diff --git a/advisories/unreviewed/2022/08/GHSA-2ww6-gh4g-5q93/GHSA-2ww6-gh4g-5q93.json b/advisories/unreviewed/2022/08/GHSA-2ww6-gh4g-5q93/GHSA-2ww6-gh4g-5q93.json index ed799fb4d32..c79b5e29b6a 100644 --- a/advisories/unreviewed/2022/08/GHSA-2ww6-gh4g-5q93/GHSA-2ww6-gh4g-5q93.json +++ b/advisories/unreviewed/2022/08/GHSA-2ww6-gh4g-5q93/GHSA-2ww6-gh4g-5q93.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/08/GHSA-g4vf-3p39-qqvm/GHSA-g4vf-3p39-qqvm.json b/advisories/unreviewed/2022/08/GHSA-g4vf-3p39-qqvm/GHSA-g4vf-3p39-qqvm.json index 344442a090d..d69bc14e2f9 100644 --- a/advisories/unreviewed/2022/08/GHSA-g4vf-3p39-qqvm/GHSA-g4vf-3p39-qqvm.json +++ b/advisories/unreviewed/2022/08/GHSA-g4vf-3p39-qqvm/GHSA-g4vf-3p39-qqvm.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/08/GHSA-jx6j-76gr-qfqf/GHSA-jx6j-76gr-qfqf.json b/advisories/unreviewed/2022/08/GHSA-jx6j-76gr-qfqf/GHSA-jx6j-76gr-qfqf.json index 774f3e331d0..cf712d5fee0 100644 --- a/advisories/unreviewed/2022/08/GHSA-jx6j-76gr-qfqf/GHSA-jx6j-76gr-qfqf.json +++ b/advisories/unreviewed/2022/08/GHSA-jx6j-76gr-qfqf/GHSA-jx6j-76gr-qfqf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jx6j-76gr-qfqf", - "modified": "2022-09-01T00:00:25Z", + "modified": "2025-05-29T18:31:08Z", "published": "2022-08-25T00:00:25Z", "aliases": [ "CVE-2022-32857" @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-319" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/08/GHSA-mv7m-fwq2-hc3h/GHSA-mv7m-fwq2-hc3h.json b/advisories/unreviewed/2022/08/GHSA-mv7m-fwq2-hc3h/GHSA-mv7m-fwq2-hc3h.json index 6918eb0b760..1891b752fc6 100644 --- a/advisories/unreviewed/2022/08/GHSA-mv7m-fwq2-hc3h/GHSA-mv7m-fwq2-hc3h.json +++ b/advisories/unreviewed/2022/08/GHSA-mv7m-fwq2-hc3h/GHSA-mv7m-fwq2-hc3h.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/08/GHSA-q53v-392r-55mw/GHSA-q53v-392r-55mw.json b/advisories/unreviewed/2022/08/GHSA-q53v-392r-55mw/GHSA-q53v-392r-55mw.json index 64306a87284..dedda621fcb 100644 --- a/advisories/unreviewed/2022/08/GHSA-q53v-392r-55mw/GHSA-q53v-392r-55mw.json +++ b/advisories/unreviewed/2022/08/GHSA-q53v-392r-55mw/GHSA-q53v-392r-55mw.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-285" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/08/GHSA-wwpp-xpcq-g2vc/GHSA-wwpp-xpcq-g2vc.json b/advisories/unreviewed/2022/08/GHSA-wwpp-xpcq-g2vc/GHSA-wwpp-xpcq-g2vc.json index cf8c2f96418..8f900ccb7d7 100644 --- a/advisories/unreviewed/2022/08/GHSA-wwpp-xpcq-g2vc/GHSA-wwpp-xpcq-g2vc.json +++ b/advisories/unreviewed/2022/08/GHSA-wwpp-xpcq-g2vc/GHSA-wwpp-xpcq-g2vc.json @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-3gcx-7vw9-42m9/GHSA-3gcx-7vw9-42m9.json b/advisories/unreviewed/2022/09/GHSA-3gcx-7vw9-42m9/GHSA-3gcx-7vw9-42m9.json index ad9c27f6acd..b40cecf628c 100644 --- a/advisories/unreviewed/2022/09/GHSA-3gcx-7vw9-42m9/GHSA-3gcx-7vw9-42m9.json +++ b/advisories/unreviewed/2022/09/GHSA-3gcx-7vw9-42m9/GHSA-3gcx-7vw9-42m9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3gcx-7vw9-42m9", - "modified": "2022-09-22T00:00:26Z", + "modified": "2025-05-29T18:31:08Z", "published": "2022-09-20T00:00:21Z", "aliases": [ "CVE-2022-38351" diff --git a/advisories/unreviewed/2022/09/GHSA-p9vf-jjj8-m5r9/GHSA-p9vf-jjj8-m5r9.json b/advisories/unreviewed/2022/09/GHSA-p9vf-jjj8-m5r9/GHSA-p9vf-jjj8-m5r9.json index 40ffd6d4416..0bb08dbbaf7 100644 --- a/advisories/unreviewed/2022/09/GHSA-p9vf-jjj8-m5r9/GHSA-p9vf-jjj8-m5r9.json +++ b/advisories/unreviewed/2022/09/GHSA-p9vf-jjj8-m5r9/GHSA-p9vf-jjj8-m5r9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p9vf-jjj8-m5r9", - "modified": "2022-09-23T00:00:41Z", + "modified": "2025-05-29T18:31:08Z", "published": "2022-09-20T00:00:21Z", "aliases": [ "CVE-2022-28321" @@ -34,6 +34,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-287", "CWE-863" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2022/09/GHSA-vxvm-35wp-ppw8/GHSA-vxvm-35wp-ppw8.json b/advisories/unreviewed/2022/09/GHSA-vxvm-35wp-ppw8/GHSA-vxvm-35wp-ppw8.json index 07694b62523..f68a4c6af3d 100644 --- a/advisories/unreviewed/2022/09/GHSA-vxvm-35wp-ppw8/GHSA-vxvm-35wp-ppw8.json +++ b/advisories/unreviewed/2022/09/GHSA-vxvm-35wp-ppw8/GHSA-vxvm-35wp-ppw8.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/01/GHSA-28jc-7xfh-6mvp/GHSA-28jc-7xfh-6mvp.json b/advisories/unreviewed/2024/01/GHSA-28jc-7xfh-6mvp/GHSA-28jc-7xfh-6mvp.json index 7fdaf4b8abe..b55bb7f5f44 100644 --- a/advisories/unreviewed/2024/01/GHSA-28jc-7xfh-6mvp/GHSA-28jc-7xfh-6mvp.json +++ b/advisories/unreviewed/2024/01/GHSA-28jc-7xfh-6mvp/GHSA-28jc-7xfh-6mvp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-28jc-7xfh-6mvp", - "modified": "2024-02-02T06:30:31Z", + "modified": "2025-05-29T18:31:08Z", "published": "2024-01-25T03:30:59Z", "aliases": [ "CVE-2024-0625" diff --git a/advisories/unreviewed/2024/01/GHSA-7fpg-4q3m-78rq/GHSA-7fpg-4q3m-78rq.json b/advisories/unreviewed/2024/01/GHSA-7fpg-4q3m-78rq/GHSA-7fpg-4q3m-78rq.json index 5b1f7968197..a93c333c467 100644 --- a/advisories/unreviewed/2024/01/GHSA-7fpg-4q3m-78rq/GHSA-7fpg-4q3m-78rq.json +++ b/advisories/unreviewed/2024/01/GHSA-7fpg-4q3m-78rq/GHSA-7fpg-4q3m-78rq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7fpg-4q3m-78rq", - "modified": "2024-02-03T00:31:32Z", + "modified": "2025-05-29T18:31:10Z", "published": "2024-01-29T15:30:29Z", "aliases": [ "CVE-2023-6391" diff --git a/advisories/unreviewed/2024/01/GHSA-f44w-wxhf-f354/GHSA-f44w-wxhf-f354.json b/advisories/unreviewed/2024/01/GHSA-f44w-wxhf-f354/GHSA-f44w-wxhf-f354.json index 4eaef3a8280..39760c22de5 100644 --- a/advisories/unreviewed/2024/01/GHSA-f44w-wxhf-f354/GHSA-f44w-wxhf-f354.json +++ b/advisories/unreviewed/2024/01/GHSA-f44w-wxhf-f354/GHSA-f44w-wxhf-f354.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f44w-wxhf-f354", - "modified": "2024-02-03T00:31:33Z", + "modified": "2025-05-29T18:31:10Z", "published": "2024-01-29T15:30:30Z", "aliases": [ "CVE-2023-7199" diff --git a/advisories/unreviewed/2024/01/GHSA-xqff-gxc3-2x4v/GHSA-xqff-gxc3-2x4v.json b/advisories/unreviewed/2024/01/GHSA-xqff-gxc3-2x4v/GHSA-xqff-gxc3-2x4v.json index 2ae543fe29e..e69d99bb61e 100644 --- a/advisories/unreviewed/2024/01/GHSA-xqff-gxc3-2x4v/GHSA-xqff-gxc3-2x4v.json +++ b/advisories/unreviewed/2024/01/GHSA-xqff-gxc3-2x4v/GHSA-xqff-gxc3-2x4v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xqff-gxc3-2x4v", - "modified": "2024-02-03T00:31:33Z", + "modified": "2025-05-29T18:31:10Z", "published": "2024-01-29T15:30:29Z", "aliases": [ "CVE-2023-6530" diff --git a/advisories/unreviewed/2024/06/GHSA-2273-x2j3-xp63/GHSA-2273-x2j3-xp63.json b/advisories/unreviewed/2024/06/GHSA-2273-x2j3-xp63/GHSA-2273-x2j3-xp63.json index 8033a247061..e6279cca619 100644 --- a/advisories/unreviewed/2024/06/GHSA-2273-x2j3-xp63/GHSA-2273-x2j3-xp63.json +++ b/advisories/unreviewed/2024/06/GHSA-2273-x2j3-xp63/GHSA-2273-x2j3-xp63.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-cf26-j7rw-5r6f/GHSA-cf26-j7rw-5r6f.json b/advisories/unreviewed/2024/07/GHSA-cf26-j7rw-5r6f/GHSA-cf26-j7rw-5r6f.json index add89818a69..e50f0b435fb 100644 --- a/advisories/unreviewed/2024/07/GHSA-cf26-j7rw-5r6f/GHSA-cf26-j7rw-5r6f.json +++ b/advisories/unreviewed/2024/07/GHSA-cf26-j7rw-5r6f/GHSA-cf26-j7rw-5r6f.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-qjv9-wmrf-56gg/GHSA-qjv9-wmrf-56gg.json b/advisories/unreviewed/2024/07/GHSA-qjv9-wmrf-56gg/GHSA-qjv9-wmrf-56gg.json index d3f21d28d09..76572952fa5 100644 --- a/advisories/unreviewed/2024/07/GHSA-qjv9-wmrf-56gg/GHSA-qjv9-wmrf-56gg.json +++ b/advisories/unreviewed/2024/07/GHSA-qjv9-wmrf-56gg/GHSA-qjv9-wmrf-56gg.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-vfqx-2vvp-j7qq/GHSA-vfqx-2vvp-j7qq.json b/advisories/unreviewed/2024/07/GHSA-vfqx-2vvp-j7qq/GHSA-vfqx-2vvp-j7qq.json index 713f385a59f..80df767e06e 100644 --- a/advisories/unreviewed/2024/07/GHSA-vfqx-2vvp-j7qq/GHSA-vfqx-2vvp-j7qq.json +++ b/advisories/unreviewed/2024/07/GHSA-vfqx-2vvp-j7qq/GHSA-vfqx-2vvp-j7qq.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-w3pw-m4q2-x98m/GHSA-w3pw-m4q2-x98m.json b/advisories/unreviewed/2024/07/GHSA-w3pw-m4q2-x98m/GHSA-w3pw-m4q2-x98m.json index da90e41cb29..7d62a2c36f5 100644 --- a/advisories/unreviewed/2024/07/GHSA-w3pw-m4q2-x98m/GHSA-w3pw-m4q2-x98m.json +++ b/advisories/unreviewed/2024/07/GHSA-w3pw-m4q2-x98m/GHSA-w3pw-m4q2-x98m.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/08/GHSA-f8wm-p3c6-g898/GHSA-f8wm-p3c6-g898.json b/advisories/unreviewed/2024/08/GHSA-f8wm-p3c6-g898/GHSA-f8wm-p3c6-g898.json index 792cad69d2b..91f82daf941 100644 --- a/advisories/unreviewed/2024/08/GHSA-f8wm-p3c6-g898/GHSA-f8wm-p3c6-g898.json +++ b/advisories/unreviewed/2024/08/GHSA-f8wm-p3c6-g898/GHSA-f8wm-p3c6-g898.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/08/GHSA-vqgx-gpv3-58p3/GHSA-vqgx-gpv3-58p3.json b/advisories/unreviewed/2024/08/GHSA-vqgx-gpv3-58p3/GHSA-vqgx-gpv3-58p3.json index 23badf3a85f..7cfd7806c9a 100644 --- a/advisories/unreviewed/2024/08/GHSA-vqgx-gpv3-58p3/GHSA-vqgx-gpv3-58p3.json +++ b/advisories/unreviewed/2024/08/GHSA-vqgx-gpv3-58p3/GHSA-vqgx-gpv3-58p3.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/08/GHSA-xhpw-qr8c-jfj2/GHSA-xhpw-qr8c-jfj2.json b/advisories/unreviewed/2024/08/GHSA-xhpw-qr8c-jfj2/GHSA-xhpw-qr8c-jfj2.json index abeaae945b1..dce7a9e2db7 100644 --- a/advisories/unreviewed/2024/08/GHSA-xhpw-qr8c-jfj2/GHSA-xhpw-qr8c-jfj2.json +++ b/advisories/unreviewed/2024/08/GHSA-xhpw-qr8c-jfj2/GHSA-xhpw-qr8c-jfj2.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-2mx4-jrqf-62cp/GHSA-2mx4-jrqf-62cp.json b/advisories/unreviewed/2025/05/GHSA-2mx4-jrqf-62cp/GHSA-2mx4-jrqf-62cp.json index 90a28a33a54..6878d0a7a8b 100644 --- a/advisories/unreviewed/2025/05/GHSA-2mx4-jrqf-62cp/GHSA-2mx4-jrqf-62cp.json +++ b/advisories/unreviewed/2025/05/GHSA-2mx4-jrqf-62cp/GHSA-2mx4-jrqf-62cp.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-4mmr-2w8p-whcr/GHSA-4mmr-2w8p-whcr.json b/advisories/unreviewed/2025/05/GHSA-4mmr-2w8p-whcr/GHSA-4mmr-2w8p-whcr.json new file mode 100644 index 00000000000..c09557ecfc6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4mmr-2w8p-whcr/GHSA-4mmr-2w8p-whcr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4mmr-2w8p-whcr", + "modified": "2025-05-29T18:31:19Z", + "published": "2025-05-29T18:31:19Z", + "aliases": [ + "CVE-2025-3913" + ], + "details": "Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to properly validate permissions when changing team privacy settings, allowing team administrators without the 'invite user' permission to access and modify team invite IDs via the /api/v4/teams/:teamId/privacy endpoint.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3913" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-29T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-833m-w7v5-7fgm/GHSA-833m-w7v5-7fgm.json b/advisories/unreviewed/2025/05/GHSA-833m-w7v5-7fgm/GHSA-833m-w7v5-7fgm.json new file mode 100644 index 00000000000..4ace312361e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-833m-w7v5-7fgm/GHSA-833m-w7v5-7fgm.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-833m-w7v5-7fgm", + "modified": "2025-05-29T18:31:20Z", + "published": "2025-05-29T18:31:20Z", + "aliases": [ + "CVE-2025-29632" + ], + "details": "Buffer Overflow vulnerability in Free5gc v.4.0.0 allows a remote attacker to cause a denial of service via the AMF, NGAP, security.go, handler_generated.go, handleInitialUEMessageMain, DecodePlainNasNoIntegrityCheck, GetSecurityHeaderType components", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29632" + }, + { + "type": "WEB", + "url": "https://github.com/free5gc/free5gc/issues/657" + }, + { + "type": "WEB", + "url": "https://github.com/OHnogood/CVE-2025-29632" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-29T18:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8w45-j3gj-vmj3/GHSA-8w45-j3gj-vmj3.json b/advisories/unreviewed/2025/05/GHSA-8w45-j3gj-vmj3/GHSA-8w45-j3gj-vmj3.json new file mode 100644 index 00000000000..f9a789a8e56 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8w45-j3gj-vmj3/GHSA-8w45-j3gj-vmj3.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8w45-j3gj-vmj3", + "modified": "2025-05-29T18:31:20Z", + "published": "2025-05-29T18:31:20Z", + "aliases": [ + "CVE-2024-51392" + ], + "details": "An issue in OpenKnowledgeMaps Headstart v7 allows a remote attacker to escalate privileges via the url parameter of the getPDF.php component", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51392" + }, + { + "type": "WEB", + "url": "https://github.com/OpenKnowledgeMaps/Headstart" + }, + { + "type": "WEB", + "url": "https://github.com/manisashank/CVE-Publish/blob/main/CVE-2024-51392.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-29T17:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-cccf-vfhh-2vvp/GHSA-cccf-vfhh-2vvp.json b/advisories/unreviewed/2025/05/GHSA-cccf-vfhh-2vvp/GHSA-cccf-vfhh-2vvp.json new file mode 100644 index 00000000000..94557d10fbb --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-cccf-vfhh-2vvp/GHSA-cccf-vfhh-2vvp.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cccf-vfhh-2vvp", + "modified": "2025-05-29T18:31:20Z", + "published": "2025-05-29T18:31:20Z", + "aliases": [ + "CVE-2023-41591" + ], + "details": "An issue in Open Network Foundation ONOS v2.7.0 allows attackers to create fake IP/MAC addresses and potentially execute a man-in-the-middle attack on communications between fake and real hosts.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41591" + }, + { + "type": "WEB", + "url": "https://gist.github.com/kjw6855/9764e3f51b89119473e4d2c4f64dca27" + }, + { + "type": "WEB", + "url": "https://wiki.onosproject.org/pages/viewpage.action?pageId=16122675" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-29T18:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-ch64-4x3c-w3jq/GHSA-ch64-4x3c-w3jq.json b/advisories/unreviewed/2025/05/GHSA-ch64-4x3c-w3jq/GHSA-ch64-4x3c-w3jq.json index 14a2d212177..14262cf6c91 100644 --- a/advisories/unreviewed/2025/05/GHSA-ch64-4x3c-w3jq/GHSA-ch64-4x3c-w3jq.json +++ b/advisories/unreviewed/2025/05/GHSA-ch64-4x3c-w3jq/GHSA-ch64-4x3c-w3jq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ch64-4x3c-w3jq", - "modified": "2025-05-29T15:31:07Z", + "modified": "2025-05-29T18:31:19Z", "published": "2025-05-27T21:32:17Z", "aliases": [ "CVE-2025-5278" @@ -27,6 +27,18 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2368764" }, + { + "type": "WEB", + "url": "https://cgit.git.savannah.gnu.org/cgit/coreutils.git/commit/?id=8c9602e3a145e9596dc1a63c6ed67865814b6633" + }, + { + "type": "WEB", + "url": "https://cgit.git.savannah.gnu.org/cgit/coreutils.git/tree/NEWS?id=8c9602e3a145e9596dc1a63c6ed67865814b6633#n14" + }, + { + "type": "WEB", + "url": "https://security-tracker.debian.org/tracker/CVE-2025-5278" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2025/05/27/2" @@ -34,6 +46,10 @@ { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2025/05/29/1" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/05/29/2" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/05/GHSA-fc5r-pj7x-f9m3/GHSA-fc5r-pj7x-f9m3.json b/advisories/unreviewed/2025/05/GHSA-fc5r-pj7x-f9m3/GHSA-fc5r-pj7x-f9m3.json new file mode 100644 index 00000000000..1f2b711b5b4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fc5r-pj7x-f9m3/GHSA-fc5r-pj7x-f9m3.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fc5r-pj7x-f9m3", + "modified": "2025-05-29T18:31:20Z", + "published": "2025-05-29T18:31:20Z", + "aliases": [ + "CVE-2024-53423" + ], + "details": "An issue in Open Network Foundation ONOS v2.7.0 allows attackers to cause a Denial of Service (DoS) via supplying crafted packets.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53423" + }, + { + "type": "WEB", + "url": "https://gist.github.com/kjw6855/abeecc798d138b49537393e1fd3a5e96" + }, + { + "type": "WEB", + "url": "https://wiki.onosproject.org/pages/viewpage.action?pageId=16122675" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-29T18:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fhv3-95jg-vjrh/GHSA-fhv3-95jg-vjrh.json b/advisories/unreviewed/2025/05/GHSA-fhv3-95jg-vjrh/GHSA-fhv3-95jg-vjrh.json index 2246ba4be02..21091fb4580 100644 --- a/advisories/unreviewed/2025/05/GHSA-fhv3-95jg-vjrh/GHSA-fhv3-95jg-vjrh.json +++ b/advisories/unreviewed/2025/05/GHSA-fhv3-95jg-vjrh/GHSA-fhv3-95jg-vjrh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fhv3-95jg-vjrh", - "modified": "2025-05-29T15:31:09Z", + "modified": "2025-05-29T18:31:19Z", "published": "2025-05-29T15:31:09Z", "aliases": [ "CVE-2025-48748" ], "details": "Netwrix Directory Manager (formerly Imanami GroupID) through v.10.0.7784.0 has a hard-coded password.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-798" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-29T15:15:34Z" diff --git a/advisories/unreviewed/2025/05/GHSA-hgw8-7xf9-389h/GHSA-hgw8-7xf9-389h.json b/advisories/unreviewed/2025/05/GHSA-hgw8-7xf9-389h/GHSA-hgw8-7xf9-389h.json new file mode 100644 index 00000000000..314796e53b2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hgw8-7xf9-389h/GHSA-hgw8-7xf9-389h.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hgw8-7xf9-389h", + "modified": "2025-05-29T18:31:20Z", + "published": "2025-05-29T18:31:20Z", + "aliases": [ + "CVE-2025-5323" + ], + "details": "A vulnerability, which was classified as problematic, has been found in fossasia open-event-server 1.19.1. This issue affects the function send_email_change_user_email of the file /fossasia/open-event-server/blob/development/app/api/helpers/mail.py of the component Mail Verification Handler. The manipulation leads to reliance on obfuscation or encryption of security-relevant inputs without integrity checking. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5323" + }, + { + "type": "WEB", + "url": "https://gist.github.com/superboy-zjc/31ecea91b304b8dd9871ad507467ca61" + }, + { + "type": "WEB", + "url": "https://gist.github.com/superboy-zjc/31ecea91b304b8dd9871ad507467ca61#proof-of-concept" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310493" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310493" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.580256" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-325" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-29T18:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jqqw-x8w5-v4hh/GHSA-jqqw-x8w5-v4hh.json b/advisories/unreviewed/2025/05/GHSA-jqqw-x8w5-v4hh/GHSA-jqqw-x8w5-v4hh.json index 8bbedfd617c..113719cba88 100644 --- a/advisories/unreviewed/2025/05/GHSA-jqqw-x8w5-v4hh/GHSA-jqqw-x8w5-v4hh.json +++ b/advisories/unreviewed/2025/05/GHSA-jqqw-x8w5-v4hh/GHSA-jqqw-x8w5-v4hh.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-1220" + "CWE-1220", + "CWE-863" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-m537-88r7-p568/GHSA-m537-88r7-p568.json b/advisories/unreviewed/2025/05/GHSA-m537-88r7-p568/GHSA-m537-88r7-p568.json index 3bb58f98475..c17d5f31a89 100644 --- a/advisories/unreviewed/2025/05/GHSA-m537-88r7-p568/GHSA-m537-88r7-p568.json +++ b/advisories/unreviewed/2025/05/GHSA-m537-88r7-p568/GHSA-m537-88r7-p568.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-v9g5-36x8-7xmx/GHSA-v9g5-36x8-7xmx.json b/advisories/unreviewed/2025/05/GHSA-v9g5-36x8-7xmx/GHSA-v9g5-36x8-7xmx.json index 25de93fe345..cd618d01a83 100644 --- a/advisories/unreviewed/2025/05/GHSA-v9g5-36x8-7xmx/GHSA-v9g5-36x8-7xmx.json +++ b/advisories/unreviewed/2025/05/GHSA-v9g5-36x8-7xmx/GHSA-v9g5-36x8-7xmx.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-1390" + "CWE-1390", + "CWE-287" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-v9vv-qfg5-cxfg/GHSA-v9vv-qfg5-cxfg.json b/advisories/unreviewed/2025/05/GHSA-v9vv-qfg5-cxfg/GHSA-v9vv-qfg5-cxfg.json new file mode 100644 index 00000000000..5c98c1478f4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v9vv-qfg5-cxfg/GHSA-v9vv-qfg5-cxfg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v9vv-qfg5-cxfg", + "modified": "2025-05-29T18:31:19Z", + "published": "2025-05-29T18:31:19Z", + "aliases": [ + "CVE-2025-45474" + ], + "details": "maccms10 v2025.1000.4047 is vulnerable to Server-side request forgery (SSRF) in Email Settings.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45474" + }, + { + "type": "WEB", + "url": "https://www.yuque.com/morysummer/vx41bz/ptnnp4eema601rvz" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-29T16:15:40Z" + } +} \ No newline at end of file