diff --git a/CVE-2025/CVE-2025-59xx/CVE-2025-5964.json b/CVE-2025/CVE-2025-59xx/CVE-2025-5964.json new file mode 100644 index 00000000000..8055f2de890 --- /dev/null +++ b/CVE-2025/CVE-2025-59xx/CVE-2025-5964.json @@ -0,0 +1,78 @@ +{ + "id": "CVE-2025-5964", + "sourceIdentifier": "security@m-files.com", + "published": "2025-06-15T20:15:31.037", + "lastModified": "2025-06-15T20:15:31.037", + "vulnStatus": "Received", + "cveTags": [], + "descriptions": [ + { + "lang": "en", + "value": "A path traversal issue in the API endpoint in M-Files Server before version 25.6.14925.0 allows an authenticated user to read files in the server." + } + ], + "metrics": { + "cvssMetricV40": [ + { + "source": "security@m-files.com", + "type": "Secondary", + "cvssData": { + "version": "4.0", + "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:M/U:Green", + "baseScore": 8.4, + "baseSeverity": "HIGH", + "attackVector": "NETWORK", + "attackComplexity": "LOW", + "attackRequirements": "NONE", + "privilegesRequired": "LOW", + "userInteraction": "NONE", + "vulnConfidentialityImpact": "HIGH", + "vulnIntegrityImpact": "NONE", + "vulnAvailabilityImpact": "NONE", + "subConfidentialityImpact": "HIGH", + "subIntegrityImpact": "HIGH", + "subAvailabilityImpact": "NONE", + "exploitMaturity": "NOT_DEFINED", + "confidentialityRequirement": "NOT_DEFINED", + "integrityRequirement": "NOT_DEFINED", + "availabilityRequirement": "NOT_DEFINED", + "modifiedAttackVector": "NOT_DEFINED", + "modifiedAttackComplexity": "NOT_DEFINED", + "modifiedAttackRequirements": "NOT_DEFINED", + "modifiedPrivilegesRequired": "NOT_DEFINED", + "modifiedUserInteraction": "NOT_DEFINED", + "modifiedVulnConfidentialityImpact": "NOT_DEFINED", + "modifiedVulnIntegrityImpact": "NOT_DEFINED", + "modifiedVulnAvailabilityImpact": "NOT_DEFINED", + "modifiedSubConfidentialityImpact": "NOT_DEFINED", + "modifiedSubIntegrityImpact": "NOT_DEFINED", + "modifiedSubAvailabilityImpact": "NOT_DEFINED", + "Safety": "NOT_DEFINED", + "Automatable": "NOT_DEFINED", + "Recovery": "NOT_DEFINED", + "valueDensity": "NOT_DEFINED", + "vulnerabilityResponseEffort": "MODERATE", + "providerUrgency": "GREEN" + } + } + ] + }, + "weaknesses": [ + { + "source": "security@m-files.com", + "type": "Secondary", + "description": [ + { + "lang": "en", + "value": "CWE-22" + } + ] + } + ], + "references": [ + { + "url": "https://product.m-files.com/security-advisories/cve-2025-5964", + "source": "security@m-files.com" + } + ] +} \ No newline at end of file diff --git a/README.md b/README.md index 14f0846ee40..6854f501c85 100644 --- a/README.md +++ b/README.md @@ -13,13 +13,13 @@ Repository synchronizes with the NVD every 2 hours. ### Last Repository Update ```plain -2025-06-15T20:00:19.924711+00:00 +2025-06-15T22:00:19.026163+00:00 ``` ### Most recent CVE Modification Timestamp synchronized with NVD ```plain -2025-06-15T19:15:18.793000+00:00 +2025-06-15T20:15:31.037000+00:00 ``` ### Last Data Feed Release @@ -33,22 +33,20 @@ Download and Changelog: [Click](https://github.com/fkie-cad/nvd-json-data-feeds/ ### Total Number of included CVEs ```plain -297964 +297965 ``` ### CVEs added in the last Commit -Recently added CVEs: `2` +Recently added CVEs: `1` -- [CVE-2025-5990](CVE-2025/CVE-2025-59xx/CVE-2025-5990.json) (`2025-06-15T18:15:18.267`) -- [CVE-2025-6092](CVE-2025/CVE-2025-60xx/CVE-2025-6092.json) (`2025-06-15T18:15:19.037`) +- [CVE-2025-5964](CVE-2025/CVE-2025-59xx/CVE-2025-5964.json) (`2025-06-15T20:15:31.037`) ### CVEs modified in the last Commit -Recently modified CVEs: `1` +Recently modified CVEs: `0` -- [CVE-2023-7035](CVE-2023/CVE-2023-70xx/CVE-2023-7035.json) (`2025-06-15T19:15:18.793`) ## Download and Usage diff --git a/_state.csv b/_state.csv index 7fb6d7456c8..aa6b58ee02d 100644 --- a/_state.csv +++ b/_state.csv @@ -243892,7 +243892,7 @@ CVE-2023-7030,0,0,3c0e7e678cd5c617b5ce9677e1be89fed25cef8cbc989aad9df6d54a4663d5 CVE-2023-7031,0,0,d56d1f243e4bd6c87e3002c4501e9fe5a78b6fc19e814625316adbaf20b3903f,2024-11-21T08:45:04.987000 CVE-2023-7032,0,0,90028d31b608d7a4d2fc3aaf47e6ddce9fe1fee5eae81e1705864bc5b8e20e15,2024-11-21T08:45:05.137000 CVE-2023-7033,0,0,3740bc13eb2fe0e0616085b4a70bef4c5f396920119b20e38bd7301edafc37d2,2025-01-16T05:15:09.720000 -CVE-2023-7035,0,1,325a07b42a5d13919ffe081e81d3eff67d168a9958bd33fa61975db7c83e6d19,2025-06-15T19:15:18.793000 +CVE-2023-7035,0,0,325a07b42a5d13919ffe081e81d3eff67d168a9958bd33fa61975db7c83e6d19,2025-06-15T19:15:18.793000 CVE-2023-7036,0,0,e8a0ecd56cc1901f1ceaafdfee06a05cea7e8ad945252611e87d6c4ac4ef2ec2,2024-11-21T08:45:05.700000 CVE-2023-7037,0,0,43c6fec2f65f06abfabe29dda4ceaabe11aa4fb5a5ee0860d8c7a05dfe2b8e1a,2024-11-21T08:45:05.857000 CVE-2023-7038,0,0,bd5ce6d7cbc577c782047ab2ec9f96028fdffed14ff8d4c1b0642fb5c9ec44e6,2024-11-21T08:45:06.013000 @@ -297915,6 +297915,7 @@ CVE-2025-5950,0,0,93ad1163136e8895ad3f5aa5692d2dad9460c261edec19c496108907803559 CVE-2025-5952,0,0,80f5810e94a735443b1add4b87f50d30096f6ed0c46ddf37bebc56b27e945b75,2025-06-12T16:06:39.330000 CVE-2025-5958,0,0,f189a14363fc4d75c8d60dd1aebc0840ad33088eead9b86da76a6c6b49cb8c7c,2025-06-12T16:06:20.180000 CVE-2025-5959,0,0,be0aeb32ea54fd6e98466bb46bd49ebea303e5490307c8cf597d926f785408ab,2025-06-12T16:06:20.180000 +CVE-2025-5964,1,1,5e9fa268f55b2b4fbeec5b451c86faa73086b84d7e65c1082d54c5e6a41fdc94,2025-06-15T20:15:31.037000 CVE-2025-5969,0,0,c1cc21e3e671c92cd4500d184398151db62163dec64f67d18a86b28ac5130697,2025-06-12T16:06:29.520000 CVE-2025-5970,0,0,f0af781466168ba00ad4d1f00a851825386cb204e76cc709e911a3d2faabbc12,2025-06-12T16:06:29.520000 CVE-2025-5971,0,0,f31780a27da79cfd4bdd73e0275c3322aabb65327151b3ade03d0ff9052df285,2025-06-12T16:06:29.520000 @@ -297931,7 +297932,7 @@ CVE-2025-5982,0,0,0c7dea74cc8efc70e60ba20222cf4cd8ed64924645dcf72550beef2f337a91 CVE-2025-5984,0,0,7cfaf20c4da70667d156850823eee53a39a37c9deae6d419cb0c5d32dacf8676,2025-06-12T16:06:20.180000 CVE-2025-5985,0,0,ebcdda4dcd61ee165daceb4c1cf64a9b8507d5f9de3a48b2f52bb73592cb298b,2025-06-12T16:06:20.180000 CVE-2025-5986,0,0,dd95f639f37e975a11d2593698d4d1fa27a00a42ab756d34661be25296fae63b,2025-06-12T16:06:20.180000 -CVE-2025-5990,1,1,961673ab9954b97229be3fc18a50e664a0bc9fa9400cb93454dd37859378dd5b,2025-06-15T18:15:18.267000 +CVE-2025-5990,0,0,961673ab9954b97229be3fc18a50e664a0bc9fa9400cb93454dd37859378dd5b,2025-06-15T18:15:18.267000 CVE-2025-5991,0,0,2d56ef31c39d49ebda5cce54941d2d07bc366906f8f2e10ec12b1264a4709a15,2025-06-12T16:06:20.180000 CVE-2025-5996,0,0,6d836d2b7cc11df634eb3440d15936d2a06ec9995d3d02eb7a9226ed3b7059e0,2025-06-12T16:06:20.180000 CVE-2025-6001,0,0,6947a76225acd2e0352dafdcc9d8c8832898e935ce2588bd16c7b63b5eaaea42,2025-06-12T16:06:20.180000 @@ -297962,4 +297963,4 @@ CVE-2025-6083,0,0,5e291165aed4c74479ba71d7ab91f6f809097d9cd4c0b19093249b128e4fa5 CVE-2025-6089,0,0,1082dde39a9a857add821028ed23d128072d550fdb8ad36ad1f948e836ba053f,2025-06-15T13:15:33.353000 CVE-2025-6090,0,0,e27818139ece2411b32b2e625852fcc342cc8f5d5f99f49ddd3d8c5d380302a8,2025-06-15T15:15:19.303000 CVE-2025-6091,0,0,581c1cfa5c591595b15c75e858563a24f75318a6fba57a73b264350d4caca8d2,2025-06-15T17:15:18.360000 -CVE-2025-6092,1,1,610090ee4899c7756bc69bf8b3a79dc8f05e4845772e95595392d1ed6df1eb10,2025-06-15T18:15:19.037000 +CVE-2025-6092,0,0,610090ee4899c7756bc69bf8b3a79dc8f05e4845772e95595392d1ed6df1eb10,2025-06-15T18:15:19.037000