From ed9d09a17c62ad1c5b299bf631ce8d6ab0b4b180 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 16 Apr 2025 21:32:32 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-24rv-q44g-ghvg.json | 2 +- .../GHSA-2jxj-qmh4-m829.json | 2 +- .../GHSA-37vm-wf43-5763.json | 4 +- .../GHSA-3gph-54h9-x2ff.json | 6 +- .../GHSA-4q43-phw7-hf98.json | 2 +- .../GHSA-594c-767g-25xp.json | 2 +- .../GHSA-62cr-8xrr-9jw8.json | 2 +- .../GHSA-6r4x-4f9j-f8gp.json | 2 +- .../GHSA-7qjh-9xmf-42f9.json | 2 +- .../GHSA-8qhc-6qh8-x5fq.json | 2 +- .../GHSA-95rh-hf54-5mj7.json | 2 +- .../GHSA-fgq9-7jq6-9m7c.json | 2 +- .../GHSA-g97r-cxx6-j4pf.json | 2 +- .../GHSA-hqg9-2w7q-vr32.json | 2 +- .../GHSA-p388-vj4p-5xgx.json | 2 +- .../GHSA-rmcr-gcf2-8pqc.json | 3 +- .../GHSA-x47v-hfj4-3538.json | 2 +- .../GHSA-xxp8-6xrm-59q8.json | 6 +- .../GHSA-phrr-qc3r-4v9p.json | 3 +- .../GHSA-22vg-rjg9-5qfr.json | 4 +- .../GHSA-258c-748x-qf4g.json | 15 +++-- .../GHSA-297c-p9xm-3rhf.json | 15 +++-- .../GHSA-3cqv-h6hf-3729.json | 4 +- .../GHSA-3hm7-965w-frx6.json | 36 +++++++++++ .../GHSA-4fx4-vxg4-984r.json | 56 ++++++++++++++++ .../GHSA-5265-p799-mv2x.json | 37 +++++++++++ .../GHSA-666v-qpgj-3325.json | 4 +- .../GHSA-7w3p-xrff-wp88.json | 4 +- .../GHSA-84f3-9gqw-jffw.json | 4 +- .../GHSA-887c-mr87-cxwp.json | 64 +++++++++++++++++++ .../GHSA-8f6m-fvf9-6397.json | 46 +++++++++++++ .../GHSA-8r2x-x7m3-7w85.json | 52 +++++++++++++++ .../GHSA-8wwc-fv22-w76f.json | 4 +- .../GHSA-93cp-7wrg-cfw7.json | 52 +++++++++++++++ .../GHSA-9cv6-q9x4-94jp.json | 4 +- .../GHSA-9f5x-9jj2-7f3w.json | 15 +++-- .../GHSA-9hjg-77w4-4h5j.json | 36 +++++++++++ .../GHSA-9vh5-xhwh-w9v4.json | 33 ++++++++++ .../GHSA-c2x2-vjwh-p8qp.json | 4 +- .../GHSA-chj7-pc2g-84px.json | 33 ++++++++++ .../GHSA-f9px-2356-59h7.json | 11 +++- .../GHSA-fqxf-49hh-94mj.json | 29 +++++++++ .../GHSA-g2fr-wj73-rxrw.json | 15 +++-- .../GHSA-gv66-5jhq-833c.json | 15 +++-- .../GHSA-gwfx-rx3p-m9qf.json | 15 +++-- .../GHSA-hcw4-c8qw-p53q.json | 15 +++-- .../GHSA-hxf7-8x3f-fqrw.json | 4 +- .../GHSA-j68v-9w62-948r.json | 4 +- .../GHSA-j9rv-6qvq-mvqj.json | 35 ++++++++++ .../GHSA-jj4c-9qx7-h4pc.json | 33 ++++++++++ .../GHSA-jpv9-q37j-qv98.json | 29 +++++++++ .../GHSA-jr74-ph2w-qpmv.json | 4 +- .../GHSA-jx72-hjqg-63p5.json | 15 +++-- .../GHSA-m56x-56wx-f6f3.json | 4 +- .../GHSA-mc54-4f73-wx8x.json | 29 +++++++++ .../GHSA-mp2g-3625-m5pp.json | 29 +++++++++ .../GHSA-p349-27r5-4p76.json | 15 +++-- .../GHSA-p66x-34qj-fv9h.json | 4 +- .../GHSA-pm6h-v4xq-4ph9.json | 36 +++++++++++ .../GHSA-pmgp-fgv4-prx4.json | 29 +++++++++ .../GHSA-q4hh-vrvh-r4h7.json | 46 +++++++++++++ .../GHSA-qg2m-2384-5gwx.json | 52 +++++++++++++++ .../GHSA-qg97-xp64-p6pc.json | 35 ++++++++++ .../GHSA-qvp8-h356-jgg7.json | 56 ++++++++++++++++ .../GHSA-r225-m4mc-h9h3.json | 36 +++++++++++ .../GHSA-r33r-9v86-jfxp.json | 4 +- .../GHSA-r3xh-xmm6-qp4w.json | 15 +++-- .../GHSA-r8m2-5fw8-37h4.json | 4 +- .../GHSA-v38h-c3ff-rmhw.json | 37 +++++++++++ .../GHSA-v943-7xrm-g7pr.json | 15 +++-- .../GHSA-vp28-c453-wwjq.json | 29 +++++++++ .../GHSA-wcvm-x9qx-m58v.json | 52 +++++++++++++++ .../GHSA-wx3c-jgwq-c5hx.json | 52 +++++++++++++++ .../GHSA-xrmr-grfc-w665.json | 4 +- .../GHSA-xx97-cmjp-pm7g.json | 4 +- 75 files changed, 1300 insertions(+), 83 deletions(-) create mode 100644 advisories/unreviewed/2025/04/GHSA-3hm7-965w-frx6/GHSA-3hm7-965w-frx6.json create mode 100644 advisories/unreviewed/2025/04/GHSA-4fx4-vxg4-984r/GHSA-4fx4-vxg4-984r.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5265-p799-mv2x/GHSA-5265-p799-mv2x.json create mode 100644 advisories/unreviewed/2025/04/GHSA-887c-mr87-cxwp/GHSA-887c-mr87-cxwp.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8f6m-fvf9-6397/GHSA-8f6m-fvf9-6397.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8r2x-x7m3-7w85/GHSA-8r2x-x7m3-7w85.json create mode 100644 advisories/unreviewed/2025/04/GHSA-93cp-7wrg-cfw7/GHSA-93cp-7wrg-cfw7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-9hjg-77w4-4h5j/GHSA-9hjg-77w4-4h5j.json create mode 100644 advisories/unreviewed/2025/04/GHSA-9vh5-xhwh-w9v4/GHSA-9vh5-xhwh-w9v4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-chj7-pc2g-84px/GHSA-chj7-pc2g-84px.json create mode 100644 advisories/unreviewed/2025/04/GHSA-fqxf-49hh-94mj/GHSA-fqxf-49hh-94mj.json create mode 100644 advisories/unreviewed/2025/04/GHSA-j9rv-6qvq-mvqj/GHSA-j9rv-6qvq-mvqj.json create mode 100644 advisories/unreviewed/2025/04/GHSA-jj4c-9qx7-h4pc/GHSA-jj4c-9qx7-h4pc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-jpv9-q37j-qv98/GHSA-jpv9-q37j-qv98.json create mode 100644 advisories/unreviewed/2025/04/GHSA-mc54-4f73-wx8x/GHSA-mc54-4f73-wx8x.json create mode 100644 advisories/unreviewed/2025/04/GHSA-mp2g-3625-m5pp/GHSA-mp2g-3625-m5pp.json create mode 100644 advisories/unreviewed/2025/04/GHSA-pm6h-v4xq-4ph9/GHSA-pm6h-v4xq-4ph9.json create mode 100644 advisories/unreviewed/2025/04/GHSA-pmgp-fgv4-prx4/GHSA-pmgp-fgv4-prx4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-q4hh-vrvh-r4h7/GHSA-q4hh-vrvh-r4h7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-qg2m-2384-5gwx/GHSA-qg2m-2384-5gwx.json create mode 100644 advisories/unreviewed/2025/04/GHSA-qg97-xp64-p6pc/GHSA-qg97-xp64-p6pc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-qvp8-h356-jgg7/GHSA-qvp8-h356-jgg7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-r225-m4mc-h9h3/GHSA-r225-m4mc-h9h3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-v38h-c3ff-rmhw/GHSA-v38h-c3ff-rmhw.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vp28-c453-wwjq/GHSA-vp28-c453-wwjq.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wcvm-x9qx-m58v/GHSA-wcvm-x9qx-m58v.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wx3c-jgwq-c5hx/GHSA-wx3c-jgwq-c5hx.json diff --git a/advisories/unreviewed/2022/12/GHSA-24rv-q44g-ghvg/GHSA-24rv-q44g-ghvg.json b/advisories/unreviewed/2022/12/GHSA-24rv-q44g-ghvg/GHSA-24rv-q44g-ghvg.json index 9f2c9a98f82..fb1291e3568 100644 --- a/advisories/unreviewed/2022/12/GHSA-24rv-q44g-ghvg/GHSA-24rv-q44g-ghvg.json +++ b/advisories/unreviewed/2022/12/GHSA-24rv-q44g-ghvg/GHSA-24rv-q44g-ghvg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-24rv-q44g-ghvg", - "modified": "2022-12-24T06:30:25Z", + "modified": "2025-04-16T21:30:29Z", "published": "2022-12-20T21:30:17Z", "aliases": [ "CVE-2022-46318" diff --git a/advisories/unreviewed/2022/12/GHSA-2jxj-qmh4-m829/GHSA-2jxj-qmh4-m829.json b/advisories/unreviewed/2022/12/GHSA-2jxj-qmh4-m829/GHSA-2jxj-qmh4-m829.json index 60c66b7a58e..1b3ce95ae5d 100644 --- a/advisories/unreviewed/2022/12/GHSA-2jxj-qmh4-m829/GHSA-2jxj-qmh4-m829.json +++ b/advisories/unreviewed/2022/12/GHSA-2jxj-qmh4-m829/GHSA-2jxj-qmh4-m829.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2jxj-qmh4-m829", - "modified": "2022-12-29T21:30:30Z", + "modified": "2025-04-16T21:30:27Z", "published": "2022-12-20T21:30:18Z", "aliases": [ "CVE-2022-41591" diff --git a/advisories/unreviewed/2022/12/GHSA-37vm-wf43-5763/GHSA-37vm-wf43-5763.json b/advisories/unreviewed/2022/12/GHSA-37vm-wf43-5763/GHSA-37vm-wf43-5763.json index 2bc42b9bbeb..5f21cba7ecc 100644 --- a/advisories/unreviewed/2022/12/GHSA-37vm-wf43-5763/GHSA-37vm-wf43-5763.json +++ b/advisories/unreviewed/2022/12/GHSA-37vm-wf43-5763/GHSA-37vm-wf43-5763.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-319" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-3gph-54h9-x2ff/GHSA-3gph-54h9-x2ff.json b/advisories/unreviewed/2022/12/GHSA-3gph-54h9-x2ff/GHSA-3gph-54h9-x2ff.json index 0210e0f2120..6ea720b49bf 100644 --- a/advisories/unreviewed/2022/12/GHSA-3gph-54h9-x2ff/GHSA-3gph-54h9-x2ff.json +++ b/advisories/unreviewed/2022/12/GHSA-3gph-54h9-x2ff/GHSA-3gph-54h9-x2ff.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3gph-54h9-x2ff", - "modified": "2022-12-29T18:30:24Z", + "modified": "2025-04-16T21:30:26Z", "published": "2022-12-20T21:30:19Z", "aliases": [ "CVE-2022-46424" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46424" }, + { + "type": "WEB", + "url": "https://hackmd.io/%40slASVrz_SrW7NQCsunofeA/B1rKQuzDj" + }, { "type": "WEB", "url": "https://hackmd.io/@slASVrz_SrW7NQCsunofeA/B1rKQuzDj" diff --git a/advisories/unreviewed/2022/12/GHSA-4q43-phw7-hf98/GHSA-4q43-phw7-hf98.json b/advisories/unreviewed/2022/12/GHSA-4q43-phw7-hf98/GHSA-4q43-phw7-hf98.json index 0f7f0773027..2979e73eb5a 100644 --- a/advisories/unreviewed/2022/12/GHSA-4q43-phw7-hf98/GHSA-4q43-phw7-hf98.json +++ b/advisories/unreviewed/2022/12/GHSA-4q43-phw7-hf98/GHSA-4q43-phw7-hf98.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4q43-phw7-hf98", - "modified": "2022-12-24T06:30:25Z", + "modified": "2025-04-16T21:30:29Z", "published": "2022-12-20T21:30:17Z", "aliases": [ "CVE-2022-46323" diff --git a/advisories/unreviewed/2022/12/GHSA-594c-767g-25xp/GHSA-594c-767g-25xp.json b/advisories/unreviewed/2022/12/GHSA-594c-767g-25xp/GHSA-594c-767g-25xp.json index 041d8768191..036105cfbd8 100644 --- a/advisories/unreviewed/2022/12/GHSA-594c-767g-25xp/GHSA-594c-767g-25xp.json +++ b/advisories/unreviewed/2022/12/GHSA-594c-767g-25xp/GHSA-594c-767g-25xp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-594c-767g-25xp", - "modified": "2022-12-24T06:30:25Z", + "modified": "2025-04-16T21:30:29Z", "published": "2022-12-20T21:30:17Z", "aliases": [ "CVE-2022-46319" diff --git a/advisories/unreviewed/2022/12/GHSA-62cr-8xrr-9jw8/GHSA-62cr-8xrr-9jw8.json b/advisories/unreviewed/2022/12/GHSA-62cr-8xrr-9jw8/GHSA-62cr-8xrr-9jw8.json index 2523496cbe6..9227367229e 100644 --- a/advisories/unreviewed/2022/12/GHSA-62cr-8xrr-9jw8/GHSA-62cr-8xrr-9jw8.json +++ b/advisories/unreviewed/2022/12/GHSA-62cr-8xrr-9jw8/GHSA-62cr-8xrr-9jw8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-62cr-8xrr-9jw8", - "modified": "2022-12-24T06:30:25Z", + "modified": "2025-04-16T21:30:29Z", "published": "2022-12-20T21:30:17Z", "aliases": [ "CVE-2022-46325" diff --git a/advisories/unreviewed/2022/12/GHSA-6r4x-4f9j-f8gp/GHSA-6r4x-4f9j-f8gp.json b/advisories/unreviewed/2022/12/GHSA-6r4x-4f9j-f8gp/GHSA-6r4x-4f9j-f8gp.json index accd60d9230..bfc21776fd3 100644 --- a/advisories/unreviewed/2022/12/GHSA-6r4x-4f9j-f8gp/GHSA-6r4x-4f9j-f8gp.json +++ b/advisories/unreviewed/2022/12/GHSA-6r4x-4f9j-f8gp/GHSA-6r4x-4f9j-f8gp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6r4x-4f9j-f8gp", - "modified": "2022-12-24T06:30:25Z", + "modified": "2025-04-16T21:30:29Z", "published": "2022-12-20T21:30:17Z", "aliases": [ "CVE-2022-46320" diff --git a/advisories/unreviewed/2022/12/GHSA-7qjh-9xmf-42f9/GHSA-7qjh-9xmf-42f9.json b/advisories/unreviewed/2022/12/GHSA-7qjh-9xmf-42f9/GHSA-7qjh-9xmf-42f9.json index fd6f1e949c6..c7f12a76401 100644 --- a/advisories/unreviewed/2022/12/GHSA-7qjh-9xmf-42f9/GHSA-7qjh-9xmf-42f9.json +++ b/advisories/unreviewed/2022/12/GHSA-7qjh-9xmf-42f9/GHSA-7qjh-9xmf-42f9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7qjh-9xmf-42f9", - "modified": "2022-12-29T21:30:30Z", + "modified": "2025-04-16T21:30:26Z", "published": "2022-12-20T21:30:18Z", "aliases": [ "CVE-2022-38733" diff --git a/advisories/unreviewed/2022/12/GHSA-8qhc-6qh8-x5fq/GHSA-8qhc-6qh8-x5fq.json b/advisories/unreviewed/2022/12/GHSA-8qhc-6qh8-x5fq/GHSA-8qhc-6qh8-x5fq.json index 0499f8e9c13..07cb098e5f1 100644 --- a/advisories/unreviewed/2022/12/GHSA-8qhc-6qh8-x5fq/GHSA-8qhc-6qh8-x5fq.json +++ b/advisories/unreviewed/2022/12/GHSA-8qhc-6qh8-x5fq/GHSA-8qhc-6qh8-x5fq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8qhc-6qh8-x5fq", - "modified": "2022-12-24T06:30:25Z", + "modified": "2025-04-16T21:30:29Z", "published": "2022-12-20T21:30:17Z", "aliases": [ "CVE-2022-46322" diff --git a/advisories/unreviewed/2022/12/GHSA-95rh-hf54-5mj7/GHSA-95rh-hf54-5mj7.json b/advisories/unreviewed/2022/12/GHSA-95rh-hf54-5mj7/GHSA-95rh-hf54-5mj7.json index 79f89da0fda..2098300b7a7 100644 --- a/advisories/unreviewed/2022/12/GHSA-95rh-hf54-5mj7/GHSA-95rh-hf54-5mj7.json +++ b/advisories/unreviewed/2022/12/GHSA-95rh-hf54-5mj7/GHSA-95rh-hf54-5mj7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-95rh-hf54-5mj7", - "modified": "2022-12-24T06:30:25Z", + "modified": "2025-04-16T21:30:29Z", "published": "2022-12-20T21:30:17Z", "aliases": [ "CVE-2022-46326" diff --git a/advisories/unreviewed/2022/12/GHSA-fgq9-7jq6-9m7c/GHSA-fgq9-7jq6-9m7c.json b/advisories/unreviewed/2022/12/GHSA-fgq9-7jq6-9m7c/GHSA-fgq9-7jq6-9m7c.json index 3f9ec410286..565a060fb3d 100644 --- a/advisories/unreviewed/2022/12/GHSA-fgq9-7jq6-9m7c/GHSA-fgq9-7jq6-9m7c.json +++ b/advisories/unreviewed/2022/12/GHSA-fgq9-7jq6-9m7c/GHSA-fgq9-7jq6-9m7c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fgq9-7jq6-9m7c", - "modified": "2022-12-24T06:30:25Z", + "modified": "2025-04-16T21:30:29Z", "published": "2022-12-20T21:30:17Z", "aliases": [ "CVE-2022-46324" diff --git a/advisories/unreviewed/2022/12/GHSA-g97r-cxx6-j4pf/GHSA-g97r-cxx6-j4pf.json b/advisories/unreviewed/2022/12/GHSA-g97r-cxx6-j4pf/GHSA-g97r-cxx6-j4pf.json index ade58ce1ea8..a2e284cce88 100644 --- a/advisories/unreviewed/2022/12/GHSA-g97r-cxx6-j4pf/GHSA-g97r-cxx6-j4pf.json +++ b/advisories/unreviewed/2022/12/GHSA-g97r-cxx6-j4pf/GHSA-g97r-cxx6-j4pf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g97r-cxx6-j4pf", - "modified": "2022-12-24T06:30:26Z", + "modified": "2025-04-16T21:30:28Z", "published": "2022-12-20T21:30:18Z", "aliases": [ "CVE-2022-41596" diff --git a/advisories/unreviewed/2022/12/GHSA-hqg9-2w7q-vr32/GHSA-hqg9-2w7q-vr32.json b/advisories/unreviewed/2022/12/GHSA-hqg9-2w7q-vr32/GHSA-hqg9-2w7q-vr32.json index 438ed1054eb..991d127cad3 100644 --- a/advisories/unreviewed/2022/12/GHSA-hqg9-2w7q-vr32/GHSA-hqg9-2w7q-vr32.json +++ b/advisories/unreviewed/2022/12/GHSA-hqg9-2w7q-vr32/GHSA-hqg9-2w7q-vr32.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hqg9-2w7q-vr32", - "modified": "2022-12-24T06:30:25Z", + "modified": "2025-04-16T21:30:28Z", "published": "2022-12-20T21:30:17Z", "aliases": [ "CVE-2022-46317" diff --git a/advisories/unreviewed/2022/12/GHSA-p388-vj4p-5xgx/GHSA-p388-vj4p-5xgx.json b/advisories/unreviewed/2022/12/GHSA-p388-vj4p-5xgx/GHSA-p388-vj4p-5xgx.json index 7a638d178d1..fb7dc1f7ac7 100644 --- a/advisories/unreviewed/2022/12/GHSA-p388-vj4p-5xgx/GHSA-p388-vj4p-5xgx.json +++ b/advisories/unreviewed/2022/12/GHSA-p388-vj4p-5xgx/GHSA-p388-vj4p-5xgx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p388-vj4p-5xgx", - "modified": "2022-12-24T06:30:25Z", + "modified": "2025-04-16T21:30:29Z", "published": "2022-12-20T21:30:17Z", "aliases": [ "CVE-2022-46321" diff --git a/advisories/unreviewed/2022/12/GHSA-rmcr-gcf2-8pqc/GHSA-rmcr-gcf2-8pqc.json b/advisories/unreviewed/2022/12/GHSA-rmcr-gcf2-8pqc/GHSA-rmcr-gcf2-8pqc.json index 5095efeef32..0c2b756bdef 100644 --- a/advisories/unreviewed/2022/12/GHSA-rmcr-gcf2-8pqc/GHSA-rmcr-gcf2-8pqc.json +++ b/advisories/unreviewed/2022/12/GHSA-rmcr-gcf2-8pqc/GHSA-rmcr-gcf2-8pqc.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-x47v-hfj4-3538/GHSA-x47v-hfj4-3538.json b/advisories/unreviewed/2022/12/GHSA-x47v-hfj4-3538/GHSA-x47v-hfj4-3538.json index efc7d16d0f7..578bf2e9570 100644 --- a/advisories/unreviewed/2022/12/GHSA-x47v-hfj4-3538/GHSA-x47v-hfj4-3538.json +++ b/advisories/unreviewed/2022/12/GHSA-x47v-hfj4-3538/GHSA-x47v-hfj4-3538.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x47v-hfj4-3538", - "modified": "2022-12-24T06:30:26Z", + "modified": "2025-04-16T21:30:28Z", "published": "2022-12-20T21:30:18Z", "aliases": [ "CVE-2022-41599" diff --git a/advisories/unreviewed/2022/12/GHSA-xxp8-6xrm-59q8/GHSA-xxp8-6xrm-59q8.json b/advisories/unreviewed/2022/12/GHSA-xxp8-6xrm-59q8/GHSA-xxp8-6xrm-59q8.json index aa5f2beda12..9295b74eb29 100644 --- a/advisories/unreviewed/2022/12/GHSA-xxp8-6xrm-59q8/GHSA-xxp8-6xrm-59q8.json +++ b/advisories/unreviewed/2022/12/GHSA-xxp8-6xrm-59q8/GHSA-xxp8-6xrm-59q8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xxp8-6xrm-59q8", - "modified": "2022-12-28T18:30:20Z", + "modified": "2025-04-16T21:30:26Z", "published": "2022-12-20T21:30:19Z", "aliases": [ "CVE-2022-46428" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46428" }, + { + "type": "WEB", + "url": "https://hackmd.io/%40slASVrz_SrW7NQCsunofeA/S1hP34Hvj" + }, { "type": "WEB", "url": "https://hackmd.io/@slASVrz_SrW7NQCsunofeA/S1hP34Hvj" diff --git a/advisories/unreviewed/2024/03/GHSA-phrr-qc3r-4v9p/GHSA-phrr-qc3r-4v9p.json b/advisories/unreviewed/2024/03/GHSA-phrr-qc3r-4v9p/GHSA-phrr-qc3r-4v9p.json index a8efc302855..7c6cdb87e05 100644 --- a/advisories/unreviewed/2024/03/GHSA-phrr-qc3r-4v9p/GHSA-phrr-qc3r-4v9p.json +++ b/advisories/unreviewed/2024/03/GHSA-phrr-qc3r-4v9p/GHSA-phrr-qc3r-4v9p.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-22vg-rjg9-5qfr/GHSA-22vg-rjg9-5qfr.json b/advisories/unreviewed/2025/04/GHSA-22vg-rjg9-5qfr/GHSA-22vg-rjg9-5qfr.json index 4a93e63c563..411a6c025f7 100644 --- a/advisories/unreviewed/2025/04/GHSA-22vg-rjg9-5qfr/GHSA-22vg-rjg9-5qfr.json +++ b/advisories/unreviewed/2025/04/GHSA-22vg-rjg9-5qfr/GHSA-22vg-rjg9-5qfr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-258c-748x-qf4g/GHSA-258c-748x-qf4g.json b/advisories/unreviewed/2025/04/GHSA-258c-748x-qf4g/GHSA-258c-748x-qf4g.json index 7de6be5d931..b0e20ea93a9 100644 --- a/advisories/unreviewed/2025/04/GHSA-258c-748x-qf4g/GHSA-258c-748x-qf4g.json +++ b/advisories/unreviewed/2025/04/GHSA-258c-748x-qf4g/GHSA-258c-748x-qf4g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-258c-748x-qf4g", - "modified": "2025-04-16T00:31:38Z", + "modified": "2025-04-16T21:30:55Z", "published": "2025-04-16T00:31:38Z", "aliases": [ "CVE-2025-25458" ], "details": "Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serverName2.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-15T23:15:42Z" diff --git a/advisories/unreviewed/2025/04/GHSA-297c-p9xm-3rhf/GHSA-297c-p9xm-3rhf.json b/advisories/unreviewed/2025/04/GHSA-297c-p9xm-3rhf/GHSA-297c-p9xm-3rhf.json index 3365701688b..0a3af3bcaef 100644 --- a/advisories/unreviewed/2025/04/GHSA-297c-p9xm-3rhf/GHSA-297c-p9xm-3rhf.json +++ b/advisories/unreviewed/2025/04/GHSA-297c-p9xm-3rhf/GHSA-297c-p9xm-3rhf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-297c-p9xm-3rhf", - "modified": "2025-04-15T21:31:43Z", + "modified": "2025-04-16T21:30:50Z", "published": "2025-04-15T21:31:43Z", "aliases": [ "CVE-2025-29213" ], "details": "A zip slip vulnerability in the component \\service\\migrate\\MigrateForm.java of JEEWMS v3.7 allows attackers to execute arbitrary code via a crafted Zip file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-15T19:16:07Z" diff --git a/advisories/unreviewed/2025/04/GHSA-3cqv-h6hf-3729/GHSA-3cqv-h6hf-3729.json b/advisories/unreviewed/2025/04/GHSA-3cqv-h6hf-3729/GHSA-3cqv-h6hf-3729.json index a06606cdbf7..0dd7993b67c 100644 --- a/advisories/unreviewed/2025/04/GHSA-3cqv-h6hf-3729/GHSA-3cqv-h6hf-3729.json +++ b/advisories/unreviewed/2025/04/GHSA-3cqv-h6hf-3729/GHSA-3cqv-h6hf-3729.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-732" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-3hm7-965w-frx6/GHSA-3hm7-965w-frx6.json b/advisories/unreviewed/2025/04/GHSA-3hm7-965w-frx6/GHSA-3hm7-965w-frx6.json new file mode 100644 index 00000000000..50e739cb758 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3hm7-965w-frx6/GHSA-3hm7-965w-frx6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3hm7-965w-frx6", + "modified": "2025-04-16T21:30:57Z", + "published": "2025-04-16T21:30:57Z", + "aliases": [ + "CVE-2025-29650" + ], + "details": "SQL Injection vulnerability exists in the TP-Link M7200 4G LTE Mobile Wi-Fi Router Firmware Version: 1.0.7 Build 180127 Rel.55998n, allowing an unauthenticated attacker to inject malicious SQL statements via the username and password fields.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29650" + }, + { + "type": "WEB", + "url": "https://github.com/TheVeteran1/Vulnerability-Research/blob/main/CVE-2025-29650" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T20:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4fx4-vxg4-984r/GHSA-4fx4-vxg4-984r.json b/advisories/unreviewed/2025/04/GHSA-4fx4-vxg4-984r/GHSA-4fx4-vxg4-984r.json new file mode 100644 index 00000000000..4b2dd680f19 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4fx4-vxg4-984r/GHSA-4fx4-vxg4-984r.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4fx4-vxg4-984r", + "modified": "2025-04-16T21:30:59Z", + "published": "2025-04-16T21:30:59Z", + "aliases": [ + "CVE-2025-3729" + ], + "details": "A vulnerability, which was classified as critical, has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. This issue affects some unknown processing of the file backup.php of the component Database Backup Handler. The manipulation of the argument txtdbname leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3729" + }, + { + "type": "WEB", + "url": "https://github.com/yaklang/IRifyScanResult/blob/main/Web-based%20Pharmacy%20Product%20Management%20System/rce_in_backup.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.305075" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.305075" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.553631" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T21:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5265-p799-mv2x/GHSA-5265-p799-mv2x.json b/advisories/unreviewed/2025/04/GHSA-5265-p799-mv2x/GHSA-5265-p799-mv2x.json new file mode 100644 index 00000000000..a92883ffba9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5265-p799-mv2x/GHSA-5265-p799-mv2x.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5265-p799-mv2x", + "modified": "2025-04-16T21:30:48Z", + "published": "2025-04-16T21:30:48Z", + "aliases": [ + "CVE-2022-49049" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/secretmem: fix panic when growing a memfd_secret\n\nWhen one tries to grow an existing memfd_secret with ftruncate, one gets\na panic [1]. For example, doing the following reliably induces the\npanic:\n\n fd = memfd_secret();\n\n ftruncate(fd, 10);\n ptr = mmap(NULL, 10, PROT_READ | PROT_WRITE, MAP_SHARED, fd, 0);\n strcpy(ptr, \"123456789\");\n\n munmap(ptr, 10);\n ftruncate(fd, 20);\n\nThe basic reason for this is, when we grow with ftruncate, we call down\ninto simple_setattr, and then truncate_inode_pages_range, and eventually\nwe try to zero part of the memory. The normal truncation code does this\nvia the direct map (i.e., it calls page_address() and hands that to\nmemset()).\n\nFor memfd_secret though, we specifically don't map our pages via the\ndirect map (i.e. we call set_direct_map_invalid_noflush() on every\nfault). So the address returned by page_address() isn't useful, and\nwhen we try to memset() with it we panic.\n\nThis patch avoids the panic by implementing a custom setattr for\nmemfd_secret, which detects resizes specifically (setting the size for\nthe first time works just fine, since there are no existing pages to try\nto zero), and rejects them with EINVAL.\n\nOne could argue growing should be supported, but I think that will\nrequire a significantly more lengthy change. So, I propose a minimal\nfix for the benefit of stable kernels, and then perhaps to extend\nmemfd_secret to support growing in a separate patch.\n\n[1]:\n\n BUG: unable to handle page fault for address: ffffa0a889277028\n #PF: supervisor write access in kernel mode\n #PF: error_code(0x0002) - not-present page\n PGD afa01067 P4D afa01067 PUD 83f909067 PMD 83f8bf067 PTE 800ffffef6d88060\n Oops: 0002 [#1] PREEMPT SMP DEBUG_PAGEALLOC PTI\n CPU: 0 PID: 281 Comm: repro Not tainted 5.17.0-dbg-DEV #1\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014\n RIP: 0010:memset_erms+0x9/0x10\n Code: c1 e9 03 40 0f b6 f6 48 b8 01 01 01 01 01 01 01 01 48 0f af c6 f3 48 ab 89 d1 f3 aa 4c 89 c8 c3 90 49 89 f9 40 88 f0 48 89 d1 aa 4c 89 c8 c3 90 49 89 fa 40 0f b6 ce 48 b8 01 01 01 01 01 01\n RSP: 0018:ffffb932c09afbf0 EFLAGS: 00010246\n RAX: 0000000000000000 RBX: ffffda63c4249dc0 RCX: 0000000000000fd8\n RDX: 0000000000000fd8 RSI: 0000000000000000 RDI: ffffa0a889277028\n RBP: ffffb932c09afc00 R08: 0000000000001000 R09: ffffa0a889277028\n R10: 0000000000020023 R11: 0000000000000000 R12: ffffda63c4249dc0\n R13: ffffa0a890d70d98 R14: 0000000000000028 R15: 0000000000000fd8\n FS: 00007f7294899580(0000) GS:ffffa0af9bc00000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: ffffa0a889277028 CR3: 0000000107ef6006 CR4: 0000000000370ef0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n Call Trace:\n ? zero_user_segments+0x82/0x190\n truncate_inode_partial_folio+0xd4/0x2a0\n truncate_inode_pages_range+0x380/0x830\n truncate_setsize+0x63/0x80\n simple_setattr+0x37/0x60\n notify_change+0x3d8/0x4d0\n do_sys_ftruncate+0x162/0x1d0\n __x64_sys_ftruncate+0x1c/0x20\n do_syscall_64+0x44/0xa0\n entry_SYSCALL_64_after_hwframe+0x44/0xae\n Modules linked in: xhci_pci xhci_hcd virtio_net net_failover failover virtio_blk virtio_balloon uhci_hcd ohci_pci ohci_hcd evdev ehci_pci ehci_hcd 9pnet_virtio 9p netfs 9pnet\n CR2: ffffa0a889277028\n\n[lkp@intel.com: secretmem_iops can be static]\n[axelrasmussen@google.com: return EINVAL]", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49049" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9d3b877daf805fed29be8f61aa3d0ea37df82c7b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b6d17c67885a5624e96eb30c4178c65eea8374bf" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f9b141f93659e09a52e28791ccbaf69c273b8e92" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:00:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-666v-qpgj-3325/GHSA-666v-qpgj-3325.json b/advisories/unreviewed/2025/04/GHSA-666v-qpgj-3325/GHSA-666v-qpgj-3325.json index b0d13a2ca2b..a89a4e82de5 100644 --- a/advisories/unreviewed/2025/04/GHSA-666v-qpgj-3325/GHSA-666v-qpgj-3325.json +++ b/advisories/unreviewed/2025/04/GHSA-666v-qpgj-3325/GHSA-666v-qpgj-3325.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-7w3p-xrff-wp88/GHSA-7w3p-xrff-wp88.json b/advisories/unreviewed/2025/04/GHSA-7w3p-xrff-wp88/GHSA-7w3p-xrff-wp88.json index dbce39f4529..3449cae2389 100644 --- a/advisories/unreviewed/2025/04/GHSA-7w3p-xrff-wp88/GHSA-7w3p-xrff-wp88.json +++ b/advisories/unreviewed/2025/04/GHSA-7w3p-xrff-wp88/GHSA-7w3p-xrff-wp88.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-84f3-9gqw-jffw/GHSA-84f3-9gqw-jffw.json b/advisories/unreviewed/2025/04/GHSA-84f3-9gqw-jffw/GHSA-84f3-9gqw-jffw.json index 2971bc99937..4b4906448a8 100644 --- a/advisories/unreviewed/2025/04/GHSA-84f3-9gqw-jffw/GHSA-84f3-9gqw-jffw.json +++ b/advisories/unreviewed/2025/04/GHSA-84f3-9gqw-jffw/GHSA-84f3-9gqw-jffw.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-887c-mr87-cxwp/GHSA-887c-mr87-cxwp.json b/advisories/unreviewed/2025/04/GHSA-887c-mr87-cxwp/GHSA-887c-mr87-cxwp.json new file mode 100644 index 00000000000..2d6008feb2e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-887c-mr87-cxwp/GHSA-887c-mr87-cxwp.json @@ -0,0 +1,64 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-887c-mr87-cxwp", + "modified": "2025-04-16T21:30:59Z", + "published": "2025-04-16T21:30:59Z", + "aliases": [ + "CVE-2025-3730" + ], + "details": "A vulnerability, which was classified as problematic, was found in PyTorch 2.6.0. Affected is the function torch.nn.functional.ctc_loss of the file aten/src/ATen/native/LossCTC.cpp. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The name of the patch is 46fc5d8e360127361211cb237d5f9eef0223e567. It is recommended to apply a patch to fix this issue.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3730" + }, + { + "type": "WEB", + "url": "https://github.com/pytorch/pytorch/issues/150835" + }, + { + "type": "WEB", + "url": "https://github.com/pytorch/pytorch/issues/150835#issue-2979082232" + }, + { + "type": "WEB", + "url": "https://github.com/pytorch/pytorch/pull/150981" + }, + { + "type": "WEB", + "url": "https://github.com/timocafe/tewart-pytorch/commit/46fc5d8e360127361211cb237d5f9eef0223e567" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.305076" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.305076" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.553645" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-404" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T21:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8f6m-fvf9-6397/GHSA-8f6m-fvf9-6397.json b/advisories/unreviewed/2025/04/GHSA-8f6m-fvf9-6397/GHSA-8f6m-fvf9-6397.json new file mode 100644 index 00000000000..59a6b124824 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8f6m-fvf9-6397/GHSA-8f6m-fvf9-6397.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8f6m-fvf9-6397", + "modified": "2025-04-16T21:30:57Z", + "published": "2025-04-16T21:30:56Z", + "aliases": [ + "CVE-2025-31200" + ], + "details": "A memory corruption issue was addressed with improved bounds checking. This issue is fixed in tvOS 18.4.1, visionOS 2.4.1, iOS iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1. Processing an audio stream in a maliciously crafted media file may result in code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31200" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122282" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122400" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122401" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122402" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T19:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8r2x-x7m3-7w85/GHSA-8r2x-x7m3-7w85.json b/advisories/unreviewed/2025/04/GHSA-8r2x-x7m3-7w85/GHSA-8r2x-x7m3-7w85.json new file mode 100644 index 00000000000..66f299c0fbf --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8r2x-x7m3-7w85/GHSA-8r2x-x7m3-7w85.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8r2x-x7m3-7w85", + "modified": "2025-04-16T21:30:58Z", + "published": "2025-04-16T21:30:58Z", + "aliases": [ + "CVE-2025-3723" + ], + "details": "A vulnerability was found in PCMan FTP Server 2.0.7 and classified as critical. This issue affects some unknown processing of the component MDTM Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3723" + }, + { + "type": "WEB", + "url": "https://fitoxs.com/exploit/exploit-d41d8cd98f00b204e9800998ecf8427e.txt" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.305069" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.305069" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.552796" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T20:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8wwc-fv22-w76f/GHSA-8wwc-fv22-w76f.json b/advisories/unreviewed/2025/04/GHSA-8wwc-fv22-w76f/GHSA-8wwc-fv22-w76f.json index bf2ae834de5..3f9f28277f5 100644 --- a/advisories/unreviewed/2025/04/GHSA-8wwc-fv22-w76f/GHSA-8wwc-fv22-w76f.json +++ b/advisories/unreviewed/2025/04/GHSA-8wwc-fv22-w76f/GHSA-8wwc-fv22-w76f.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-732" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-93cp-7wrg-cfw7/GHSA-93cp-7wrg-cfw7.json b/advisories/unreviewed/2025/04/GHSA-93cp-7wrg-cfw7/GHSA-93cp-7wrg-cfw7.json new file mode 100644 index 00000000000..5a323599bfe --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-93cp-7wrg-cfw7/GHSA-93cp-7wrg-cfw7.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-93cp-7wrg-cfw7", + "modified": "2025-04-16T21:30:58Z", + "published": "2025-04-16T21:30:58Z", + "aliases": [ + "CVE-2025-3724" + ], + "details": "A vulnerability was found in PCMan FTP Server 2.0.7. It has been classified as critical. Affected is an unknown function of the component DIR Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3724" + }, + { + "type": "WEB", + "url": "https://fitoxs.com/exploit/exploit-21232f297a57a5a743894a0e4a801fc3.txt" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.305070" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.305070" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.552808" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T20:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9cv6-q9x4-94jp/GHSA-9cv6-q9x4-94jp.json b/advisories/unreviewed/2025/04/GHSA-9cv6-q9x4-94jp/GHSA-9cv6-q9x4-94jp.json index d3999fda9c8..e6ad579aa1c 100644 --- a/advisories/unreviewed/2025/04/GHSA-9cv6-q9x4-94jp/GHSA-9cv6-q9x4-94jp.json +++ b/advisories/unreviewed/2025/04/GHSA-9cv6-q9x4-94jp/GHSA-9cv6-q9x4-94jp.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-732" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-9f5x-9jj2-7f3w/GHSA-9f5x-9jj2-7f3w.json b/advisories/unreviewed/2025/04/GHSA-9f5x-9jj2-7f3w/GHSA-9f5x-9jj2-7f3w.json index f54966b2bfd..59f36d4016e 100644 --- a/advisories/unreviewed/2025/04/GHSA-9f5x-9jj2-7f3w/GHSA-9f5x-9jj2-7f3w.json +++ b/advisories/unreviewed/2025/04/GHSA-9f5x-9jj2-7f3w/GHSA-9f5x-9jj2-7f3w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9f5x-9jj2-7f3w", - "modified": "2025-04-16T18:31:51Z", + "modified": "2025-04-16T21:30:56Z", "published": "2025-04-16T18:31:51Z", "aliases": [ "CVE-2024-40068" ], "details": "Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at id_generator/admin/?page=templates/manage_template&id=1.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T17:15:48Z" diff --git a/advisories/unreviewed/2025/04/GHSA-9hjg-77w4-4h5j/GHSA-9hjg-77w4-4h5j.json b/advisories/unreviewed/2025/04/GHSA-9hjg-77w4-4h5j/GHSA-9hjg-77w4-4h5j.json new file mode 100644 index 00000000000..3769a669887 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9hjg-77w4-4h5j/GHSA-9hjg-77w4-4h5j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9hjg-77w4-4h5j", + "modified": "2025-04-16T21:30:57Z", + "published": "2025-04-16T21:30:57Z", + "aliases": [ + "CVE-2025-32817" + ], + "details": "A Improper Link Resolution vulnerability (CWE-59) in the SonicWall Connect Tunnel Windows (32 and 64 bit) client, this results in unauthorized file overwrite, potentially leading to denial of service or file corruption.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32817" + }, + { + "type": "WEB", + "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0007" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T20:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9vh5-xhwh-w9v4/GHSA-9vh5-xhwh-w9v4.json b/advisories/unreviewed/2025/04/GHSA-9vh5-xhwh-w9v4/GHSA-9vh5-xhwh-w9v4.json new file mode 100644 index 00000000000..174c3120099 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9vh5-xhwh-w9v4/GHSA-9vh5-xhwh-w9v4.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9vh5-xhwh-w9v4", + "modified": "2025-04-16T21:30:59Z", + "published": "2025-04-16T21:30:59Z", + "aliases": [ + "CVE-2025-29709" + ], + "details": "SourceCodester Company Website CMS 1.0 has a File upload vulnerability via the \"Create portfolio\" file /dashboard/portfolio.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29709" + }, + { + "type": "WEB", + "url": "https://github.com/fupanc-w1n/fupanc/blob/main/php/CVE-2025-29709.md" + }, + { + "type": "WEB", + "url": "https://github.com/fupanc-w1n/fupanc/blob/main/php/Company%20Website%20CMS2.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T21:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c2x2-vjwh-p8qp/GHSA-c2x2-vjwh-p8qp.json b/advisories/unreviewed/2025/04/GHSA-c2x2-vjwh-p8qp/GHSA-c2x2-vjwh-p8qp.json index 1569388308c..0cf5197248a 100644 --- a/advisories/unreviewed/2025/04/GHSA-c2x2-vjwh-p8qp/GHSA-c2x2-vjwh-p8qp.json +++ b/advisories/unreviewed/2025/04/GHSA-c2x2-vjwh-p8qp/GHSA-c2x2-vjwh-p8qp.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-732" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-chj7-pc2g-84px/GHSA-chj7-pc2g-84px.json b/advisories/unreviewed/2025/04/GHSA-chj7-pc2g-84px/GHSA-chj7-pc2g-84px.json new file mode 100644 index 00000000000..ca138eb6029 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-chj7-pc2g-84px/GHSA-chj7-pc2g-84px.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-chj7-pc2g-84px", + "modified": "2025-04-16T21:30:59Z", + "published": "2025-04-16T21:30:59Z", + "aliases": [ + "CVE-2025-29710" + ], + "details": "SourceCodester Company Website CMS 1.0 is vulnerable to Cross Site Scripting (XSS) via /dashboard/Services.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29710" + }, + { + "type": "WEB", + "url": "https://github.com/fupanc-w1n/fupanc/blob/main/php/CVE-2025-29710.md" + }, + { + "type": "WEB", + "url": "https://github.com/fupanc-w1n/fupanc/blob/main/php/Company%20Website%20CMS3.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T21:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f9px-2356-59h7/GHSA-f9px-2356-59h7.json b/advisories/unreviewed/2025/04/GHSA-f9px-2356-59h7/GHSA-f9px-2356-59h7.json index 763020a6a2d..f17b2e78ea1 100644 --- a/advisories/unreviewed/2025/04/GHSA-f9px-2356-59h7/GHSA-f9px-2356-59h7.json +++ b/advisories/unreviewed/2025/04/GHSA-f9px-2356-59h7/GHSA-f9px-2356-59h7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f9px-2356-59h7", - "modified": "2025-04-16T18:31:53Z", + "modified": "2025-04-16T21:30:56Z", "published": "2025-04-16T18:31:53Z", "aliases": [ "CVE-2025-3733" ], "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal baguetteBox.Js allows Cross-Site Scripting (XSS).This issue affects baguetteBox.Js: from 0.0.0 before 2.0.4, from 3.0.0 before 3.0.1.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T17:15:49Z" diff --git a/advisories/unreviewed/2025/04/GHSA-fqxf-49hh-94mj/GHSA-fqxf-49hh-94mj.json b/advisories/unreviewed/2025/04/GHSA-fqxf-49hh-94mj/GHSA-fqxf-49hh-94mj.json new file mode 100644 index 00000000000..5205c85e780 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fqxf-49hh-94mj/GHSA-fqxf-49hh-94mj.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fqxf-49hh-94mj", + "modified": "2025-04-16T21:30:58Z", + "published": "2025-04-16T21:30:58Z", + "aliases": [ + "CVE-2024-55372" + ], + "details": "Wallos <=2.38.2 has a file upload vulnerability in the restore database function, which allows unauthenticated users to restore database by uploading a ZIP file. The contents of the ZIP file are extracted on the server. This functionality enables an unauthenticated attacker to upload malicious files to the server. Once a web shell is installed, the attacker gains the ability to execute arbitrary commands.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55372" + }, + { + "type": "WEB", + "url": "https://www.datafarm.co.th/blog/CVE-2024-55371-and-CVE-2024-55372-Malicious-File-Upload-to-RCE-in-Wallos-Application" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T21:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g2fr-wj73-rxrw/GHSA-g2fr-wj73-rxrw.json b/advisories/unreviewed/2025/04/GHSA-g2fr-wj73-rxrw/GHSA-g2fr-wj73-rxrw.json index b65ca2f333f..767b7478b08 100644 --- a/advisories/unreviewed/2025/04/GHSA-g2fr-wj73-rxrw/GHSA-g2fr-wj73-rxrw.json +++ b/advisories/unreviewed/2025/04/GHSA-g2fr-wj73-rxrw/GHSA-g2fr-wj73-rxrw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g2fr-wj73-rxrw", - "modified": "2025-04-15T21:31:44Z", + "modified": "2025-04-16T21:30:50Z", "published": "2025-04-15T21:31:44Z", "aliases": [ "CVE-2024-44843" ], "details": "An issue in the web socket handshake process of SteVe v3.7.1 allows attackers to bypass authentication and execute arbitrary coammands via supplying crafted OCPP requests.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-15T21:15:46Z" diff --git a/advisories/unreviewed/2025/04/GHSA-gv66-5jhq-833c/GHSA-gv66-5jhq-833c.json b/advisories/unreviewed/2025/04/GHSA-gv66-5jhq-833c/GHSA-gv66-5jhq-833c.json index 91e70f36099..41394ef32a5 100644 --- a/advisories/unreviewed/2025/04/GHSA-gv66-5jhq-833c/GHSA-gv66-5jhq-833c.json +++ b/advisories/unreviewed/2025/04/GHSA-gv66-5jhq-833c/GHSA-gv66-5jhq-833c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gv66-5jhq-833c", - "modified": "2025-04-16T00:31:39Z", + "modified": "2025-04-16T21:30:55Z", "published": "2025-04-16T00:31:39Z", "aliases": [ "CVE-2025-25453" ], "details": "Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serviceName2.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-15T23:15:42Z" diff --git a/advisories/unreviewed/2025/04/GHSA-gwfx-rx3p-m9qf/GHSA-gwfx-rx3p-m9qf.json b/advisories/unreviewed/2025/04/GHSA-gwfx-rx3p-m9qf/GHSA-gwfx-rx3p-m9qf.json index 7774e927eb2..d47d74088e6 100644 --- a/advisories/unreviewed/2025/04/GHSA-gwfx-rx3p-m9qf/GHSA-gwfx-rx3p-m9qf.json +++ b/advisories/unreviewed/2025/04/GHSA-gwfx-rx3p-m9qf/GHSA-gwfx-rx3p-m9qf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gwfx-rx3p-m9qf", - "modified": "2025-04-16T00:31:38Z", + "modified": "2025-04-16T21:30:54Z", "published": "2025-04-16T00:31:38Z", "aliases": [ "CVE-2025-22911" ], "details": "RE11S v1.11 was discovered to contain a stack overflow via the rootAPmac parameter in the formiNICbasicREP function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-15T23:15:42Z" diff --git a/advisories/unreviewed/2025/04/GHSA-hcw4-c8qw-p53q/GHSA-hcw4-c8qw-p53q.json b/advisories/unreviewed/2025/04/GHSA-hcw4-c8qw-p53q/GHSA-hcw4-c8qw-p53q.json index c5ba70a48e5..553d2311ba1 100644 --- a/advisories/unreviewed/2025/04/GHSA-hcw4-c8qw-p53q/GHSA-hcw4-c8qw-p53q.json +++ b/advisories/unreviewed/2025/04/GHSA-hcw4-c8qw-p53q/GHSA-hcw4-c8qw-p53q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hcw4-c8qw-p53q", - "modified": "2025-04-16T18:31:54Z", + "modified": "2025-04-16T21:30:56Z", "published": "2025-04-16T18:31:54Z", "aliases": [ "CVE-2024-53304" ], "details": "An issue in LRQA Nettitude PoshC2 after commit 09ee2cf allows unauthenticated attackers to connect to the C2 server and execute arbitrary commands via posing as an infected machine.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T18:16:03Z" diff --git a/advisories/unreviewed/2025/04/GHSA-hxf7-8x3f-fqrw/GHSA-hxf7-8x3f-fqrw.json b/advisories/unreviewed/2025/04/GHSA-hxf7-8x3f-fqrw/GHSA-hxf7-8x3f-fqrw.json index f3de83d92e1..496ed95bce7 100644 --- a/advisories/unreviewed/2025/04/GHSA-hxf7-8x3f-fqrw/GHSA-hxf7-8x3f-fqrw.json +++ b/advisories/unreviewed/2025/04/GHSA-hxf7-8x3f-fqrw/GHSA-hxf7-8x3f-fqrw.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-j68v-9w62-948r/GHSA-j68v-9w62-948r.json b/advisories/unreviewed/2025/04/GHSA-j68v-9w62-948r/GHSA-j68v-9w62-948r.json index 48888ae3a71..469add8a04f 100644 --- a/advisories/unreviewed/2025/04/GHSA-j68v-9w62-948r/GHSA-j68v-9w62-948r.json +++ b/advisories/unreviewed/2025/04/GHSA-j68v-9w62-948r/GHSA-j68v-9w62-948r.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-732" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-j9rv-6qvq-mvqj/GHSA-j9rv-6qvq-mvqj.json b/advisories/unreviewed/2025/04/GHSA-j9rv-6qvq-mvqj/GHSA-j9rv-6qvq-mvqj.json new file mode 100644 index 00000000000..7b45229fb42 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j9rv-6qvq-mvqj/GHSA-j9rv-6qvq-mvqj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j9rv-6qvq-mvqj", + "modified": "2025-04-16T21:30:59Z", + "published": "2025-04-16T21:30:59Z", + "aliases": [ + "CVE-2025-3620" + ], + "details": "Use after free in USB in Google Chrome prior to 135.0.7049.95 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3620" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2025/04/stable-channel-update-for-desktop_15.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/405292639" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T21:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jj4c-9qx7-h4pc/GHSA-jj4c-9qx7-h4pc.json b/advisories/unreviewed/2025/04/GHSA-jj4c-9qx7-h4pc/GHSA-jj4c-9qx7-h4pc.json new file mode 100644 index 00000000000..b2081d28156 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jj4c-9qx7-h4pc/GHSA-jj4c-9qx7-h4pc.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jj4c-9qx7-h4pc", + "modified": "2025-04-16T21:30:59Z", + "published": "2025-04-16T21:30:59Z", + "aliases": [ + "CVE-2025-29708" + ], + "details": "SourceCodester Company Website CMS 1.0 contains a file upload vulnerability via the \"Create Services\" file /dashboard/Services.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29708" + }, + { + "type": "WEB", + "url": "https://github.com/fupanc-w1n/fupanc/blob/main/php/CVE-2025-29708.md" + }, + { + "type": "WEB", + "url": "https://github.com/fupanc-w1n/fupanc/blob/main/php/Company%20Website%20CMS1.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T21:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jpv9-q37j-qv98/GHSA-jpv9-q37j-qv98.json b/advisories/unreviewed/2025/04/GHSA-jpv9-q37j-qv98/GHSA-jpv9-q37j-qv98.json new file mode 100644 index 00000000000..1e559edb048 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jpv9-q37j-qv98/GHSA-jpv9-q37j-qv98.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jpv9-q37j-qv98", + "modified": "2025-04-16T21:30:57Z", + "published": "2025-04-16T21:30:57Z", + "aliases": [ + "CVE-2025-29651" + ], + "details": "SQL Injection vulnerability exists in the TP-Link M7650 4G LTE Mobile Wi-Fi Router Firmware Version: 1.0.7 Build 170623 Rel.1022n, allowing an unauthenticated attacker to inject malicious SQL statements via the username and password fields.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29651" + }, + { + "type": "WEB", + "url": "https://github.com/TheVeteran1/Vulnerability-Research/blob/main/CVE-2025-29651" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T20:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jr74-ph2w-qpmv/GHSA-jr74-ph2w-qpmv.json b/advisories/unreviewed/2025/04/GHSA-jr74-ph2w-qpmv/GHSA-jr74-ph2w-qpmv.json index 0266a87f564..86afbecc4bf 100644 --- a/advisories/unreviewed/2025/04/GHSA-jr74-ph2w-qpmv/GHSA-jr74-ph2w-qpmv.json +++ b/advisories/unreviewed/2025/04/GHSA-jr74-ph2w-qpmv/GHSA-jr74-ph2w-qpmv.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-jx72-hjqg-63p5/GHSA-jx72-hjqg-63p5.json b/advisories/unreviewed/2025/04/GHSA-jx72-hjqg-63p5/GHSA-jx72-hjqg-63p5.json index b2de870417d..a59d7ff7bff 100644 --- a/advisories/unreviewed/2025/04/GHSA-jx72-hjqg-63p5/GHSA-jx72-hjqg-63p5.json +++ b/advisories/unreviewed/2025/04/GHSA-jx72-hjqg-63p5/GHSA-jx72-hjqg-63p5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jx72-hjqg-63p5", - "modified": "2025-04-16T00:31:34Z", + "modified": "2025-04-16T21:30:53Z", "published": "2025-04-16T00:31:34Z", "aliases": [ "CVE-2024-49200" ], "details": "An issue was discovered in AcpiS3SaveDxe and ChipsetSvcDxe in Insyde InsydeH2O with kernel 5.2 though 5.7. A potential DXE memory corruption vulnerability has been identified. The root cause is use of a pointer originating from the value of an NVRAM variable as the target of a write operation. This can be leveraged by an attacker to perform arbitrary writes, potentially leading to arbitrary code execution. The issue has been fixed in kernel 5.2, Version 05.29.44; kernel 5.3, Version 05.38.44; kernel 5.4, Version 05.46.44; kernel 5.5, Version 05.54.44; kernel 5.6, Version 05.61.44; and kernel 5.7, Version 05.70.44.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-15T22:15:15Z" diff --git a/advisories/unreviewed/2025/04/GHSA-m56x-56wx-f6f3/GHSA-m56x-56wx-f6f3.json b/advisories/unreviewed/2025/04/GHSA-m56x-56wx-f6f3/GHSA-m56x-56wx-f6f3.json index 45a8e61727c..4826e36fed5 100644 --- a/advisories/unreviewed/2025/04/GHSA-m56x-56wx-f6f3/GHSA-m56x-56wx-f6f3.json +++ b/advisories/unreviewed/2025/04/GHSA-m56x-56wx-f6f3/GHSA-m56x-56wx-f6f3.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-mc54-4f73-wx8x/GHSA-mc54-4f73-wx8x.json b/advisories/unreviewed/2025/04/GHSA-mc54-4f73-wx8x/GHSA-mc54-4f73-wx8x.json new file mode 100644 index 00000000000..ee88668337e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mc54-4f73-wx8x/GHSA-mc54-4f73-wx8x.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mc54-4f73-wx8x", + "modified": "2025-04-16T21:30:59Z", + "published": "2025-04-16T21:30:59Z", + "aliases": [ + "CVE-2025-28072" + ], + "details": "PHPGurukul Pre-School Enrollment System is vulnerable to Directory Traversal in manage-teachers.php.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28072" + }, + { + "type": "WEB", + "url": "https://github.com/baixiaobi/TST/blob/main/README.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T21:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mp2g-3625-m5pp/GHSA-mp2g-3625-m5pp.json b/advisories/unreviewed/2025/04/GHSA-mp2g-3625-m5pp/GHSA-mp2g-3625-m5pp.json new file mode 100644 index 00000000000..bae20aa60ad --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mp2g-3625-m5pp/GHSA-mp2g-3625-m5pp.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mp2g-3625-m5pp", + "modified": "2025-04-16T21:30:58Z", + "published": "2025-04-16T21:30:58Z", + "aliases": [ + "CVE-2024-55371" + ], + "details": "Wallos <= 2.38.2 has a file upload vulnerability in the restore backup function, which allows authenticated users to restore backups by uploading a ZIP file. The contents of the ZIP file are extracted on the server. This functionality enables an authenticated attacker (being an administrator is not required) to upload malicious files to the server. Once a web shell is installed, the attacker gains the ability to execute arbitrary commands.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55371" + }, + { + "type": "WEB", + "url": "https://www.datafarm.co.th/blog/CVE-2024-55371-and-CVE-2024-55372-Malicious-File-Upload-to-RCE-in-Wallos-Application" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T21:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p349-27r5-4p76/GHSA-p349-27r5-4p76.json b/advisories/unreviewed/2025/04/GHSA-p349-27r5-4p76/GHSA-p349-27r5-4p76.json index 73278b6ddac..7a06f0d0ba6 100644 --- a/advisories/unreviewed/2025/04/GHSA-p349-27r5-4p76/GHSA-p349-27r5-4p76.json +++ b/advisories/unreviewed/2025/04/GHSA-p349-27r5-4p76/GHSA-p349-27r5-4p76.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p349-27r5-4p76", - "modified": "2025-04-16T18:31:52Z", + "modified": "2025-04-16T21:30:56Z", "published": "2025-04-16T18:31:52Z", "aliases": [ "CVE-2024-40070" ], "details": "Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_generator/classes/Users.php?f=save. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T17:15:48Z" diff --git a/advisories/unreviewed/2025/04/GHSA-p66x-34qj-fv9h/GHSA-p66x-34qj-fv9h.json b/advisories/unreviewed/2025/04/GHSA-p66x-34qj-fv9h/GHSA-p66x-34qj-fv9h.json index 1d55a9390cb..51c60ff1946 100644 --- a/advisories/unreviewed/2025/04/GHSA-p66x-34qj-fv9h/GHSA-p66x-34qj-fv9h.json +++ b/advisories/unreviewed/2025/04/GHSA-p66x-34qj-fv9h/GHSA-p66x-34qj-fv9h.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-732" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-pm6h-v4xq-4ph9/GHSA-pm6h-v4xq-4ph9.json b/advisories/unreviewed/2025/04/GHSA-pm6h-v4xq-4ph9/GHSA-pm6h-v4xq-4ph9.json new file mode 100644 index 00000000000..402e3f38c86 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pm6h-v4xq-4ph9/GHSA-pm6h-v4xq-4ph9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pm6h-v4xq-4ph9", + "modified": "2025-04-16T21:30:57Z", + "published": "2025-04-16T21:30:57Z", + "aliases": [ + "CVE-2025-29648" + ], + "details": "SQL Injection vulnerability exists in the TP-Link EAP120 router s login dashboard (version 1.0), allowing an unauthenticated attacker to inject malicious SQL statements via the login fields.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29648" + }, + { + "type": "WEB", + "url": "https://github.com/TheVeteran1/Vulnerability-Research/blob/main/CVE-2025-29648" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T20:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pmgp-fgv4-prx4/GHSA-pmgp-fgv4-prx4.json b/advisories/unreviewed/2025/04/GHSA-pmgp-fgv4-prx4/GHSA-pmgp-fgv4-prx4.json new file mode 100644 index 00000000000..df89213ec74 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pmgp-fgv4-prx4/GHSA-pmgp-fgv4-prx4.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pmgp-fgv4-prx4", + "modified": "2025-04-16T21:30:57Z", + "published": "2025-04-16T21:30:57Z", + "aliases": [ + "CVE-2025-29652" + ], + "details": "SQL Injection vulnerability exists in the TP-Link M7000 4G LTE Mobile Wi-Fi Router Firmware Version: 1.0.7 Build 180127 Rel.55998n, allowing an unauthenticated attacker to inject malicious SQL statements via the username and password fields", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29652" + }, + { + "type": "WEB", + "url": "https://github.com/TheVeteran1/Vulnerability-Research/blob/main/CVE-2025-29652" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T20:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-q4hh-vrvh-r4h7/GHSA-q4hh-vrvh-r4h7.json b/advisories/unreviewed/2025/04/GHSA-q4hh-vrvh-r4h7/GHSA-q4hh-vrvh-r4h7.json new file mode 100644 index 00000000000..1094706846a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-q4hh-vrvh-r4h7/GHSA-q4hh-vrvh-r4h7.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q4hh-vrvh-r4h7", + "modified": "2025-04-16T21:30:57Z", + "published": "2025-04-16T21:30:57Z", + "aliases": [ + "CVE-2025-31201" + ], + "details": "This issue was addressed by removing the vulnerable code. This issue is fixed in tvOS 18.4.1, visionOS 2.4.1, iOS iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31201" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122282" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122400" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122401" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122402" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T19:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qg2m-2384-5gwx/GHSA-qg2m-2384-5gwx.json b/advisories/unreviewed/2025/04/GHSA-qg2m-2384-5gwx/GHSA-qg2m-2384-5gwx.json new file mode 100644 index 00000000000..cb6bed0ab1a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qg2m-2384-5gwx/GHSA-qg2m-2384-5gwx.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qg2m-2384-5gwx", + "modified": "2025-04-16T21:30:58Z", + "published": "2025-04-16T21:30:58Z", + "aliases": [ + "CVE-2025-3726" + ], + "details": "A vulnerability was found in PCMan FTP Server 2.0.7. It has been rated as critical. Affected by this issue is some unknown functionality of the component CD Command Handler. The manipulation leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3726" + }, + { + "type": "WEB", + "url": "https://fitoxs.com/exploit/exploit-900150983cd24fb0d6963f7d28e17f72.txt" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.305072" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.305072" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.552815" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T20:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qg97-xp64-p6pc/GHSA-qg97-xp64-p6pc.json b/advisories/unreviewed/2025/04/GHSA-qg97-xp64-p6pc/GHSA-qg97-xp64-p6pc.json new file mode 100644 index 00000000000..69f7e44cc38 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qg97-xp64-p6pc/GHSA-qg97-xp64-p6pc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qg97-xp64-p6pc", + "modified": "2025-04-16T21:30:59Z", + "published": "2025-04-16T21:30:59Z", + "aliases": [ + "CVE-2025-3619" + ], + "details": "Heap buffer overflow in Codecs in Google Chrome on Windows prior to 135.0.7049.95 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3619" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2025/04/stable-channel-update-for-desktop_15.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/409619251" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T21:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qvp8-h356-jgg7/GHSA-qvp8-h356-jgg7.json b/advisories/unreviewed/2025/04/GHSA-qvp8-h356-jgg7/GHSA-qvp8-h356-jgg7.json new file mode 100644 index 00000000000..e80b178782e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qvp8-h356-jgg7/GHSA-qvp8-h356-jgg7.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qvp8-h356-jgg7", + "modified": "2025-04-16T21:30:59Z", + "published": "2025-04-16T21:30:59Z", + "aliases": [ + "CVE-2025-3728" + ], + "details": "A vulnerability classified as critical was found in SourceCodester Simple Hotel Booking System 1.0. This vulnerability affects the function Login. The manipulation of the argument uname leads to buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3728" + }, + { + "type": "WEB", + "url": "https://github.com/eeeee-vul/CVE/issues/3" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.305074" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.305074" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.553627" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T21:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-r225-m4mc-h9h3/GHSA-r225-m4mc-h9h3.json b/advisories/unreviewed/2025/04/GHSA-r225-m4mc-h9h3/GHSA-r225-m4mc-h9h3.json new file mode 100644 index 00000000000..bc7d1e3f233 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-r225-m4mc-h9h3/GHSA-r225-m4mc-h9h3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r225-m4mc-h9h3", + "modified": "2025-04-16T21:30:57Z", + "published": "2025-04-16T21:30:57Z", + "aliases": [ + "CVE-2025-29649" + ], + "details": "SQL Injection vulnerability exists in the TP-Link TL-WR840N router s login dashboard (version 1.0), allowing an unauthenticated attacker to inject malicious SQL statements via the username and password fields.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29649" + }, + { + "type": "WEB", + "url": "https://github.com/TheVeteran1/Vulnerability-Research/blob/main/CVE-2025-29649" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T20:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-r33r-9v86-jfxp/GHSA-r33r-9v86-jfxp.json b/advisories/unreviewed/2025/04/GHSA-r33r-9v86-jfxp/GHSA-r33r-9v86-jfxp.json index 82e5afceaf3..133b8bebbde 100644 --- a/advisories/unreviewed/2025/04/GHSA-r33r-9v86-jfxp/GHSA-r33r-9v86-jfxp.json +++ b/advisories/unreviewed/2025/04/GHSA-r33r-9v86-jfxp/GHSA-r33r-9v86-jfxp.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-r3xh-xmm6-qp4w/GHSA-r3xh-xmm6-qp4w.json b/advisories/unreviewed/2025/04/GHSA-r3xh-xmm6-qp4w/GHSA-r3xh-xmm6-qp4w.json index fc46b46eb95..3c771ab002c 100644 --- a/advisories/unreviewed/2025/04/GHSA-r3xh-xmm6-qp4w/GHSA-r3xh-xmm6-qp4w.json +++ b/advisories/unreviewed/2025/04/GHSA-r3xh-xmm6-qp4w/GHSA-r3xh-xmm6-qp4w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r3xh-xmm6-qp4w", - "modified": "2025-04-15T21:31:43Z", + "modified": "2025-04-16T21:30:49Z", "published": "2025-04-15T21:31:43Z", "aliases": [ "CVE-2025-22903" ], "details": "TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the pin parameter in the function setWiFiWpsConfig.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-15T19:16:07Z" diff --git a/advisories/unreviewed/2025/04/GHSA-r8m2-5fw8-37h4/GHSA-r8m2-5fw8-37h4.json b/advisories/unreviewed/2025/04/GHSA-r8m2-5fw8-37h4/GHSA-r8m2-5fw8-37h4.json index aa1706bec03..e0175f983b6 100644 --- a/advisories/unreviewed/2025/04/GHSA-r8m2-5fw8-37h4/GHSA-r8m2-5fw8-37h4.json +++ b/advisories/unreviewed/2025/04/GHSA-r8m2-5fw8-37h4/GHSA-r8m2-5fw8-37h4.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-v38h-c3ff-rmhw/GHSA-v38h-c3ff-rmhw.json b/advisories/unreviewed/2025/04/GHSA-v38h-c3ff-rmhw/GHSA-v38h-c3ff-rmhw.json new file mode 100644 index 00000000000..ffc161ba3b9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v38h-c3ff-rmhw/GHSA-v38h-c3ff-rmhw.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v38h-c3ff-rmhw", + "modified": "2025-04-16T21:30:59Z", + "published": "2025-04-16T21:30:59Z", + "aliases": [ + "CVE-2025-26153" + ], + "details": "A Stored XSS vulnerability exists in the message compose feature of Chamilo LMS 1.11.28. Attackers can inject malicious scripts into messages, which execute when victims, such as administrators, reply to the message.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26153" + }, + { + "type": "WEB", + "url": "https://github.com/chamilo/chamilo-lms/commit/beb07770d674fcc9db6df0e59aab107678c28682" + }, + { + "type": "WEB", + "url": "https://github.com/chamilo/chamilo-lms/commit/d5c29cf39ac30d7364a52bba4036c3e870412066" + }, + { + "type": "WEB", + "url": "https://gist.github.com/NoSpaceAvailable/234acdf57b5d7b29b2f39090c1686bc8" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T21:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-v943-7xrm-g7pr/GHSA-v943-7xrm-g7pr.json b/advisories/unreviewed/2025/04/GHSA-v943-7xrm-g7pr/GHSA-v943-7xrm-g7pr.json index e82c1366fef..2b3c3016977 100644 --- a/advisories/unreviewed/2025/04/GHSA-v943-7xrm-g7pr/GHSA-v943-7xrm-g7pr.json +++ b/advisories/unreviewed/2025/04/GHSA-v943-7xrm-g7pr/GHSA-v943-7xrm-g7pr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v943-7xrm-g7pr", - "modified": "2025-04-16T00:31:38Z", + "modified": "2025-04-16T21:30:54Z", "published": "2025-04-16T00:31:37Z", "aliases": [ "CVE-2025-29471" ], "details": "Cross Site Scripting vulnerability in Nagios Log Server v.2024R1.3.1 allows a remote attacker to execute arbitrary code via a payload into the Email field.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-15T22:15:25Z" diff --git a/advisories/unreviewed/2025/04/GHSA-vp28-c453-wwjq/GHSA-vp28-c453-wwjq.json b/advisories/unreviewed/2025/04/GHSA-vp28-c453-wwjq/GHSA-vp28-c453-wwjq.json new file mode 100644 index 00000000000..c4f3581e14a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vp28-c453-wwjq/GHSA-vp28-c453-wwjq.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vp28-c453-wwjq", + "modified": "2025-04-16T21:30:57Z", + "published": "2025-04-16T21:30:57Z", + "aliases": [ + "CVE-2025-29653" + ], + "details": "SQL Injection vulnerability exists in the TP-Link M7450 4G LTE Mobile Wi-Fi Router Firmware Version: 1.0.2 Build 170306 Rel.1015n, allowing an unauthenticated attacker to inject malicious SQL statements via the username and password fields.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29653" + }, + { + "type": "WEB", + "url": "https://github.com/TheVeteran1/Vulnerability-Research/blob/main/CVE-2025-29653" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T20:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wcvm-x9qx-m58v/GHSA-wcvm-x9qx-m58v.json b/advisories/unreviewed/2025/04/GHSA-wcvm-x9qx-m58v/GHSA-wcvm-x9qx-m58v.json new file mode 100644 index 00000000000..d3529cf92a9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wcvm-x9qx-m58v/GHSA-wcvm-x9qx-m58v.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wcvm-x9qx-m58v", + "modified": "2025-04-16T21:30:58Z", + "published": "2025-04-16T21:30:58Z", + "aliases": [ + "CVE-2025-3725" + ], + "details": "A vulnerability was found in PCMan FTP Server 2.0.7. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component MIC Command Handler. The manipulation leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3725" + }, + { + "type": "WEB", + "url": "https://fitoxs.com/exploit/exploit-827ccb0eea8a706c4c34a16891f84e7b.txt" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.305071" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.305071" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.552814" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T20:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wx3c-jgwq-c5hx/GHSA-wx3c-jgwq-c5hx.json b/advisories/unreviewed/2025/04/GHSA-wx3c-jgwq-c5hx/GHSA-wx3c-jgwq-c5hx.json new file mode 100644 index 00000000000..ff0632fe068 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wx3c-jgwq-c5hx/GHSA-wx3c-jgwq-c5hx.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wx3c-jgwq-c5hx", + "modified": "2025-04-16T21:31:00Z", + "published": "2025-04-16T21:30:59Z", + "aliases": [ + "CVE-2025-3727" + ], + "details": "A vulnerability classified as critical has been found in PCMan FTP Server 2.0.7. This affects an unknown part of the component STATUS Command Handler. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3727" + }, + { + "type": "WEB", + "url": "https://fitoxs.com/exploit/exploit-5ebe2294ecd0e0f08eab7690d2a6ee69.txt" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.305073" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.305073" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.552816" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-16T21:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xrmr-grfc-w665/GHSA-xrmr-grfc-w665.json b/advisories/unreviewed/2025/04/GHSA-xrmr-grfc-w665/GHSA-xrmr-grfc-w665.json index 0097aa769b2..bf7467b6d9a 100644 --- a/advisories/unreviewed/2025/04/GHSA-xrmr-grfc-w665/GHSA-xrmr-grfc-w665.json +++ b/advisories/unreviewed/2025/04/GHSA-xrmr-grfc-w665/GHSA-xrmr-grfc-w665.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-732" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-xx97-cmjp-pm7g/GHSA-xx97-cmjp-pm7g.json b/advisories/unreviewed/2025/04/GHSA-xx97-cmjp-pm7g/GHSA-xx97-cmjp-pm7g.json index 31f7e5105cd..d61960eed7f 100644 --- a/advisories/unreviewed/2025/04/GHSA-xx97-cmjp-pm7g/GHSA-xx97-cmjp-pm7g.json +++ b/advisories/unreviewed/2025/04/GHSA-xx97-cmjp-pm7g/GHSA-xx97-cmjp-pm7g.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-732" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null,