diff --git a/advisories/unreviewed/2024/01/GHSA-36h5-gw9w-mwx2/GHSA-36h5-gw9w-mwx2.json b/advisories/unreviewed/2024/01/GHSA-36h5-gw9w-mwx2/GHSA-36h5-gw9w-mwx2.json index 612a5b3545d..bc5764833da 100644 --- a/advisories/unreviewed/2024/01/GHSA-36h5-gw9w-mwx2/GHSA-36h5-gw9w-mwx2.json +++ b/advisories/unreviewed/2024/01/GHSA-36h5-gw9w-mwx2/GHSA-36h5-gw9w-mwx2.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/01/GHSA-43h6-xw53-hc6g/GHSA-43h6-xw53-hc6g.json b/advisories/unreviewed/2024/01/GHSA-43h6-xw53-hc6g/GHSA-43h6-xw53-hc6g.json index b97caffed95..16e36b0fb5e 100644 --- a/advisories/unreviewed/2024/01/GHSA-43h6-xw53-hc6g/GHSA-43h6-xw53-hc6g.json +++ b/advisories/unreviewed/2024/01/GHSA-43h6-xw53-hc6g/GHSA-43h6-xw53-hc6g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-43h6-xw53-hc6g", - "modified": "2024-01-22T21:31:07Z", + "modified": "2025-06-11T18:35:38Z", "published": "2024-01-16T18:31:09Z", "aliases": [ "CVE-2023-3211" diff --git a/advisories/unreviewed/2024/01/GHSA-46c3-xj3x-x8jw/GHSA-46c3-xj3x-x8jw.json b/advisories/unreviewed/2024/01/GHSA-46c3-xj3x-x8jw/GHSA-46c3-xj3x-x8jw.json index 8f0b7a66f71..ae9a7d860aa 100644 --- a/advisories/unreviewed/2024/01/GHSA-46c3-xj3x-x8jw/GHSA-46c3-xj3x-x8jw.json +++ b/advisories/unreviewed/2024/01/GHSA-46c3-xj3x-x8jw/GHSA-46c3-xj3x-x8jw.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/01/GHSA-5h5w-7f25-q75w/GHSA-5h5w-7f25-q75w.json b/advisories/unreviewed/2024/01/GHSA-5h5w-7f25-q75w/GHSA-5h5w-7f25-q75w.json index ff925599fd5..110eb20b342 100644 --- a/advisories/unreviewed/2024/01/GHSA-5h5w-7f25-q75w/GHSA-5h5w-7f25-q75w.json +++ b/advisories/unreviewed/2024/01/GHSA-5h5w-7f25-q75w/GHSA-5h5w-7f25-q75w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5h5w-7f25-q75w", - "modified": "2024-01-23T21:30:19Z", + "modified": "2025-06-11T18:35:37Z", "published": "2024-01-16T18:31:08Z", "aliases": [ "CVE-2021-24432" diff --git a/advisories/unreviewed/2024/01/GHSA-9gmp-mjhc-r22w/GHSA-9gmp-mjhc-r22w.json b/advisories/unreviewed/2024/01/GHSA-9gmp-mjhc-r22w/GHSA-9gmp-mjhc-r22w.json index 9babaa28521..6a78420ebfc 100644 --- a/advisories/unreviewed/2024/01/GHSA-9gmp-mjhc-r22w/GHSA-9gmp-mjhc-r22w.json +++ b/advisories/unreviewed/2024/01/GHSA-9gmp-mjhc-r22w/GHSA-9gmp-mjhc-r22w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9gmp-mjhc-r22w", - "modified": "2024-02-03T03:30:27Z", + "modified": "2025-06-11T18:35:39Z", "published": "2024-01-29T15:30:29Z", "aliases": [ "CVE-2023-5943" diff --git a/advisories/unreviewed/2024/01/GHSA-9j2m-4pqq-wmh6/GHSA-9j2m-4pqq-wmh6.json b/advisories/unreviewed/2024/01/GHSA-9j2m-4pqq-wmh6/GHSA-9j2m-4pqq-wmh6.json index 9169c1a8f92..75fdebc9574 100644 --- a/advisories/unreviewed/2024/01/GHSA-9j2m-4pqq-wmh6/GHSA-9j2m-4pqq-wmh6.json +++ b/advisories/unreviewed/2024/01/GHSA-9j2m-4pqq-wmh6/GHSA-9j2m-4pqq-wmh6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9j2m-4pqq-wmh6", - "modified": "2024-01-26T21:30:21Z", + "modified": "2025-06-11T18:35:38Z", "published": "2024-01-22T21:31:07Z", "aliases": [ "CVE-2023-6384" diff --git a/advisories/unreviewed/2024/01/GHSA-fpx6-qj6w-4m83/GHSA-fpx6-qj6w-4m83.json b/advisories/unreviewed/2024/01/GHSA-fpx6-qj6w-4m83/GHSA-fpx6-qj6w-4m83.json index bb928dd77c2..24af4748853 100644 --- a/advisories/unreviewed/2024/01/GHSA-fpx6-qj6w-4m83/GHSA-fpx6-qj6w-4m83.json +++ b/advisories/unreviewed/2024/01/GHSA-fpx6-qj6w-4m83/GHSA-fpx6-qj6w-4m83.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fpx6-qj6w-4m83", - "modified": "2024-01-24T18:31:00Z", + "modified": "2025-06-11T18:35:38Z", "published": "2024-01-16T18:31:09Z", "aliases": [ "CVE-2022-3604" diff --git a/advisories/unreviewed/2024/01/GHSA-fv3c-xwjm-jfxw/GHSA-fv3c-xwjm-jfxw.json b/advisories/unreviewed/2024/01/GHSA-fv3c-xwjm-jfxw/GHSA-fv3c-xwjm-jfxw.json index cb2b2a2524a..5e28d4c8afc 100644 --- a/advisories/unreviewed/2024/01/GHSA-fv3c-xwjm-jfxw/GHSA-fv3c-xwjm-jfxw.json +++ b/advisories/unreviewed/2024/01/GHSA-fv3c-xwjm-jfxw/GHSA-fv3c-xwjm-jfxw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fv3c-xwjm-jfxw", - "modified": "2024-01-19T21:30:34Z", + "modified": "2025-06-11T18:35:37Z", "published": "2024-01-16T09:30:18Z", "aliases": [ "CVE-2023-52111" diff --git a/advisories/unreviewed/2024/01/GHSA-hjjv-gwf3-fpj2/GHSA-hjjv-gwf3-fpj2.json b/advisories/unreviewed/2024/01/GHSA-hjjv-gwf3-fpj2/GHSA-hjjv-gwf3-fpj2.json index abcce26ace1..5e80e5316c0 100644 --- a/advisories/unreviewed/2024/01/GHSA-hjjv-gwf3-fpj2/GHSA-hjjv-gwf3-fpj2.json +++ b/advisories/unreviewed/2024/01/GHSA-hjjv-gwf3-fpj2/GHSA-hjjv-gwf3-fpj2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hjjv-gwf3-fpj2", - "modified": "2024-01-23T15:30:57Z", + "modified": "2025-06-11T18:35:38Z", "published": "2024-01-16T18:31:10Z", "aliases": [ "CVE-2023-4797" diff --git a/advisories/unreviewed/2024/01/GHSA-hw3h-gc2r-whp8/GHSA-hw3h-gc2r-whp8.json b/advisories/unreviewed/2024/01/GHSA-hw3h-gc2r-whp8/GHSA-hw3h-gc2r-whp8.json index 0f3052f7d6f..db3b9f05d70 100644 --- a/advisories/unreviewed/2024/01/GHSA-hw3h-gc2r-whp8/GHSA-hw3h-gc2r-whp8.json +++ b/advisories/unreviewed/2024/01/GHSA-hw3h-gc2r-whp8/GHSA-hw3h-gc2r-whp8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hw3h-gc2r-whp8", - "modified": "2024-01-19T21:30:34Z", + "modified": "2025-06-11T18:35:37Z", "published": "2024-01-16T18:31:09Z", "aliases": [ "CVE-2022-0775" diff --git a/advisories/unreviewed/2024/01/GHSA-jmf9-hpf4-qhp5/GHSA-jmf9-hpf4-qhp5.json b/advisories/unreviewed/2024/01/GHSA-jmf9-hpf4-qhp5/GHSA-jmf9-hpf4-qhp5.json index ca05e6ab6a1..76fc17ece9c 100644 --- a/advisories/unreviewed/2024/01/GHSA-jmf9-hpf4-qhp5/GHSA-jmf9-hpf4-qhp5.json +++ b/advisories/unreviewed/2024/01/GHSA-jmf9-hpf4-qhp5/GHSA-jmf9-hpf4-qhp5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jmf9-hpf4-qhp5", - "modified": "2024-01-25T03:30:58Z", + "modified": "2025-06-11T18:35:38Z", "published": "2024-01-22T21:31:07Z", "aliases": [ "CVE-2023-6456" diff --git a/advisories/unreviewed/2024/01/GHSA-m653-22c6-v2w8/GHSA-m653-22c6-v2w8.json b/advisories/unreviewed/2024/01/GHSA-m653-22c6-v2w8/GHSA-m653-22c6-v2w8.json index affcad5d2d3..d85b6c01a82 100644 --- a/advisories/unreviewed/2024/01/GHSA-m653-22c6-v2w8/GHSA-m653-22c6-v2w8.json +++ b/advisories/unreviewed/2024/01/GHSA-m653-22c6-v2w8/GHSA-m653-22c6-v2w8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m653-22c6-v2w8", - "modified": "2024-02-05T18:31:36Z", + "modified": "2025-06-11T18:35:39Z", "published": "2024-01-29T15:30:30Z", "aliases": [ "CVE-2023-7204" diff --git a/advisories/unreviewed/2024/01/GHSA-phjg-gj5x-8j96/GHSA-phjg-gj5x-8j96.json b/advisories/unreviewed/2024/01/GHSA-phjg-gj5x-8j96/GHSA-phjg-gj5x-8j96.json index ad429dba0a8..b79ab06aa5b 100644 --- a/advisories/unreviewed/2024/01/GHSA-phjg-gj5x-8j96/GHSA-phjg-gj5x-8j96.json +++ b/advisories/unreviewed/2024/01/GHSA-phjg-gj5x-8j96/GHSA-phjg-gj5x-8j96.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-phjg-gj5x-8j96", - "modified": "2024-01-19T21:30:34Z", + "modified": "2025-06-11T18:35:37Z", "published": "2024-01-15T18:30:18Z", "aliases": [ "CVE-2023-6623" diff --git a/advisories/unreviewed/2024/01/GHSA-pm8g-4f93-7m8m/GHSA-pm8g-4f93-7m8m.json b/advisories/unreviewed/2024/01/GHSA-pm8g-4f93-7m8m/GHSA-pm8g-4f93-7m8m.json index ba97b85bb94..7890e5fffca 100644 --- a/advisories/unreviewed/2024/01/GHSA-pm8g-4f93-7m8m/GHSA-pm8g-4f93-7m8m.json +++ b/advisories/unreviewed/2024/01/GHSA-pm8g-4f93-7m8m/GHSA-pm8g-4f93-7m8m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pm8g-4f93-7m8m", - "modified": "2024-01-23T15:30:57Z", + "modified": "2025-06-11T18:35:38Z", "published": "2024-01-16T18:31:10Z", "aliases": [ "CVE-2023-6373" diff --git a/advisories/unreviewed/2024/01/GHSA-q37p-g696-qhwm/GHSA-q37p-g696-qhwm.json b/advisories/unreviewed/2024/01/GHSA-q37p-g696-qhwm/GHSA-q37p-g696-qhwm.json index ed49cb0b9cd..401217525e0 100644 --- a/advisories/unreviewed/2024/01/GHSA-q37p-g696-qhwm/GHSA-q37p-g696-qhwm.json +++ b/advisories/unreviewed/2024/01/GHSA-q37p-g696-qhwm/GHSA-q37p-g696-qhwm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q37p-g696-qhwm", - "modified": "2024-01-31T15:30:19Z", + "modified": "2025-06-11T18:35:39Z", "published": "2024-01-24T00:30:32Z", "aliases": [ "CVE-2021-42142" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://seclists.org/fulldisclosure/2024/Jan/15" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/15" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-qcfg-49mv-9hvw/GHSA-qcfg-49mv-9hvw.json b/advisories/unreviewed/2024/01/GHSA-qcfg-49mv-9hvw/GHSA-qcfg-49mv-9hvw.json index e4790561710..090f273eb55 100644 --- a/advisories/unreviewed/2024/01/GHSA-qcfg-49mv-9hvw/GHSA-qcfg-49mv-9hvw.json +++ b/advisories/unreviewed/2024/01/GHSA-qcfg-49mv-9hvw/GHSA-qcfg-49mv-9hvw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qcfg-49mv-9hvw", - "modified": "2024-01-24T18:31:00Z", + "modified": "2025-06-11T18:35:38Z", "published": "2024-01-16T18:31:09Z", "aliases": [ "CVE-2022-3836" diff --git a/advisories/unreviewed/2024/01/GHSA-qp39-g94h-cxxf/GHSA-qp39-g94h-cxxf.json b/advisories/unreviewed/2024/01/GHSA-qp39-g94h-cxxf/GHSA-qp39-g94h-cxxf.json index 2255c91e3c7..261578a7281 100644 --- a/advisories/unreviewed/2024/01/GHSA-qp39-g94h-cxxf/GHSA-qp39-g94h-cxxf.json +++ b/advisories/unreviewed/2024/01/GHSA-qp39-g94h-cxxf/GHSA-qp39-g94h-cxxf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qp39-g94h-cxxf", - "modified": "2024-01-23T21:30:20Z", + "modified": "2025-06-11T18:35:37Z", "published": "2024-01-16T18:31:09Z", "aliases": [ "CVE-2022-1617" diff --git a/advisories/unreviewed/2024/01/GHSA-r34p-xvw4-c7qj/GHSA-r34p-xvw4-c7qj.json b/advisories/unreviewed/2024/01/GHSA-r34p-xvw4-c7qj/GHSA-r34p-xvw4-c7qj.json index d913557fbc7..d7500f2ec61 100644 --- a/advisories/unreviewed/2024/01/GHSA-r34p-xvw4-c7qj/GHSA-r34p-xvw4-c7qj.json +++ b/advisories/unreviewed/2024/01/GHSA-r34p-xvw4-c7qj/GHSA-r34p-xvw4-c7qj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r34p-xvw4-c7qj", - "modified": "2024-01-22T21:31:07Z", + "modified": "2025-06-11T18:35:38Z", "published": "2024-01-16T18:31:09Z", "aliases": [ "CVE-2023-0389" diff --git a/advisories/unreviewed/2024/01/GHSA-w6c8-6gw8-5gvp/GHSA-w6c8-6gw8-5gvp.json b/advisories/unreviewed/2024/01/GHSA-w6c8-6gw8-5gvp/GHSA-w6c8-6gw8-5gvp.json index 4a61ef02476..552268b2d33 100644 --- a/advisories/unreviewed/2024/01/GHSA-w6c8-6gw8-5gvp/GHSA-w6c8-6gw8-5gvp.json +++ b/advisories/unreviewed/2024/01/GHSA-w6c8-6gw8-5gvp/GHSA-w6c8-6gw8-5gvp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w6c8-6gw8-5gvp", - "modified": "2024-02-03T00:31:33Z", + "modified": "2025-06-11T18:35:39Z", "published": "2024-01-29T15:30:29Z", "aliases": [ "CVE-2023-6946" diff --git a/advisories/unreviewed/2024/01/GHSA-wfgq-9f7c-xcw5/GHSA-wfgq-9f7c-xcw5.json b/advisories/unreviewed/2024/01/GHSA-wfgq-9f7c-xcw5/GHSA-wfgq-9f7c-xcw5.json index 501bc3b9d48..c974eba7322 100644 --- a/advisories/unreviewed/2024/01/GHSA-wfgq-9f7c-xcw5/GHSA-wfgq-9f7c-xcw5.json +++ b/advisories/unreviewed/2024/01/GHSA-wfgq-9f7c-xcw5/GHSA-wfgq-9f7c-xcw5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wfgq-9f7c-xcw5", - "modified": "2024-01-23T15:30:57Z", + "modified": "2025-06-11T18:35:38Z", "published": "2024-01-16T18:31:09Z", "aliases": [ "CVE-2023-1405" diff --git a/advisories/unreviewed/2024/01/GHSA-x73f-6qwm-hh3x/GHSA-x73f-6qwm-hh3x.json b/advisories/unreviewed/2024/01/GHSA-x73f-6qwm-hh3x/GHSA-x73f-6qwm-hh3x.json index 21d408009d2..4ddc56981b0 100644 --- a/advisories/unreviewed/2024/01/GHSA-x73f-6qwm-hh3x/GHSA-x73f-6qwm-hh3x.json +++ b/advisories/unreviewed/2024/01/GHSA-x73f-6qwm-hh3x/GHSA-x73f-6qwm-hh3x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x73f-6qwm-hh3x", - "modified": "2024-01-30T18:30:19Z", + "modified": "2025-06-11T18:35:38Z", "published": "2024-01-23T15:30:58Z", "aliases": [ "CVE-2024-0748" diff --git a/advisories/unreviewed/2025/05/GHSA-353c-hm8f-g46h/GHSA-353c-hm8f-g46h.json b/advisories/unreviewed/2025/05/GHSA-353c-hm8f-g46h/GHSA-353c-hm8f-g46h.json index 84ada8d5e31..aa1978dce47 100644 --- a/advisories/unreviewed/2025/05/GHSA-353c-hm8f-g46h/GHSA-353c-hm8f-g46h.json +++ b/advisories/unreviewed/2025/05/GHSA-353c-hm8f-g46h/GHSA-353c-hm8f-g46h.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-4jg8-qc3w-j5hx/GHSA-4jg8-qc3w-j5hx.json b/advisories/unreviewed/2025/05/GHSA-4jg8-qc3w-j5hx/GHSA-4jg8-qc3w-j5hx.json index 0b46c3c2246..1e018744df2 100644 --- a/advisories/unreviewed/2025/05/GHSA-4jg8-qc3w-j5hx/GHSA-4jg8-qc3w-j5hx.json +++ b/advisories/unreviewed/2025/05/GHSA-4jg8-qc3w-j5hx/GHSA-4jg8-qc3w-j5hx.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-559f-7rvx-wm9p/GHSA-559f-7rvx-wm9p.json b/advisories/unreviewed/2025/05/GHSA-559f-7rvx-wm9p/GHSA-559f-7rvx-wm9p.json index c09bc27c6f6..65126076707 100644 --- a/advisories/unreviewed/2025/05/GHSA-559f-7rvx-wm9p/GHSA-559f-7rvx-wm9p.json +++ b/advisories/unreviewed/2025/05/GHSA-559f-7rvx-wm9p/GHSA-559f-7rvx-wm9p.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-69xj-9qh4-v9hv/GHSA-69xj-9qh4-v9hv.json b/advisories/unreviewed/2025/05/GHSA-69xj-9qh4-v9hv/GHSA-69xj-9qh4-v9hv.json index dbc42caa27e..a4622f6d1e8 100644 --- a/advisories/unreviewed/2025/05/GHSA-69xj-9qh4-v9hv/GHSA-69xj-9qh4-v9hv.json +++ b/advisories/unreviewed/2025/05/GHSA-69xj-9qh4-v9hv/GHSA-69xj-9qh4-v9hv.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-7vrj-wjmg-rqm2/GHSA-7vrj-wjmg-rqm2.json b/advisories/unreviewed/2025/05/GHSA-7vrj-wjmg-rqm2/GHSA-7vrj-wjmg-rqm2.json index 9e8ba201ffb..1cce9ed0db7 100644 --- a/advisories/unreviewed/2025/05/GHSA-7vrj-wjmg-rqm2/GHSA-7vrj-wjmg-rqm2.json +++ b/advisories/unreviewed/2025/05/GHSA-7vrj-wjmg-rqm2/GHSA-7vrj-wjmg-rqm2.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-7x4v-3vr9-6h78/GHSA-7x4v-3vr9-6h78.json b/advisories/unreviewed/2025/05/GHSA-7x4v-3vr9-6h78/GHSA-7x4v-3vr9-6h78.json index 1b415a90724..08ac7851487 100644 --- a/advisories/unreviewed/2025/05/GHSA-7x4v-3vr9-6h78/GHSA-7x4v-3vr9-6h78.json +++ b/advisories/unreviewed/2025/05/GHSA-7x4v-3vr9-6h78/GHSA-7x4v-3vr9-6h78.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-9g8q-q3hj-343m/GHSA-9g8q-q3hj-343m.json b/advisories/unreviewed/2025/05/GHSA-9g8q-q3hj-343m/GHSA-9g8q-q3hj-343m.json index 5df717d1031..698116b4468 100644 --- a/advisories/unreviewed/2025/05/GHSA-9g8q-q3hj-343m/GHSA-9g8q-q3hj-343m.json +++ b/advisories/unreviewed/2025/05/GHSA-9g8q-q3hj-343m/GHSA-9g8q-q3hj-343m.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-9m4x-m322-8xcp/GHSA-9m4x-m322-8xcp.json b/advisories/unreviewed/2025/05/GHSA-9m4x-m322-8xcp/GHSA-9m4x-m322-8xcp.json index 472ba358ffd..d4c0241b0ea 100644 --- a/advisories/unreviewed/2025/05/GHSA-9m4x-m322-8xcp/GHSA-9m4x-m322-8xcp.json +++ b/advisories/unreviewed/2025/05/GHSA-9m4x-m322-8xcp/GHSA-9m4x-m322-8xcp.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-c8hj-rjcv-xx48/GHSA-c8hj-rjcv-xx48.json b/advisories/unreviewed/2025/05/GHSA-c8hj-rjcv-xx48/GHSA-c8hj-rjcv-xx48.json index d3e02a1b524..a46d9f8fc20 100644 --- a/advisories/unreviewed/2025/05/GHSA-c8hj-rjcv-xx48/GHSA-c8hj-rjcv-xx48.json +++ b/advisories/unreviewed/2025/05/GHSA-c8hj-rjcv-xx48/GHSA-c8hj-rjcv-xx48.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-chqc-5pg2-gc95/GHSA-chqc-5pg2-gc95.json b/advisories/unreviewed/2025/05/GHSA-chqc-5pg2-gc95/GHSA-chqc-5pg2-gc95.json index 9639c503963..1cf766e0372 100644 --- a/advisories/unreviewed/2025/05/GHSA-chqc-5pg2-gc95/GHSA-chqc-5pg2-gc95.json +++ b/advisories/unreviewed/2025/05/GHSA-chqc-5pg2-gc95/GHSA-chqc-5pg2-gc95.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-g453-c6fq-7fg3/GHSA-g453-c6fq-7fg3.json b/advisories/unreviewed/2025/05/GHSA-g453-c6fq-7fg3/GHSA-g453-c6fq-7fg3.json index e5871a74ba4..b0920452bd7 100644 --- a/advisories/unreviewed/2025/05/GHSA-g453-c6fq-7fg3/GHSA-g453-c6fq-7fg3.json +++ b/advisories/unreviewed/2025/05/GHSA-g453-c6fq-7fg3/GHSA-g453-c6fq-7fg3.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-gmhj-76hp-7wh3/GHSA-gmhj-76hp-7wh3.json b/advisories/unreviewed/2025/05/GHSA-gmhj-76hp-7wh3/GHSA-gmhj-76hp-7wh3.json index 66f70288082..8d115d7eb1e 100644 --- a/advisories/unreviewed/2025/05/GHSA-gmhj-76hp-7wh3/GHSA-gmhj-76hp-7wh3.json +++ b/advisories/unreviewed/2025/05/GHSA-gmhj-76hp-7wh3/GHSA-gmhj-76hp-7wh3.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-918" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-j2p9-f4vx-cp2g/GHSA-j2p9-f4vx-cp2g.json b/advisories/unreviewed/2025/05/GHSA-j2p9-f4vx-cp2g/GHSA-j2p9-f4vx-cp2g.json index b268531cea1..872fcd05222 100644 --- a/advisories/unreviewed/2025/05/GHSA-j2p9-f4vx-cp2g/GHSA-j2p9-f4vx-cp2g.json +++ b/advisories/unreviewed/2025/05/GHSA-j2p9-f4vx-cp2g/GHSA-j2p9-f4vx-cp2g.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-78" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-j7cm-jxq2-h8q5/GHSA-j7cm-jxq2-h8q5.json b/advisories/unreviewed/2025/05/GHSA-j7cm-jxq2-h8q5/GHSA-j7cm-jxq2-h8q5.json index c69b2835658..e388ed45807 100644 --- a/advisories/unreviewed/2025/05/GHSA-j7cm-jxq2-h8q5/GHSA-j7cm-jxq2-h8q5.json +++ b/advisories/unreviewed/2025/05/GHSA-j7cm-jxq2-h8q5/GHSA-j7cm-jxq2-h8q5.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-vcr6-vwcj-r3r3/GHSA-vcr6-vwcj-r3r3.json b/advisories/unreviewed/2025/05/GHSA-vcr6-vwcj-r3r3/GHSA-vcr6-vwcj-r3r3.json index 60ae9fcb775..2f7bf2e579d 100644 --- a/advisories/unreviewed/2025/05/GHSA-vcr6-vwcj-r3r3/GHSA-vcr6-vwcj-r3r3.json +++ b/advisories/unreviewed/2025/05/GHSA-vcr6-vwcj-r3r3/GHSA-vcr6-vwcj-r3r3.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-vf8r-rhw4-6q8g/GHSA-vf8r-rhw4-6q8g.json b/advisories/unreviewed/2025/05/GHSA-vf8r-rhw4-6q8g/GHSA-vf8r-rhw4-6q8g.json index c55ca540f3e..15b9d94f7a6 100644 --- a/advisories/unreviewed/2025/05/GHSA-vf8r-rhw4-6q8g/GHSA-vf8r-rhw4-6q8g.json +++ b/advisories/unreviewed/2025/05/GHSA-vf8r-rhw4-6q8g/GHSA-vf8r-rhw4-6q8g.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-w589-4j7g-6889/GHSA-w589-4j7g-6889.json b/advisories/unreviewed/2025/05/GHSA-w589-4j7g-6889/GHSA-w589-4j7g-6889.json index 2944ffbb09c..40fb24044bc 100644 --- a/advisories/unreviewed/2025/05/GHSA-w589-4j7g-6889/GHSA-w589-4j7g-6889.json +++ b/advisories/unreviewed/2025/05/GHSA-w589-4j7g-6889/GHSA-w589-4j7g-6889.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-x9mr-w276-h3c2/GHSA-x9mr-w276-h3c2.json b/advisories/unreviewed/2025/05/GHSA-x9mr-w276-h3c2/GHSA-x9mr-w276-h3c2.json index 446bc974adf..6bd0338df3c 100644 --- a/advisories/unreviewed/2025/05/GHSA-x9mr-w276-h3c2/GHSA-x9mr-w276-h3c2.json +++ b/advisories/unreviewed/2025/05/GHSA-x9mr-w276-h3c2/GHSA-x9mr-w276-h3c2.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-xqrc-6556-5gcq/GHSA-xqrc-6556-5gcq.json b/advisories/unreviewed/2025/05/GHSA-xqrc-6556-5gcq/GHSA-xqrc-6556-5gcq.json index 582b47c072a..054ce493692 100644 --- a/advisories/unreviewed/2025/05/GHSA-xqrc-6556-5gcq/GHSA-xqrc-6556-5gcq.json +++ b/advisories/unreviewed/2025/05/GHSA-xqrc-6556-5gcq/GHSA-xqrc-6556-5gcq.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-xvf2-x5rr-6g4q/GHSA-xvf2-x5rr-6g4q.json b/advisories/unreviewed/2025/05/GHSA-xvf2-x5rr-6g4q/GHSA-xvf2-x5rr-6g4q.json index 5b4f67e68e8..7fa5fc99f7e 100644 --- a/advisories/unreviewed/2025/05/GHSA-xvf2-x5rr-6g4q/GHSA-xvf2-x5rr-6g4q.json +++ b/advisories/unreviewed/2025/05/GHSA-xvf2-x5rr-6g4q/GHSA-xvf2-x5rr-6g4q.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/06/GHSA-23fj-6rwp-5rq6/GHSA-23fj-6rwp-5rq6.json b/advisories/unreviewed/2025/06/GHSA-23fj-6rwp-5rq6/GHSA-23fj-6rwp-5rq6.json index 990d46bbd29..ca9b74b00d3 100644 --- a/advisories/unreviewed/2025/06/GHSA-23fj-6rwp-5rq6/GHSA-23fj-6rwp-5rq6.json +++ b/advisories/unreviewed/2025/06/GHSA-23fj-6rwp-5rq6/GHSA-23fj-6rwp-5rq6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-23fj-6rwp-5rq6", - "modified": "2025-06-10T21:31:22Z", + "modified": "2025-06-11T18:35:42Z", "published": "2025-06-10T21:31:22Z", "aliases": [ "CVE-2025-43576" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://helpx.adobe.com/security/products/acrobat/apsb25-57.html" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2170" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/06/GHSA-56hj-j6mv-g5fc/GHSA-56hj-j6mv-g5fc.json b/advisories/unreviewed/2025/06/GHSA-56hj-j6mv-g5fc/GHSA-56hj-j6mv-g5fc.json new file mode 100644 index 00000000000..2e6ffd8b618 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-56hj-j6mv-g5fc/GHSA-56hj-j6mv-g5fc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-56hj-j6mv-g5fc", + "modified": "2025-06-11T18:35:43Z", + "published": "2025-06-11T18:35:43Z", + "aliases": [ + "CVE-2025-6002" + ], + "details": "An unrestricted file upload vulnerability exists in the Product Image section of the VirtueMart backend. Authenticated attackers can upload files with arbitrary extensions, including executable or malicious files, potentially leading to remote code execution or other security impacts depending on server configuration.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-6002" + }, + { + "type": "WEB", + "url": "https://blog.blacklanternsecurity.com/p/doomla-zero-days" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T17:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-62jj-gr2r-5c34/GHSA-62jj-gr2r-5c34.json b/advisories/unreviewed/2025/06/GHSA-62jj-gr2r-5c34/GHSA-62jj-gr2r-5c34.json new file mode 100644 index 00000000000..4f6ee2b8705 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-62jj-gr2r-5c34/GHSA-62jj-gr2r-5c34.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62jj-gr2r-5c34", + "modified": "2025-06-11T18:35:43Z", + "published": "2025-06-11T18:35:43Z", + "aliases": [ + "CVE-2025-4673" + ], + "details": "Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4673" + }, + { + "type": "WEB", + "url": "https://go.dev/cl/679257" + }, + { + "type": "WEB", + "url": "https://go.dev/issue/73816" + }, + { + "type": "WEB", + "url": "https://groups.google.com/g/golang-announce/c/ufZ8WpEsA3A" + }, + { + "type": "WEB", + "url": "https://pkg.go.dev/vuln/GO-2025-3751" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T17:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-6f52-wpx2-hvf2/GHSA-6f52-wpx2-hvf2.json b/advisories/unreviewed/2025/06/GHSA-6f52-wpx2-hvf2/GHSA-6f52-wpx2-hvf2.json new file mode 100644 index 00000000000..88dc60ef52f --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-6f52-wpx2-hvf2/GHSA-6f52-wpx2-hvf2.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6f52-wpx2-hvf2", + "modified": "2025-06-11T18:35:43Z", + "published": "2025-06-11T18:35:43Z", + "aliases": [ + "CVE-2025-22874" + ], + "details": "Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22874" + }, + { + "type": "WEB", + "url": "https://go.dev/cl/670375" + }, + { + "type": "WEB", + "url": "https://go.dev/issue/73612" + }, + { + "type": "WEB", + "url": "https://groups.google.com/g/golang-announce/c/ufZ8WpEsA3A" + }, + { + "type": "WEB", + "url": "https://pkg.go.dev/vuln/GO-2025-3749" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T17:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-8jmh-8q7v-83gf/GHSA-8jmh-8q7v-83gf.json b/advisories/unreviewed/2025/06/GHSA-8jmh-8q7v-83gf/GHSA-8jmh-8q7v-83gf.json index a360a1092c6..ed839347a02 100644 --- a/advisories/unreviewed/2025/06/GHSA-8jmh-8q7v-83gf/GHSA-8jmh-8q7v-83gf.json +++ b/advisories/unreviewed/2025/06/GHSA-8jmh-8q7v-83gf/GHSA-8jmh-8q7v-83gf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8jmh-8q7v-83gf", - "modified": "2025-06-10T21:31:23Z", + "modified": "2025-06-11T18:35:43Z", "published": "2025-06-10T21:31:23Z", "aliases": [ "CVE-2025-43578" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://helpx.adobe.com/security/products/acrobat/apsb25-57.html" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2159" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/06/GHSA-8vrc-phw3-jc6v/GHSA-8vrc-phw3-jc6v.json b/advisories/unreviewed/2025/06/GHSA-8vrc-phw3-jc6v/GHSA-8vrc-phw3-jc6v.json new file mode 100644 index 00000000000..a4506edaf9c --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-8vrc-phw3-jc6v/GHSA-8vrc-phw3-jc6v.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8vrc-phw3-jc6v", + "modified": "2025-06-11T18:35:43Z", + "published": "2025-06-11T18:35:43Z", + "aliases": [ + "CVE-2025-1699" + ], + "details": "An incorrect default permissions vulnerability was reported in the MotoSignature application that could result in unauthorized access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1699" + }, + { + "type": "WEB", + "url": "https://en-us.support.motorola.com/app/answers/detail/a_id/186729" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T17:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-gr5f-7m4r-g5r6/GHSA-gr5f-7m4r-g5r6.json b/advisories/unreviewed/2025/06/GHSA-gr5f-7m4r-g5r6/GHSA-gr5f-7m4r-g5r6.json new file mode 100644 index 00000000000..743ca033ade --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-gr5f-7m4r-g5r6/GHSA-gr5f-7m4r-g5r6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gr5f-7m4r-g5r6", + "modified": "2025-06-11T18:35:43Z", + "published": "2025-06-11T18:35:43Z", + "aliases": [ + "CVE-2025-0923" + ], + "details": "IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 stores source code on the web server that could aid in further attacks against the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0923" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7234674" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-540" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T18:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-h6x7-66p5-f6g7/GHSA-h6x7-66p5-f6g7.json b/advisories/unreviewed/2025/06/GHSA-h6x7-66p5-f6g7/GHSA-h6x7-66p5-f6g7.json new file mode 100644 index 00000000000..0a7ccbf581c --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-h6x7-66p5-f6g7/GHSA-h6x7-66p5-f6g7.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h6x7-66p5-f6g7", + "modified": "2025-06-11T18:35:43Z", + "published": "2025-06-11T18:35:43Z", + "aliases": [ + "CVE-2025-26383" + ], + "details": "The iSTAR Configuration Utility (ICU) tool leaks memory, which could result in the unintended exposure of unauthorized data from the Windows PC that ICU is running on.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26383" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-146-01" + }, + { + "type": "WEB", + "url": "https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-457" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-jrv8-vff8-5jvw/GHSA-jrv8-vff8-5jvw.json b/advisories/unreviewed/2025/06/GHSA-jrv8-vff8-5jvw/GHSA-jrv8-vff8-5jvw.json new file mode 100644 index 00000000000..1cc64e1b1fd --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-jrv8-vff8-5jvw/GHSA-jrv8-vff8-5jvw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jrv8-vff8-5jvw", + "modified": "2025-06-11T18:35:43Z", + "published": "2025-06-11T18:35:43Z", + "aliases": [ + "CVE-2025-6001" + ], + "details": "A Cross-Site Request Forgery (CSRF) vulnerability exists in the product image upload function of VirtueMart that bypasses the CSRF protection token. An attacker is able to craft a special CSRF request which will allow unrestricted file upload into the VirtueMart media manager.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-6001" + }, + { + "type": "WEB", + "url": "https://blog.blacklanternsecurity.com/p/doomla-zero-days" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T17:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-jw54-c8rr-pjpq/GHSA-jw54-c8rr-pjpq.json b/advisories/unreviewed/2025/06/GHSA-jw54-c8rr-pjpq/GHSA-jw54-c8rr-pjpq.json new file mode 100644 index 00000000000..509476be44c --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-jw54-c8rr-pjpq/GHSA-jw54-c8rr-pjpq.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jw54-c8rr-pjpq", + "modified": "2025-06-11T18:35:43Z", + "published": "2025-06-11T18:35:43Z", + "aliases": [ + "CVE-2025-0913" + ], + "details": "os.OpenFile(path, os.O_CREATE|O_EXCL) behaved differently on Unix and Windows systems when the target path was a dangling symlink. On Unix systems, OpenFile with O_CREATE and O_EXCL flags never follows symlinks. On Windows, when the target path was a symlink to a nonexistent location, OpenFile would create a file in that location. OpenFile now always returns an error when the O_CREATE and O_EXCL flags are both set and the target path is a symlink.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0913" + }, + { + "type": "WEB", + "url": "https://go.dev/cl/672396" + }, + { + "type": "WEB", + "url": "https://go.dev/issue/73702" + }, + { + "type": "WEB", + "url": "https://groups.google.com/g/golang-announce/c/ufZ8WpEsA3A" + }, + { + "type": "WEB", + "url": "https://pkg.go.dev/vuln/GO-2025-3750" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T18:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-mqr9-mgqq-52rq/GHSA-mqr9-mgqq-52rq.json b/advisories/unreviewed/2025/06/GHSA-mqr9-mgqq-52rq/GHSA-mqr9-mgqq-52rq.json new file mode 100644 index 00000000000..720872eca84 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-mqr9-mgqq-52rq/GHSA-mqr9-mgqq-52rq.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mqr9-mgqq-52rq", + "modified": "2025-06-11T18:35:43Z", + "published": "2025-06-11T18:35:43Z", + "aliases": [ + "CVE-2025-40915" + ], + "details": "Mojolicious::Plugin::CSRF 1.03 for Perl uses a weak random number source for generating CSRF tokens.\n\nThat version of the module generates tokens as an MD5 of the process id, the current time, and a single call to the built-in rand() function.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40915" + }, + { + "type": "WEB", + "url": "https://metacpan.org/release/GRYPHON/Mojolicious-Plugin-CSRF-1.04/changes" + }, + { + "type": "WEB", + "url": "https://metacpan.org/release/GRYPHON/Mojolicious-Plugin-CSRF-1.04/diff/GRYPHON/Mojolicious-Plugin-CSRF-1.03" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-338" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T17:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-mxfp-8jmj-4hp9/GHSA-mxfp-8jmj-4hp9.json b/advisories/unreviewed/2025/06/GHSA-mxfp-8jmj-4hp9/GHSA-mxfp-8jmj-4hp9.json new file mode 100644 index 00000000000..d1bd34999e4 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-mxfp-8jmj-4hp9/GHSA-mxfp-8jmj-4hp9.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mxfp-8jmj-4hp9", + "modified": "2025-06-11T18:35:40Z", + "published": "2025-06-11T18:35:40Z", + "aliases": [ + "CVE-2024-45194" + ], + "details": "In Zimbra Collaboration (ZCS) 9.0 and 10.0, a vulnerability in the Webmail Modern UI allows execution of stored Cross-Site Scripting (XSS) payloads. An attacker with administrative access to the Zimbra Administration Panel can inject malicious JavaScript code while configuring an email account. This injected code is stored on the server and executed in the context of the victim's browser when interacting with specific elements in the web interface. (The vulnerability can be mitigated by properly sanitizing input parameters to prevent the injection of malicious code.)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45194" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Zimbra_Releases/10.0.9#Security_Fixes" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.1#Security_Fixes" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P41#Security_Fixes" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-21T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-q35w-g473-6c73/GHSA-q35w-g473-6c73.json b/advisories/unreviewed/2025/06/GHSA-q35w-g473-6c73/GHSA-q35w-g473-6c73.json new file mode 100644 index 00000000000..f3fd0d873f0 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-q35w-g473-6c73/GHSA-q35w-g473-6c73.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q35w-g473-6c73", + "modified": "2025-06-11T18:35:43Z", + "published": "2025-06-11T18:35:43Z", + "aliases": [ + "CVE-2025-0917" + ], + "details": "IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0917" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7234674" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T18:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-r58j-66xv-q95w/GHSA-r58j-66xv-q95w.json b/advisories/unreviewed/2025/06/GHSA-r58j-66xv-q95w/GHSA-r58j-66xv-q95w.json new file mode 100644 index 00000000000..f1e2a239f84 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-r58j-66xv-q95w/GHSA-r58j-66xv-q95w.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r58j-66xv-q95w", + "modified": "2025-06-11T18:35:43Z", + "published": "2025-06-11T18:35:43Z", + "aliases": [ + "CVE-2025-1698" + ], + "details": "Null pointer exception vulnerabilities were reported in the fingerprint sensor service that could allow a local attacker to cause a denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1698" + }, + { + "type": "WEB", + "url": "https://en-us.support.motorola.com/app/answers/detail/a_id/186728" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T17:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-v9x3-f4g7-pgm4/GHSA-v9x3-f4g7-pgm4.json b/advisories/unreviewed/2025/06/GHSA-v9x3-f4g7-pgm4/GHSA-v9x3-f4g7-pgm4.json new file mode 100644 index 00000000000..1052cc30f98 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-v9x3-f4g7-pgm4/GHSA-v9x3-f4g7-pgm4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v9x3-f4g7-pgm4", + "modified": "2025-06-11T18:35:43Z", + "published": "2025-06-11T18:35:43Z", + "aliases": [ + "CVE-2025-25032" + ], + "details": "IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 could allow an authenticated user to cause a denial of service by sending a specially crafted request that would exhaust memory resources.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25032" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7234674" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-w3qg-5chj-8g9g/GHSA-w3qg-5chj-8g9g.json b/advisories/unreviewed/2025/06/GHSA-w3qg-5chj-8g9g/GHSA-w3qg-5chj-8g9g.json new file mode 100644 index 00000000000..ab40eb8743a --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-w3qg-5chj-8g9g/GHSA-w3qg-5chj-8g9g.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w3qg-5chj-8g9g", + "modified": "2025-06-11T18:35:43Z", + "published": "2025-06-11T18:35:43Z", + "aliases": [ + "CVE-2025-40912" + ], + "details": "CryptX for Perl before version 0.065 contains a dependency that may be susceptible to malformed unicode.\n\nCryptX embeds the tomcrypt library. The versions of that library in CryptX before 0.065 may be susceptible to CVE-2019-17362.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40912" + }, + { + "type": "WEB", + "url": "https://github.com/libtom/libtomcrypt/issues/507" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T18:15:25Z" + } +} \ No newline at end of file