From 197d04d9a6edfdac65f175200b0548de2d2d286c Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 21 May 2025 18:36:00 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-94xg-qm4r-9r7c.json | 6 +- .../GHSA-33cr-xf9m-fqqr.json | 2 +- .../GHSA-343h-h5v5-82rq.json | 7 ++- .../GHSA-433m-5r62-794r.json | 6 +- .../GHSA-4p6f-vmpg-88hm.json | 2 +- .../GHSA-833h-m63r-586v.json | 9 ++- .../GHSA-8jfv-vfxw-8q23.json | 2 +- .../GHSA-938g-35m6-qcp8.json | 9 ++- .../GHSA-f75q-r8vf-45pj.json | 6 +- .../GHSA-j3x6-vg5f-vx5p.json | 7 ++- .../GHSA-m5cg-qjmp-pw59.json | 6 +- .../GHSA-mrhr-c569-5wjh.json | 6 +- .../GHSA-pfqr-532x-cjjm.json | 7 ++- .../GHSA-q3pp-76rw-fqvm.json | 4 +- .../GHSA-r496-34w8-f379.json | 11 +++- .../GHSA-rpc9-wm96-3rrj.json | 2 +- .../GHSA-v748-qg3r-j62x.json | 6 +- .../GHSA-v8jg-p3fp-g968.json | 2 +- .../GHSA-w8pp-8gqf-chff.json | 6 +- .../GHSA-wgj9-cwmq-97x8.json | 2 +- .../GHSA-244c-33wx-j66j.json | 3 +- .../GHSA-7crf-mwwj-hvjp.json | 6 +- .../GHSA-c73j-8h5p-xxxr.json | 2 +- .../GHSA-cg43-3q5j-mwp7.json | 3 +- .../GHSA-x374-f9hj-5h8v.json | 4 +- .../GHSA-3r92-3wmq-rmm2.json | 4 +- .../GHSA-6m97-f4vx-x87g.json | 4 +- .../GHSA-9wv3-p38x-5wqv.json | 4 +- .../GHSA-hj6q-qv48-rgmf.json | 3 +- .../GHSA-p2v5-rvqj-c2xc.json | 4 +- .../GHSA-pw46-7qrx-4mc7.json | 3 +- .../GHSA-w27p-m7fr-3hpc.json | 3 +- .../GHSA-233v-5pqm-q596.json | 36 ++++++++++++ .../GHSA-256j-g634-v955.json | 3 +- .../GHSA-25g9-6gwc-gv6w.json | 36 ++++++++++++ .../GHSA-2w4w-qvp3-4g7g.json | 11 +++- .../GHSA-3c8c-p5w2-6pxx.json | 36 ++++++++++++ .../GHSA-3gpm-vq72-xv9v.json | 3 +- .../GHSA-3h4g-vcc2-xxf3.json | 36 ++++++++++++ .../GHSA-435v-q3pr-69h4.json | 36 ++++++++++++ .../GHSA-463c-jhp2-4mm7.json | 36 ++++++++++++ .../GHSA-472r-j47f-hrmv.json | 36 ++++++++++++ .../GHSA-4mmg-25h6-f798.json | 3 +- .../GHSA-57ff-cj28-pc38.json | 3 +- .../GHSA-58wr-734j-3p76.json | 36 ++++++++++++ .../GHSA-5fvr-4vv2-228w.json | 52 +++++++++++++++++ .../GHSA-69j7-c2h8-2cmf.json | 36 ++++++++++++ .../GHSA-6jfj-hxvq-rv4x.json | 56 +++++++++++++++++++ .../GHSA-6wpw-9mr8-qhv3.json | 3 +- .../GHSA-7f35-3w2m-gw5h.json | 3 +- .../GHSA-7mfw-wgr7-m3jg.json | 33 +++++++++++ .../GHSA-7v5f-m633-5wg2.json | 36 ++++++++++++ .../GHSA-88w2-frvv-mx6x.json | 33 +++++++++++ .../GHSA-9mgg-ww23-jfhc.json | 29 ++++++++++ .../GHSA-9qq5-w3c8-q244.json | 3 +- .../GHSA-9r82-ff34-6w3x.json | 36 ++++++++++++ .../GHSA-c2rm-m5xr-92gg.json | 15 +++-- .../GHSA-cmvj-3pj4-hrr7.json | 29 ++++++++++ .../GHSA-cvgc-mx2w-h3w8.json | 36 ++++++++++++ .../GHSA-fhgm-mxgh-gfpj.json | 10 +++- .../GHSA-fhm3-85qw-2fgx.json | 36 ++++++++++++ .../GHSA-fj3h-m99f-v4q3.json | 36 ++++++++++++ .../GHSA-g2xr-q6h2-7768.json | 36 ++++++++++++ .../GHSA-g6hf-3766-f3gv.json | 36 ++++++++++++ .../GHSA-g7h8-28jj-qxmf.json | 40 +++++++++++++ .../GHSA-h5wh-vhj4-rr58.json | 36 ++++++++++++ .../GHSA-j2vv-r926-8gq3.json | 33 +++++++++++ .../GHSA-jrwq-36rx-842c.json | 36 ++++++++++++ .../GHSA-m526-j28f-j8qx.json | 36 ++++++++++++ .../GHSA-m9wr-pvw8-mgmm.json | 36 ++++++++++++ .../GHSA-pjw9-wpcr-r3vj.json | 3 +- .../GHSA-pmc7-hgjr-qwv3.json | 36 ++++++++++++ .../GHSA-pqqp-7cp8-vxvf.json | 56 +++++++++++++++++++ .../GHSA-qc9j-84j3-74vm.json | 3 +- .../GHSA-qmj3-7hgm-pxgp.json | 15 +++-- .../GHSA-rgg6-wh38-9vv5.json | 3 +- .../GHSA-rxf3-624f-c767.json | 36 ++++++++++++ .../GHSA-v5fv-w3r3-cxrv.json | 36 ++++++++++++ .../GHSA-w5x3-j5vg-94wj.json | 3 +- .../GHSA-w687-qrqx-jr57.json | 36 ++++++++++++ .../GHSA-w6p4-84vc-qc2w.json | 56 +++++++++++++++++++ .../GHSA-wwq7-vmjh-7v57.json | 3 +- .../GHSA-xg53-mhh9-3cq7.json | 31 ++++++++++ .../GHSA-xgmm-9xmm-8qv5.json | 3 +- .../GHSA-xmq3-c6r3-6cm9.json | 29 ++++++++++ .../GHSA-xq83-m7pg-gg42.json | 36 ++++++++++++ .../GHSA-xw2w-jc5r-g6r7.json | 36 ++++++++++++ .../GHSA-xwrw-9qxw-gm75.json | 15 +++-- 88 files changed, 1604 insertions(+), 65 deletions(-) create mode 100644 advisories/unreviewed/2025/05/GHSA-233v-5pqm-q596/GHSA-233v-5pqm-q596.json create mode 100644 advisories/unreviewed/2025/05/GHSA-25g9-6gwc-gv6w/GHSA-25g9-6gwc-gv6w.json create mode 100644 advisories/unreviewed/2025/05/GHSA-3c8c-p5w2-6pxx/GHSA-3c8c-p5w2-6pxx.json create mode 100644 advisories/unreviewed/2025/05/GHSA-3h4g-vcc2-xxf3/GHSA-3h4g-vcc2-xxf3.json create mode 100644 advisories/unreviewed/2025/05/GHSA-435v-q3pr-69h4/GHSA-435v-q3pr-69h4.json create mode 100644 advisories/unreviewed/2025/05/GHSA-463c-jhp2-4mm7/GHSA-463c-jhp2-4mm7.json create mode 100644 advisories/unreviewed/2025/05/GHSA-472r-j47f-hrmv/GHSA-472r-j47f-hrmv.json create mode 100644 advisories/unreviewed/2025/05/GHSA-58wr-734j-3p76/GHSA-58wr-734j-3p76.json create mode 100644 advisories/unreviewed/2025/05/GHSA-5fvr-4vv2-228w/GHSA-5fvr-4vv2-228w.json create mode 100644 advisories/unreviewed/2025/05/GHSA-69j7-c2h8-2cmf/GHSA-69j7-c2h8-2cmf.json create mode 100644 advisories/unreviewed/2025/05/GHSA-6jfj-hxvq-rv4x/GHSA-6jfj-hxvq-rv4x.json create mode 100644 advisories/unreviewed/2025/05/GHSA-7mfw-wgr7-m3jg/GHSA-7mfw-wgr7-m3jg.json create mode 100644 advisories/unreviewed/2025/05/GHSA-7v5f-m633-5wg2/GHSA-7v5f-m633-5wg2.json create mode 100644 advisories/unreviewed/2025/05/GHSA-88w2-frvv-mx6x/GHSA-88w2-frvv-mx6x.json create mode 100644 advisories/unreviewed/2025/05/GHSA-9mgg-ww23-jfhc/GHSA-9mgg-ww23-jfhc.json create mode 100644 advisories/unreviewed/2025/05/GHSA-9r82-ff34-6w3x/GHSA-9r82-ff34-6w3x.json create mode 100644 advisories/unreviewed/2025/05/GHSA-cmvj-3pj4-hrr7/GHSA-cmvj-3pj4-hrr7.json create mode 100644 advisories/unreviewed/2025/05/GHSA-cvgc-mx2w-h3w8/GHSA-cvgc-mx2w-h3w8.json create mode 100644 advisories/unreviewed/2025/05/GHSA-fhm3-85qw-2fgx/GHSA-fhm3-85qw-2fgx.json create mode 100644 advisories/unreviewed/2025/05/GHSA-fj3h-m99f-v4q3/GHSA-fj3h-m99f-v4q3.json create mode 100644 advisories/unreviewed/2025/05/GHSA-g2xr-q6h2-7768/GHSA-g2xr-q6h2-7768.json create mode 100644 advisories/unreviewed/2025/05/GHSA-g6hf-3766-f3gv/GHSA-g6hf-3766-f3gv.json create mode 100644 advisories/unreviewed/2025/05/GHSA-g7h8-28jj-qxmf/GHSA-g7h8-28jj-qxmf.json create mode 100644 advisories/unreviewed/2025/05/GHSA-h5wh-vhj4-rr58/GHSA-h5wh-vhj4-rr58.json create mode 100644 advisories/unreviewed/2025/05/GHSA-j2vv-r926-8gq3/GHSA-j2vv-r926-8gq3.json create mode 100644 advisories/unreviewed/2025/05/GHSA-jrwq-36rx-842c/GHSA-jrwq-36rx-842c.json create mode 100644 advisories/unreviewed/2025/05/GHSA-m526-j28f-j8qx/GHSA-m526-j28f-j8qx.json create mode 100644 advisories/unreviewed/2025/05/GHSA-m9wr-pvw8-mgmm/GHSA-m9wr-pvw8-mgmm.json create mode 100644 advisories/unreviewed/2025/05/GHSA-pmc7-hgjr-qwv3/GHSA-pmc7-hgjr-qwv3.json create mode 100644 advisories/unreviewed/2025/05/GHSA-pqqp-7cp8-vxvf/GHSA-pqqp-7cp8-vxvf.json create mode 100644 advisories/unreviewed/2025/05/GHSA-rxf3-624f-c767/GHSA-rxf3-624f-c767.json create mode 100644 advisories/unreviewed/2025/05/GHSA-v5fv-w3r3-cxrv/GHSA-v5fv-w3r3-cxrv.json create mode 100644 advisories/unreviewed/2025/05/GHSA-w687-qrqx-jr57/GHSA-w687-qrqx-jr57.json create mode 100644 advisories/unreviewed/2025/05/GHSA-w6p4-84vc-qc2w/GHSA-w6p4-84vc-qc2w.json create mode 100644 advisories/unreviewed/2025/05/GHSA-xg53-mhh9-3cq7/GHSA-xg53-mhh9-3cq7.json create mode 100644 advisories/unreviewed/2025/05/GHSA-xmq3-c6r3-6cm9/GHSA-xmq3-c6r3-6cm9.json create mode 100644 advisories/unreviewed/2025/05/GHSA-xq83-m7pg-gg42/GHSA-xq83-m7pg-gg42.json create mode 100644 advisories/unreviewed/2025/05/GHSA-xw2w-jc5r-g6r7/GHSA-xw2w-jc5r-g6r7.json diff --git a/advisories/unreviewed/2022/05/GHSA-94xg-qm4r-9r7c/GHSA-94xg-qm4r-9r7c.json b/advisories/unreviewed/2022/05/GHSA-94xg-qm4r-9r7c/GHSA-94xg-qm4r-9r7c.json index eb08b037d48..f159a7a758b 100644 --- a/advisories/unreviewed/2022/05/GHSA-94xg-qm4r-9r7c/GHSA-94xg-qm4r-9r7c.json +++ b/advisories/unreviewed/2022/05/GHSA-94xg-qm4r-9r7c/GHSA-94xg-qm4r-9r7c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-94xg-qm4r-9r7c", - "modified": "2024-04-04T01:13:42Z", + "modified": "2025-05-21T18:32:58Z", "published": "2022-05-24T16:49:51Z", "aliases": [ "CVE-2017-12652" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2017-12652" }, + { + "type": "WEB", + "url": "https://github.com/pnggroup/libpng/commit/347538efbdc21b8df684ebd92d37400b3ce85d55" + }, { "type": "WEB", "url": "https://github.com/glennrp/libpng/blob/df7e9dae0c4aac63d55361e35709c864fa1b8363/ANNOUNCE" diff --git a/advisories/unreviewed/2022/09/GHSA-33cr-xf9m-fqqr/GHSA-33cr-xf9m-fqqr.json b/advisories/unreviewed/2022/09/GHSA-33cr-xf9m-fqqr/GHSA-33cr-xf9m-fqqr.json index de61908434d..17192f3f6f1 100644 --- a/advisories/unreviewed/2022/09/GHSA-33cr-xf9m-fqqr/GHSA-33cr-xf9m-fqqr.json +++ b/advisories/unreviewed/2022/09/GHSA-33cr-xf9m-fqqr/GHSA-33cr-xf9m-fqqr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-33cr-xf9m-fqqr", - "modified": "2022-09-29T00:00:22Z", + "modified": "2025-05-21T18:32:59Z", "published": "2022-09-27T00:00:20Z", "aliases": [ "CVE-2022-3198" diff --git a/advisories/unreviewed/2022/09/GHSA-343h-h5v5-82rq/GHSA-343h-h5v5-82rq.json b/advisories/unreviewed/2022/09/GHSA-343h-h5v5-82rq/GHSA-343h-h5v5-82rq.json index 350fc485b6c..b769ead6114 100644 --- a/advisories/unreviewed/2022/09/GHSA-343h-h5v5-82rq/GHSA-343h-h5v5-82rq.json +++ b/advisories/unreviewed/2022/09/GHSA-343h-h5v5-82rq/GHSA-343h-h5v5-82rq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-343h-h5v5-82rq", - "modified": "2022-09-29T00:00:22Z", + "modified": "2025-05-21T18:32:59Z", "published": "2022-09-27T00:00:20Z", "aliases": [ "CVE-2022-3057" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://crbug.com/1336904" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" @@ -38,6 +42,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-352", "CWE-863" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/09/GHSA-433m-5r62-794r/GHSA-433m-5r62-794r.json b/advisories/unreviewed/2022/09/GHSA-433m-5r62-794r/GHSA-433m-5r62-794r.json index 4a6af60b0b4..ea2ecb06c38 100644 --- a/advisories/unreviewed/2022/09/GHSA-433m-5r62-794r/GHSA-433m-5r62-794r.json +++ b/advisories/unreviewed/2022/09/GHSA-433m-5r62-794r/GHSA-433m-5r62-794r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-433m-5r62-794r", - "modified": "2022-09-29T00:00:26Z", + "modified": "2025-05-21T18:32:58Z", "published": "2022-09-27T00:00:19Z", "aliases": [ "CVE-2022-3050" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://crbug.com/1337132" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" diff --git a/advisories/unreviewed/2022/09/GHSA-4p6f-vmpg-88hm/GHSA-4p6f-vmpg-88hm.json b/advisories/unreviewed/2022/09/GHSA-4p6f-vmpg-88hm/GHSA-4p6f-vmpg-88hm.json index 8d44b38d3d2..fbb7fa2f43d 100644 --- a/advisories/unreviewed/2022/09/GHSA-4p6f-vmpg-88hm/GHSA-4p6f-vmpg-88hm.json +++ b/advisories/unreviewed/2022/09/GHSA-4p6f-vmpg-88hm/GHSA-4p6f-vmpg-88hm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4p6f-vmpg-88hm", - "modified": "2022-09-29T00:00:22Z", + "modified": "2025-05-21T18:33:00Z", "published": "2022-09-27T00:00:20Z", "aliases": [ "CVE-2022-3200" diff --git a/advisories/unreviewed/2022/09/GHSA-833h-m63r-586v/GHSA-833h-m63r-586v.json b/advisories/unreviewed/2022/09/GHSA-833h-m63r-586v/GHSA-833h-m63r-586v.json index 0c58bd91861..ebe8d41da93 100644 --- a/advisories/unreviewed/2022/09/GHSA-833h-m63r-586v/GHSA-833h-m63r-586v.json +++ b/advisories/unreviewed/2022/09/GHSA-833h-m63r-586v/GHSA-833h-m63r-586v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-833h-m63r-586v", - "modified": "2022-09-30T00:00:42Z", + "modified": "2025-05-21T18:33:04Z", "published": "2022-09-28T00:00:16Z", "aliases": [ "CVE-2022-3303" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2022/11/msg00001.html" }, + { + "type": "WEB", + "url": "https://lore.kernel.org/all/CAFcO6XN7JDM4xSXGhtusQfS2mSBcx50VJKwQpCq=WeLt57aaZA%40mail.gmail.com" + }, { "type": "WEB", "url": "https://lore.kernel.org/all/CAFcO6XN7JDM4xSXGhtusQfS2mSBcx50VJKwQpCq=WeLt57aaZA@mail.gmail.com" @@ -38,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-362" + "CWE-362", + "CWE-667" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/09/GHSA-8jfv-vfxw-8q23/GHSA-8jfv-vfxw-8q23.json b/advisories/unreviewed/2022/09/GHSA-8jfv-vfxw-8q23/GHSA-8jfv-vfxw-8q23.json index 8507437ab63..19295e554b9 100644 --- a/advisories/unreviewed/2022/09/GHSA-8jfv-vfxw-8q23/GHSA-8jfv-vfxw-8q23.json +++ b/advisories/unreviewed/2022/09/GHSA-8jfv-vfxw-8q23/GHSA-8jfv-vfxw-8q23.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8jfv-vfxw-8q23", - "modified": "2022-10-04T00:00:23Z", + "modified": "2025-05-21T18:32:58Z", "published": "2022-09-27T00:00:22Z", "aliases": [ "CVE-2022-36159" diff --git a/advisories/unreviewed/2022/09/GHSA-938g-35m6-qcp8/GHSA-938g-35m6-qcp8.json b/advisories/unreviewed/2022/09/GHSA-938g-35m6-qcp8/GHSA-938g-35m6-qcp8.json index bfc02c1ef76..07fac5e656c 100644 --- a/advisories/unreviewed/2022/09/GHSA-938g-35m6-qcp8/GHSA-938g-35m6-qcp8.json +++ b/advisories/unreviewed/2022/09/GHSA-938g-35m6-qcp8/GHSA-938g-35m6-qcp8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-938g-35m6-qcp8", - "modified": "2022-09-29T00:00:27Z", + "modified": "2025-05-21T18:32:58Z", "published": "2022-09-27T00:00:20Z", "aliases": [ "CVE-2022-3048" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://crbug.com/1303308" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" @@ -38,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-862" + "CWE-862", + "CWE-863" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/09/GHSA-f75q-r8vf-45pj/GHSA-f75q-r8vf-45pj.json b/advisories/unreviewed/2022/09/GHSA-f75q-r8vf-45pj/GHSA-f75q-r8vf-45pj.json index a4746b5b24e..d0be551e19c 100644 --- a/advisories/unreviewed/2022/09/GHSA-f75q-r8vf-45pj/GHSA-f75q-r8vf-45pj.json +++ b/advisories/unreviewed/2022/09/GHSA-f75q-r8vf-45pj/GHSA-f75q-r8vf-45pj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f75q-r8vf-45pj", - "modified": "2022-10-01T00:00:16Z", + "modified": "2025-05-21T18:33:03Z", "published": "2022-09-28T00:00:17Z", "aliases": [ "CVE-2022-34326" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-j3x6-vg5f-vx5p/GHSA-j3x6-vg5f-vx5p.json b/advisories/unreviewed/2022/09/GHSA-j3x6-vg5f-vx5p/GHSA-j3x6-vg5f-vx5p.json index c0e7686892a..22a66b0588c 100644 --- a/advisories/unreviewed/2022/09/GHSA-j3x6-vg5f-vx5p/GHSA-j3x6-vg5f-vx5p.json +++ b/advisories/unreviewed/2022/09/GHSA-j3x6-vg5f-vx5p/GHSA-j3x6-vg5f-vx5p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j3x6-vg5f-vx5p", - "modified": "2022-09-29T00:00:27Z", + "modified": "2025-05-21T18:32:58Z", "published": "2022-09-27T00:00:19Z", "aliases": [ "CVE-2022-3049" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://crbug.com/1316892" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" @@ -38,6 +42,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-362", "CWE-416" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/09/GHSA-m5cg-qjmp-pw59/GHSA-m5cg-qjmp-pw59.json b/advisories/unreviewed/2022/09/GHSA-m5cg-qjmp-pw59/GHSA-m5cg-qjmp-pw59.json index 515b6e51ef4..a203955cb68 100644 --- a/advisories/unreviewed/2022/09/GHSA-m5cg-qjmp-pw59/GHSA-m5cg-qjmp-pw59.json +++ b/advisories/unreviewed/2022/09/GHSA-m5cg-qjmp-pw59/GHSA-m5cg-qjmp-pw59.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m5cg-qjmp-pw59", - "modified": "2022-09-29T00:00:23Z", + "modified": "2025-05-21T18:32:58Z", "published": "2022-09-27T00:00:22Z", "aliases": [ "CVE-2022-38553" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://demo.creativeitem.com/academy/home" }, + { + "type": "WEB", + "url": "https://demo.creativeitem.com/academy/home/search?query=%22%3E%3Cscript%3Ealert%28%22XSS%22%29%3C/script%3E" + }, { "type": "WEB", "url": "https://demo.creativeitem.com/academy/home/search?query=%22%3E%3Cscript%3Ealert(%22XSS%22)%3C/script%3E" diff --git a/advisories/unreviewed/2022/09/GHSA-mrhr-c569-5wjh/GHSA-mrhr-c569-5wjh.json b/advisories/unreviewed/2022/09/GHSA-mrhr-c569-5wjh/GHSA-mrhr-c569-5wjh.json index 4f654c1dc11..2cae9231e09 100644 --- a/advisories/unreviewed/2022/09/GHSA-mrhr-c569-5wjh/GHSA-mrhr-c569-5wjh.json +++ b/advisories/unreviewed/2022/09/GHSA-mrhr-c569-5wjh/GHSA-mrhr-c569-5wjh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mrhr-c569-5wjh", - "modified": "2022-09-29T00:00:20Z", + "modified": "2025-05-21T18:32:58Z", "published": "2022-09-27T00:00:20Z", "aliases": [ "CVE-2022-3051" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://crbug.com/1345245" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" diff --git a/advisories/unreviewed/2022/09/GHSA-pfqr-532x-cjjm/GHSA-pfqr-532x-cjjm.json b/advisories/unreviewed/2022/09/GHSA-pfqr-532x-cjjm/GHSA-pfqr-532x-cjjm.json index ee854598b94..41629d2899f 100644 --- a/advisories/unreviewed/2022/09/GHSA-pfqr-532x-cjjm/GHSA-pfqr-532x-cjjm.json +++ b/advisories/unreviewed/2022/09/GHSA-pfqr-532x-cjjm/GHSA-pfqr-532x-cjjm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pfqr-532x-cjjm", - "modified": "2022-09-29T00:00:20Z", + "modified": "2025-05-21T18:32:59Z", "published": "2022-09-27T00:00:20Z", "aliases": [ "CVE-2022-3071" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://crbug.com/1333995" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" @@ -38,6 +42,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-362", "CWE-416" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/09/GHSA-q3pp-76rw-fqvm/GHSA-q3pp-76rw-fqvm.json b/advisories/unreviewed/2022/09/GHSA-q3pp-76rw-fqvm/GHSA-q3pp-76rw-fqvm.json index e716993324d..38480f91d5d 100644 --- a/advisories/unreviewed/2022/09/GHSA-q3pp-76rw-fqvm/GHSA-q3pp-76rw-fqvm.json +++ b/advisories/unreviewed/2022/09/GHSA-q3pp-76rw-fqvm/GHSA-q3pp-76rw-fqvm.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-r496-34w8-f379/GHSA-r496-34w8-f379.json b/advisories/unreviewed/2022/09/GHSA-r496-34w8-f379/GHSA-r496-34w8-f379.json index e61c70e9f8f..135f044a3c4 100644 --- a/advisories/unreviewed/2022/09/GHSA-r496-34w8-f379/GHSA-r496-34w8-f379.json +++ b/advisories/unreviewed/2022/09/GHSA-r496-34w8-f379/GHSA-r496-34w8-f379.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r496-34w8-f379", - "modified": "2022-09-29T00:00:23Z", + "modified": "2025-05-21T18:32:58Z", "published": "2022-09-27T00:00:20Z", "aliases": [ "CVE-2022-3056" @@ -27,6 +27,14 @@ "type": "WEB", "url": "https://crbug.com/1329460" }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/40059762" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" @@ -38,6 +46,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-693", "CWE-863" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/09/GHSA-rpc9-wm96-3rrj/GHSA-rpc9-wm96-3rrj.json b/advisories/unreviewed/2022/09/GHSA-rpc9-wm96-3rrj/GHSA-rpc9-wm96-3rrj.json index 8c1b26aa8d0..b99204c10ab 100644 --- a/advisories/unreviewed/2022/09/GHSA-rpc9-wm96-3rrj/GHSA-rpc9-wm96-3rrj.json +++ b/advisories/unreviewed/2022/09/GHSA-rpc9-wm96-3rrj/GHSA-rpc9-wm96-3rrj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rpc9-wm96-3rrj", - "modified": "2022-09-29T00:00:22Z", + "modified": "2025-05-21T18:32:59Z", "published": "2022-09-27T00:00:20Z", "aliases": [ "CVE-2022-3199" diff --git a/advisories/unreviewed/2022/09/GHSA-v748-qg3r-j62x/GHSA-v748-qg3r-j62x.json b/advisories/unreviewed/2022/09/GHSA-v748-qg3r-j62x/GHSA-v748-qg3r-j62x.json index 126649ca4be..89bd699521f 100644 --- a/advisories/unreviewed/2022/09/GHSA-v748-qg3r-j62x/GHSA-v748-qg3r-j62x.json +++ b/advisories/unreviewed/2022/09/GHSA-v748-qg3r-j62x/GHSA-v748-qg3r-j62x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v748-qg3r-j62x", - "modified": "2022-09-29T00:00:23Z", + "modified": "2025-05-21T18:32:59Z", "published": "2022-09-27T00:00:20Z", "aliases": [ "CVE-2022-3058" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://crbug.com/1337676" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" diff --git a/advisories/unreviewed/2022/09/GHSA-v8jg-p3fp-g968/GHSA-v8jg-p3fp-g968.json b/advisories/unreviewed/2022/09/GHSA-v8jg-p3fp-g968/GHSA-v8jg-p3fp-g968.json index 38b373e0ff6..ce8b7f5776e 100644 --- a/advisories/unreviewed/2022/09/GHSA-v8jg-p3fp-g968/GHSA-v8jg-p3fp-g968.json +++ b/advisories/unreviewed/2022/09/GHSA-v8jg-p3fp-g968/GHSA-v8jg-p3fp-g968.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v8jg-p3fp-g968", - "modified": "2022-10-04T00:00:20Z", + "modified": "2025-05-21T18:33:02Z", "published": "2022-09-28T00:00:18Z", "aliases": [ "CVE-2021-27853" diff --git a/advisories/unreviewed/2022/09/GHSA-w8pp-8gqf-chff/GHSA-w8pp-8gqf-chff.json b/advisories/unreviewed/2022/09/GHSA-w8pp-8gqf-chff/GHSA-w8pp-8gqf-chff.json index fd0f5ad80e3..a5ed4b92144 100644 --- a/advisories/unreviewed/2022/09/GHSA-w8pp-8gqf-chff/GHSA-w8pp-8gqf-chff.json +++ b/advisories/unreviewed/2022/09/GHSA-w8pp-8gqf-chff/GHSA-w8pp-8gqf-chff.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w8pp-8gqf-chff", - "modified": "2022-10-04T00:00:23Z", + "modified": "2025-05-21T18:32:58Z", "published": "2022-09-27T00:00:22Z", "aliases": [ "CVE-2022-36158" @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-425" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-wgj9-cwmq-97x8/GHSA-wgj9-cwmq-97x8.json b/advisories/unreviewed/2022/09/GHSA-wgj9-cwmq-97x8/GHSA-wgj9-cwmq-97x8.json index 95b5c3568c5..17253702f70 100644 --- a/advisories/unreviewed/2022/09/GHSA-wgj9-cwmq-97x8/GHSA-wgj9-cwmq-97x8.json +++ b/advisories/unreviewed/2022/09/GHSA-wgj9-cwmq-97x8/GHSA-wgj9-cwmq-97x8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wgj9-cwmq-97x8", - "modified": "2022-09-30T00:00:41Z", + "modified": "2025-05-21T18:32:58Z", "published": "2022-09-27T00:00:23Z", "aliases": [ "CVE-2022-38970" diff --git a/advisories/unreviewed/2025/02/GHSA-244c-33wx-j66j/GHSA-244c-33wx-j66j.json b/advisories/unreviewed/2025/02/GHSA-244c-33wx-j66j/GHSA-244c-33wx-j66j.json index 15c69d464c2..f6763dccef3 100644 --- a/advisories/unreviewed/2025/02/GHSA-244c-33wx-j66j/GHSA-244c-33wx-j66j.json +++ b/advisories/unreviewed/2025/02/GHSA-244c-33wx-j66j/GHSA-244c-33wx-j66j.json @@ -50,7 +50,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-404" + "CWE-404", + "CWE-476" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-7crf-mwwj-hvjp/GHSA-7crf-mwwj-hvjp.json b/advisories/unreviewed/2025/02/GHSA-7crf-mwwj-hvjp/GHSA-7crf-mwwj-hvjp.json index 1253ab4edcc..65dbd7bcc03 100644 --- a/advisories/unreviewed/2025/02/GHSA-7crf-mwwj-hvjp/GHSA-7crf-mwwj-hvjp.json +++ b/advisories/unreviewed/2025/02/GHSA-7crf-mwwj-hvjp/GHSA-7crf-mwwj-hvjp.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7crf-mwwj-hvjp", - "modified": "2025-02-27T21:32:16Z", + "modified": "2025-05-21T18:33:24Z", "published": "2025-02-27T21:32:16Z", "aliases": [ "CVE-2025-0767" ], "details": "WP Activity Log 5.3.2 was found to be vulnerable. Unvalidated user input is used directly in an unserialize function in myapp/classes/Writers/class-csv-writer.php.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2025/02/GHSA-c73j-8h5p-xxxr/GHSA-c73j-8h5p-xxxr.json b/advisories/unreviewed/2025/02/GHSA-c73j-8h5p-xxxr/GHSA-c73j-8h5p-xxxr.json index 75c0cfbb853..00f591aed05 100644 --- a/advisories/unreviewed/2025/02/GHSA-c73j-8h5p-xxxr/GHSA-c73j-8h5p-xxxr.json +++ b/advisories/unreviewed/2025/02/GHSA-c73j-8h5p-xxxr/GHSA-c73j-8h5p-xxxr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c73j-8h5p-xxxr", - "modified": "2025-02-17T12:30:31Z", + "modified": "2025-05-21T18:33:24Z", "published": "2025-02-17T12:30:31Z", "aliases": [ "CVE-2025-26771" diff --git a/advisories/unreviewed/2025/02/GHSA-cg43-3q5j-mwp7/GHSA-cg43-3q5j-mwp7.json b/advisories/unreviewed/2025/02/GHSA-cg43-3q5j-mwp7/GHSA-cg43-3q5j-mwp7.json index 482ba839778..2f2e9d2c31c 100644 --- a/advisories/unreviewed/2025/02/GHSA-cg43-3q5j-mwp7/GHSA-cg43-3q5j-mwp7.json +++ b/advisories/unreviewed/2025/02/GHSA-cg43-3q5j-mwp7/GHSA-cg43-3q5j-mwp7.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-290" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-x374-f9hj-5h8v/GHSA-x374-f9hj-5h8v.json b/advisories/unreviewed/2025/02/GHSA-x374-f9hj-5h8v/GHSA-x374-f9hj-5h8v.json index 12018022664..129567d250f 100644 --- a/advisories/unreviewed/2025/02/GHSA-x374-f9hj-5h8v/GHSA-x374-f9hj-5h8v.json +++ b/advisories/unreviewed/2025/02/GHSA-x374-f9hj-5h8v/GHSA-x374-f9hj-5h8v.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-3r92-3wmq-rmm2/GHSA-3r92-3wmq-rmm2.json b/advisories/unreviewed/2025/03/GHSA-3r92-3wmq-rmm2/GHSA-3r92-3wmq-rmm2.json index 940bc8d99e6..b8023578526 100644 --- a/advisories/unreviewed/2025/03/GHSA-3r92-3wmq-rmm2/GHSA-3r92-3wmq-rmm2.json +++ b/advisories/unreviewed/2025/03/GHSA-3r92-3wmq-rmm2/GHSA-3r92-3wmq-rmm2.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-6m97-f4vx-x87g/GHSA-6m97-f4vx-x87g.json b/advisories/unreviewed/2025/03/GHSA-6m97-f4vx-x87g/GHSA-6m97-f4vx-x87g.json index 05e18417f23..a2681f2a7c7 100644 --- a/advisories/unreviewed/2025/03/GHSA-6m97-f4vx-x87g/GHSA-6m97-f4vx-x87g.json +++ b/advisories/unreviewed/2025/03/GHSA-6m97-f4vx-x87g/GHSA-6m97-f4vx-x87g.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-9wv3-p38x-5wqv/GHSA-9wv3-p38x-5wqv.json b/advisories/unreviewed/2025/03/GHSA-9wv3-p38x-5wqv/GHSA-9wv3-p38x-5wqv.json index 7e23812ee92..f38c99b45f2 100644 --- a/advisories/unreviewed/2025/03/GHSA-9wv3-p38x-5wqv/GHSA-9wv3-p38x-5wqv.json +++ b/advisories/unreviewed/2025/03/GHSA-9wv3-p38x-5wqv/GHSA-9wv3-p38x-5wqv.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-hj6q-qv48-rgmf/GHSA-hj6q-qv48-rgmf.json b/advisories/unreviewed/2025/03/GHSA-hj6q-qv48-rgmf/GHSA-hj6q-qv48-rgmf.json index 9da8f5ad8a4..835c01b2726 100644 --- a/advisories/unreviewed/2025/03/GHSA-hj6q-qv48-rgmf/GHSA-hj6q-qv48-rgmf.json +++ b/advisories/unreviewed/2025/03/GHSA-hj6q-qv48-rgmf/GHSA-hj6q-qv48-rgmf.json @@ -50,7 +50,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-77" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-p2v5-rvqj-c2xc/GHSA-p2v5-rvqj-c2xc.json b/advisories/unreviewed/2025/03/GHSA-p2v5-rvqj-c2xc/GHSA-p2v5-rvqj-c2xc.json index 56ae26aa20f..93795ef2d57 100644 --- a/advisories/unreviewed/2025/03/GHSA-p2v5-rvqj-c2xc/GHSA-p2v5-rvqj-c2xc.json +++ b/advisories/unreviewed/2025/03/GHSA-p2v5-rvqj-c2xc/GHSA-p2v5-rvqj-c2xc.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-pw46-7qrx-4mc7/GHSA-pw46-7qrx-4mc7.json b/advisories/unreviewed/2025/03/GHSA-pw46-7qrx-4mc7/GHSA-pw46-7qrx-4mc7.json index 74059453363..f5f90d3feb7 100644 --- a/advisories/unreviewed/2025/03/GHSA-pw46-7qrx-4mc7/GHSA-pw46-7qrx-4mc7.json +++ b/advisories/unreviewed/2025/03/GHSA-pw46-7qrx-4mc7/GHSA-pw46-7qrx-4mc7.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-w27p-m7fr-3hpc/GHSA-w27p-m7fr-3hpc.json b/advisories/unreviewed/2025/03/GHSA-w27p-m7fr-3hpc/GHSA-w27p-m7fr-3hpc.json index 2d57e60d394..e560ae5b005 100644 --- a/advisories/unreviewed/2025/03/GHSA-w27p-m7fr-3hpc/GHSA-w27p-m7fr-3hpc.json +++ b/advisories/unreviewed/2025/03/GHSA-w27p-m7fr-3hpc/GHSA-w27p-m7fr-3hpc.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-233v-5pqm-q596/GHSA-233v-5pqm-q596.json b/advisories/unreviewed/2025/05/GHSA-233v-5pqm-q596/GHSA-233v-5pqm-q596.json new file mode 100644 index 00000000000..2c56e9425a0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-233v-5pqm-q596/GHSA-233v-5pqm-q596.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-233v-5pqm-q596", + "modified": "2025-05-21T18:33:31Z", + "published": "2025-05-21T18:33:31Z", + "aliases": [ + "CVE-2025-4416" + ], + "details": "Allocation of Resources Without Limits or Throttling vulnerability in Drupal Events Log Track allows Excessive Allocation.This issue affects Events Log Track: from 0.0.0 before 3.1.11, from 4.0.0 before 4.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4416" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-059" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T17:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-256j-g634-v955/GHSA-256j-g634-v955.json b/advisories/unreviewed/2025/05/GHSA-256j-g634-v955/GHSA-256j-g634-v955.json index 04ef08800fd..c5e7c3faf76 100644 --- a/advisories/unreviewed/2025/05/GHSA-256j-g634-v955/GHSA-256j-g634-v955.json +++ b/advisories/unreviewed/2025/05/GHSA-256j-g634-v955/GHSA-256j-g634-v955.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-25g9-6gwc-gv6w/GHSA-25g9-6gwc-gv6w.json b/advisories/unreviewed/2025/05/GHSA-25g9-6gwc-gv6w/GHSA-25g9-6gwc-gv6w.json new file mode 100644 index 00000000000..50ce07699e5 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-25g9-6gwc-gv6w/GHSA-25g9-6gwc-gv6w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-25g9-6gwc-gv6w", + "modified": "2025-05-21T18:33:31Z", + "published": "2025-05-21T18:33:31Z", + "aliases": [ + "CVE-2025-48011" + ], + "details": "Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal One Time Password allows Functionality Bypass.This issue affects One Time Password: from 0.0.0 before 1.3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48011" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-062" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T17:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2w4w-qvp3-4g7g/GHSA-2w4w-qvp3-4g7g.json b/advisories/unreviewed/2025/05/GHSA-2w4w-qvp3-4g7g/GHSA-2w4w-qvp3-4g7g.json index aa3a4dde208..5a5afd1442a 100644 --- a/advisories/unreviewed/2025/05/GHSA-2w4w-qvp3-4g7g/GHSA-2w4w-qvp3-4g7g.json +++ b/advisories/unreviewed/2025/05/GHSA-2w4w-qvp3-4g7g/GHSA-2w4w-qvp3-4g7g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2w4w-qvp3-4g7g", - "modified": "2025-05-21T15:30:33Z", + "modified": "2025-05-21T18:33:30Z", "published": "2025-05-21T15:30:33Z", "aliases": [ "CVE-2025-48415" ], "details": "A USB backdoor feature can be triggered by attaching a USB drive that contains specially crafted \"salia.ini\" files. The .ini file can contain several \"commands\" that could be exploited by an attacker to export or modify the device configuration, enable an SSH backdoor  or perform other administrative actions. Ultimately, this backdoor also allows arbitrary execution of OS commands.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-749" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-21T13:16:02Z" diff --git a/advisories/unreviewed/2025/05/GHSA-3c8c-p5w2-6pxx/GHSA-3c8c-p5w2-6pxx.json b/advisories/unreviewed/2025/05/GHSA-3c8c-p5w2-6pxx/GHSA-3c8c-p5w2-6pxx.json new file mode 100644 index 00000000000..5b60bb9e804 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3c8c-p5w2-6pxx/GHSA-3c8c-p5w2-6pxx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3c8c-p5w2-6pxx", + "modified": "2025-05-21T18:33:31Z", + "published": "2025-05-21T18:33:31Z", + "aliases": [ + "CVE-2025-20258" + ], + "details": "A vulnerability in the self-service portal of Cisco Duo could allow an unauthenticated, remote attacker to inject arbitrary commands into emails that are sent by the service.\n\n This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by injecting arbitrary commands into a portion of an email that is sent by the service. A successful exploit could allow the attacker to send emails that contain malicious content to unsuspecting users.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20258" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-duo-ssp-cmd-inj-RCmYrNA" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T17:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3gpm-vq72-xv9v/GHSA-3gpm-vq72-xv9v.json b/advisories/unreviewed/2025/05/GHSA-3gpm-vq72-xv9v/GHSA-3gpm-vq72-xv9v.json index 95a36f529dc..8596d47f326 100644 --- a/advisories/unreviewed/2025/05/GHSA-3gpm-vq72-xv9v/GHSA-3gpm-vq72-xv9v.json +++ b/advisories/unreviewed/2025/05/GHSA-3gpm-vq72-xv9v/GHSA-3gpm-vq72-xv9v.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-3h4g-vcc2-xxf3/GHSA-3h4g-vcc2-xxf3.json b/advisories/unreviewed/2025/05/GHSA-3h4g-vcc2-xxf3/GHSA-3h4g-vcc2-xxf3.json new file mode 100644 index 00000000000..19f276dde95 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3h4g-vcc2-xxf3/GHSA-3h4g-vcc2-xxf3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3h4g-vcc2-xxf3", + "modified": "2025-05-21T18:33:31Z", + "published": "2025-05-21T18:33:31Z", + "aliases": [ + "CVE-2025-20242" + ], + "details": "A vulnerability in the Cloud Connect component of Cisco Unified Contact Center Enterprise (CCE) could allow an unauthenticated, remote attacker to read and modify data on an affected device.\n\n This vulnerability is due to a lack of proper authentication controls. An attacker could exploit this vulnerability by sending crafted TCP data to a specific port on an affected device. A successful exploit could allow the attacker to read or modify data on the affected device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20242" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-contcent-insuffacces-ArDOVhN8" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T17:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-435v-q3pr-69h4/GHSA-435v-q3pr-69h4.json b/advisories/unreviewed/2025/05/GHSA-435v-q3pr-69h4/GHSA-435v-q3pr-69h4.json new file mode 100644 index 00000000000..b7b168cc6b6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-435v-q3pr-69h4/GHSA-435v-q3pr-69h4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-435v-q3pr-69h4", + "modified": "2025-05-21T18:33:31Z", + "published": "2025-05-21T18:33:31Z", + "aliases": [ + "CVE-2025-20113" + ], + "details": "A vulnerability in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to elevate privileges to Administrator for a limited set of functions on an affected system.\n\nThis vulnerability is due to insufficient server-side validation of user-supplied parameters in API or HTTP requests. An attacker could exploit this vulnerability by submitting a crafted API or HTTP request to an affected system. A successful exploit could allow the attacker to access, modify, or delete data beyond the sphere of their intended access level, including obtaining potentially sensitive information stored in the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20113" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cuis-priv-esc-3Pk96SU4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-602" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T17:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-463c-jhp2-4mm7/GHSA-463c-jhp2-4mm7.json b/advisories/unreviewed/2025/05/GHSA-463c-jhp2-4mm7/GHSA-463c-jhp2-4mm7.json new file mode 100644 index 00000000000..b236997e46b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-463c-jhp2-4mm7/GHSA-463c-jhp2-4mm7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-463c-jhp2-4mm7", + "modified": "2025-05-21T18:33:30Z", + "published": "2025-05-21T18:33:30Z", + "aliases": [ + "CVE-2025-48204" + ], + "details": "The ns_backup extension through 13.0.0 for TYPO3 allows command injection.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48204" + }, + { + "type": "WEB", + "url": "https://typo3.org/security/advisory/typo3-ext-sa-2025-007" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T16:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-472r-j47f-hrmv/GHSA-472r-j47f-hrmv.json b/advisories/unreviewed/2025/05/GHSA-472r-j47f-hrmv/GHSA-472r-j47f-hrmv.json new file mode 100644 index 00000000000..8fe6c9d528b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-472r-j47f-hrmv/GHSA-472r-j47f-hrmv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-472r-j47f-hrmv", + "modified": "2025-05-21T18:33:31Z", + "published": "2025-05-21T18:33:31Z", + "aliases": [ + "CVE-2025-2102" + ], + "details": "Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Passwordless on Windows allows Privilege Escalation.This issue affects HYPR Passwordless: before 10.1.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:A/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2102" + }, + { + "type": "WEB", + "url": "https://www.hypr.com/trust-center/security-advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T18:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4mmg-25h6-f798/GHSA-4mmg-25h6-f798.json b/advisories/unreviewed/2025/05/GHSA-4mmg-25h6-f798/GHSA-4mmg-25h6-f798.json index 08294d235f4..4cb67a75974 100644 --- a/advisories/unreviewed/2025/05/GHSA-4mmg-25h6-f798/GHSA-4mmg-25h6-f798.json +++ b/advisories/unreviewed/2025/05/GHSA-4mmg-25h6-f798/GHSA-4mmg-25h6-f798.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-57ff-cj28-pc38/GHSA-57ff-cj28-pc38.json b/advisories/unreviewed/2025/05/GHSA-57ff-cj28-pc38/GHSA-57ff-cj28-pc38.json index 85f773cca25..4a490e46fef 100644 --- a/advisories/unreviewed/2025/05/GHSA-57ff-cj28-pc38/GHSA-57ff-cj28-pc38.json +++ b/advisories/unreviewed/2025/05/GHSA-57ff-cj28-pc38/GHSA-57ff-cj28-pc38.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-58wr-734j-3p76/GHSA-58wr-734j-3p76.json b/advisories/unreviewed/2025/05/GHSA-58wr-734j-3p76/GHSA-58wr-734j-3p76.json new file mode 100644 index 00000000000..035b104c40c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-58wr-734j-3p76/GHSA-58wr-734j-3p76.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-58wr-734j-3p76", + "modified": "2025-05-21T18:33:31Z", + "published": "2025-05-21T18:33:31Z", + "aliases": [ + "CVE-2025-20246" + ], + "details": "A vulnerability in Cisco Webex could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack.\n\n A vulnerability is due to improper filtering of user-supplied input. An attacker could exploit this vulnerability by persuading a user to follow a malicious link. A successful exploit could allow the attacker to conduct a cross-site scripting attack against the targeted user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20246" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-xss-7teQtFn8" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T17:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5fvr-4vv2-228w/GHSA-5fvr-4vv2-228w.json b/advisories/unreviewed/2025/05/GHSA-5fvr-4vv2-228w/GHSA-5fvr-4vv2-228w.json new file mode 100644 index 00000000000..3a5cf661eb5 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5fvr-4vv2-228w/GHSA-5fvr-4vv2-228w.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5fvr-4vv2-228w", + "modified": "2025-05-21T18:33:32Z", + "published": "2025-05-21T18:33:32Z", + "aliases": [ + "CVE-2025-5033" + ], + "details": "A vulnerability classified as problematic was found in XiaoBingby TeaCMS 2.0.2. Affected by this vulnerability is an unknown functionality of the file src/main/java/me/teacms/controller/admin/UserManageController/addUser. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5033" + }, + { + "type": "WEB", + "url": "https://gitee.com/xiaobingby/TeaCMS/issues/IBYRPK" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309853" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309853" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.580729" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T18:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-69j7-c2h8-2cmf/GHSA-69j7-c2h8-2cmf.json b/advisories/unreviewed/2025/05/GHSA-69j7-c2h8-2cmf/GHSA-69j7-c2h8-2cmf.json new file mode 100644 index 00000000000..2abec70b097 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-69j7-c2h8-2cmf/GHSA-69j7-c2h8-2cmf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-69j7-c2h8-2cmf", + "modified": "2025-05-21T18:33:31Z", + "published": "2025-05-21T18:33:31Z", + "aliases": [ + "CVE-2025-20267" + ], + "details": "A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.\n\nThis vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have valid administrative credentials.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20267" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-stored-xss-Yff54m73" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-80" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T17:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6jfj-hxvq-rv4x/GHSA-6jfj-hxvq-rv4x.json b/advisories/unreviewed/2025/05/GHSA-6jfj-hxvq-rv4x/GHSA-6jfj-hxvq-rv4x.json new file mode 100644 index 00000000000..5bc8172365b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6jfj-hxvq-rv4x/GHSA-6jfj-hxvq-rv4x.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6jfj-hxvq-rv4x", + "modified": "2025-05-21T18:33:31Z", + "published": "2025-05-21T18:33:31Z", + "aliases": [ + "CVE-2025-5032" + ], + "details": "A vulnerability classified as critical has been found in Campcodes Online Shopping Portal 1.0. Affected is an unknown function of the file /admin/edit-category.php. The manipulation of the argument Category leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5032" + }, + { + "type": "WEB", + "url": "https://github.com/xiaoyuxiaoyuqwq/cve/issues/1" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309852" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309852" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.580601" + }, + { + "type": "WEB", + "url": "https://www.campcodes.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T17:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6wpw-9mr8-qhv3/GHSA-6wpw-9mr8-qhv3.json b/advisories/unreviewed/2025/05/GHSA-6wpw-9mr8-qhv3/GHSA-6wpw-9mr8-qhv3.json index 2d05fb46c69..4c0594ed29a 100644 --- a/advisories/unreviewed/2025/05/GHSA-6wpw-9mr8-qhv3/GHSA-6wpw-9mr8-qhv3.json +++ b/advisories/unreviewed/2025/05/GHSA-6wpw-9mr8-qhv3/GHSA-6wpw-9mr8-qhv3.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-7f35-3w2m-gw5h/GHSA-7f35-3w2m-gw5h.json b/advisories/unreviewed/2025/05/GHSA-7f35-3w2m-gw5h/GHSA-7f35-3w2m-gw5h.json index 8ae47704c71..ffb3c946f10 100644 --- a/advisories/unreviewed/2025/05/GHSA-7f35-3w2m-gw5h/GHSA-7f35-3w2m-gw5h.json +++ b/advisories/unreviewed/2025/05/GHSA-7f35-3w2m-gw5h/GHSA-7f35-3w2m-gw5h.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-7mfw-wgr7-m3jg/GHSA-7mfw-wgr7-m3jg.json b/advisories/unreviewed/2025/05/GHSA-7mfw-wgr7-m3jg/GHSA-7mfw-wgr7-m3jg.json new file mode 100644 index 00000000000..ae5a89fb75c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7mfw-wgr7-m3jg/GHSA-7mfw-wgr7-m3jg.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7mfw-wgr7-m3jg", + "modified": "2025-05-21T18:33:32Z", + "published": "2025-05-21T18:33:32Z", + "aliases": [ + "CVE-2025-5020" + ], + "details": "Opening maliciously-crafted URLs in Firefox from other apps such as Safari could have allowed attackers to spoof website addresses if the URLs utilized non-HTTP schemes used internally by the Firefox iOS client This vulnerability affects Firefox for iOS < 139.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5020" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1951558" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-39" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T18:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7v5f-m633-5wg2/GHSA-7v5f-m633-5wg2.json b/advisories/unreviewed/2025/05/GHSA-7v5f-m633-5wg2/GHSA-7v5f-m633-5wg2.json new file mode 100644 index 00000000000..57a64f5f9af --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7v5f-m633-5wg2/GHSA-7v5f-m633-5wg2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7v5f-m633-5wg2", + "modified": "2025-05-21T18:33:29Z", + "published": "2025-05-21T18:33:29Z", + "aliases": [ + "CVE-2025-48414" + ], + "details": "There are several scripts in the web interface that are accessible via undocumented hard-coded credentials. The scripts provide access to additional administrative/debug functionality and are likely intended for debugging during development and provides an additional attack surface.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48414" + }, + { + "type": "WEB", + "url": "https://r.sec-consult.com/echarge" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-798" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T12:16:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-88w2-frvv-mx6x/GHSA-88w2-frvv-mx6x.json b/advisories/unreviewed/2025/05/GHSA-88w2-frvv-mx6x/GHSA-88w2-frvv-mx6x.json new file mode 100644 index 00000000000..b23d69a458b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-88w2-frvv-mx6x/GHSA-88w2-frvv-mx6x.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-88w2-frvv-mx6x", + "modified": "2025-05-21T18:33:31Z", + "published": "2025-05-21T18:33:31Z", + "aliases": [ + "CVE-2025-25539" + ], + "details": "Local File Inclusion vulnerability in Vasco v3.14and before allows a remote attacker to obtain sensitive information via help menu.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25539" + }, + { + "type": "WEB", + "url": "https://drive.google.com/drive/folders/1Va0QP5TtsRprk-pXL3bUfCwTSjYbqnLK?usp=sharing" + }, + { + "type": "WEB", + "url": "https://gist.github.com/sornram9254/15eb12579b7acda8ba021217366960bd" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T17:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9mgg-ww23-jfhc/GHSA-9mgg-ww23-jfhc.json b/advisories/unreviewed/2025/05/GHSA-9mgg-ww23-jfhc/GHSA-9mgg-ww23-jfhc.json new file mode 100644 index 00000000000..0a5b601120a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9mgg-ww23-jfhc/GHSA-9mgg-ww23-jfhc.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9mgg-ww23-jfhc", + "modified": "2025-05-21T18:33:30Z", + "published": "2025-05-21T18:33:30Z", + "aliases": [ + "CVE-2025-27997" + ], + "details": "An issue in Blizzard Battle.net v2.40.0.15267 allows attackers to escalate privileges via placing a crafted shell script or executable into the C:\\ProgramData directory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27997" + }, + { + "type": "WEB", + "url": "https://gist.github.com/sornram9254/4593dd5eb2bcca50d68dc6ac70e40b24" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T16:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9qq5-w3c8-q244/GHSA-9qq5-w3c8-q244.json b/advisories/unreviewed/2025/05/GHSA-9qq5-w3c8-q244/GHSA-9qq5-w3c8-q244.json index 8c4de770e4c..6945f8518bf 100644 --- a/advisories/unreviewed/2025/05/GHSA-9qq5-w3c8-q244/GHSA-9qq5-w3c8-q244.json +++ b/advisories/unreviewed/2025/05/GHSA-9qq5-w3c8-q244/GHSA-9qq5-w3c8-q244.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-9r82-ff34-6w3x/GHSA-9r82-ff34-6w3x.json b/advisories/unreviewed/2025/05/GHSA-9r82-ff34-6w3x/GHSA-9r82-ff34-6w3x.json new file mode 100644 index 00000000000..a67ffd65a3a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9r82-ff34-6w3x/GHSA-9r82-ff34-6w3x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9r82-ff34-6w3x", + "modified": "2025-05-21T18:33:31Z", + "published": "2025-05-21T18:33:31Z", + "aliases": [ + "CVE-2025-20114" + ], + "details": "A vulnerability in the API of Cisco Unified Intelligence Center could allow an authenticated, remote attacker to perform a horizontal privilege escalation attack on an affected system.\n\nThis vulnerability is due to insufficient validation of user-supplied parameters in API requests. An attacker could exploit this vulnerability by submitting crafted API requests to an affected system to execute an insecure direct object reference attack. A successful exploit could allow the attacker to access specific data that is associated with different users on the affected system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20114" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cuis-priv-esc-3Pk96SU4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T17:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c2rm-m5xr-92gg/GHSA-c2rm-m5xr-92gg.json b/advisories/unreviewed/2025/05/GHSA-c2rm-m5xr-92gg/GHSA-c2rm-m5xr-92gg.json index 433617a4050..c2925d8b12d 100644 --- a/advisories/unreviewed/2025/05/GHSA-c2rm-m5xr-92gg/GHSA-c2rm-m5xr-92gg.json +++ b/advisories/unreviewed/2025/05/GHSA-c2rm-m5xr-92gg/GHSA-c2rm-m5xr-92gg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c2rm-m5xr-92gg", - "modified": "2025-05-21T15:30:34Z", + "modified": "2025-05-21T18:33:30Z", "published": "2025-05-21T15:30:34Z", "aliases": [ "CVE-2024-42922" ], "details": "AAPanel v7.0.7 was discovered to contain an OS command injection vulnerability.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-21T14:15:26Z" diff --git a/advisories/unreviewed/2025/05/GHSA-cmvj-3pj4-hrr7/GHSA-cmvj-3pj4-hrr7.json b/advisories/unreviewed/2025/05/GHSA-cmvj-3pj4-hrr7/GHSA-cmvj-3pj4-hrr7.json new file mode 100644 index 00000000000..78a0d99bce3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-cmvj-3pj4-hrr7/GHSA-cmvj-3pj4-hrr7.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cmvj-3pj4-hrr7", + "modified": "2025-05-21T18:33:30Z", + "published": "2025-05-21T18:33:30Z", + "aliases": [ + "CVE-2025-27998" + ], + "details": "An issue in Valvesoftware Steam Client Steam Client 1738026274 allows attackers to escalate privileges via a crafted executable or DLL.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27998" + }, + { + "type": "WEB", + "url": "https://gist.github.com/sornram9254/e8d10efcf246cc50ff3d4f837b261616" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T16:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-cvgc-mx2w-h3w8/GHSA-cvgc-mx2w-h3w8.json b/advisories/unreviewed/2025/05/GHSA-cvgc-mx2w-h3w8/GHSA-cvgc-mx2w-h3w8.json new file mode 100644 index 00000000000..0bff7c893c5 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-cvgc-mx2w-h3w8/GHSA-cvgc-mx2w-h3w8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cvgc-mx2w-h3w8", + "modified": "2025-05-21T18:33:30Z", + "published": "2025-05-21T18:33:30Z", + "aliases": [ + "CVE-2025-48205" + ], + "details": "The sr_feuser_register extension through 12.4.8 for TYPO3 allows Insecure Direct Object Reference.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48205" + }, + { + "type": "WEB", + "url": "https://typo3.org/security/advisory/typo3-ext-sa-2025-008" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-425" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T16:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fhgm-mxgh-gfpj/GHSA-fhgm-mxgh-gfpj.json b/advisories/unreviewed/2025/05/GHSA-fhgm-mxgh-gfpj/GHSA-fhgm-mxgh-gfpj.json index 03d71214201..2aa4faf879c 100644 --- a/advisories/unreviewed/2025/05/GHSA-fhgm-mxgh-gfpj/GHSA-fhgm-mxgh-gfpj.json +++ b/advisories/unreviewed/2025/05/GHSA-fhgm-mxgh-gfpj/GHSA-fhgm-mxgh-gfpj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fhgm-mxgh-gfpj", - "modified": "2025-05-19T21:30:31Z", + "modified": "2025-05-21T18:33:26Z", "published": "2025-05-18T00:30:27Z", "aliases": [ "CVE-2025-4918" @@ -34,6 +34,14 @@ { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2025-38" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/cve-2025-4918-detect-firefox-out-of-bounds-write" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/cve-2025-4918-mitigate-firefox-out-of-bounds-write" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/05/GHSA-fhm3-85qw-2fgx/GHSA-fhm3-85qw-2fgx.json b/advisories/unreviewed/2025/05/GHSA-fhm3-85qw-2fgx/GHSA-fhm3-85qw-2fgx.json new file mode 100644 index 00000000000..360e1276e99 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fhm3-85qw-2fgx/GHSA-fhm3-85qw-2fgx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fhm3-85qw-2fgx", + "modified": "2025-05-21T18:33:31Z", + "published": "2025-05-21T18:33:31Z", + "aliases": [ + "CVE-2025-4415" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Piwik PRO allows Cross-Site Scripting (XSS).This issue affects Piwik PRO: from 0.0.0 before 1.3.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4415" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-058" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T17:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fj3h-m99f-v4q3/GHSA-fj3h-m99f-v4q3.json b/advisories/unreviewed/2025/05/GHSA-fj3h-m99f-v4q3/GHSA-fj3h-m99f-v4q3.json new file mode 100644 index 00000000000..8f4c080f3b1 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fj3h-m99f-v4q3/GHSA-fj3h-m99f-v4q3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fj3h-m99f-v4q3", + "modified": "2025-05-21T18:33:31Z", + "published": "2025-05-21T18:33:31Z", + "aliases": [ + "CVE-2025-48010" + ], + "details": "Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal One Time Password allows Functionality Bypass.This issue affects One Time Password: from 0.0.0 before 1.3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48010" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-061" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T17:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g2xr-q6h2-7768/GHSA-g2xr-q6h2-7768.json b/advisories/unreviewed/2025/05/GHSA-g2xr-q6h2-7768/GHSA-g2xr-q6h2-7768.json new file mode 100644 index 00000000000..94dd03fedbe --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g2xr-q6h2-7768/GHSA-g2xr-q6h2-7768.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g2xr-q6h2-7768", + "modified": "2025-05-21T18:33:30Z", + "published": "2025-05-21T18:33:30Z", + "aliases": [ + "CVE-2025-0372" + ], + "details": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in HYPR Passwordless on Windows allows Privilege Escalation.This issue affects HYPR Passwordless: before 10.1.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0372" + }, + { + "type": "WEB", + "url": "https://www.hypr.com/trust-center/security-advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T17:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g6hf-3766-f3gv/GHSA-g6hf-3766-f3gv.json b/advisories/unreviewed/2025/05/GHSA-g6hf-3766-f3gv/GHSA-g6hf-3766-f3gv.json new file mode 100644 index 00000000000..16eb2a6960e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g6hf-3766-f3gv/GHSA-g6hf-3766-f3gv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g6hf-3766-f3gv", + "modified": "2025-05-21T18:33:31Z", + "published": "2025-05-21T18:33:31Z", + "aliases": [ + "CVE-2025-20257" + ], + "details": "A vulnerability in an API subsystem of Cisco Secure Network Analytics Manager and Cisco Secure Network Analytics Virtual Manager could allow an authenticated, remote attacker with low privileges to generate fraudulent findings that are used to generate alarms and alerts on an affected product.\n\nThi vulnerability is due to insufficient authorization enforcement on a specific API. An attacker could exploit this vulnerability by authenticating as a low-privileged user and performing API calls with crafted input. A successful exploit could allow the attacker to obfuscate legitimate findings in analytics reports or create false indications with alarms and alerts on an affected device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20257" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sna-apiacv-4B6X5ysw" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T17:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g7h8-28jj-qxmf/GHSA-g7h8-28jj-qxmf.json b/advisories/unreviewed/2025/05/GHSA-g7h8-28jj-qxmf/GHSA-g7h8-28jj-qxmf.json new file mode 100644 index 00000000000..ac51197f616 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g7h8-28jj-qxmf/GHSA-g7h8-28jj-qxmf.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g7h8-28jj-qxmf", + "modified": "2025-05-21T18:33:30Z", + "published": "2025-05-21T18:33:30Z", + "aliases": [ + "CVE-2025-4008" + ], + "details": "The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge system through a web application written in CGI shell scripts and C.\n\nThis web interface exposes an endpoint that is vulnerable to command injection.\n\nRemote unauthenticated attackers can gain arbitrary command execution with elevated privileges ( root ) on affected devices.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4008" + }, + { + "type": "WEB", + "url": "https://forum.meteohub.de/viewtopic.php?t=18687" + }, + { + "type": "WEB", + "url": "https://www.onekey.com/resource/security-advisory-remote-command-execution-on-smartbedded-meteobridge-cve-2025-4008" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T16:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h5wh-vhj4-rr58/GHSA-h5wh-vhj4-rr58.json b/advisories/unreviewed/2025/05/GHSA-h5wh-vhj4-rr58/GHSA-h5wh-vhj4-rr58.json new file mode 100644 index 00000000000..c9393f26a61 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h5wh-vhj4-rr58/GHSA-h5wh-vhj4-rr58.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h5wh-vhj4-rr58", + "modified": "2025-05-21T18:33:31Z", + "published": "2025-05-21T18:33:31Z", + "aliases": [ + "CVE-2025-20247" + ], + "details": "A vulnerability in Cisco Webex could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack.\n\n A vulnerability is due to improper filtering of user-supplied input. An attacker could exploit this vulnerability by persuading a user to follow a malicious link. A successful exploit could allow the attacker to conduct a cross-site scripting attack against the targeted user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20247" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-xss-7teQtFn8" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T17:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-j2vv-r926-8gq3/GHSA-j2vv-r926-8gq3.json b/advisories/unreviewed/2025/05/GHSA-j2vv-r926-8gq3/GHSA-j2vv-r926-8gq3.json new file mode 100644 index 00000000000..b96dc8cc5d4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-j2vv-r926-8gq3/GHSA-j2vv-r926-8gq3.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j2vv-r926-8gq3", + "modified": "2025-05-21T18:33:30Z", + "published": "2025-05-21T18:33:30Z", + "aliases": [ + "CVE-2024-56428" + ], + "details": "The local iLabClient database in itech iLabClient 3.7.1 allows local attackers to read cleartext credentials (from the CONFIGS table) for their servers configured in the client.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56428" + }, + { + "type": "WEB", + "url": "https://github.com/lisa-2905/CVE-2024-56428" + }, + { + "type": "WEB", + "url": "https://itech-gmbh.de/#ueber-itech" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T17:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jrwq-36rx-842c/GHSA-jrwq-36rx-842c.json b/advisories/unreviewed/2025/05/GHSA-jrwq-36rx-842c/GHSA-jrwq-36rx-842c.json new file mode 100644 index 00000000000..2b002db077c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jrwq-36rx-842c/GHSA-jrwq-36rx-842c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jrwq-36rx-842c", + "modified": "2025-05-21T18:33:31Z", + "published": "2025-05-21T18:33:31Z", + "aliases": [ + "CVE-2025-20255" + ], + "details": "A vulnerability in client join services of Cisco Webex Meetings could allow an unauthenticated, remote attacker to manipulate cached HTTP responses within the meeting join service.\n\n This vulnerability is due to improper handling of malicious HTTP requests to the affected service. An attacker could exploit this vulnerability by manipulating stored HTTP responses within the service, also known as HTTP cache poisoning. A successful exploit could allow the attacker to cause the Webex Meetings service to return incorrect HTTP responses to clients.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20255" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-cache-Q4xbkQBG" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-349" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T17:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-m526-j28f-j8qx/GHSA-m526-j28f-j8qx.json b/advisories/unreviewed/2025/05/GHSA-m526-j28f-j8qx/GHSA-m526-j28f-j8qx.json new file mode 100644 index 00000000000..f02dc2aaf0c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-m526-j28f-j8qx/GHSA-m526-j28f-j8qx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m526-j28f-j8qx", + "modified": "2025-05-21T18:33:31Z", + "published": "2025-05-21T18:33:31Z", + "aliases": [ + "CVE-2025-20250" + ], + "details": "A vulnerability in Cisco Webex could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack.\n\n A vulnerability is due to improper filtering of user-supplied input. An attacker could exploit this vulnerability by persuading a user to follow a malicious link. A successful exploit could allow the attacker to conduct a cross-site scripting attack against the targeted user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20250" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-xss-7teQtFn8" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T17:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-m9wr-pvw8-mgmm/GHSA-m9wr-pvw8-mgmm.json b/advisories/unreviewed/2025/05/GHSA-m9wr-pvw8-mgmm/GHSA-m9wr-pvw8-mgmm.json new file mode 100644 index 00000000000..0cb06012c2d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-m9wr-pvw8-mgmm/GHSA-m9wr-pvw8-mgmm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m9wr-pvw8-mgmm", + "modified": "2025-05-21T18:33:31Z", + "published": "2025-05-21T18:33:31Z", + "aliases": [ + "CVE-2025-48012" + ], + "details": "Authentication Bypass by Capture-replay vulnerability in Drupal One Time Password allows Remote Services with Stolen Credentials.This issue affects One Time Password: from 0.0.0 before 1.3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48012" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-063" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-294" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T17:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-pjw9-wpcr-r3vj/GHSA-pjw9-wpcr-r3vj.json b/advisories/unreviewed/2025/05/GHSA-pjw9-wpcr-r3vj/GHSA-pjw9-wpcr-r3vj.json index 238c39309d4..3e59aca6651 100644 --- a/advisories/unreviewed/2025/05/GHSA-pjw9-wpcr-r3vj/GHSA-pjw9-wpcr-r3vj.json +++ b/advisories/unreviewed/2025/05/GHSA-pjw9-wpcr-r3vj/GHSA-pjw9-wpcr-r3vj.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-pmc7-hgjr-qwv3/GHSA-pmc7-hgjr-qwv3.json b/advisories/unreviewed/2025/05/GHSA-pmc7-hgjr-qwv3/GHSA-pmc7-hgjr-qwv3.json new file mode 100644 index 00000000000..d11317430ca --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pmc7-hgjr-qwv3/GHSA-pmc7-hgjr-qwv3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pmc7-hgjr-qwv3", + "modified": "2025-05-21T18:33:31Z", + "published": "2025-05-21T18:33:31Z", + "aliases": [ + "CVE-2025-20152" + ], + "details": "A vulnerability in the RADIUS message processing feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.\n\nThis vulnerability is due to improper handling of certain RADIUS requests. An attacker could exploit this vulnerability by sending a specific authentication request to a network access device (NAD) that uses Cisco ISE for authentication, authorization, and accounting (AAA). A successful exploit could allow the attacker to cause Cisco ISE to reload.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20152" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-restart-ss-uf986G2Q" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T17:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-pqqp-7cp8-vxvf/GHSA-pqqp-7cp8-vxvf.json b/advisories/unreviewed/2025/05/GHSA-pqqp-7cp8-vxvf/GHSA-pqqp-7cp8-vxvf.json new file mode 100644 index 00000000000..16f21e29158 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pqqp-7cp8-vxvf/GHSA-pqqp-7cp8-vxvf.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pqqp-7cp8-vxvf", + "modified": "2025-05-21T18:33:32Z", + "published": "2025-05-21T18:33:31Z", + "aliases": [ + "CVE-2025-5031" + ], + "details": "A vulnerability was found in Ackites KillWxapkg up to 2.4.1. It has been rated as problematic. This issue affects some unknown processing of the component wxapkg File Decompression Handler. The manipulation leads to resource consumption. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5031" + }, + { + "type": "WEB", + "url": "https://github.com/Ackites/KillWxapkg/issues/86" + }, + { + "type": "WEB", + "url": "https://github.com/Ackites/KillWxapkg/issues/86#issue-3053628148" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309851" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309851" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.580524" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T17:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qc9j-84j3-74vm/GHSA-qc9j-84j3-74vm.json b/advisories/unreviewed/2025/05/GHSA-qc9j-84j3-74vm/GHSA-qc9j-84j3-74vm.json index fdeb8d17fc5..2e05984c403 100644 --- a/advisories/unreviewed/2025/05/GHSA-qc9j-84j3-74vm/GHSA-qc9j-84j3-74vm.json +++ b/advisories/unreviewed/2025/05/GHSA-qc9j-84j3-74vm/GHSA-qc9j-84j3-74vm.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-qmj3-7hgm-pxgp/GHSA-qmj3-7hgm-pxgp.json b/advisories/unreviewed/2025/05/GHSA-qmj3-7hgm-pxgp/GHSA-qmj3-7hgm-pxgp.json index 2fb937fadcd..60945031738 100644 --- a/advisories/unreviewed/2025/05/GHSA-qmj3-7hgm-pxgp/GHSA-qmj3-7hgm-pxgp.json +++ b/advisories/unreviewed/2025/05/GHSA-qmj3-7hgm-pxgp/GHSA-qmj3-7hgm-pxgp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qmj3-7hgm-pxgp", - "modified": "2025-05-21T15:30:34Z", + "modified": "2025-05-21T18:33:30Z", "published": "2025-05-21T15:30:34Z", "aliases": [ "CVE-2025-44895" ], "details": "FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ipv4Aclkey parameter in the web_acl_ipv4BasedAceAdd function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-21T14:15:30Z" diff --git a/advisories/unreviewed/2025/05/GHSA-rgg6-wh38-9vv5/GHSA-rgg6-wh38-9vv5.json b/advisories/unreviewed/2025/05/GHSA-rgg6-wh38-9vv5/GHSA-rgg6-wh38-9vv5.json index 9706d5fd619..08f14e799a3 100644 --- a/advisories/unreviewed/2025/05/GHSA-rgg6-wh38-9vv5/GHSA-rgg6-wh38-9vv5.json +++ b/advisories/unreviewed/2025/05/GHSA-rgg6-wh38-9vv5/GHSA-rgg6-wh38-9vv5.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-rxf3-624f-c767/GHSA-rxf3-624f-c767.json b/advisories/unreviewed/2025/05/GHSA-rxf3-624f-c767/GHSA-rxf3-624f-c767.json new file mode 100644 index 00000000000..f2f40794a2d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rxf3-624f-c767/GHSA-rxf3-624f-c767.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rxf3-624f-c767", + "modified": "2025-05-21T18:33:31Z", + "published": "2025-05-21T18:33:31Z", + "aliases": [ + "CVE-2025-48009" + ], + "details": "Missing Authorization vulnerability in Drupal Single Content Sync allows Functionality Misuse.This issue affects Single Content Sync: from 0.0.0 before 1.4.12.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48009" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-060" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T17:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v5fv-w3r3-cxrv/GHSA-v5fv-w3r3-cxrv.json b/advisories/unreviewed/2025/05/GHSA-v5fv-w3r3-cxrv/GHSA-v5fv-w3r3-cxrv.json new file mode 100644 index 00000000000..81005180601 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v5fv-w3r3-cxrv/GHSA-v5fv-w3r3-cxrv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v5fv-w3r3-cxrv", + "modified": "2025-05-21T18:33:29Z", + "published": "2025-05-21T18:33:29Z", + "aliases": [ + "CVE-2025-27803" + ], + "details": "The devices do not implement any authentication for the web interface or the MQTT server. An attacker who has network access to the device immediately gets administrative access to the devices and can perform arbitrary administrative actions and reconfigure the devices or potentially gain access to sensitive data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27803" + }, + { + "type": "WEB", + "url": "https://r.sec-consult.com/echarge" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T12:16:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w5x3-j5vg-94wj/GHSA-w5x3-j5vg-94wj.json b/advisories/unreviewed/2025/05/GHSA-w5x3-j5vg-94wj/GHSA-w5x3-j5vg-94wj.json index 609cfcf34f1..99f77f41d8b 100644 --- a/advisories/unreviewed/2025/05/GHSA-w5x3-j5vg-94wj/GHSA-w5x3-j5vg-94wj.json +++ b/advisories/unreviewed/2025/05/GHSA-w5x3-j5vg-94wj/GHSA-w5x3-j5vg-94wj.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-w687-qrqx-jr57/GHSA-w687-qrqx-jr57.json b/advisories/unreviewed/2025/05/GHSA-w687-qrqx-jr57/GHSA-w687-qrqx-jr57.json new file mode 100644 index 00000000000..5f2e36e9b3a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w687-qrqx-jr57/GHSA-w687-qrqx-jr57.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w687-qrqx-jr57", + "modified": "2025-05-21T18:33:31Z", + "published": "2025-05-21T18:33:31Z", + "aliases": [ + "CVE-2025-20256" + ], + "details": "A vulnerability in the web-based management interface of Cisco Secure Network Analytics Manager and Cisco Secure Network Analytics Virtual Manager could allow an authenticated, remote attacker with valid administrative credentials to execute arbitrary commands as root on the underlying operating system.\n\nThis vulnerability is due to insufficient input validation in specific fields of the web-based management interface. An attacker with valid administrative credentials could exploit this vulnerability by sending crafted input to an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20256" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sna-ssti-dPuLqSmZ" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T17:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w6p4-84vc-qc2w/GHSA-w6p4-84vc-qc2w.json b/advisories/unreviewed/2025/05/GHSA-w6p4-84vc-qc2w/GHSA-w6p4-84vc-qc2w.json new file mode 100644 index 00000000000..6a91b4395a3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w6p4-84vc-qc2w/GHSA-w6p4-84vc-qc2w.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w6p4-84vc-qc2w", + "modified": "2025-05-21T18:33:31Z", + "published": "2025-05-21T18:33:31Z", + "aliases": [ + "CVE-2025-5030" + ], + "details": "A vulnerability was found in Ackites KillWxapkg up to 2.4.1. It has been declared as critical. This vulnerability affects the function processFile of the file internal/unpack/unpack.go of the component wxapkg File Parser. The manipulation leads to os command injection. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5030" + }, + { + "type": "WEB", + "url": "https://github.com/Ackites/KillWxapkg/issues/85" + }, + { + "type": "WEB", + "url": "https://github.com/Ackites/KillWxapkg/issues/85#issue-3052039180" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309850" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309850" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.580526" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T17:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wwq7-vmjh-7v57/GHSA-wwq7-vmjh-7v57.json b/advisories/unreviewed/2025/05/GHSA-wwq7-vmjh-7v57/GHSA-wwq7-vmjh-7v57.json index a9cfc6b6973..2245301fc16 100644 --- a/advisories/unreviewed/2025/05/GHSA-wwq7-vmjh-7v57/GHSA-wwq7-vmjh-7v57.json +++ b/advisories/unreviewed/2025/05/GHSA-wwq7-vmjh-7v57/GHSA-wwq7-vmjh-7v57.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-xg53-mhh9-3cq7/GHSA-xg53-mhh9-3cq7.json b/advisories/unreviewed/2025/05/GHSA-xg53-mhh9-3cq7/GHSA-xg53-mhh9-3cq7.json new file mode 100644 index 00000000000..aa0b06315fe --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xg53-mhh9-3cq7/GHSA-xg53-mhh9-3cq7.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xg53-mhh9-3cq7", + "modified": "2025-05-21T18:33:30Z", + "published": "2025-05-21T18:33:30Z", + "aliases": [ + "CVE-2025-48206" + ], + "details": "The ns_backup extension through 13.0.0 for TYPO3 allows XSS.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48206" + }, + { + "type": "WEB", + "url": "https://typo3.org/security/advisory/typo3-ext-sa-2025-007" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T16:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xgmm-9xmm-8qv5/GHSA-xgmm-9xmm-8qv5.json b/advisories/unreviewed/2025/05/GHSA-xgmm-9xmm-8qv5/GHSA-xgmm-9xmm-8qv5.json index 45f7c46d0f1..02d1ed5b7f6 100644 --- a/advisories/unreviewed/2025/05/GHSA-xgmm-9xmm-8qv5/GHSA-xgmm-9xmm-8qv5.json +++ b/advisories/unreviewed/2025/05/GHSA-xgmm-9xmm-8qv5/GHSA-xgmm-9xmm-8qv5.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-xmq3-c6r3-6cm9/GHSA-xmq3-c6r3-6cm9.json b/advisories/unreviewed/2025/05/GHSA-xmq3-c6r3-6cm9/GHSA-xmq3-c6r3-6cm9.json new file mode 100644 index 00000000000..bb3e667d664 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xmq3-c6r3-6cm9/GHSA-xmq3-c6r3-6cm9.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xmq3-c6r3-6cm9", + "modified": "2025-05-21T18:33:31Z", + "published": "2025-05-21T18:33:31Z", + "aliases": [ + "CVE-2025-45754" + ], + "details": "A stored cross-site scripting (XSS) vulnerability exists in SeedDMS 6.0.32. This vulnerability allows an attacker to inject malicious JavaScript payloads by creating a document with an XSS payload as the document name.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45754" + }, + { + "type": "WEB", + "url": "https://www.simonjuguna.com/cve-2025-45754-stored-cross-site-scripting-xss-vulnerability-in-seeddms-v6-0-32" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T17:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xq83-m7pg-gg42/GHSA-xq83-m7pg-gg42.json b/advisories/unreviewed/2025/05/GHSA-xq83-m7pg-gg42/GHSA-xq83-m7pg-gg42.json new file mode 100644 index 00000000000..a03dfbcb26d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xq83-m7pg-gg42/GHSA-xq83-m7pg-gg42.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xq83-m7pg-gg42", + "modified": "2025-05-21T18:33:30Z", + "published": "2025-05-21T18:33:30Z", + "aliases": [ + "CVE-2025-20112" + ], + "details": "A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an authenticated, local attacker to elevate privileges to root on an affected device.\n\nThis vulnerability is due to excessive permissions that have been assigned to system commands. An attacker could exploit this vulnerability by executing crafted commands on the underlying operating system. A successful exploit could allow the attacker to escape the restricted shell and gain root privileges on the underlying operating system of an affected device. To successfully exploit this vulnerability, an attacker would need administrative access to the ESXi hypervisor.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20112" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-kkhZbHR5" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-268" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T17:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xw2w-jc5r-g6r7/GHSA-xw2w-jc5r-g6r7.json b/advisories/unreviewed/2025/05/GHSA-xw2w-jc5r-g6r7/GHSA-xw2w-jc5r-g6r7.json new file mode 100644 index 00000000000..f6999b89eed --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xw2w-jc5r-g6r7/GHSA-xw2w-jc5r-g6r7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xw2w-jc5r-g6r7", + "modified": "2025-05-21T18:33:29Z", + "published": "2025-05-21T18:33:29Z", + "aliases": [ + "CVE-2025-27804" + ], + "details": "Several OS command injection vulnerabilities exist in the device firmware in the /var/salia/mqtt.php script. By publishing a specially crafted message to a certain MQTT topic arbitrary OS commands can be executed with root permissions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27804" + }, + { + "type": "WEB", + "url": "https://r.sec-consult.com/echarge" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T12:16:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xwrw-9qxw-gm75/GHSA-xwrw-9qxw-gm75.json b/advisories/unreviewed/2025/05/GHSA-xwrw-9qxw-gm75/GHSA-xwrw-9qxw-gm75.json index b1e68219de3..771172be165 100644 --- a/advisories/unreviewed/2025/05/GHSA-xwrw-9qxw-gm75/GHSA-xwrw-9qxw-gm75.json +++ b/advisories/unreviewed/2025/05/GHSA-xwrw-9qxw-gm75/GHSA-xwrw-9qxw-gm75.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xwrw-9qxw-gm75", - "modified": "2025-05-21T15:30:34Z", + "modified": "2025-05-21T18:33:30Z", "published": "2025-05-21T15:30:34Z", "aliases": [ "CVE-2025-44892" ], "details": "FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ownekey parameter in the web_rmon_alarm_post_rmon_alarm function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-21T14:15:30Z"