diff --git a/advisories/unreviewed/2025/05/GHSA-9hrc-484x-66p9/GHSA-9hrc-484x-66p9.json b/advisories/unreviewed/2025/05/GHSA-9hrc-484x-66p9/GHSA-9hrc-484x-66p9.json new file mode 100644 index 00000000000..71e2f80ad2a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9hrc-484x-66p9/GHSA-9hrc-484x-66p9.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9hrc-484x-66p9", + "modified": "2025-05-12T09:30:28Z", + "published": "2025-05-12T09:30:28Z", + "aliases": [ + "CVE-2025-4560" + ], + "details": "The ISOinsight from Netvision has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access certain system functions. These functions include viewing the administrator list, viewing and editing IP settings, and uploading files.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4560" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/en/cp-139-10119-d9976-2.html" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-10118-80a8c-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T07:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mmrv-jr55-2p93/GHSA-mmrv-jr55-2p93.json b/advisories/unreviewed/2025/05/GHSA-mmrv-jr55-2p93/GHSA-mmrv-jr55-2p93.json new file mode 100644 index 00000000000..c4ce4b8a678 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mmrv-jr55-2p93/GHSA-mmrv-jr55-2p93.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mmrv-jr55-2p93", + "modified": "2025-05-12T09:30:28Z", + "published": "2025-05-12T09:30:28Z", + "aliases": [ + "CVE-2025-4561" + ], + "details": "The KFOX from KingFor has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privilege to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4561" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/en/cp-139-10121-ddbfa-2.html" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-10120-269d9-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T07:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-r9hp-6qhp-67mw/GHSA-r9hp-6qhp-67mw.json b/advisories/unreviewed/2025/05/GHSA-r9hp-6qhp-67mw/GHSA-r9hp-6qhp-67mw.json new file mode 100644 index 00000000000..8007de29dc4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-r9hp-6qhp-67mw/GHSA-r9hp-6qhp-67mw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r9hp-6qhp-67mw", + "modified": "2025-05-12T09:30:29Z", + "published": "2025-05-12T09:30:29Z", + "aliases": [ + "CVE-2025-3496" + ], + "details": "An unauthenticated remote attacker can cause a buffer overflow which could lead to unexpected behaviour or DoS via Bluetooth or RS-232 interface.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3496" + }, + { + "type": "WEB", + "url": "https://cert.vde.com/en/advisories/VDE-2025-026" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T08:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-x6c4-c6vc-hm96/GHSA-x6c4-c6vc-hm96.json b/advisories/unreviewed/2025/05/GHSA-x6c4-c6vc-hm96/GHSA-x6c4-c6vc-hm96.json new file mode 100644 index 00000000000..7894ac410e7 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-x6c4-c6vc-hm96/GHSA-x6c4-c6vc-hm96.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x6c4-c6vc-hm96", + "modified": "2025-05-12T09:30:29Z", + "published": "2025-05-12T09:30:29Z", + "aliases": [ + "CVE-2025-41393" + ], + "details": "Reflected cross-site scripting vulnerability exists in the laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor. If exploited, an arbitrary script may be executed on the web browser of the user who accessed Web Image Monitor. As for the details of affected product names and versions, refer to the information provided by the vendor under [References].", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-41393" + }, + { + "type": "WEB", + "url": "https://jp.ricoh.com/security/products/vulnerabilities/vul?id=ricoh-2025-000001" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN20474768" + }, + { + "type": "WEB", + "url": "https://www.ricoh.com/products/security/vulnerabilities/vul?id=ricoh-2025-000001" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T08:15:19Z" + } +} \ No newline at end of file