/GHSA-v773-rxxh-3x8r/GHSA-v773-rxxh-3x8r.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-287" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/11/GHSA-wxc6-2xqr-q2pg/GHSA-wxc6-2xqr-q2pg.json b/advisories/unreviewed/2022/11/GHSA-wxc6-2xqr-q2pg/GHSA-wxc6-2xqr-q2pg.json index d7480141453..a75cc45e705 100644 --- a/advisories/unreviewed/2022/11/GHSA-wxc6-2xqr-q2pg/GHSA-wxc6-2xqr-q2pg.json +++ b/advisories/unreviewed/2022/11/GHSA-wxc6-2xqr-q2pg/GHSA-wxc6-2xqr-q2pg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wxc6-2xqr-q2pg", - "modified": "2022-11-29T21:30:26Z", + "modified": "2025-04-25T18:31:01Z", "published": "2022-11-25T06:30:22Z", "aliases": [ "CVE-2022-2721" diff --git a/advisories/unreviewed/2024/12/GHSA-2x7c-w8p7-47f7/GHSA-2x7c-w8p7-47f7.json b/advisories/unreviewed/2024/12/GHSA-2x7c-w8p7-47f7/GHSA-2x7c-w8p7-47f7.json index 634d98eefcd..6b212910355 100644 --- a/advisories/unreviewed/2024/12/GHSA-2x7c-w8p7-47f7/GHSA-2x7c-w8p7-47f7.json +++ b/advisories/unreviewed/2024/12/GHSA-2x7c-w8p7-47f7/GHSA-2x7c-w8p7-47f7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2x7c-w8p7-47f7", - "modified": "2024-12-26T21:30:36Z", + "modified": "2025-04-25T18:31:10Z", "published": "2024-12-25T18:30:45Z", "aliases": [ "CVE-2024-56430" @@ -30,6 +30,10 @@ { "type": "WEB", "url": "https://github.com/openfheorg/openfhe-development/releases/tag/v1.2.3" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/04/25/3" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/12/GHSA-8xp8-gmmj-xc8w/GHSA-8xp8-gmmj-xc8w.json b/advisories/unreviewed/2024/12/GHSA-8xp8-gmmj-xc8w/GHSA-8xp8-gmmj-xc8w.json index 2d5b800e79b..e0508674457 100644 --- a/advisories/unreviewed/2024/12/GHSA-8xp8-gmmj-xc8w/GHSA-8xp8-gmmj-xc8w.json +++ b/advisories/unreviewed/2024/12/GHSA-8xp8-gmmj-xc8w/GHSA-8xp8-gmmj-xc8w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8xp8-gmmj-xc8w", - "modified": "2024-12-31T21:30:45Z", + "modified": "2025-04-25T18:31:10Z", "published": "2024-12-25T18:30:45Z", "aliases": [ "CVE-2024-56431" @@ -30,6 +30,10 @@ { "type": "WEB", "url": "https://github.com/xiph/theora/blob/7180717276af1ebc7da15c83162d6c5d6203aabf/lib/huffdec.c#L193" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/04/25/4" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/04/GHSA-2q5p-jwm7-4gq8/GHSA-2q5p-jwm7-4gq8.json b/advisories/unreviewed/2025/04/GHSA-2q5p-jwm7-4gq8/GHSA-2q5p-jwm7-4gq8.json new file mode 100644 index 00000000000..541fadfd4d8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2q5p-jwm7-4gq8/GHSA-2q5p-jwm7-4gq8.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2q5p-jwm7-4gq8", + "modified": "2025-04-25T18:31:11Z", + "published": "2025-04-25T18:31:11Z", + "aliases": [ + "CVE-2021-32601" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-32601" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-25T16:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2ww5-c4rg-76jh/GHSA-2ww5-c4rg-76jh.json b/advisories/unreviewed/2025/04/GHSA-2ww5-c4rg-76jh/GHSA-2ww5-c4rg-76jh.json new file mode 100644 index 00000000000..e01afb5774f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2ww5-c4rg-76jh/GHSA-2ww5-c4rg-76jh.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2ww5-c4rg-76jh", + "modified": "2025-04-25T18:31:11Z", + "published": "2025-04-25T18:31:11Z", + "aliases": [ + "CVE-2025-2069" + ], + "details": "A cross-site scripting vulnerability was reported in the FileZ client that could allow execution of code if a crafted url is visited by a local user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2069" + }, + { + "type": "WEB", + "url": "https://www.filez.com/securityPolicy/2.html?1744703100" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-25T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-58xr-825m-v3pq/GHSA-58xr-825m-v3pq.json b/advisories/unreviewed/2025/04/GHSA-58xr-825m-v3pq/GHSA-58xr-825m-v3pq.json new file mode 100644 index 00000000000..d77d18763b4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-58xr-825m-v3pq/GHSA-58xr-825m-v3pq.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-58xr-825m-v3pq", + "modified": "2025-04-25T18:31:12Z", + "published": "2025-04-25T18:31:12Z", + "aliases": [ + "CVE-2025-2070" + ], + "details": "An improper XML parsing vulnerability was reported in the FileZ client that could allow arbitrary file reads on the system if a crafted url is visited by a local user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2070" + }, + { + "type": "WEB", + "url": "https://www.filez.com/securityPolicy/2.html?1744703100" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-611" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-25T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6mpj-6mgp-p7v6/GHSA-6mpj-6mgp-p7v6.json b/advisories/unreviewed/2025/04/GHSA-6mpj-6mgp-p7v6/GHSA-6mpj-6mgp-p7v6.json new file mode 100644 index 00000000000..1adbf51402e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6mpj-6mgp-p7v6/GHSA-6mpj-6mgp-p7v6.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6mpj-6mgp-p7v6", + "modified": "2025-04-25T18:31:11Z", + "published": "2025-04-25T18:31:11Z", + "aliases": [ + "CVE-2025-2068" + ], + "details": "An open redirect vulnerability was reported in the FileZ client that could allow information disclosure if a crafted url is visited by a local user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2068" + }, + { + "type": "WEB", + "url": "https://www.filez.com/securityPolicy/2.html?1744703100" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-25T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7885-whv3-46f6/GHSA-7885-whv3-46f6.json b/advisories/unreviewed/2025/04/GHSA-7885-whv3-46f6/GHSA-7885-whv3-46f6.json new file mode 100644 index 00000000000..0d59e54664a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7885-whv3-46f6/GHSA-7885-whv3-46f6.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7885-whv3-46f6", + "modified": "2025-04-25T18:31:12Z", + "published": "2025-04-25T18:31:12Z", + "aliases": [ + "CVE-2025-25775" + ], + "details": "Codeastro Bus Ticket Booking System v1.0 is vulnerable to SQL injection via the kodetiket parameter in /BusTicket-CI/tiket/cekorder.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25775" + }, + { + "type": "WEB", + "url": "https://codeastro.com/bus-ticket-booking-system-in-php-codeigniter-with-source-code" + }, + { + "type": "WEB", + "url": "https://github.com/arunmodi/Vulnerability-Research/tree/main/CVE-2025-25775" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-25T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-794f-v4rm-x7r5/GHSA-794f-v4rm-x7r5.json b/advisories/unreviewed/2025/04/GHSA-794f-v4rm-x7r5/GHSA-794f-v4rm-x7r5.json index dffcb14fb43..df44c264a31 100644 --- a/advisories/unreviewed/2025/04/GHSA-794f-v4rm-x7r5/GHSA-794f-v4rm-x7r5.json +++ b/advisories/unreviewed/2025/04/GHSA-794f-v4rm-x7r5/GHSA-794f-v4rm-x7r5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-794f-v4rm-x7r5", - "modified": "2025-04-25T03:30:33Z", + "modified": "2025-04-25T18:31:10Z", "published": "2025-04-11T09:30:24Z", "aliases": [ "CVE-2025-3512" @@ -38,6 +38,10 @@ { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2025/04/25/1" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/04/25/2" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/04/GHSA-7g9q-ww3r-j77g/GHSA-7g9q-ww3r-j77g.json b/advisories/unreviewed/2025/04/GHSA-7g9q-ww3r-j77g/GHSA-7g9q-ww3r-j77g.json new file mode 100644 index 00000000000..90600858666 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7g9q-ww3r-j77g/GHSA-7g9q-ww3r-j77g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7g9q-ww3r-j77g", + "modified": "2025-04-25T18:31:10Z", + "published": "2025-04-17T18:31:22Z", + "aliases": [ + "CVE-2025-43015" + ], + "details": "In JetBrains RubyMine before 2025.1 remote Interpreter overwrote ports to listen on all interfaces", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43015" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1188" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-99q6-5j8j-4wv8/GHSA-99q6-5j8j-4wv8.json b/advisories/unreviewed/2025/04/GHSA-99q6-5j8j-4wv8/GHSA-99q6-5j8j-4wv8.json index fe52d655f1f..6f7d8c6fc40 100644 --- a/advisories/unreviewed/2025/04/GHSA-99q6-5j8j-4wv8/GHSA-99q6-5j8j-4wv8.json +++ b/advisories/unreviewed/2025/04/GHSA-99q6-5j8j-4wv8/GHSA-99q6-5j8j-4wv8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-99q6-5j8j-4wv8", - "modified": "2025-04-24T21:31:48Z", + "modified": "2025-04-25T18:31:10Z", "published": "2025-04-24T21:31:48Z", "aliases": [ "CVE-2025-29529" ], "details": "ITC Systems Multiplan/Matrix OneCard platform v3.7.4.1002 was discovered to contain a SQL injection vulnerability via the component Forgotpassword.aspx.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-24T21:15:24Z" diff --git a/advisories/unreviewed/2025/04/GHSA-9m3r-h728-px2f/GHSA-9m3r-h728-px2f.json b/advisories/unreviewed/2025/04/GHSA-9m3r-h728-px2f/GHSA-9m3r-h728-px2f.json index 715c22d9733..39e9a4b91cb 100644 --- a/advisories/unreviewed/2025/04/GHSA-9m3r-h728-px2f/GHSA-9m3r-h728-px2f.json +++ b/advisories/unreviewed/2025/04/GHSA-9m3r-h728-px2f/GHSA-9m3r-h728-px2f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9m3r-h728-px2f", - "modified": "2025-04-25T15:31:22Z", + "modified": "2025-04-25T18:31:11Z", "published": "2025-04-25T15:31:22Z", "aliases": [ "CVE-2025-28076" ], "details": "Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.4 and CO2Scope <= 1.3.4 allows remote authenticated attackers to execute arbitrary SQL commands via the (1) timeago, (2) user, (3) filter, (4) target, (5) p1, (6) p2, (7) p3, (8) p4, (9) p5, (10) p6, (11) p7, (12) p8, (13) p9, (14) p10, (15) p11, (16) p12, (17) p13, (18) p14, (19) p15, (20) p16, (21) p17, (22) p18, (23) p19, or (24) p20 parameter to /api/management/updateihmsettings; the (25) ID, (26) NAME, (27) CPUTHREADNB, (28) RAMCAP, or (29) DISKCAP parameter to /api/capaplan/savetemplates.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-25T15:15:36Z" diff --git a/advisories/unreviewed/2025/04/GHSA-qhx4-9cx2-q4rc/GHSA-qhx4-9cx2-q4rc.json b/advisories/unreviewed/2025/04/GHSA-qhx4-9cx2-q4rc/GHSA-qhx4-9cx2-q4rc.json index a72f81b99c1..f7650a07797 100644 --- a/advisories/unreviewed/2025/04/GHSA-qhx4-9cx2-q4rc/GHSA-qhx4-9cx2-q4rc.json +++ b/advisories/unreviewed/2025/04/GHSA-qhx4-9cx2-q4rc/GHSA-qhx4-9cx2-q4rc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qhx4-9cx2-q4rc", - "modified": "2025-04-25T15:31:21Z", + "modified": "2025-04-25T18:31:11Z", "published": "2025-04-25T15:31:21Z", "aliases": [ "CVE-2025-28354" ], "details": "An issue in the Printer Manager Systm of Entrust Corp Printer Manager D3.18.4-3 and below allows attackers to execute a directory traversal via a crafted POST request.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-25T14:15:21Z" diff --git a/advisories/unreviewed/2025/04/GHSA-rgw7-rhh8-mgf9/GHSA-rgw7-rhh8-mgf9.json b/advisories/unreviewed/2025/04/GHSA-rgw7-rhh8-mgf9/GHSA-rgw7-rhh8-mgf9.json index cdfb67c2363..f0e7cf50f96 100644 --- a/advisories/unreviewed/2025/04/GHSA-rgw7-rhh8-mgf9/GHSA-rgw7-rhh8-mgf9.json +++ b/advisories/unreviewed/2025/04/GHSA-rgw7-rhh8-mgf9/GHSA-rgw7-rhh8-mgf9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rgw7-rhh8-mgf9", - "modified": "2025-04-24T21:31:48Z", + "modified": "2025-04-25T18:31:10Z", "published": "2025-04-24T21:31:48Z", "aliases": [ "CVE-2025-25777" ], "details": "Insecure Direct Object Reference (IDOR) in Codeastro Bus Ticket Booking System v1.0 allows unauthorized access to user profiles. By manipulating the user ID in the URL, an attacker can access another user's profile without proper authentication or authorization checks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-639" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-24T21:15:23Z" diff --git a/advisories/unreviewed/2025/04/GHSA-wqxv-v2vg-q37x/GHSA-wqxv-v2vg-q37x.json b/advisories/unreviewed/2025/04/GHSA-wqxv-v2vg-q37x/GHSA-wqxv-v2vg-q37x.json new file mode 100644 index 00000000000..35e489fd8cb --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wqxv-v2vg-q37x/GHSA-wqxv-v2vg-q37x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wqxv-v2vg-q37x", + "modified": "2025-04-25T18:31:12Z", + "published": "2025-04-25T18:31:12Z", + "aliases": [ + "CVE-2025-3928" + ], + "details": "Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: \"Webservers can be compromised through bad actors creating and executing webshells.\" Fixed in version 11.36.46, 11.32.89, 11.28.141, and 11.20.217 for Windows and Linux platforms.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3928" + }, + { + "type": "WEB", + "url": "https://documentation.commvault.com/securityadvisories/CV_2025_03_1.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-25T16:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xrq2-2h92-m6m8/GHSA-xrq2-2h92-m6m8.json b/advisories/unreviewed/2025/04/GHSA-xrq2-2h92-m6m8/GHSA-xrq2-2h92-m6m8.json index ecbeaea4005..b6f1336f45d 100644 --- a/advisories/unreviewed/2025/04/GHSA-xrq2-2h92-m6m8/GHSA-xrq2-2h92-m6m8.json +++ b/advisories/unreviewed/2025/04/GHSA-xrq2-2h92-m6m8/GHSA-xrq2-2h92-m6m8.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-829", "CWE-830" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/04/GHSA-xv35-w389-wr74/GHSA-xv35-w389-wr74.json b/advisories/unreviewed/2025/04/GHSA-xv35-w389-wr74/GHSA-xv35-w389-wr74.json new file mode 100644 index 00000000000..6aa5e11e6b6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xv35-w389-wr74/GHSA-xv35-w389-wr74.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xv35-w389-wr74", + "modified": "2025-04-25T18:31:12Z", + "published": "2025-04-25T18:31:12Z", + "aliases": [ + "CVE-2024-30152" + ], + "details": "HCL SX v21 is affected by usage of a weak cryptographic algorithm. An attacker could exploit this weakness to gain access to sensitive information, modify data, or other impacts.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30152" + }, + { + "type": "WEB", + "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0120735" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-327" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-25T18:15:25Z" + } +} \ No newline at end of file