diff --git a/advisories/unreviewed/2022/08/GHSA-3m9v-ghrv-898r/GHSA-3m9v-ghrv-898r.json b/advisories/unreviewed/2022/08/GHSA-3m9v-ghrv-898r/GHSA-3m9v-ghrv-898r.json index 41e9417119c..bd715809f9f 100644 --- a/advisories/unreviewed/2022/08/GHSA-3m9v-ghrv-898r/GHSA-3m9v-ghrv-898r.json +++ b/advisories/unreviewed/2022/08/GHSA-3m9v-ghrv-898r/GHSA-3m9v-ghrv-898r.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-693" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/08/GHSA-4j9v-xrv3-fmc2/GHSA-4j9v-xrv3-fmc2.json b/advisories/unreviewed/2022/08/GHSA-4j9v-xrv3-fmc2/GHSA-4j9v-xrv3-fmc2.json index c21130f961b..c0eefdcdaef 100644 --- a/advisories/unreviewed/2022/08/GHSA-4j9v-xrv3-fmc2/GHSA-4j9v-xrv3-fmc2.json +++ b/advisories/unreviewed/2022/08/GHSA-4j9v-xrv3-fmc2/GHSA-4j9v-xrv3-fmc2.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/08/GHSA-6625-jr57-474g/GHSA-6625-jr57-474g.json b/advisories/unreviewed/2022/08/GHSA-6625-jr57-474g/GHSA-6625-jr57-474g.json index e9c5cdf9973..bb4c9629f4b 100644 --- a/advisories/unreviewed/2022/08/GHSA-6625-jr57-474g/GHSA-6625-jr57-474g.json +++ b/advisories/unreviewed/2022/08/GHSA-6625-jr57-474g/GHSA-6625-jr57-474g.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/08/GHSA-9qvw-444r-5wp7/GHSA-9qvw-444r-5wp7.json b/advisories/unreviewed/2022/08/GHSA-9qvw-444r-5wp7/GHSA-9qvw-444r-5wp7.json index fa067c02272..856d0e784cc 100644 --- a/advisories/unreviewed/2022/08/GHSA-9qvw-444r-5wp7/GHSA-9qvw-444r-5wp7.json +++ b/advisories/unreviewed/2022/08/GHSA-9qvw-444r-5wp7/GHSA-9qvw-444r-5wp7.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/08/GHSA-cjxf-hqc4-wp33/GHSA-cjxf-hqc4-wp33.json b/advisories/unreviewed/2022/08/GHSA-cjxf-hqc4-wp33/GHSA-cjxf-hqc4-wp33.json index 74fed1880a5..5e5ccd18d2c 100644 --- a/advisories/unreviewed/2022/08/GHSA-cjxf-hqc4-wp33/GHSA-cjxf-hqc4-wp33.json +++ b/advisories/unreviewed/2022/08/GHSA-cjxf-hqc4-wp33/GHSA-cjxf-hqc4-wp33.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/08/GHSA-wvr4-3qqh-rjq4/GHSA-wvr4-3qqh-rjq4.json b/advisories/unreviewed/2022/08/GHSA-wvr4-3qqh-rjq4/GHSA-wvr4-3qqh-rjq4.json index 37f0492edbf..d9336418ba7 100644 --- a/advisories/unreviewed/2022/08/GHSA-wvr4-3qqh-rjq4/GHSA-wvr4-3qqh-rjq4.json +++ b/advisories/unreviewed/2022/08/GHSA-wvr4-3qqh-rjq4/GHSA-wvr4-3qqh-rjq4.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/01/GHSA-p7pv-w5qm-8pxv/GHSA-p7pv-w5qm-8pxv.json b/advisories/unreviewed/2024/01/GHSA-p7pv-w5qm-8pxv/GHSA-p7pv-w5qm-8pxv.json index dfb5c77fda2..e2622073a9a 100644 --- a/advisories/unreviewed/2024/01/GHSA-p7pv-w5qm-8pxv/GHSA-p7pv-w5qm-8pxv.json +++ b/advisories/unreviewed/2024/01/GHSA-p7pv-w5qm-8pxv/GHSA-p7pv-w5qm-8pxv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p7pv-w5qm-8pxv", - "modified": "2024-01-18T21:30:30Z", + "modified": "2025-06-05T21:30:36Z", "published": "2024-01-12T09:30:29Z", "aliases": [ "CVE-2024-22027" diff --git a/advisories/unreviewed/2024/04/GHSA-fv5j-c825-8pf5/GHSA-fv5j-c825-8pf5.json b/advisories/unreviewed/2024/04/GHSA-fv5j-c825-8pf5/GHSA-fv5j-c825-8pf5.json index 6a42b6c7182..ff250aba7b3 100644 --- a/advisories/unreviewed/2024/04/GHSA-fv5j-c825-8pf5/GHSA-fv5j-c825-8pf5.json +++ b/advisories/unreviewed/2024/04/GHSA-fv5j-c825-8pf5/GHSA-fv5j-c825-8pf5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fv5j-c825-8pf5", - "modified": "2024-04-30T09:30:45Z", + "modified": "2025-06-05T21:30:36Z", "published": "2024-04-30T09:30:45Z", "aliases": [ "CVE-2024-1895" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-502" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-h38m-55w3-wc8q/GHSA-h38m-55w3-wc8q.json b/advisories/unreviewed/2024/04/GHSA-h38m-55w3-wc8q/GHSA-h38m-55w3-wc8q.json index 05e5f8a75ef..bbc3f732f1c 100644 --- a/advisories/unreviewed/2024/04/GHSA-h38m-55w3-wc8q/GHSA-h38m-55w3-wc8q.json +++ b/advisories/unreviewed/2024/04/GHSA-h38m-55w3-wc8q/GHSA-h38m-55w3-wc8q.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-hqqq-4jv4-jmj5/GHSA-hqqq-4jv4-jmj5.json b/advisories/unreviewed/2024/04/GHSA-hqqq-4jv4-jmj5/GHSA-hqqq-4jv4-jmj5.json index b572f45560d..3121ab8e4b4 100644 --- a/advisories/unreviewed/2024/04/GHSA-hqqq-4jv4-jmj5/GHSA-hqqq-4jv4-jmj5.json +++ b/advisories/unreviewed/2024/04/GHSA-hqqq-4jv4-jmj5/GHSA-hqqq-4jv4-jmj5.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-922" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-32qx-x64f-2vp2/GHSA-32qx-x64f-2vp2.json b/advisories/unreviewed/2024/05/GHSA-32qx-x64f-2vp2/GHSA-32qx-x64f-2vp2.json index 717c9b2b8e3..5c9e20b4e50 100644 --- a/advisories/unreviewed/2024/05/GHSA-32qx-x64f-2vp2/GHSA-32qx-x64f-2vp2.json +++ b/advisories/unreviewed/2024/05/GHSA-32qx-x64f-2vp2/GHSA-32qx-x64f-2vp2.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-4h9h-gmj5-8w43/GHSA-4h9h-gmj5-8w43.json b/advisories/unreviewed/2024/05/GHSA-4h9h-gmj5-8w43/GHSA-4h9h-gmj5-8w43.json index 3c9dd2da982..9e337cdd966 100644 --- a/advisories/unreviewed/2024/05/GHSA-4h9h-gmj5-8w43/GHSA-4h9h-gmj5-8w43.json +++ b/advisories/unreviewed/2024/05/GHSA-4h9h-gmj5-8w43/GHSA-4h9h-gmj5-8w43.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-6xcx-78g4-qrhj/GHSA-6xcx-78g4-qrhj.json b/advisories/unreviewed/2024/05/GHSA-6xcx-78g4-qrhj/GHSA-6xcx-78g4-qrhj.json index 7988490a87f..9fa6bcf8ea9 100644 --- a/advisories/unreviewed/2024/05/GHSA-6xcx-78g4-qrhj/GHSA-6xcx-78g4-qrhj.json +++ b/advisories/unreviewed/2024/05/GHSA-6xcx-78g4-qrhj/GHSA-6xcx-78g4-qrhj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6xcx-78g4-qrhj", - "modified": "2024-05-14T18:30:53Z", + "modified": "2025-06-05T21:30:38Z", "published": "2024-05-14T18:30:53Z", "aliases": [ "CVE-2024-3974" @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-7g2v-334p-xqm8/GHSA-7g2v-334p-xqm8.json b/advisories/unreviewed/2024/05/GHSA-7g2v-334p-xqm8/GHSA-7g2v-334p-xqm8.json index 81cef518e84..192541ba8b8 100644 --- a/advisories/unreviewed/2024/05/GHSA-7g2v-334p-xqm8/GHSA-7g2v-334p-xqm8.json +++ b/advisories/unreviewed/2024/05/GHSA-7g2v-334p-xqm8/GHSA-7g2v-334p-xqm8.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-g629-p7x4-5x6r/GHSA-g629-p7x4-5x6r.json b/advisories/unreviewed/2024/05/GHSA-g629-p7x4-5x6r/GHSA-g629-p7x4-5x6r.json index 12703869ddc..1c777ca86b3 100644 --- a/advisories/unreviewed/2024/05/GHSA-g629-p7x4-5x6r/GHSA-g629-p7x4-5x6r.json +++ b/advisories/unreviewed/2024/05/GHSA-g629-p7x4-5x6r/GHSA-g629-p7x4-5x6r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g629-p7x4-5x6r", - "modified": "2024-05-02T18:30:52Z", + "modified": "2025-06-05T21:30:37Z", "published": "2024-05-02T18:30:52Z", "aliases": [ "CVE-2024-1809" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-g78g-3mc4-6p43/GHSA-g78g-3mc4-6p43.json b/advisories/unreviewed/2024/05/GHSA-g78g-3mc4-6p43/GHSA-g78g-3mc4-6p43.json index 18de87f0b39..c757b74d33f 100644 --- a/advisories/unreviewed/2024/05/GHSA-g78g-3mc4-6p43/GHSA-g78g-3mc4-6p43.json +++ b/advisories/unreviewed/2024/05/GHSA-g78g-3mc4-6p43/GHSA-g78g-3mc4-6p43.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-gx29-8g9g-89w4/GHSA-gx29-8g9g-89w4.json b/advisories/unreviewed/2024/05/GHSA-gx29-8g9g-89w4/GHSA-gx29-8g9g-89w4.json index 12da1bda339..940b0db1520 100644 --- a/advisories/unreviewed/2024/05/GHSA-gx29-8g9g-89w4/GHSA-gx29-8g9g-89w4.json +++ b/advisories/unreviewed/2024/05/GHSA-gx29-8g9g-89w4/GHSA-gx29-8g9g-89w4.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-754" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-q69q-p8m9-5wq7/GHSA-q69q-p8m9-5wq7.json b/advisories/unreviewed/2024/05/GHSA-q69q-p8m9-5wq7/GHSA-q69q-p8m9-5wq7.json index 4d43fd4c6da..8a9e7da6a4e 100644 --- a/advisories/unreviewed/2024/05/GHSA-q69q-p8m9-5wq7/GHSA-q69q-p8m9-5wq7.json +++ b/advisories/unreviewed/2024/05/GHSA-q69q-p8m9-5wq7/GHSA-q69q-p8m9-5wq7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q69q-p8m9-5wq7", - "modified": "2024-05-02T18:30:52Z", + "modified": "2025-06-05T21:30:37Z", "published": "2024-05-02T18:30:52Z", "aliases": [ "CVE-2024-1584" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-qxcq-r5q3-4wq6/GHSA-qxcq-r5q3-4wq6.json b/advisories/unreviewed/2024/05/GHSA-qxcq-r5q3-4wq6/GHSA-qxcq-r5q3-4wq6.json index 20b4e17aaab..825e35c22f4 100644 --- a/advisories/unreviewed/2024/05/GHSA-qxcq-r5q3-4wq6/GHSA-qxcq-r5q3-4wq6.json +++ b/advisories/unreviewed/2024/05/GHSA-qxcq-r5q3-4wq6/GHSA-qxcq-r5q3-4wq6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qxcq-r5q3-4wq6", - "modified": "2024-05-21T12:30:52Z", + "modified": "2025-06-05T21:30:39Z", "published": "2024-05-21T12:30:52Z", "aliases": [ "CVE-2024-4700" @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-r8jx-h262-h733/GHSA-r8jx-h262-h733.json b/advisories/unreviewed/2024/05/GHSA-r8jx-h262-h733/GHSA-r8jx-h262-h733.json index 474efa1f5a3..f0aef014843 100644 --- a/advisories/unreviewed/2024/05/GHSA-r8jx-h262-h733/GHSA-r8jx-h262-h733.json +++ b/advisories/unreviewed/2024/05/GHSA-r8jx-h262-h733/GHSA-r8jx-h262-h733.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r8jx-h262-h733", - "modified": "2024-05-02T18:30:54Z", + "modified": "2025-06-05T21:30:38Z", "published": "2024-05-02T18:30:54Z", "aliases": [ "CVE-2024-3554" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-ffvv-9rpr-q6r5/GHSA-ffvv-9rpr-q6r5.json b/advisories/unreviewed/2024/06/GHSA-ffvv-9rpr-q6r5/GHSA-ffvv-9rpr-q6r5.json index 9d8aa2ccfb8..c302bab0d56 100644 --- a/advisories/unreviewed/2024/06/GHSA-ffvv-9rpr-q6r5/GHSA-ffvv-9rpr-q6r5.json +++ b/advisories/unreviewed/2024/06/GHSA-ffvv-9rpr-q6r5/GHSA-ffvv-9rpr-q6r5.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-7cmg-qwmj-9qjf/GHSA-7cmg-qwmj-9qjf.json b/advisories/unreviewed/2025/01/GHSA-7cmg-qwmj-9qjf/GHSA-7cmg-qwmj-9qjf.json index 48a29e06970..7450a8a2605 100644 --- a/advisories/unreviewed/2025/01/GHSA-7cmg-qwmj-9qjf/GHSA-7cmg-qwmj-9qjf.json +++ b/advisories/unreviewed/2025/01/GHSA-7cmg-qwmj-9qjf/GHSA-7cmg-qwmj-9qjf.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-hj25-chfx-qmx5/GHSA-hj25-chfx-qmx5.json b/advisories/unreviewed/2025/01/GHSA-hj25-chfx-qmx5/GHSA-hj25-chfx-qmx5.json index 8fa77a37364..121793c4f06 100644 --- a/advisories/unreviewed/2025/01/GHSA-hj25-chfx-qmx5/GHSA-hj25-chfx-qmx5.json +++ b/advisories/unreviewed/2025/01/GHSA-hj25-chfx-qmx5/GHSA-hj25-chfx-qmx5.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-wpxf-7pwx-p92p/GHSA-wpxf-7pwx-p92p.json b/advisories/unreviewed/2025/01/GHSA-wpxf-7pwx-p92p/GHSA-wpxf-7pwx-p92p.json index 861eb1087ad..f9b3a404b06 100644 --- a/advisories/unreviewed/2025/01/GHSA-wpxf-7pwx-p92p/GHSA-wpxf-7pwx-p92p.json +++ b/advisories/unreviewed/2025/01/GHSA-wpxf-7pwx-p92p/GHSA-wpxf-7pwx-p92p.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-2mff-4q5m-q2cm/GHSA-2mff-4q5m-q2cm.json b/advisories/unreviewed/2025/02/GHSA-2mff-4q5m-q2cm/GHSA-2mff-4q5m-q2cm.json index a1b9417489a..79e3648b6bc 100644 --- a/advisories/unreviewed/2025/02/GHSA-2mff-4q5m-q2cm/GHSA-2mff-4q5m-q2cm.json +++ b/advisories/unreviewed/2025/02/GHSA-2mff-4q5m-q2cm/GHSA-2mff-4q5m-q2cm.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-7m23-4qgm-g7v4/GHSA-7m23-4qgm-g7v4.json b/advisories/unreviewed/2025/02/GHSA-7m23-4qgm-g7v4/GHSA-7m23-4qgm-g7v4.json index 77e02c5b1ba..0333e1b6bb5 100644 --- a/advisories/unreviewed/2025/02/GHSA-7m23-4qgm-g7v4/GHSA-7m23-4qgm-g7v4.json +++ b/advisories/unreviewed/2025/02/GHSA-7m23-4qgm-g7v4/GHSA-7m23-4qgm-g7v4.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-610" + "CWE-610", + "CWE-611" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-9jp4-rjhp-hhpx/GHSA-9jp4-rjhp-hhpx.json b/advisories/unreviewed/2025/02/GHSA-9jp4-rjhp-hhpx/GHSA-9jp4-rjhp-hhpx.json index 444ec8bc1cb..b644ac0ae8d 100644 --- a/advisories/unreviewed/2025/02/GHSA-9jp4-rjhp-hhpx/GHSA-9jp4-rjhp-hhpx.json +++ b/advisories/unreviewed/2025/02/GHSA-9jp4-rjhp-hhpx/GHSA-9jp4-rjhp-hhpx.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-xpm3-5wvv-pxfh/GHSA-xpm3-5wvv-pxfh.json b/advisories/unreviewed/2025/02/GHSA-xpm3-5wvv-pxfh/GHSA-xpm3-5wvv-pxfh.json index 8b10fc56de1..5badc71adeb 100644 --- a/advisories/unreviewed/2025/02/GHSA-xpm3-5wvv-pxfh/GHSA-xpm3-5wvv-pxfh.json +++ b/advisories/unreviewed/2025/02/GHSA-xpm3-5wvv-pxfh/GHSA-xpm3-5wvv-pxfh.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-5h74-rc34-8rh3/GHSA-5h74-rc34-8rh3.json b/advisories/unreviewed/2025/03/GHSA-5h74-rc34-8rh3/GHSA-5h74-rc34-8rh3.json index f485ce29977..3f64fd05ba7 100644 --- a/advisories/unreviewed/2025/03/GHSA-5h74-rc34-8rh3/GHSA-5h74-rc34-8rh3.json +++ b/advisories/unreviewed/2025/03/GHSA-5h74-rc34-8rh3/GHSA-5h74-rc34-8rh3.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-f7g7-xhr9-wpr3/GHSA-f7g7-xhr9-wpr3.json b/advisories/unreviewed/2025/03/GHSA-f7g7-xhr9-wpr3/GHSA-f7g7-xhr9-wpr3.json index dc58993cef0..739417f33aa 100644 --- a/advisories/unreviewed/2025/03/GHSA-f7g7-xhr9-wpr3/GHSA-f7g7-xhr9-wpr3.json +++ b/advisories/unreviewed/2025/03/GHSA-f7g7-xhr9-wpr3/GHSA-f7g7-xhr9-wpr3.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-gq5x-xc6w-4j57/GHSA-gq5x-xc6w-4j57.json b/advisories/unreviewed/2025/03/GHSA-gq5x-xc6w-4j57/GHSA-gq5x-xc6w-4j57.json index a300e15f742..714961e3866 100644 --- a/advisories/unreviewed/2025/03/GHSA-gq5x-xc6w-4j57/GHSA-gq5x-xc6w-4j57.json +++ b/advisories/unreviewed/2025/03/GHSA-gq5x-xc6w-4j57/GHSA-gq5x-xc6w-4j57.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-mpcj-9v9v-j2hw/GHSA-mpcj-9v9v-j2hw.json b/advisories/unreviewed/2025/03/GHSA-mpcj-9v9v-j2hw/GHSA-mpcj-9v9v-j2hw.json index 3e26dfdba46..af9acb1a26e 100644 --- a/advisories/unreviewed/2025/03/GHSA-mpcj-9v9v-j2hw/GHSA-mpcj-9v9v-j2hw.json +++ b/advisories/unreviewed/2025/03/GHSA-mpcj-9v9v-j2hw/GHSA-mpcj-9v9v-j2hw.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-x697-98xp-h39f/GHSA-x697-98xp-h39f.json b/advisories/unreviewed/2025/04/GHSA-x697-98xp-h39f/GHSA-x697-98xp-h39f.json index 93dc608e5c2..309eeb3e3ef 100644 --- a/advisories/unreviewed/2025/04/GHSA-x697-98xp-h39f/GHSA-x697-98xp-h39f.json +++ b/advisories/unreviewed/2025/04/GHSA-x697-98xp-h39f/GHSA-x697-98xp-h39f.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-266" + "CWE-266", + "CWE-639" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-xch6-9rqg-692q/GHSA-xch6-9rqg-692q.json b/advisories/unreviewed/2025/04/GHSA-xch6-9rqg-692q/GHSA-xch6-9rqg-692q.json index 8a492ded621..7eed8ffb19c 100644 --- a/advisories/unreviewed/2025/04/GHSA-xch6-9rqg-692q/GHSA-xch6-9rqg-692q.json +++ b/advisories/unreviewed/2025/04/GHSA-xch6-9rqg-692q/GHSA-xch6-9rqg-692q.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-266" + "CWE-266", + "CWE-639" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-2445-4c8x-52p7/GHSA-2445-4c8x-52p7.json b/advisories/unreviewed/2025/05/GHSA-2445-4c8x-52p7/GHSA-2445-4c8x-52p7.json index 5db22ad664e..abf619cd053 100644 --- a/advisories/unreviewed/2025/05/GHSA-2445-4c8x-52p7/GHSA-2445-4c8x-52p7.json +++ b/advisories/unreviewed/2025/05/GHSA-2445-4c8x-52p7/GHSA-2445-4c8x-52p7.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-326" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-63p7-48v7-g6m9/GHSA-63p7-48v7-g6m9.json b/advisories/unreviewed/2025/05/GHSA-63p7-48v7-g6m9/GHSA-63p7-48v7-g6m9.json index 4f3f513154d..4bb1683533f 100644 --- a/advisories/unreviewed/2025/05/GHSA-63p7-48v7-g6m9/GHSA-63p7-48v7-g6m9.json +++ b/advisories/unreviewed/2025/05/GHSA-63p7-48v7-g6m9/GHSA-63p7-48v7-g6m9.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-f49c-fpvw-q6c9/GHSA-f49c-fpvw-q6c9.json b/advisories/unreviewed/2025/05/GHSA-f49c-fpvw-q6c9/GHSA-f49c-fpvw-q6c9.json index ddb4f012ea3..2c1c9b2204b 100644 --- a/advisories/unreviewed/2025/05/GHSA-f49c-fpvw-q6c9/GHSA-f49c-fpvw-q6c9.json +++ b/advisories/unreviewed/2025/05/GHSA-f49c-fpvw-q6c9/GHSA-f49c-fpvw-q6c9.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-qhrc-jg2f-vvhg/GHSA-qhrc-jg2f-vvhg.json b/advisories/unreviewed/2025/05/GHSA-qhrc-jg2f-vvhg/GHSA-qhrc-jg2f-vvhg.json index c63f2d499c4..e2faea51838 100644 --- a/advisories/unreviewed/2025/05/GHSA-qhrc-jg2f-vvhg/GHSA-qhrc-jg2f-vvhg.json +++ b/advisories/unreviewed/2025/05/GHSA-qhrc-jg2f-vvhg/GHSA-qhrc-jg2f-vvhg.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-r5r2-8fvf-q8hf/GHSA-r5r2-8fvf-q8hf.json b/advisories/unreviewed/2025/05/GHSA-r5r2-8fvf-q8hf/GHSA-r5r2-8fvf-q8hf.json index 9a70a04cd4c..0ea63b77f97 100644 --- a/advisories/unreviewed/2025/05/GHSA-r5r2-8fvf-q8hf/GHSA-r5r2-8fvf-q8hf.json +++ b/advisories/unreviewed/2025/05/GHSA-r5r2-8fvf-q8hf/GHSA-r5r2-8fvf-q8hf.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-vphx-gjg2-4qff/GHSA-vphx-gjg2-4qff.json b/advisories/unreviewed/2025/05/GHSA-vphx-gjg2-4qff/GHSA-vphx-gjg2-4qff.json index c70629ed714..af778bf8046 100644 --- a/advisories/unreviewed/2025/05/GHSA-vphx-gjg2-4qff/GHSA-vphx-gjg2-4qff.json +++ b/advisories/unreviewed/2025/05/GHSA-vphx-gjg2-4qff/GHSA-vphx-gjg2-4qff.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-wmgm-jqrv-9fx8/GHSA-wmgm-jqrv-9fx8.json b/advisories/unreviewed/2025/05/GHSA-wmgm-jqrv-9fx8/GHSA-wmgm-jqrv-9fx8.json index c2f245677ea..4eec91e9512 100644 --- a/advisories/unreviewed/2025/05/GHSA-wmgm-jqrv-9fx8/GHSA-wmgm-jqrv-9fx8.json +++ b/advisories/unreviewed/2025/05/GHSA-wmgm-jqrv-9fx8/GHSA-wmgm-jqrv-9fx8.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/06/GHSA-2w95-w2p8-6r8j/GHSA-2w95-w2p8-6r8j.json b/advisories/unreviewed/2025/06/GHSA-2w95-w2p8-6r8j/GHSA-2w95-w2p8-6r8j.json new file mode 100644 index 00000000000..a201fe9e4b6 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-2w95-w2p8-6r8j/GHSA-2w95-w2p8-6r8j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2w95-w2p8-6r8j", + "modified": "2025-06-05T21:30:56Z", + "published": "2025-06-05T21:30:56Z", + "aliases": [ + "CVE-2025-48133" + ], + "details": "Missing Authorization vulnerability in Uncanny Owl Uncanny Automator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Uncanny Automator: from n/a through 6.4.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48133" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/uncanny-automator/vulnerability/wordpress-uncanny-automator-6-5-0-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-05T21:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-4p6q-pmfx-rg27/GHSA-4p6q-pmfx-rg27.json b/advisories/unreviewed/2025/06/GHSA-4p6q-pmfx-rg27/GHSA-4p6q-pmfx-rg27.json new file mode 100644 index 00000000000..c94f6e30508 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-4p6q-pmfx-rg27/GHSA-4p6q-pmfx-rg27.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4p6q-pmfx-rg27", + "modified": "2025-06-05T21:30:55Z", + "published": "2025-06-05T21:30:55Z", + "aliases": [ + "CVE-2025-5677" + ], + "details": "A vulnerability was found in Campcodes Online Recruitment Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/ajax.php?action=save_application. The manipulation of the argument position_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5677" + }, + { + "type": "WEB", + "url": "https://github.com/hyx123123/cve/issues/1" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311165" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311165" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.590135" + }, + { + "type": "WEB", + "url": "https://www.campcodes.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-05T19:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-5mw2-w8pc-m6p6/GHSA-5mw2-w8pc-m6p6.json b/advisories/unreviewed/2025/06/GHSA-5mw2-w8pc-m6p6/GHSA-5mw2-w8pc-m6p6.json index 48312d0c6d0..778d2458138 100644 --- a/advisories/unreviewed/2025/06/GHSA-5mw2-w8pc-m6p6/GHSA-5mw2-w8pc-m6p6.json +++ b/advisories/unreviewed/2025/06/GHSA-5mw2-w8pc-m6p6/GHSA-5mw2-w8pc-m6p6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5mw2-w8pc-m6p6", - "modified": "2025-06-05T06:30:27Z", + "modified": "2025-06-05T21:30:52Z", "published": "2025-06-05T06:30:27Z", "aliases": [ "CVE-2025-5683" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-770" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/06/GHSA-7mvj-xfjf-frvm/GHSA-7mvj-xfjf-frvm.json b/advisories/unreviewed/2025/06/GHSA-7mvj-xfjf-frvm/GHSA-7mvj-xfjf-frvm.json new file mode 100644 index 00000000000..dd3a5110ecd --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-7mvj-xfjf-frvm/GHSA-7mvj-xfjf-frvm.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7mvj-xfjf-frvm", + "modified": "2025-06-05T21:30:54Z", + "published": "2025-06-05T21:30:54Z", + "aliases": [ + "CVE-2025-5675" + ], + "details": "A vulnerability was found in Campcodes Online Teacher Record Management System 1.0. It has been classified as critical. This affects an unknown part of the file /trms/admin/bwdates-reports-details.php. The manipulation of the argument fromdate/todate leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5675" + }, + { + "type": "WEB", + "url": "https://github.com/modestHonK/cve/issues/1" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311163" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311163" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.590124" + }, + { + "type": "WEB", + "url": "https://www.campcodes.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-05T19:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-7qrf-49g7-25m2/GHSA-7qrf-49g7-25m2.json b/advisories/unreviewed/2025/06/GHSA-7qrf-49g7-25m2/GHSA-7qrf-49g7-25m2.json new file mode 100644 index 00000000000..49a9acfc4ac --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-7qrf-49g7-25m2/GHSA-7qrf-49g7-25m2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7qrf-49g7-25m2", + "modified": "2025-06-05T21:30:56Z", + "published": "2025-06-05T21:30:56Z", + "aliases": [ + "CVE-2025-5745" + ], + "details": "The strncmp implementation optimized for the Power10 processor in the GNU C Library version 2.40 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5745" + }, + { + "type": "WEB", + "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=33060" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-665" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-05T20:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-8j5h-8vfq-q7mr/GHSA-8j5h-8vfq-q7mr.json b/advisories/unreviewed/2025/06/GHSA-8j5h-8vfq-q7mr/GHSA-8j5h-8vfq-q7mr.json new file mode 100644 index 00000000000..ddbea110d53 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-8j5h-8vfq-q7mr/GHSA-8j5h-8vfq-q7mr.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8j5h-8vfq-q7mr", + "modified": "2025-06-05T21:30:56Z", + "published": "2025-06-05T21:30:56Z", + "aliases": [ + "CVE-2025-5693" + ], + "details": "A vulnerability was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /bwdates-report-result.php. The manipulation of the argument fromdate/todate leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5693" + }, + { + "type": "WEB", + "url": "https://github.com/f1rstb100d/myCVE/issues/53" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311209" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311209" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.590183" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-05T20:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-9p66-56jj-2pxc/GHSA-9p66-56jj-2pxc.json b/advisories/unreviewed/2025/06/GHSA-9p66-56jj-2pxc/GHSA-9p66-56jj-2pxc.json new file mode 100644 index 00000000000..670ea6a24b6 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-9p66-56jj-2pxc/GHSA-9p66-56jj-2pxc.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9p66-56jj-2pxc", + "modified": "2025-06-05T21:30:55Z", + "published": "2025-06-05T21:30:55Z", + "aliases": [ + "CVE-2025-5680" + ], + "details": "A vulnerability classified as critical was found in Shenzhen Dashi Tongzhou Information Technology AgileBPM up to 2.5.0. Affected by this vulnerability is the function executeScript of the file /src/main/java/com/dstz/sys/rest/controller/SysScriptController.java of the component Groovy Script Handler. The manipulation of the argument script leads to deserialization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5680" + }, + { + "type": "WEB", + "url": "https://gitee.com/agile-bpm/agile-bpm-basic/issues/ICAPT5" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311167" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311167" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.585108" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-05T20:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-cvg9-q978-4569/GHSA-cvg9-q978-4569.json b/advisories/unreviewed/2025/06/GHSA-cvg9-q978-4569/GHSA-cvg9-q978-4569.json index 334dab1042a..9fb210c3619 100644 --- a/advisories/unreviewed/2025/06/GHSA-cvg9-q978-4569/GHSA-cvg9-q978-4569.json +++ b/advisories/unreviewed/2025/06/GHSA-cvg9-q978-4569/GHSA-cvg9-q978-4569.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cvg9-q978-4569", - "modified": "2025-06-05T18:30:39Z", + "modified": "2025-06-05T21:30:52Z", "published": "2025-06-05T12:31:09Z", "aliases": [ "CVE-2011-10007" @@ -38,6 +38,10 @@ { "type": "WEB", "url": "https://rt.cpan.org/Public/Bug/Display.html?id=64504" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/06/05/4" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/06/GHSA-h443-cvc4-gwr4/GHSA-h443-cvc4-gwr4.json b/advisories/unreviewed/2025/06/GHSA-h443-cvc4-gwr4/GHSA-h443-cvc4-gwr4.json new file mode 100644 index 00000000000..e27c19692cc --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-h443-cvc4-gwr4/GHSA-h443-cvc4-gwr4.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h443-cvc4-gwr4", + "modified": "2025-06-05T21:30:54Z", + "published": "2025-06-05T21:30:54Z", + "aliases": [ + "CVE-2025-5674" + ], + "details": "A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file urinalysis_form.php. The manipulation of the argument urinalysis_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5674" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/yuyuchenchen/vuln-pdf/blob/main/0603CVE.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311162" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311162" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.590120" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-05T19:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-h5rh-9xr7-mqj3/GHSA-h5rh-9xr7-mqj3.json b/advisories/unreviewed/2025/06/GHSA-h5rh-9xr7-mqj3/GHSA-h5rh-9xr7-mqj3.json new file mode 100644 index 00000000000..66bd9f9c405 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-h5rh-9xr7-mqj3/GHSA-h5rh-9xr7-mqj3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h5rh-9xr7-mqj3", + "modified": "2025-06-05T21:30:56Z", + "published": "2025-06-05T21:30:56Z", + "aliases": [ + "CVE-2025-47966" + ], + "details": "Exposure of sensitive information to an unauthorized actor in Power Automate allows an unauthorized attacker to elevate privileges over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47966" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47966" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-05T21:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-hqwp-qwfv-mhrx/GHSA-hqwp-qwfv-mhrx.json b/advisories/unreviewed/2025/06/GHSA-hqwp-qwfv-mhrx/GHSA-hqwp-qwfv-mhrx.json new file mode 100644 index 00000000000..b11e4ef067b --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-hqwp-qwfv-mhrx/GHSA-hqwp-qwfv-mhrx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hqwp-qwfv-mhrx", + "modified": "2025-06-05T21:30:55Z", + "published": "2025-06-05T21:30:55Z", + "aliases": [ + "CVE-2025-5702" + ], + "details": "The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5702" + }, + { + "type": "WEB", + "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=33056" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-665" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-05T19:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-qp9x-rm9w-4j32/GHSA-qp9x-rm9w-4j32.json b/advisories/unreviewed/2025/06/GHSA-qp9x-rm9w-4j32/GHSA-qp9x-rm9w-4j32.json new file mode 100644 index 00000000000..3cb501986c4 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-qp9x-rm9w-4j32/GHSA-qp9x-rm9w-4j32.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qp9x-rm9w-4j32", + "modified": "2025-06-05T21:30:55Z", + "published": "2025-06-05T21:30:55Z", + "aliases": [ + "CVE-2025-5679" + ], + "details": "A vulnerability classified as critical has been found in Shenzhen Dashi Tongzhou Information Technology AgileBPM up to 2.5.0. Affected is the function parseStrByFreeMarker of the file /src/main/java/com/dstz/sys/rest/controller/SysToolsController.java. The manipulation of the argument str leads to deserialization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5679" + }, + { + "type": "WEB", + "url": "https://gitee.com/agile-bpm/agile-bpm-basic/issues/ICAQWG" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311166" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311166" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.585127" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-05T19:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-v53f-hxpp-whfr/GHSA-v53f-hxpp-whfr.json b/advisories/unreviewed/2025/06/GHSA-v53f-hxpp-whfr/GHSA-v53f-hxpp-whfr.json new file mode 100644 index 00000000000..76c77f4b8f8 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-v53f-hxpp-whfr/GHSA-v53f-hxpp-whfr.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v53f-hxpp-whfr", + "modified": "2025-06-05T21:30:57Z", + "published": "2025-06-05T21:30:57Z", + "aliases": [ + "CVE-2025-5694" + ], + "details": "A vulnerability was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /search-report-result.php. The manipulation of the argument serachdata leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5694" + }, + { + "type": "WEB", + "url": "https://github.com/f1rstb100d/myCVE/issues/54" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311210" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311210" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.590184" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-05T21:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-wxmp-jjxp-g7gp/GHSA-wxmp-jjxp-g7gp.json b/advisories/unreviewed/2025/06/GHSA-wxmp-jjxp-g7gp/GHSA-wxmp-jjxp-g7gp.json new file mode 100644 index 00000000000..aaabe18c4eb --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-wxmp-jjxp-g7gp/GHSA-wxmp-jjxp-g7gp.json @@ -0,0 +1,68 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wxmp-jjxp-g7gp", + "modified": "2025-06-05T21:30:57Z", + "published": "2025-06-05T21:30:57Z", + "aliases": [ + "CVE-2025-5695" + ], + "details": "A vulnerability classified as critical has been found in FLIR AX8 up to 1.46.16. This affects the function subscribe_to_spot/subscribe_to_delta/subscribe_to_alarm of the file /usr/www/application/models/subscriptions.php of the component Backend. The manipulation leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.55.16 is able to address this issue. It is recommended to upgrade the affected component.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5695" + }, + { + "type": "WEB", + "url": "https://flir.custhelp.com/app/account/fl_download_software" + }, + { + "type": "WEB", + "url": "https://github.com/YZS17/CVE/blob/main/Command%20injection%20vulnerability%20in%20subscribe_to_delta()%20in%20FLIR%20AX8.md" + }, + { + "type": "WEB", + "url": "https://github.com/YZS17/CVE/blob/main/Command%20injection%20vulnerability%20in%20subscribe_to_spot()%20in%20FLIR%20AX8.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311211" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311211" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.584532" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.585715" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.585716" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-05T21:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-x3gp-jj7p-mpcw/GHSA-x3gp-jj7p-mpcw.json b/advisories/unreviewed/2025/06/GHSA-x3gp-jj7p-mpcw/GHSA-x3gp-jj7p-mpcw.json new file mode 100644 index 00000000000..65627a570b8 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-x3gp-jj7p-mpcw/GHSA-x3gp-jj7p-mpcw.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x3gp-jj7p-mpcw", + "modified": "2025-06-05T21:30:55Z", + "published": "2025-06-05T21:30:55Z", + "aliases": [ + "CVE-2025-5676" + ], + "details": "A vulnerability was found in Campcodes Online Recruitment Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/ajax.php?action=login. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5676" + }, + { + "type": "WEB", + "url": "https://github.com/hyx123123/cve/issues/2" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311164" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311164" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.590134" + }, + { + "type": "WEB", + "url": "https://www.campcodes.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-05T19:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-xcpr-3f8f-3c77/GHSA-xcpr-3f8f-3c77.json b/advisories/unreviewed/2025/06/GHSA-xcpr-3f8f-3c77/GHSA-xcpr-3f8f-3c77.json new file mode 100644 index 00000000000..826b8359411 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-xcpr-3f8f-3c77/GHSA-xcpr-3f8f-3c77.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xcpr-3f8f-3c77", + "modified": "2025-06-05T21:30:56Z", + "published": "2025-06-05T21:30:56Z", + "aliases": [ + "CVE-2025-5685" + ], + "details": "A vulnerability, which was classified as critical, was found in Tenda CH22 1.0.0.1. This affects the function formNatlimit of the file /goform/Natlimit. The manipulation of the argument page leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5685" + }, + { + "type": "WEB", + "url": "https://github.com/xubeining/Cve_report/blob/main/A%20remote%20code%20execution%20vulnerability%20in%20the%20router%20CH22%20V1.0.0.1%20manufactured%20by%20Shenzhen%20Jixiangtengda%20Technology%20Co.%2C%20Ltd1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311169" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311169" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.590153" + }, + { + "type": "WEB", + "url": "https://www.tenda.com.cn" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-05T20:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-xh2q-mw6g-7hg3/GHSA-xh2q-mw6g-7hg3.json b/advisories/unreviewed/2025/06/GHSA-xh2q-mw6g-7hg3/GHSA-xh2q-mw6g-7hg3.json new file mode 100644 index 00000000000..0c2d2880d59 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-xh2q-mw6g-7hg3/GHSA-xh2q-mw6g-7hg3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xh2q-mw6g-7hg3", + "modified": "2025-06-05T21:30:55Z", + "published": "2025-06-05T21:30:55Z", + "aliases": [ + "CVE-2025-43026" + ], + "details": "A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.44.18.0. The vulnerability could potentially allow a local attacker to escalate privileges via an arbitrary file write.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43026" + }, + { + "type": "WEB", + "url": "https://support.hp.com/us-en/document/ish_12617979-12618008-16/hpsbgn04022" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-281" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-05T20:15:26Z" + } +} \ No newline at end of file