diff --git a/advisories/unreviewed/2024/08/GHSA-8chj-vfwh-89pj/GHSA-8chj-vfwh-89pj.json b/advisories/unreviewed/2024/08/GHSA-8chj-vfwh-89pj/GHSA-8chj-vfwh-89pj.json index 3dfe3ec0a9e..a228c960a74 100644 --- a/advisories/unreviewed/2024/08/GHSA-8chj-vfwh-89pj/GHSA-8chj-vfwh-89pj.json +++ b/advisories/unreviewed/2024/08/GHSA-8chj-vfwh-89pj/GHSA-8chj-vfwh-89pj.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/08/GHSA-c84x-657q-q6vq/GHSA-c84x-657q-q6vq.json b/advisories/unreviewed/2024/08/GHSA-c84x-657q-q6vq/GHSA-c84x-657q-q6vq.json index 151b551041c..11be0689eeb 100644 --- a/advisories/unreviewed/2024/08/GHSA-c84x-657q-q6vq/GHSA-c84x-657q-q6vq.json +++ b/advisories/unreviewed/2024/08/GHSA-c84x-657q-q6vq/GHSA-c84x-657q-q6vq.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/10/GHSA-3v5j-fcwv-g4wv/GHSA-3v5j-fcwv-g4wv.json b/advisories/unreviewed/2024/10/GHSA-3v5j-fcwv-g4wv/GHSA-3v5j-fcwv-g4wv.json index 239b354745b..90c721e7c0e 100644 --- a/advisories/unreviewed/2024/10/GHSA-3v5j-fcwv-g4wv/GHSA-3v5j-fcwv-g4wv.json +++ b/advisories/unreviewed/2024/10/GHSA-3v5j-fcwv-g4wv/GHSA-3v5j-fcwv-g4wv.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-77" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/10/GHSA-f7gw-gr5r-rr7w/GHSA-f7gw-gr5r-rr7w.json b/advisories/unreviewed/2024/10/GHSA-f7gw-gr5r-rr7w/GHSA-f7gw-gr5r-rr7w.json index b89c7af8dfe..75503c11543 100644 --- a/advisories/unreviewed/2024/10/GHSA-f7gw-gr5r-rr7w/GHSA-f7gw-gr5r-rr7w.json +++ b/advisories/unreviewed/2024/10/GHSA-f7gw-gr5r-rr7w/GHSA-f7gw-gr5r-rr7w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f7gw-gr5r-rr7w", - "modified": "2024-10-29T06:30:46Z", + "modified": "2025-05-17T03:30:31Z", "published": "2024-10-29T06:30:46Z", "aliases": [ "CVE-2024-10000" diff --git a/advisories/unreviewed/2024/10/GHSA-rq4q-7xvx-8f5w/GHSA-rq4q-7xvx-8f5w.json b/advisories/unreviewed/2024/10/GHSA-rq4q-7xvx-8f5w/GHSA-rq4q-7xvx-8f5w.json index 3a2d6cc8af4..206f39dabfb 100644 --- a/advisories/unreviewed/2024/10/GHSA-rq4q-7xvx-8f5w/GHSA-rq4q-7xvx-8f5w.json +++ b/advisories/unreviewed/2024/10/GHSA-rq4q-7xvx-8f5w/GHSA-rq4q-7xvx-8f5w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rq4q-7xvx-8f5w", - "modified": "2024-10-16T03:31:33Z", + "modified": "2025-05-17T03:30:30Z", "published": "2024-10-16T03:31:33Z", "aliases": [ "CVE-2024-9305" diff --git a/advisories/unreviewed/2024/10/GHSA-v4cx-r43j-pwh7/GHSA-v4cx-r43j-pwh7.json b/advisories/unreviewed/2024/10/GHSA-v4cx-r43j-pwh7/GHSA-v4cx-r43j-pwh7.json index 2e2b24dff37..e1fb19c2dc4 100644 --- a/advisories/unreviewed/2024/10/GHSA-v4cx-r43j-pwh7/GHSA-v4cx-r43j-pwh7.json +++ b/advisories/unreviewed/2024/10/GHSA-v4cx-r43j-pwh7/GHSA-v4cx-r43j-pwh7.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/10/GHSA-x599-839j-7f7f/GHSA-x599-839j-7f7f.json b/advisories/unreviewed/2024/10/GHSA-x599-839j-7f7f/GHSA-x599-839j-7f7f.json index 6458a51a4c7..ccc548b101d 100644 --- a/advisories/unreviewed/2024/10/GHSA-x599-839j-7f7f/GHSA-x599-839j-7f7f.json +++ b/advisories/unreviewed/2024/10/GHSA-x599-839j-7f7f/GHSA-x599-839j-7f7f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x599-839j-7f7f", - "modified": "2024-10-29T06:30:46Z", + "modified": "2025-05-17T03:30:31Z", "published": "2024-10-29T06:30:46Z", "aliases": [ "CVE-2024-10008" diff --git a/advisories/unreviewed/2024/11/GHSA-qx29-vw3w-p54v/GHSA-qx29-vw3w-p54v.json b/advisories/unreviewed/2024/11/GHSA-qx29-vw3w-p54v/GHSA-qx29-vw3w-p54v.json index e108e1de4b5..0f9e2b96a4a 100644 --- a/advisories/unreviewed/2024/11/GHSA-qx29-vw3w-p54v/GHSA-qx29-vw3w-p54v.json +++ b/advisories/unreviewed/2024/11/GHSA-qx29-vw3w-p54v/GHSA-qx29-vw3w-p54v.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-3q36-3ffw-mmf8/GHSA-3q36-3ffw-mmf8.json b/advisories/unreviewed/2024/12/GHSA-3q36-3ffw-mmf8/GHSA-3q36-3ffw-mmf8.json index 3174c6b751c..1f2dc858339 100644 --- a/advisories/unreviewed/2024/12/GHSA-3q36-3ffw-mmf8/GHSA-3q36-3ffw-mmf8.json +++ b/advisories/unreviewed/2024/12/GHSA-3q36-3ffw-mmf8/GHSA-3q36-3ffw-mmf8.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-5w62-ppvg-pwpq/GHSA-5w62-ppvg-pwpq.json b/advisories/unreviewed/2024/12/GHSA-5w62-ppvg-pwpq/GHSA-5w62-ppvg-pwpq.json index d4e51ab81c4..0f3242c46ad 100644 --- a/advisories/unreviewed/2024/12/GHSA-5w62-ppvg-pwpq/GHSA-5w62-ppvg-pwpq.json +++ b/advisories/unreviewed/2024/12/GHSA-5w62-ppvg-pwpq/GHSA-5w62-ppvg-pwpq.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-78rp-3qj9-9ccf/GHSA-78rp-3qj9-9ccf.json b/advisories/unreviewed/2024/12/GHSA-78rp-3qj9-9ccf/GHSA-78rp-3qj9-9ccf.json index 1601c62cbc4..b83c58ee779 100644 --- a/advisories/unreviewed/2024/12/GHSA-78rp-3qj9-9ccf/GHSA-78rp-3qj9-9ccf.json +++ b/advisories/unreviewed/2024/12/GHSA-78rp-3qj9-9ccf/GHSA-78rp-3qj9-9ccf.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-9m9r-rw59-qh84/GHSA-9m9r-rw59-qh84.json b/advisories/unreviewed/2024/12/GHSA-9m9r-rw59-qh84/GHSA-9m9r-rw59-qh84.json index 6750039af6a..0cff66fee1a 100644 --- a/advisories/unreviewed/2024/12/GHSA-9m9r-rw59-qh84/GHSA-9m9r-rw59-qh84.json +++ b/advisories/unreviewed/2024/12/GHSA-9m9r-rw59-qh84/GHSA-9m9r-rw59-qh84.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-j376-8r6p-32f7/GHSA-j376-8r6p-32f7.json b/advisories/unreviewed/2024/12/GHSA-j376-8r6p-32f7/GHSA-j376-8r6p-32f7.json index 217e0841764..f932263b84b 100644 --- a/advisories/unreviewed/2024/12/GHSA-j376-8r6p-32f7/GHSA-j376-8r6p-32f7.json +++ b/advisories/unreviewed/2024/12/GHSA-j376-8r6p-32f7/GHSA-j376-8r6p-32f7.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-j3vp-3p2j-8q53/GHSA-j3vp-3p2j-8q53.json b/advisories/unreviewed/2024/12/GHSA-j3vp-3p2j-8q53/GHSA-j3vp-3p2j-8q53.json index a67045a1012..bf7a26bdb38 100644 --- a/advisories/unreviewed/2024/12/GHSA-j3vp-3p2j-8q53/GHSA-j3vp-3p2j-8q53.json +++ b/advisories/unreviewed/2024/12/GHSA-j3vp-3p2j-8q53/GHSA-j3vp-3p2j-8q53.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-22" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-j4cm-37xq-935g/GHSA-j4cm-37xq-935g.json b/advisories/unreviewed/2024/12/GHSA-j4cm-37xq-935g/GHSA-j4cm-37xq-935g.json index efbebd60ffe..8867493898d 100644 --- a/advisories/unreviewed/2024/12/GHSA-j4cm-37xq-935g/GHSA-j4cm-37xq-935g.json +++ b/advisories/unreviewed/2024/12/GHSA-j4cm-37xq-935g/GHSA-j4cm-37xq-935g.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-rhjp-3r26-6vqh/GHSA-rhjp-3r26-6vqh.json b/advisories/unreviewed/2024/12/GHSA-rhjp-3r26-6vqh/GHSA-rhjp-3r26-6vqh.json index 0606185e36f..e35fd450e29 100644 --- a/advisories/unreviewed/2024/12/GHSA-rhjp-3r26-6vqh/GHSA-rhjp-3r26-6vqh.json +++ b/advisories/unreviewed/2024/12/GHSA-rhjp-3r26-6vqh/GHSA-rhjp-3r26-6vqh.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-wg9r-cvfj-5cg2/GHSA-wg9r-cvfj-5cg2.json b/advisories/unreviewed/2024/12/GHSA-wg9r-cvfj-5cg2/GHSA-wg9r-cvfj-5cg2.json index e5a900559c6..efba7827f21 100644 --- a/advisories/unreviewed/2024/12/GHSA-wg9r-cvfj-5cg2/GHSA-wg9r-cvfj-5cg2.json +++ b/advisories/unreviewed/2024/12/GHSA-wg9r-cvfj-5cg2/GHSA-wg9r-cvfj-5cg2.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-89wj-jvpp-gwhf/GHSA-89wj-jvpp-gwhf.json b/advisories/unreviewed/2025/01/GHSA-89wj-jvpp-gwhf/GHSA-89wj-jvpp-gwhf.json index 52d2176bc3b..c0cf0b3014f 100644 --- a/advisories/unreviewed/2025/01/GHSA-89wj-jvpp-gwhf/GHSA-89wj-jvpp-gwhf.json +++ b/advisories/unreviewed/2025/01/GHSA-89wj-jvpp-gwhf/GHSA-89wj-jvpp-gwhf.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-2hgg-g6cr-365f/GHSA-2hgg-g6cr-365f.json b/advisories/unreviewed/2025/05/GHSA-2hgg-g6cr-365f/GHSA-2hgg-g6cr-365f.json index c59205077f4..2244368b572 100644 --- a/advisories/unreviewed/2025/05/GHSA-2hgg-g6cr-365f/GHSA-2hgg-g6cr-365f.json +++ b/advisories/unreviewed/2025/05/GHSA-2hgg-g6cr-365f/GHSA-2hgg-g6cr-365f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2hgg-g6cr-365f", - "modified": "2025-05-16T21:32:13Z", + "modified": "2025-05-17T03:30:32Z", "published": "2025-05-16T21:32:13Z", "aliases": [ "CVE-2025-32407" ], "details": "Samsung Internet for Galaxy Watch version 5.0.9, available up until Samsung Galaxy Watch 3, does not properly validate TLS certificates, allowing for an attacker to impersonate any and all websites visited by the user. This is a critical misconfiguration in the way the browser validates the identity of the server. It negates the use of HTTPS as a secure channel, allowing for Man-in-the-Middle attacks, stealing sensitive information or modifying incoming and outgoing traffic. NOTE: This vulnerability is in an end-of-life product that is no longer maintained by the vendor.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-295" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-16T21:15:35Z" diff --git a/advisories/unreviewed/2025/05/GHSA-4jfp-89f3-9pw7/GHSA-4jfp-89f3-9pw7.json b/advisories/unreviewed/2025/05/GHSA-4jfp-89f3-9pw7/GHSA-4jfp-89f3-9pw7.json index c2af8787420..5659554b292 100644 --- a/advisories/unreviewed/2025/05/GHSA-4jfp-89f3-9pw7/GHSA-4jfp-89f3-9pw7.json +++ b/advisories/unreviewed/2025/05/GHSA-4jfp-89f3-9pw7/GHSA-4jfp-89f3-9pw7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4jfp-89f3-9pw7", - "modified": "2025-05-15T21:31:27Z", + "modified": "2025-05-17T03:30:31Z", "published": "2025-05-15T21:31:27Z", "aliases": [ "CVE-2023-7088" ], "details": "The Add SVG Support for Media Uploader | inventivo WordPress plugin through 1.0.5 does not sanitize uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:30Z" diff --git a/advisories/unreviewed/2025/05/GHSA-5pww-x83q-7gjh/GHSA-5pww-x83q-7gjh.json b/advisories/unreviewed/2025/05/GHSA-5pww-x83q-7gjh/GHSA-5pww-x83q-7gjh.json index 30139ae8063..3c3cfdb5ca7 100644 --- a/advisories/unreviewed/2025/05/GHSA-5pww-x83q-7gjh/GHSA-5pww-x83q-7gjh.json +++ b/advisories/unreviewed/2025/05/GHSA-5pww-x83q-7gjh/GHSA-5pww-x83q-7gjh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5pww-x83q-7gjh", - "modified": "2025-05-16T18:31:08Z", + "modified": "2025-05-17T03:30:32Z", "published": "2025-05-16T18:31:08Z", "aliases": [ "CVE-2025-40906" ], "details": "BSON::XS versions 0.8.4 and earlier for Perl includes a bundled libbson 1.1.7, which has several vulnerabilities.\n\nThose include CVE-2017-14227, CVE-2018-16790, CVE-2023-0437, CVE-2024-6381, CVE-2024-6383, and CVE-2025-0755. \n\nBSON-XS was the official Perl XS implementation of MongoDB's BSON serialization, but this distribution has reached its end of life as of August 13, 2020 and is no longer supported.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-1104" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-16T16:15:41Z" diff --git a/advisories/unreviewed/2025/05/GHSA-8mm9-c4mg-vfjh/GHSA-8mm9-c4mg-vfjh.json b/advisories/unreviewed/2025/05/GHSA-8mm9-c4mg-vfjh/GHSA-8mm9-c4mg-vfjh.json index fe73f2bd68b..df585a4be8c 100644 --- a/advisories/unreviewed/2025/05/GHSA-8mm9-c4mg-vfjh/GHSA-8mm9-c4mg-vfjh.json +++ b/advisories/unreviewed/2025/05/GHSA-8mm9-c4mg-vfjh/GHSA-8mm9-c4mg-vfjh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8mm9-c4mg-vfjh", - "modified": "2025-05-16T21:32:12Z", + "modified": "2025-05-17T03:30:32Z", "published": "2025-05-16T21:32:12Z", "aliases": [ "CVE-2025-4802" ], "details": "Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or calls to NSS functions such as getaddrinfo).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -21,13 +26,17 @@ { "type": "WEB", "url": "https://sourceware.org/cgit/glibc/commit/?id=1e18586c5820e329f741d5c710275e165581380e" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/05/16/7" } ], "database_specific": { "cwe_ids": [ "CWE-426" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-16T20:15:22Z" diff --git a/advisories/unreviewed/2025/05/GHSA-989c-235q-c52g/GHSA-989c-235q-c52g.json b/advisories/unreviewed/2025/05/GHSA-989c-235q-c52g/GHSA-989c-235q-c52g.json new file mode 100644 index 00000000000..a49be2391f2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-989c-235q-c52g/GHSA-989c-235q-c52g.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-989c-235q-c52g", + "modified": "2025-05-17T03:30:32Z", + "published": "2025-05-17T03:30:32Z", + "aliases": [ + "CVE-2025-4814" + ], + "details": "A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /pages/supplier_add.php. The manipulation of the argument Name leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4814" + }, + { + "type": "WEB", + "url": "https://github.com/iGGbondTC/cve/issues/1" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309271" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309271" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.574081" + }, + { + "type": "WEB", + "url": "https://www.campcodes.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-17T03:17:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fvhp-x5xr-47xv/GHSA-fvhp-x5xr-47xv.json b/advisories/unreviewed/2025/05/GHSA-fvhp-x5xr-47xv/GHSA-fvhp-x5xr-47xv.json index a3418352aac..9faf78a86a4 100644 --- a/advisories/unreviewed/2025/05/GHSA-fvhp-x5xr-47xv/GHSA-fvhp-x5xr-47xv.json +++ b/advisories/unreviewed/2025/05/GHSA-fvhp-x5xr-47xv/GHSA-fvhp-x5xr-47xv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fvhp-x5xr-47xv", - "modified": "2025-05-16T21:32:12Z", + "modified": "2025-05-17T03:30:32Z", "published": "2025-05-16T21:32:12Z", "aliases": [ "CVE-2022-4363" ], "details": "The Wholesale Market WordPress plugin before 2.2.2, Wholesale Market for WooCommerce WordPress plugin before 2.0.1 have a flawed CSRF check when updating their settings, which could allow attackers to make a logged in admin update them via a CSRF attack", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-16T21:15:33Z" diff --git a/advisories/unreviewed/2025/05/GHSA-p3p9-wgx4-mq3v/GHSA-p3p9-wgx4-mq3v.json b/advisories/unreviewed/2025/05/GHSA-p3p9-wgx4-mq3v/GHSA-p3p9-wgx4-mq3v.json new file mode 100644 index 00000000000..bf785b3135d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p3p9-wgx4-mq3v/GHSA-p3p9-wgx4-mq3v.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p3p9-wgx4-mq3v", + "modified": "2025-05-17T03:30:33Z", + "published": "2025-05-17T03:30:33Z", + "aliases": [ + "CVE-2025-4815" + ], + "details": "A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /pages/supplier_update.php. The manipulation of the argument Name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4815" + }, + { + "type": "WEB", + "url": "https://github.com/iGGbondTC/cve/issues/2" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309272" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309272" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.574082" + }, + { + "type": "WEB", + "url": "https://www.campcodes.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-17T03:17:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vxgw-vvr8-p42m/GHSA-vxgw-vvr8-p42m.json b/advisories/unreviewed/2025/05/GHSA-vxgw-vvr8-p42m/GHSA-vxgw-vvr8-p42m.json index 4f805824fec..f7741c38164 100644 --- a/advisories/unreviewed/2025/05/GHSA-vxgw-vvr8-p42m/GHSA-vxgw-vvr8-p42m.json +++ b/advisories/unreviewed/2025/05/GHSA-vxgw-vvr8-p42m/GHSA-vxgw-vvr8-p42m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vxgw-vvr8-p42m", - "modified": "2025-05-15T21:31:27Z", + "modified": "2025-05-17T03:30:31Z", "published": "2025-05-15T21:31:27Z", "aliases": [ "CVE-2023-7086" ], "details": "The SVG Uploads Support WordPress plugin through 2.1.1 does not sanitize uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:29Z" diff --git a/advisories/unreviewed/2025/05/GHSA-wq25-m95j-8rw5/GHSA-wq25-m95j-8rw5.json b/advisories/unreviewed/2025/05/GHSA-wq25-m95j-8rw5/GHSA-wq25-m95j-8rw5.json new file mode 100644 index 00000000000..434da592b88 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wq25-m95j-8rw5/GHSA-wq25-m95j-8rw5.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wq25-m95j-8rw5", + "modified": "2025-05-17T03:30:32Z", + "published": "2025-05-17T03:30:32Z", + "aliases": [ + "CVE-2025-1706" + ], + "details": "Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kernel exceptions.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1706" + }, + { + "type": "WEB", + "url": "https://www.imaginationtech.com/gpu-driver-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-17T01:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wxm4-3j5f-3j3v/GHSA-wxm4-3j5f-3j3v.json b/advisories/unreviewed/2025/05/GHSA-wxm4-3j5f-3j3v/GHSA-wxm4-3j5f-3j3v.json new file mode 100644 index 00000000000..f098c81954b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wxm4-3j5f-3j3v/GHSA-wxm4-3j5f-3j3v.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wxm4-3j5f-3j3v", + "modified": "2025-05-17T03:30:32Z", + "published": "2025-05-17T03:30:32Z", + "aliases": [ + "CVE-2024-47893" + ], + "details": "Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to read and/or write data outside the Guest's virtualised GPU memory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47893" + }, + { + "type": "WEB", + "url": "https://www.imaginationtech.com/gpu-driver-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-823" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-17T01:15:17Z" + } +} \ No newline at end of file