diff --git a/advisories/github-reviewed/2023/07/GHSA-m88m-crr9-jvqq/GHSA-m88m-crr9-jvqq.json b/advisories/github-reviewed/2023/07/GHSA-m88m-crr9-jvqq/GHSA-m88m-crr9-jvqq.json index 2caf1b4f5ff..82abbb64b34 100644 --- a/advisories/github-reviewed/2023/07/GHSA-m88m-crr9-jvqq/GHSA-m88m-crr9-jvqq.json +++ b/advisories/github-reviewed/2023/07/GHSA-m88m-crr9-jvqq/GHSA-m88m-crr9-jvqq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m88m-crr9-jvqq", - "modified": "2023-07-18T18:47:27Z", + "modified": "2025-06-10T15:30:40Z", "published": "2023-07-18T18:47:27Z", "aliases": [ "CVE-2023-37476" diff --git a/advisories/unreviewed/2022/05/GHSA-jqh6-vqxw-fcv3/GHSA-jqh6-vqxw-fcv3.json b/advisories/unreviewed/2022/05/GHSA-jqh6-vqxw-fcv3/GHSA-jqh6-vqxw-fcv3.json index cb8e2b76cca..e63789235a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-jqh6-vqxw-fcv3/GHSA-jqh6-vqxw-fcv3.json +++ b/advisories/unreviewed/2022/05/GHSA-jqh6-vqxw-fcv3/GHSA-jqh6-vqxw-fcv3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jqh6-vqxw-fcv3", - "modified": "2025-04-11T04:17:53Z", + "modified": "2025-06-10T15:30:31Z", "published": "2022-05-14T03:59:59Z", "aliases": [ "CVE-2013-6954" ], "details": "The png_do_expand_palette function in libpng before 1.6.8 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via (1) a PLTE chunk of zero bytes or (2) a NULL palette, related to pngrtran.c and pngset.c.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -116,7 +121,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-476" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-h2vp-92vw-43mf/GHSA-h2vp-92vw-43mf.json b/advisories/unreviewed/2024/04/GHSA-h2vp-92vw-43mf/GHSA-h2vp-92vw-43mf.json index 71b7b06cdd7..7c06acf2f1f 100644 --- a/advisories/unreviewed/2024/04/GHSA-h2vp-92vw-43mf/GHSA-h2vp-92vw-43mf.json +++ b/advisories/unreviewed/2024/04/GHSA-h2vp-92vw-43mf/GHSA-h2vp-92vw-43mf.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-42p9-p46j-wc9w/GHSA-42p9-p46j-wc9w.json b/advisories/unreviewed/2025/05/GHSA-42p9-p46j-wc9w/GHSA-42p9-p46j-wc9w.json index de50eca3476..a925cd745ae 100644 --- a/advisories/unreviewed/2025/05/GHSA-42p9-p46j-wc9w/GHSA-42p9-p46j-wc9w.json +++ b/advisories/unreviewed/2025/05/GHSA-42p9-p46j-wc9w/GHSA-42p9-p46j-wc9w.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-5qff-4269-vc22/GHSA-5qff-4269-vc22.json b/advisories/unreviewed/2025/05/GHSA-5qff-4269-vc22/GHSA-5qff-4269-vc22.json index c7f5ba62e76..6d0e44fef7f 100644 --- a/advisories/unreviewed/2025/05/GHSA-5qff-4269-vc22/GHSA-5qff-4269-vc22.json +++ b/advisories/unreviewed/2025/05/GHSA-5qff-4269-vc22/GHSA-5qff-4269-vc22.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-7wxh-2hv2-977q/GHSA-7wxh-2hv2-977q.json b/advisories/unreviewed/2025/05/GHSA-7wxh-2hv2-977q/GHSA-7wxh-2hv2-977q.json index 4a1ad0bda5e..c8def081a62 100644 --- a/advisories/unreviewed/2025/05/GHSA-7wxh-2hv2-977q/GHSA-7wxh-2hv2-977q.json +++ b/advisories/unreviewed/2025/05/GHSA-7wxh-2hv2-977q/GHSA-7wxh-2hv2-977q.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-f5ww-x9w7-q9v2/GHSA-f5ww-x9w7-q9v2.json b/advisories/unreviewed/2025/05/GHSA-f5ww-x9w7-q9v2/GHSA-f5ww-x9w7-q9v2.json index a378cda0967..3a21492b73e 100644 --- a/advisories/unreviewed/2025/05/GHSA-f5ww-x9w7-q9v2/GHSA-f5ww-x9w7-q9v2.json +++ b/advisories/unreviewed/2025/05/GHSA-f5ww-x9w7-q9v2/GHSA-f5ww-x9w7-q9v2.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-f8vr-vg6x-hfpr/GHSA-f8vr-vg6x-hfpr.json b/advisories/unreviewed/2025/05/GHSA-f8vr-vg6x-hfpr/GHSA-f8vr-vg6x-hfpr.json index ebed74374ef..f63a8640cbd 100644 --- a/advisories/unreviewed/2025/05/GHSA-f8vr-vg6x-hfpr/GHSA-f8vr-vg6x-hfpr.json +++ b/advisories/unreviewed/2025/05/GHSA-f8vr-vg6x-hfpr/GHSA-f8vr-vg6x-hfpr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-ffvf-jcq5-f366/GHSA-ffvf-jcq5-f366.json b/advisories/unreviewed/2025/05/GHSA-ffvf-jcq5-f366/GHSA-ffvf-jcq5-f366.json index 91a1411aeac..50bce0f9e9d 100644 --- a/advisories/unreviewed/2025/05/GHSA-ffvf-jcq5-f366/GHSA-ffvf-jcq5-f366.json +++ b/advisories/unreviewed/2025/05/GHSA-ffvf-jcq5-f366/GHSA-ffvf-jcq5-f366.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-gprh-m7xv-mqpj/GHSA-gprh-m7xv-mqpj.json b/advisories/unreviewed/2025/05/GHSA-gprh-m7xv-mqpj/GHSA-gprh-m7xv-mqpj.json index 28743ac8f91..066a6052373 100644 --- a/advisories/unreviewed/2025/05/GHSA-gprh-m7xv-mqpj/GHSA-gprh-m7xv-mqpj.json +++ b/advisories/unreviewed/2025/05/GHSA-gprh-m7xv-mqpj/GHSA-gprh-m7xv-mqpj.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-pvvp-x3x5-w98p/GHSA-pvvp-x3x5-w98p.json b/advisories/unreviewed/2025/05/GHSA-pvvp-x3x5-w98p/GHSA-pvvp-x3x5-w98p.json index bda0081219b..2c6d81d38cd 100644 --- a/advisories/unreviewed/2025/05/GHSA-pvvp-x3x5-w98p/GHSA-pvvp-x3x5-w98p.json +++ b/advisories/unreviewed/2025/05/GHSA-pvvp-x3x5-w98p/GHSA-pvvp-x3x5-w98p.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-qp9v-5v7f-q6f8/GHSA-qp9v-5v7f-q6f8.json b/advisories/unreviewed/2025/05/GHSA-qp9v-5v7f-q6f8/GHSA-qp9v-5v7f-q6f8.json index 88f092574b2..b2d970a704d 100644 --- a/advisories/unreviewed/2025/05/GHSA-qp9v-5v7f-q6f8/GHSA-qp9v-5v7f-q6f8.json +++ b/advisories/unreviewed/2025/05/GHSA-qp9v-5v7f-q6f8/GHSA-qp9v-5v7f-q6f8.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-r5wg-fxw7-6v36/GHSA-r5wg-fxw7-6v36.json b/advisories/unreviewed/2025/05/GHSA-r5wg-fxw7-6v36/GHSA-r5wg-fxw7-6v36.json index 0bd2edd44fb..ea7cc6ead57 100644 --- a/advisories/unreviewed/2025/05/GHSA-r5wg-fxw7-6v36/GHSA-r5wg-fxw7-6v36.json +++ b/advisories/unreviewed/2025/05/GHSA-r5wg-fxw7-6v36/GHSA-r5wg-fxw7-6v36.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-v6jx-8472-465v/GHSA-v6jx-8472-465v.json b/advisories/unreviewed/2025/05/GHSA-v6jx-8472-465v/GHSA-v6jx-8472-465v.json index 38ff369d1e9..0d8209ef65f 100644 --- a/advisories/unreviewed/2025/05/GHSA-v6jx-8472-465v/GHSA-v6jx-8472-465v.json +++ b/advisories/unreviewed/2025/05/GHSA-v6jx-8472-465v/GHSA-v6jx-8472-465v.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-x5f2-w3c3-pvvg/GHSA-x5f2-w3c3-pvvg.json b/advisories/unreviewed/2025/05/GHSA-x5f2-w3c3-pvvg/GHSA-x5f2-w3c3-pvvg.json index a2ebc7266e4..71b764ac73a 100644 --- a/advisories/unreviewed/2025/05/GHSA-x5f2-w3c3-pvvg/GHSA-x5f2-w3c3-pvvg.json +++ b/advisories/unreviewed/2025/05/GHSA-x5f2-w3c3-pvvg/GHSA-x5f2-w3c3-pvvg.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-xw9h-x6h4-fc8r/GHSA-xw9h-x6h4-fc8r.json b/advisories/unreviewed/2025/05/GHSA-xw9h-x6h4-fc8r/GHSA-xw9h-x6h4-fc8r.json index 84dfd678595..a00d446ac2f 100644 --- a/advisories/unreviewed/2025/05/GHSA-xw9h-x6h4-fc8r/GHSA-xw9h-x6h4-fc8r.json +++ b/advisories/unreviewed/2025/05/GHSA-xw9h-x6h4-fc8r/GHSA-xw9h-x6h4-fc8r.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/06/GHSA-23p3-9m3p-qpwp/GHSA-23p3-9m3p-qpwp.json b/advisories/unreviewed/2025/06/GHSA-23p3-9m3p-qpwp/GHSA-23p3-9m3p-qpwp.json new file mode 100644 index 00000000000..5488bb1c8fa --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-23p3-9m3p-qpwp/GHSA-23p3-9m3p-qpwp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23p3-9m3p-qpwp", + "modified": "2025-06-10T15:30:47Z", + "published": "2025-06-10T15:30:47Z", + "aliases": [ + "CVE-2025-49511" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in uxper Civi Framework allows Cross Site Request Forgery.This issue affects Civi Framework: from n/a through 2.1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49511" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/civi-framework/vulnerability/wordpress-civi-framework-plugin-2-1-6-cross-site-request-forgery-csrf-to-user-deactivation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T13:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-3cc4-93g3-9qw4/GHSA-3cc4-93g3-9qw4.json b/advisories/unreviewed/2025/06/GHSA-3cc4-93g3-9qw4/GHSA-3cc4-93g3-9qw4.json index 207ae104d6c..eb0e282f9ea 100644 --- a/advisories/unreviewed/2025/06/GHSA-3cc4-93g3-9qw4/GHSA-3cc4-93g3-9qw4.json +++ b/advisories/unreviewed/2025/06/GHSA-3cc4-93g3-9qw4/GHSA-3cc4-93g3-9qw4.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/06/GHSA-3gx7-hcg4-pm64/GHSA-3gx7-hcg4-pm64.json b/advisories/unreviewed/2025/06/GHSA-3gx7-hcg4-pm64/GHSA-3gx7-hcg4-pm64.json index 787d28772a7..79d64961cac 100644 --- a/advisories/unreviewed/2025/06/GHSA-3gx7-hcg4-pm64/GHSA-3gx7-hcg4-pm64.json +++ b/advisories/unreviewed/2025/06/GHSA-3gx7-hcg4-pm64/GHSA-3gx7-hcg4-pm64.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/06/GHSA-426g-4c29-jjpr/GHSA-426g-4c29-jjpr.json b/advisories/unreviewed/2025/06/GHSA-426g-4c29-jjpr/GHSA-426g-4c29-jjpr.json index db706ae971c..d31fc45e0ed 100644 --- a/advisories/unreviewed/2025/06/GHSA-426g-4c29-jjpr/GHSA-426g-4c29-jjpr.json +++ b/advisories/unreviewed/2025/06/GHSA-426g-4c29-jjpr/GHSA-426g-4c29-jjpr.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/06/GHSA-5gpp-h74r-6jj3/GHSA-5gpp-h74r-6jj3.json b/advisories/unreviewed/2025/06/GHSA-5gpp-h74r-6jj3/GHSA-5gpp-h74r-6jj3.json index a9a364a38f0..1de756a0370 100644 --- a/advisories/unreviewed/2025/06/GHSA-5gpp-h74r-6jj3/GHSA-5gpp-h74r-6jj3.json +++ b/advisories/unreviewed/2025/06/GHSA-5gpp-h74r-6jj3/GHSA-5gpp-h74r-6jj3.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/06/GHSA-5r93-p7fh-7rjj/GHSA-5r93-p7fh-7rjj.json b/advisories/unreviewed/2025/06/GHSA-5r93-p7fh-7rjj/GHSA-5r93-p7fh-7rjj.json new file mode 100644 index 00000000000..da5969e44c2 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-5r93-p7fh-7rjj/GHSA-5r93-p7fh-7rjj.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5r93-p7fh-7rjj", + "modified": "2025-06-10T15:30:48Z", + "published": "2025-06-10T15:30:47Z", + "aliases": [ + "CVE-2025-26395" + ], + "details": "SolarWinds Observability Self-Hosted\n\n was susceptible to a cross-site scripting (XSS) vulnerability due to an unsanitized field in the URL. The attack requires authentication using an administrator-level account and user interaction is required.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26395" + }, + { + "type": "WEB", + "url": "https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/hco_2025-2_release_notes.htm" + }, + { + "type": "WEB", + "url": "https://www.solarwinds.com/trust-center/security-advisories/CVE-2025-26395" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-77r3-7jcc-r6rj/GHSA-77r3-7jcc-r6rj.json b/advisories/unreviewed/2025/06/GHSA-77r3-7jcc-r6rj/GHSA-77r3-7jcc-r6rj.json new file mode 100644 index 00000000000..44e95e3a156 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-77r3-7jcc-r6rj/GHSA-77r3-7jcc-r6rj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-77r3-7jcc-r6rj", + "modified": "2025-06-10T15:30:47Z", + "published": "2025-06-10T15:30:47Z", + "aliases": [ + "CVE-2025-49507" + ], + "details": "Deserialization of Untrusted Data vulnerability in LoftOcean CozyStay allows Object Injection.This issue affects CozyStay: from n/a before 1.7.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49507" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/cozystay/vulnerability/wordpress-cozystay-1-7-1-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T13:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-7c9g-m69r-456f/GHSA-7c9g-m69r-456f.json b/advisories/unreviewed/2025/06/GHSA-7c9g-m69r-456f/GHSA-7c9g-m69r-456f.json new file mode 100644 index 00000000000..85121634243 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-7c9g-m69r-456f/GHSA-7c9g-m69r-456f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7c9g-m69r-456f", + "modified": "2025-06-10T15:30:46Z", + "published": "2025-06-10T15:30:46Z", + "aliases": [ + "CVE-2025-49454" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in LoftOcean TinySalt allows PHP Local File Inclusion.This issue affects TinySalt: from n/a before 3.10.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49454" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/tinysalt/vulnerability/wordpress-tinysalt-3-10-0-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T13:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-8gfp-4v63-m7x8/GHSA-8gfp-4v63-m7x8.json b/advisories/unreviewed/2025/06/GHSA-8gfp-4v63-m7x8/GHSA-8gfp-4v63-m7x8.json index b68bc7ceedd..fef426fe176 100644 --- a/advisories/unreviewed/2025/06/GHSA-8gfp-4v63-m7x8/GHSA-8gfp-4v63-m7x8.json +++ b/advisories/unreviewed/2025/06/GHSA-8gfp-4v63-m7x8/GHSA-8gfp-4v63-m7x8.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/06/GHSA-8xw7-4mc5-fmf8/GHSA-8xw7-4mc5-fmf8.json b/advisories/unreviewed/2025/06/GHSA-8xw7-4mc5-fmf8/GHSA-8xw7-4mc5-fmf8.json new file mode 100644 index 00000000000..2580dc6d969 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-8xw7-4mc5-fmf8/GHSA-8xw7-4mc5-fmf8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8xw7-4mc5-fmf8", + "modified": "2025-06-10T15:30:47Z", + "published": "2025-06-10T15:30:47Z", + "aliases": [ + "CVE-2025-49510" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WPFactory Min Max Step Quantity Limits Manager for WooCommerce allows Cross Site Request Forgery.This issue affects Min Max Step Quantity Limits Manager for WooCommerce: from n/a through 5.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49510" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/product-quantity-for-woocommerce/vulnerability/wordpress-min-max-step-quantity-limits-manager-for-woocommerce-plugin-5-1-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T13:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-955w-rv3v-9m9p/GHSA-955w-rv3v-9m9p.json b/advisories/unreviewed/2025/06/GHSA-955w-rv3v-9m9p/GHSA-955w-rv3v-9m9p.json index a773ca880c1..4c6bc56dc49 100644 --- a/advisories/unreviewed/2025/06/GHSA-955w-rv3v-9m9p/GHSA-955w-rv3v-9m9p.json +++ b/advisories/unreviewed/2025/06/GHSA-955w-rv3v-9m9p/GHSA-955w-rv3v-9m9p.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/06/GHSA-9vpr-8qr7-4pg3/GHSA-9vpr-8qr7-4pg3.json b/advisories/unreviewed/2025/06/GHSA-9vpr-8qr7-4pg3/GHSA-9vpr-8qr7-4pg3.json new file mode 100644 index 00000000000..6477509e719 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-9vpr-8qr7-4pg3/GHSA-9vpr-8qr7-4pg3.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9vpr-8qr7-4pg3", + "modified": "2025-06-10T15:30:48Z", + "published": "2025-06-10T15:30:48Z", + "aliases": [ + "CVE-2025-37100" + ], + "details": "A vulnerability in the APIs of HPE Aruba Networking Private 5G CoreĀ could potentially expose sensitive information to unauthorized users. \nA successful exploitation could allow an attacker to iteratively navigate through the filesystem and ultimately download protected system files containing sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37100" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04883en_us&docLocale=en_US" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T15:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-c845-c9fv-7m52/GHSA-c845-c9fv-7m52.json b/advisories/unreviewed/2025/06/GHSA-c845-c9fv-7m52/GHSA-c845-c9fv-7m52.json index 575b87dbd84..e3432ec433b 100644 --- a/advisories/unreviewed/2025/06/GHSA-c845-c9fv-7m52/GHSA-c845-c9fv-7m52.json +++ b/advisories/unreviewed/2025/06/GHSA-c845-c9fv-7m52/GHSA-c845-c9fv-7m52.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/06/GHSA-c9fr-q3m5-j6mm/GHSA-c9fr-q3m5-j6mm.json b/advisories/unreviewed/2025/06/GHSA-c9fr-q3m5-j6mm/GHSA-c9fr-q3m5-j6mm.json new file mode 100644 index 00000000000..0e5c2185dbc --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-c9fr-q3m5-j6mm/GHSA-c9fr-q3m5-j6mm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c9fr-q3m5-j6mm", + "modified": "2025-06-10T15:30:47Z", + "published": "2025-06-10T15:30:47Z", + "aliases": [ + "CVE-2025-22463" + ], + "details": "A hardcoded key in Ivanti Workspace Control before version 10.19.10.0 allows a local authenticated attacker to decrypt the stored environment password.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22463" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Workspace-Control-CVE-2025-5353-CVE-CVE-2025-22463-CVE-2025-22455" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-321" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-cccr-r78j-qx4c/GHSA-cccr-r78j-qx4c.json b/advisories/unreviewed/2025/06/GHSA-cccr-r78j-qx4c/GHSA-cccr-r78j-qx4c.json index abf8a8eba16..e2190866541 100644 --- a/advisories/unreviewed/2025/06/GHSA-cccr-r78j-qx4c/GHSA-cccr-r78j-qx4c.json +++ b/advisories/unreviewed/2025/06/GHSA-cccr-r78j-qx4c/GHSA-cccr-r78j-qx4c.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/06/GHSA-fq7j-84fx-gr99/GHSA-fq7j-84fx-gr99.json b/advisories/unreviewed/2025/06/GHSA-fq7j-84fx-gr99/GHSA-fq7j-84fx-gr99.json index 4b284851590..7a0869e755c 100644 --- a/advisories/unreviewed/2025/06/GHSA-fq7j-84fx-gr99/GHSA-fq7j-84fx-gr99.json +++ b/advisories/unreviewed/2025/06/GHSA-fq7j-84fx-gr99/GHSA-fq7j-84fx-gr99.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/06/GHSA-hqc8-8fj8-x6ff/GHSA-hqc8-8fj8-x6ff.json b/advisories/unreviewed/2025/06/GHSA-hqc8-8fj8-x6ff/GHSA-hqc8-8fj8-x6ff.json new file mode 100644 index 00000000000..ffa695ae9d7 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-hqc8-8fj8-x6ff/GHSA-hqc8-8fj8-x6ff.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hqc8-8fj8-x6ff", + "modified": "2025-06-10T15:30:48Z", + "published": "2025-06-10T15:30:47Z", + "aliases": [ + "CVE-2025-22455" + ], + "details": "A hardcoded key in Ivanti Workspace Control before version 10.19.0.0 allows a local authenticated attacker to decrypt stored SQL credentials.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22455" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Workspace-Control-CVE-2025-5353-CVE-CVE-2025-22463-CVE-2025-22455" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-321" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-jh26-j8cj-qf46/GHSA-jh26-j8cj-qf46.json b/advisories/unreviewed/2025/06/GHSA-jh26-j8cj-qf46/GHSA-jh26-j8cj-qf46.json new file mode 100644 index 00000000000..4ad735d717b --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-jh26-j8cj-qf46/GHSA-jh26-j8cj-qf46.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jh26-j8cj-qf46", + "modified": "2025-06-10T15:30:48Z", + "published": "2025-06-10T15:30:48Z", + "aliases": [ + "CVE-2025-26394" + ], + "details": "SolarWinds Observability Self-Hosted\n\n is susceptible to an open redirection vulnerability. The URL is not properly sanitized, and an attacker could manipulate the string to redirect a user to a malicious site. The attack complexity is high, and authentication is required.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26394" + }, + { + "type": "WEB", + "url": "https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/hco_2025-2_release_notes.htm" + }, + { + "type": "WEB", + "url": "https://www.solarwinds.com/trust-center/security-advisories/CVE-2025-26394" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-mfw6-88f6-x9r5/GHSA-mfw6-88f6-x9r5.json b/advisories/unreviewed/2025/06/GHSA-mfw6-88f6-x9r5/GHSA-mfw6-88f6-x9r5.json index 5be1deed49e..056e29cd4b0 100644 --- a/advisories/unreviewed/2025/06/GHSA-mfw6-88f6-x9r5/GHSA-mfw6-88f6-x9r5.json +++ b/advisories/unreviewed/2025/06/GHSA-mfw6-88f6-x9r5/GHSA-mfw6-88f6-x9r5.json @@ -50,7 +50,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-77" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/06/GHSA-pww7-j9v6-xc6j/GHSA-pww7-j9v6-xc6j.json b/advisories/unreviewed/2025/06/GHSA-pww7-j9v6-xc6j/GHSA-pww7-j9v6-xc6j.json index e71fadfbf7e..d60a5975f31 100644 --- a/advisories/unreviewed/2025/06/GHSA-pww7-j9v6-xc6j/GHSA-pww7-j9v6-xc6j.json +++ b/advisories/unreviewed/2025/06/GHSA-pww7-j9v6-xc6j/GHSA-pww7-j9v6-xc6j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pww7-j9v6-xc6j", - "modified": "2025-06-05T15:31:32Z", + "modified": "2025-06-10T15:30:42Z", "published": "2025-06-05T15:31:32Z", "aliases": [ "CVE-2025-47827" ], "details": "In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-347" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-05T14:15:32Z" diff --git a/advisories/unreviewed/2025/06/GHSA-px3c-rfv8-7mvg/GHSA-px3c-rfv8-7mvg.json b/advisories/unreviewed/2025/06/GHSA-px3c-rfv8-7mvg/GHSA-px3c-rfv8-7mvg.json new file mode 100644 index 00000000000..6d960f07d4e --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-px3c-rfv8-7mvg/GHSA-px3c-rfv8-7mvg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-px3c-rfv8-7mvg", + "modified": "2025-06-10T15:30:48Z", + "published": "2025-06-10T15:30:48Z", + "aliases": [ + "CVE-2025-5353" + ], + "details": "A hardcoded key in Ivanti Workspace Control before version 10.19.10.0 allows a local authenticated attacker to decrypt stored SQL credentials.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5353" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Workspace-Control-CVE-2025-5353-CVE-CVE-2025-22463-CVE-2025-22455" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-321" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T15:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-q7w9-cj7c-qxxx/GHSA-q7w9-cj7c-qxxx.json b/advisories/unreviewed/2025/06/GHSA-q7w9-cj7c-qxxx/GHSA-q7w9-cj7c-qxxx.json new file mode 100644 index 00000000000..6a5e24982eb --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-q7w9-cj7c-qxxx/GHSA-q7w9-cj7c-qxxx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q7w9-cj7c-qxxx", + "modified": "2025-06-10T15:30:47Z", + "published": "2025-06-10T15:30:47Z", + "aliases": [ + "CVE-2025-49509" + ], + "details": "Missing Authorization vulnerability in Roland Beaussant Audio Editor & Recorder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Audio Editor & Recorder: from n/a through 2.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49509" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/audio-editor-recorder/vulnerability/wordpress-audio-editor-recorder-plugin-2-2-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T13:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-qg9v-5p67-cg3r/GHSA-qg9v-5p67-cg3r.json b/advisories/unreviewed/2025/06/GHSA-qg9v-5p67-cg3r/GHSA-qg9v-5p67-cg3r.json index 6755e7c4214..4308babd4c1 100644 --- a/advisories/unreviewed/2025/06/GHSA-qg9v-5p67-cg3r/GHSA-qg9v-5p67-cg3r.json +++ b/advisories/unreviewed/2025/06/GHSA-qg9v-5p67-cg3r/GHSA-qg9v-5p67-cg3r.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-434" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/06/GHSA-rjh7-68rg-pqhm/GHSA-rjh7-68rg-pqhm.json b/advisories/unreviewed/2025/06/GHSA-rjh7-68rg-pqhm/GHSA-rjh7-68rg-pqhm.json index d9e91e8d38b..a59874216f9 100644 --- a/advisories/unreviewed/2025/06/GHSA-rjh7-68rg-pqhm/GHSA-rjh7-68rg-pqhm.json +++ b/advisories/unreviewed/2025/06/GHSA-rjh7-68rg-pqhm/GHSA-rjh7-68rg-pqhm.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/06/GHSA-rv56-m3gf-cgwm/GHSA-rv56-m3gf-cgwm.json b/advisories/unreviewed/2025/06/GHSA-rv56-m3gf-cgwm/GHSA-rv56-m3gf-cgwm.json index 6e59863bd14..e2f76a46c0e 100644 --- a/advisories/unreviewed/2025/06/GHSA-rv56-m3gf-cgwm/GHSA-rv56-m3gf-cgwm.json +++ b/advisories/unreviewed/2025/06/GHSA-rv56-m3gf-cgwm/GHSA-rv56-m3gf-cgwm.json @@ -50,7 +50,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-77" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/06/GHSA-v5f4-pm7v-cv3f/GHSA-v5f4-pm7v-cv3f.json b/advisories/unreviewed/2025/06/GHSA-v5f4-pm7v-cv3f/GHSA-v5f4-pm7v-cv3f.json new file mode 100644 index 00000000000..b8803b3a4ae --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-v5f4-pm7v-cv3f/GHSA-v5f4-pm7v-cv3f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v5f4-pm7v-cv3f", + "modified": "2025-06-10T15:30:46Z", + "published": "2025-06-10T15:30:46Z", + "aliases": [ + "CVE-2025-49455" + ], + "details": "Deserialization of Untrusted Data vulnerability in LoftOcean TinySalt allows Object Injection.This issue affects TinySalt: from n/a before 3.10.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49455" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/tinysalt/vulnerability/wordpress-tinysalt-3-10-0-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T13:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-v96f-2g2g-34fx/GHSA-v96f-2g2g-34fx.json b/advisories/unreviewed/2025/06/GHSA-v96f-2g2g-34fx/GHSA-v96f-2g2g-34fx.json new file mode 100644 index 00000000000..16c1300c841 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-v96f-2g2g-34fx/GHSA-v96f-2g2g-34fx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v96f-2g2g-34fx", + "modified": "2025-06-10T15:30:48Z", + "published": "2025-06-10T15:30:48Z", + "aliases": [ + "CVE-2025-46612" + ], + "details": "The Panel Designer dashboard in Airleader Master and Easy before 6.36 allows remote attackers to execute arbitrary commands via a wizard/workspace.jsp unrestricted file upload. To exploit this, the attacker must login to the administrator console (default credentials are weak and easily guessable) and upload a JSP file via the Panel Designer dashboard.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46612" + }, + { + "type": "WEB", + "url": "https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2025-036.txt" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T15:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-vpjf-3h3c-229h/GHSA-vpjf-3h3c-229h.json b/advisories/unreviewed/2025/06/GHSA-vpjf-3h3c-229h/GHSA-vpjf-3h3c-229h.json index f7d8e851e39..c8c3d6959af 100644 --- a/advisories/unreviewed/2025/06/GHSA-vpjf-3h3c-229h/GHSA-vpjf-3h3c-229h.json +++ b/advisories/unreviewed/2025/06/GHSA-vpjf-3h3c-229h/GHSA-vpjf-3h3c-229h.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/06/GHSA-wgp9-c2jp-6pqr/GHSA-wgp9-c2jp-6pqr.json b/advisories/unreviewed/2025/06/GHSA-wgp9-c2jp-6pqr/GHSA-wgp9-c2jp-6pqr.json index b35b20b608a..458450dea14 100644 --- a/advisories/unreviewed/2025/06/GHSA-wgp9-c2jp-6pqr/GHSA-wgp9-c2jp-6pqr.json +++ b/advisories/unreviewed/2025/06/GHSA-wgp9-c2jp-6pqr/GHSA-wgp9-c2jp-6pqr.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/06/GHSA-wmcj-jppg-46xh/GHSA-wmcj-jppg-46xh.json b/advisories/unreviewed/2025/06/GHSA-wmcj-jppg-46xh/GHSA-wmcj-jppg-46xh.json new file mode 100644 index 00000000000..1de4abdd9b2 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-wmcj-jppg-46xh/GHSA-wmcj-jppg-46xh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wmcj-jppg-46xh", + "modified": "2025-06-10T15:30:48Z", + "published": "2025-06-10T15:30:48Z", + "aliases": [ + "CVE-2025-5335" + ], + "details": "A maliciously crafted binary file when downloaded could lead to escalation of privileges to NT AUTHORITY/SYSTEM due to an untrusted search path being utilized in the Autodesk Installer application. Exploitation of this vulnerability may lead to code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5335" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0010" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-426" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T15:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-x4gv-4vpc-956p/GHSA-x4gv-4vpc-956p.json b/advisories/unreviewed/2025/06/GHSA-x4gv-4vpc-956p/GHSA-x4gv-4vpc-956p.json index 395ecf7b66d..c2f1acce8d1 100644 --- a/advisories/unreviewed/2025/06/GHSA-x4gv-4vpc-956p/GHSA-x4gv-4vpc-956p.json +++ b/advisories/unreviewed/2025/06/GHSA-x4gv-4vpc-956p/GHSA-x4gv-4vpc-956p.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/06/GHSA-xcpr-3f8f-3c77/GHSA-xcpr-3f8f-3c77.json b/advisories/unreviewed/2025/06/GHSA-xcpr-3f8f-3c77/GHSA-xcpr-3f8f-3c77.json index 826b8359411..ea8aaf2cbf9 100644 --- a/advisories/unreviewed/2025/06/GHSA-xcpr-3f8f-3c77/GHSA-xcpr-3f8f-3c77.json +++ b/advisories/unreviewed/2025/06/GHSA-xcpr-3f8f-3c77/GHSA-xcpr-3f8f-3c77.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/06/GHSA-xh52-5493-q8vx/GHSA-xh52-5493-q8vx.json b/advisories/unreviewed/2025/06/GHSA-xh52-5493-q8vx/GHSA-xh52-5493-q8vx.json index e44c2118b5f..2ed7829889f 100644 --- a/advisories/unreviewed/2025/06/GHSA-xh52-5493-q8vx/GHSA-xh52-5493-q8vx.json +++ b/advisories/unreviewed/2025/06/GHSA-xh52-5493-q8vx/GHSA-xh52-5493-q8vx.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "MODERATE", "github_reviewed": false,