From 2326af2cad60b2f8f2bfd2694825f9e52ee6b27f Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 3 Jun 2025 21:32:05 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-87g3-rx63-rrch.json | 3 +- .../GHSA-pfjw-c288-q656.json | 2 +- .../GHSA-8xhg-wqv3-qqf5.json | 6 +- .../GHSA-24gf-6m5f-h6pg.json | 8 +- .../GHSA-2cxg-9g49-xwfp.json | 4 +- .../GHSA-4j3v-h4q8-j269.json | 4 +- .../GHSA-6h64-v4gr-6gvr.json | 4 +- .../GHSA-6p66-xcjh-mgwv.json | 8 +- .../GHSA-9hq4-m6mm-522h.json | 4 +- .../GHSA-g4m4-7p6w-x8jv.json | 4 +- .../GHSA-jf62-g97c-j9x3.json | 4 +- .../GHSA-jj67-79h2-3725.json | 4 +- .../GHSA-jj9w-xpp6-gqpf.json | 4 +- .../GHSA-jp7h-g39h-xfp6.json | 2 +- .../GHSA-mw5r-4xcp-384g.json | 4 +- .../GHSA-pg84-6g27-3r3m.json | 6 +- .../GHSA-qfqc-q85j-6m33.json | 4 +- .../GHSA-wpfm-839m-3pxg.json | 4 +- .../GHSA-xvjx-j3q9-j35p.json | 6 +- .../GHSA-2cwc-8x85-2774.json | 4 +- .../GHSA-2q4f-xv44-vmqf.json | 4 +- .../GHSA-39f6-9c52-27p8.json | 1 + .../GHSA-3f8r-x482-8qpg.json | 7 +- .../GHSA-5r2p-47vm-6fh9.json | 3 +- .../GHSA-6f2h-vg2p-qhf2.json | 8 +- .../GHSA-ccx2-385m-5g4m.json | 4 +- .../GHSA-g5p5-rhqv-c3qj.json | 4 +- .../GHSA-j75r-xrr2-rgp6.json | 8 +- .../GHSA-jxrx-5cg2-pj56.json | 7 +- .../GHSA-q58q-2fxh-6w6r.json | 7 +- .../GHSA-v4cg-mf2j-mwp7.json | 4 +- .../GHSA-xqc9-88mp-rfhw.json | 4 +- .../GHSA-qjrp-xr9r-wmrg.json | 2 +- .../GHSA-28m4-49gg-78fx.json | 56 ++++++++++++ .../GHSA-2pg8-h2j6-28xm.json | 30 ++++++- .../GHSA-36xg-7wfq-m2jj.json | 52 +++++++++++ .../GHSA-3jrw-q59w-mpr2.json | 15 +++- .../GHSA-4g4g-fqw4-prp2.json | 10 ++- .../GHSA-5gr5-vmmr-82g6.json | 15 +++- .../GHSA-62pm-4mgm-x6wg.json | 56 ++++++++++++ .../GHSA-68pj-xrp5-vccj.json | 10 ++- .../GHSA-6r6c-684h-9j7p.json | 10 ++- .../GHSA-7fq6-gf52-6m77.json | 33 +++++++ .../GHSA-7v6m-28jr-rg84.json | 88 +++++++++++++++++++ .../GHSA-7wc4-mx57-5w73.json | 33 +++++++ .../GHSA-8v33-w22p-qf3q.json | 52 +++++++++++ .../GHSA-p72v-37h5-753v.json | 10 ++- .../GHSA-rxpg-c894-3g4j.json | 33 +++++++ .../GHSA-wrc6-3hf5-f858.json | 40 +++++++++ .../GHSA-x7cg-3x6g-hghf.json | 52 +++++++++++ 50 files changed, 680 insertions(+), 67 deletions(-) create mode 100644 advisories/unreviewed/2025/06/GHSA-28m4-49gg-78fx/GHSA-28m4-49gg-78fx.json create mode 100644 advisories/unreviewed/2025/06/GHSA-36xg-7wfq-m2jj/GHSA-36xg-7wfq-m2jj.json create mode 100644 advisories/unreviewed/2025/06/GHSA-62pm-4mgm-x6wg/GHSA-62pm-4mgm-x6wg.json create mode 100644 advisories/unreviewed/2025/06/GHSA-7fq6-gf52-6m77/GHSA-7fq6-gf52-6m77.json create mode 100644 advisories/unreviewed/2025/06/GHSA-7v6m-28jr-rg84/GHSA-7v6m-28jr-rg84.json create mode 100644 advisories/unreviewed/2025/06/GHSA-7wc4-mx57-5w73/GHSA-7wc4-mx57-5w73.json create mode 100644 advisories/unreviewed/2025/06/GHSA-8v33-w22p-qf3q/GHSA-8v33-w22p-qf3q.json create mode 100644 advisories/unreviewed/2025/06/GHSA-rxpg-c894-3g4j/GHSA-rxpg-c894-3g4j.json create mode 100644 advisories/unreviewed/2025/06/GHSA-wrc6-3hf5-f858/GHSA-wrc6-3hf5-f858.json create mode 100644 advisories/unreviewed/2025/06/GHSA-x7cg-3x6g-hghf/GHSA-x7cg-3x6g-hghf.json diff --git a/advisories/unreviewed/2022/09/GHSA-87g3-rx63-rrch/GHSA-87g3-rx63-rrch.json b/advisories/unreviewed/2022/09/GHSA-87g3-rx63-rrch/GHSA-87g3-rx63-rrch.json index 51294f7a0d7..01c3790db6e 100644 --- a/advisories/unreviewed/2022/09/GHSA-87g3-rx63-rrch/GHSA-87g3-rx63-rrch.json +++ b/advisories/unreviewed/2022/09/GHSA-87g3-rx63-rrch/GHSA-87g3-rx63-rrch.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-87g3-rx63-rrch", - "modified": "2022-09-18T00:00:32Z", + "modified": "2025-06-03T21:30:30Z", "published": "2022-09-17T00:00:36Z", "aliases": [ "CVE-2021-42949" @@ -34,6 +34,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-287", "CWE-326" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2022/09/GHSA-pfjw-c288-q656/GHSA-pfjw-c288-q656.json b/advisories/unreviewed/2022/09/GHSA-pfjw-c288-q656/GHSA-pfjw-c288-q656.json index 2fd28794d99..4d613b721c3 100644 --- a/advisories/unreviewed/2022/09/GHSA-pfjw-c288-q656/GHSA-pfjw-c288-q656.json +++ b/advisories/unreviewed/2022/09/GHSA-pfjw-c288-q656/GHSA-pfjw-c288-q656.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pfjw-c288-q656", - "modified": "2022-09-23T00:00:42Z", + "modified": "2025-06-03T21:30:32Z", "published": "2022-09-20T00:00:22Z", "aliases": [ "CVE-2022-23767" diff --git a/advisories/unreviewed/2023/12/GHSA-8xhg-wqv3-qqf5/GHSA-8xhg-wqv3-qqf5.json b/advisories/unreviewed/2023/12/GHSA-8xhg-wqv3-qqf5/GHSA-8xhg-wqv3-qqf5.json index 698dcbeb5d3..0206590f1f6 100644 --- a/advisories/unreviewed/2023/12/GHSA-8xhg-wqv3-qqf5/GHSA-8xhg-wqv3-qqf5.json +++ b/advisories/unreviewed/2023/12/GHSA-8xhg-wqv3-qqf5/GHSA-8xhg-wqv3-qqf5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8xhg-wqv3-qqf5", - "modified": "2023-12-14T15:30:23Z", + "modified": "2025-06-03T21:30:33Z", "published": "2023-12-14T15:30:23Z", "aliases": [ "CVE-2023-49739" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://patchstack.com/database/vulnerability/powerpack-elements/wordpress-powerpack-pro-for-elementor-plugin-2-9-23-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/powerpack-elements/vulnerability/wordpress-powerpack-pro-for-elementor-plugin-2-9-23-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-24gf-6m5f-h6pg/GHSA-24gf-6m5f-h6pg.json b/advisories/unreviewed/2024/01/GHSA-24gf-6m5f-h6pg/GHSA-24gf-6m5f-h6pg.json index f77c5699f54..e4b904cfe16 100644 --- a/advisories/unreviewed/2024/01/GHSA-24gf-6m5f-h6pg/GHSA-24gf-6m5f-h6pg.json +++ b/advisories/unreviewed/2024/01/GHSA-24gf-6m5f-h6pg/GHSA-24gf-6m5f-h6pg.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-24gf-6m5f-h6pg", - "modified": "2024-01-31T18:31:26Z", + "modified": "2025-06-03T21:30:33Z", "published": "2024-01-31T18:31:26Z", "aliases": [ "CVE-2024-21888" ], - "details": "A privilege escalation vulnerability in web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a user to elevate privileges to that of an administrator. ", + "details": "A privilege escalation vulnerability in web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a user to elevate privileges to that of an administrator.", "severity": [ { "type": "CVSS_V3", @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/01/GHSA-2cxg-9g49-xwfp/GHSA-2cxg-9g49-xwfp.json b/advisories/unreviewed/2024/01/GHSA-2cxg-9g49-xwfp/GHSA-2cxg-9g49-xwfp.json index d6e6b617f20..b3026ecf6cc 100644 --- a/advisories/unreviewed/2024/01/GHSA-2cxg-9g49-xwfp/GHSA-2cxg-9g49-xwfp.json +++ b/advisories/unreviewed/2024/01/GHSA-2cxg-9g49-xwfp/GHSA-2cxg-9g49-xwfp.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/01/GHSA-4j3v-h4q8-j269/GHSA-4j3v-h4q8-j269.json b/advisories/unreviewed/2024/01/GHSA-4j3v-h4q8-j269/GHSA-4j3v-h4q8-j269.json index 11a0992a9c4..552ed69d160 100644 --- a/advisories/unreviewed/2024/01/GHSA-4j3v-h4q8-j269/GHSA-4j3v-h4q8-j269.json +++ b/advisories/unreviewed/2024/01/GHSA-4j3v-h4q8-j269/GHSA-4j3v-h4q8-j269.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-77" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/01/GHSA-6h64-v4gr-6gvr/GHSA-6h64-v4gr-6gvr.json b/advisories/unreviewed/2024/01/GHSA-6h64-v4gr-6gvr/GHSA-6h64-v4gr-6gvr.json index 2bb23b2da7c..240bd1d1b2a 100644 --- a/advisories/unreviewed/2024/01/GHSA-6h64-v4gr-6gvr/GHSA-6h64-v4gr-6gvr.json +++ b/advisories/unreviewed/2024/01/GHSA-6h64-v4gr-6gvr/GHSA-6h64-v4gr-6gvr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/01/GHSA-6p66-xcjh-mgwv/GHSA-6p66-xcjh-mgwv.json b/advisories/unreviewed/2024/01/GHSA-6p66-xcjh-mgwv/GHSA-6p66-xcjh-mgwv.json index 79f95f69c3c..a2b1d624a19 100644 --- a/advisories/unreviewed/2024/01/GHSA-6p66-xcjh-mgwv/GHSA-6p66-xcjh-mgwv.json +++ b/advisories/unreviewed/2024/01/GHSA-6p66-xcjh-mgwv/GHSA-6p66-xcjh-mgwv.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-6p66-xcjh-mgwv", - "modified": "2024-01-16T18:31:11Z", + "modified": "2025-06-03T21:30:33Z", "published": "2024-01-16T18:31:11Z", "aliases": [ "CVE-2023-37523" ], - "details": "Missing or insecure tags in the HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower could allow an attacker to execute a malicious script on the user's browser.\n", + "details": "Missing or insecure tags in the HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower could allow an attacker to execute a malicious script on the user's browser.", "severity": [ { "type": "CVSS_V3", @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/01/GHSA-9hq4-m6mm-522h/GHSA-9hq4-m6mm-522h.json b/advisories/unreviewed/2024/01/GHSA-9hq4-m6mm-522h/GHSA-9hq4-m6mm-522h.json index 734c819ebd6..84070750c16 100644 --- a/advisories/unreviewed/2024/01/GHSA-9hq4-m6mm-522h/GHSA-9hq4-m6mm-522h.json +++ b/advisories/unreviewed/2024/01/GHSA-9hq4-m6mm-522h/GHSA-9hq4-m6mm-522h.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/01/GHSA-g4m4-7p6w-x8jv/GHSA-g4m4-7p6w-x8jv.json b/advisories/unreviewed/2024/01/GHSA-g4m4-7p6w-x8jv/GHSA-g4m4-7p6w-x8jv.json index 3c129838d14..646f9685e4e 100644 --- a/advisories/unreviewed/2024/01/GHSA-g4m4-7p6w-x8jv/GHSA-g4m4-7p6w-x8jv.json +++ b/advisories/unreviewed/2024/01/GHSA-g4m4-7p6w-x8jv/GHSA-g4m4-7p6w-x8jv.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/01/GHSA-jf62-g97c-j9x3/GHSA-jf62-g97c-j9x3.json b/advisories/unreviewed/2024/01/GHSA-jf62-g97c-j9x3/GHSA-jf62-g97c-j9x3.json index 51b2af57645..c74002d5e50 100644 --- a/advisories/unreviewed/2024/01/GHSA-jf62-g97c-j9x3/GHSA-jf62-g97c-j9x3.json +++ b/advisories/unreviewed/2024/01/GHSA-jf62-g97c-j9x3/GHSA-jf62-g97c-j9x3.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-jf62-g97c-j9x3", - "modified": "2024-01-09T18:30:27Z", + "modified": "2025-06-03T21:30:32Z", "published": "2024-01-03T03:30:33Z", "aliases": [ "CVE-2023-50342" ], - "details": "HCL DRYiCE MyXalytics is impacted by an Insecure Direct Object Reference (IDOR) vulnerability.  A user can obtain certain details about another user as a result of improper access control.\n", + "details": "HCL DRYiCE MyXalytics is impacted by an Insecure Direct Object Reference (IDOR) vulnerability.  A user can obtain certain details about another user as a result of improper access control.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/01/GHSA-jj67-79h2-3725/GHSA-jj67-79h2-3725.json b/advisories/unreviewed/2024/01/GHSA-jj67-79h2-3725/GHSA-jj67-79h2-3725.json index 4be99cbf1ac..227c5a76278 100644 --- a/advisories/unreviewed/2024/01/GHSA-jj67-79h2-3725/GHSA-jj67-79h2-3725.json +++ b/advisories/unreviewed/2024/01/GHSA-jj67-79h2-3725/GHSA-jj67-79h2-3725.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-285" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/01/GHSA-jj9w-xpp6-gqpf/GHSA-jj9w-xpp6-gqpf.json b/advisories/unreviewed/2024/01/GHSA-jj9w-xpp6-gqpf/GHSA-jj9w-xpp6-gqpf.json index cca9624eb9c..9b129dacb13 100644 --- a/advisories/unreviewed/2024/01/GHSA-jj9w-xpp6-gqpf/GHSA-jj9w-xpp6-gqpf.json +++ b/advisories/unreviewed/2024/01/GHSA-jj9w-xpp6-gqpf/GHSA-jj9w-xpp6-gqpf.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/01/GHSA-jp7h-g39h-xfp6/GHSA-jp7h-g39h-xfp6.json b/advisories/unreviewed/2024/01/GHSA-jp7h-g39h-xfp6/GHSA-jp7h-g39h-xfp6.json index 08882defb24..ca5208c1bcf 100644 --- a/advisories/unreviewed/2024/01/GHSA-jp7h-g39h-xfp6/GHSA-jp7h-g39h-xfp6.json +++ b/advisories/unreviewed/2024/01/GHSA-jp7h-g39h-xfp6/GHSA-jp7h-g39h-xfp6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jp7h-g39h-xfp6", - "modified": "2024-01-22T15:30:22Z", + "modified": "2025-06-03T21:30:32Z", "published": "2024-01-16T06:30:31Z", "aliases": [ "CVE-2024-21673" diff --git a/advisories/unreviewed/2024/01/GHSA-mw5r-4xcp-384g/GHSA-mw5r-4xcp-384g.json b/advisories/unreviewed/2024/01/GHSA-mw5r-4xcp-384g/GHSA-mw5r-4xcp-384g.json index 3dd0bd4ff47..789a998492a 100644 --- a/advisories/unreviewed/2024/01/GHSA-mw5r-4xcp-384g/GHSA-mw5r-4xcp-384g.json +++ b/advisories/unreviewed/2024/01/GHSA-mw5r-4xcp-384g/GHSA-mw5r-4xcp-384g.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/01/GHSA-pg84-6g27-3r3m/GHSA-pg84-6g27-3r3m.json b/advisories/unreviewed/2024/01/GHSA-pg84-6g27-3r3m/GHSA-pg84-6g27-3r3m.json index 7c9041bd3ea..8f452d92809 100644 --- a/advisories/unreviewed/2024/01/GHSA-pg84-6g27-3r3m/GHSA-pg84-6g27-3r3m.json +++ b/advisories/unreviewed/2024/01/GHSA-pg84-6g27-3r3m/GHSA-pg84-6g27-3r3m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pg84-6g27-3r3m", - "modified": "2024-01-17T00:30:21Z", + "modified": "2025-06-03T21:30:33Z", "published": "2024-01-17T00:30:21Z", "aliases": [ "CVE-2024-20971" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/01/GHSA-qfqc-q85j-6m33/GHSA-qfqc-q85j-6m33.json b/advisories/unreviewed/2024/01/GHSA-qfqc-q85j-6m33/GHSA-qfqc-q85j-6m33.json index 3fa8fefdcc0..7a245ff9384 100644 --- a/advisories/unreviewed/2024/01/GHSA-qfqc-q85j-6m33/GHSA-qfqc-q85j-6m33.json +++ b/advisories/unreviewed/2024/01/GHSA-qfqc-q85j-6m33/GHSA-qfqc-q85j-6m33.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/01/GHSA-wpfm-839m-3pxg/GHSA-wpfm-839m-3pxg.json b/advisories/unreviewed/2024/01/GHSA-wpfm-839m-3pxg/GHSA-wpfm-839m-3pxg.json index 10d8a06b8f2..11c0d0cbcff 100644 --- a/advisories/unreviewed/2024/01/GHSA-wpfm-839m-3pxg/GHSA-wpfm-839m-3pxg.json +++ b/advisories/unreviewed/2024/01/GHSA-wpfm-839m-3pxg/GHSA-wpfm-839m-3pxg.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/01/GHSA-xvjx-j3q9-j35p/GHSA-xvjx-j3q9-j35p.json b/advisories/unreviewed/2024/01/GHSA-xvjx-j3q9-j35p/GHSA-xvjx-j3q9-j35p.json index 760eaf7f444..b45445d7f33 100644 --- a/advisories/unreviewed/2024/01/GHSA-xvjx-j3q9-j35p/GHSA-xvjx-j3q9-j35p.json +++ b/advisories/unreviewed/2024/01/GHSA-xvjx-j3q9-j35p/GHSA-xvjx-j3q9-j35p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xvjx-j3q9-j35p", - "modified": "2024-01-17T00:30:21Z", + "modified": "2025-06-03T21:30:33Z", "published": "2024-01-17T00:30:21Z", "aliases": [ "CVE-2024-20969" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-2cwc-8x85-2774/GHSA-2cwc-8x85-2774.json b/advisories/unreviewed/2024/02/GHSA-2cwc-8x85-2774/GHSA-2cwc-8x85-2774.json index 0bb12a054d0..fb8acee529a 100644 --- a/advisories/unreviewed/2024/02/GHSA-2cwc-8x85-2774/GHSA-2cwc-8x85-2774.json +++ b/advisories/unreviewed/2024/02/GHSA-2cwc-8x85-2774/GHSA-2cwc-8x85-2774.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-2cwc-8x85-2774", - "modified": "2024-02-02T21:31:29Z", + "modified": "2025-06-03T21:30:33Z", "published": "2024-02-02T21:31:29Z", "aliases": [ "CVE-2024-23553" ], - "details": "A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform exists due to missing a specific http header attribute. \n", + "details": "A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform exists due to missing a specific http header attribute.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/02/GHSA-2q4f-xv44-vmqf/GHSA-2q4f-xv44-vmqf.json b/advisories/unreviewed/2024/02/GHSA-2q4f-xv44-vmqf/GHSA-2q4f-xv44-vmqf.json index 148e68b808f..f4c60ca32a5 100644 --- a/advisories/unreviewed/2024/02/GHSA-2q4f-xv44-vmqf/GHSA-2q4f-xv44-vmqf.json +++ b/advisories/unreviewed/2024/02/GHSA-2q4f-xv44-vmqf/GHSA-2q4f-xv44-vmqf.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-2q4f-xv44-vmqf", - "modified": "2024-02-10T06:30:18Z", + "modified": "2025-06-03T21:30:33Z", "published": "2024-02-06T21:30:26Z", "aliases": [ "CVE-2024-22238" ], - "details": "Aria Operations for Networks contains a cross site scripting vulnerability. A malicious actor with admin privileges may be able to inject malicious code into user profile configurations due to improper input sanitization. ", + "details": "Aria Operations for Networks contains a cross site scripting vulnerability. A malicious actor with admin privileges may be able to inject malicious code into user profile configurations due to improper input sanitization.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/02/GHSA-39f6-9c52-27p8/GHSA-39f6-9c52-27p8.json b/advisories/unreviewed/2024/02/GHSA-39f6-9c52-27p8/GHSA-39f6-9c52-27p8.json index 32685791df4..654d952bad7 100644 --- a/advisories/unreviewed/2024/02/GHSA-39f6-9c52-27p8/GHSA-39f6-9c52-27p8.json +++ b/advisories/unreviewed/2024/02/GHSA-39f6-9c52-27p8/GHSA-39f6-9c52-27p8.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-256", "CWE-312" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/02/GHSA-3f8r-x482-8qpg/GHSA-3f8r-x482-8qpg.json b/advisories/unreviewed/2024/02/GHSA-3f8r-x482-8qpg/GHSA-3f8r-x482-8qpg.json index f1b8ab4b001..a042eacb4d3 100644 --- a/advisories/unreviewed/2024/02/GHSA-3f8r-x482-8qpg/GHSA-3f8r-x482-8qpg.json +++ b/advisories/unreviewed/2024/02/GHSA-3f8r-x482-8qpg/GHSA-3f8r-x482-8qpg.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-3f8r-x482-8qpg", - "modified": "2024-09-05T15:33:32Z", + "modified": "2025-06-03T21:30:34Z", "published": "2024-02-10T00:31:59Z", "aliases": [ "CVE-2023-45718" ], - "details": "Sametime is impacted by a failure to invalidate sessions. The application is setting sensitive cookie values in a persistent manner in Sametime Web clients. When this happens, cookie values can remain valid even after a user has closed out their session.  \n", + "details": "Sametime is impacted by a failure to invalidate sessions. The application is setting sensitive cookie values in a persistent manner in Sametime Web clients. When this happens, cookie values can remain valid even after a user has closed out their session.  ", "severity": [ { "type": "CVSS_V3", @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-384" + "CWE-384", + "CWE-613" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-5r2p-47vm-6fh9/GHSA-5r2p-47vm-6fh9.json b/advisories/unreviewed/2024/02/GHSA-5r2p-47vm-6fh9/GHSA-5r2p-47vm-6fh9.json index 357cda05a65..5c8c195a0d7 100644 --- a/advisories/unreviewed/2024/02/GHSA-5r2p-47vm-6fh9/GHSA-5r2p-47vm-6fh9.json +++ b/advisories/unreviewed/2024/02/GHSA-5r2p-47vm-6fh9/GHSA-5r2p-47vm-6fh9.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-307" + "CWE-307", + "CWE-644" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-6f2h-vg2p-qhf2/GHSA-6f2h-vg2p-qhf2.json b/advisories/unreviewed/2024/02/GHSA-6f2h-vg2p-qhf2/GHSA-6f2h-vg2p-qhf2.json index d17d139c1dd..f721dacfc95 100644 --- a/advisories/unreviewed/2024/02/GHSA-6f2h-vg2p-qhf2/GHSA-6f2h-vg2p-qhf2.json +++ b/advisories/unreviewed/2024/02/GHSA-6f2h-vg2p-qhf2/GHSA-6f2h-vg2p-qhf2.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-6f2h-vg2p-qhf2", - "modified": "2024-02-03T06:30:24Z", + "modified": "2025-06-03T21:30:33Z", "published": "2024-02-03T06:30:24Z", "aliases": [ "CVE-2024-23550" ], - "details": "HCL DevOps Deploy / HCL Launch (UCD) could disclose sensitive user information when installing the Windows agent.\n", + "details": "HCL DevOps Deploy / HCL Launch (UCD) could disclose sensitive user information when installing the Windows agent.", "severity": [ { "type": "CVSS_V3", @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-ccx2-385m-5g4m/GHSA-ccx2-385m-5g4m.json b/advisories/unreviewed/2024/02/GHSA-ccx2-385m-5g4m/GHSA-ccx2-385m-5g4m.json index ec6e52833f4..2bbf907c3c3 100644 --- a/advisories/unreviewed/2024/02/GHSA-ccx2-385m-5g4m/GHSA-ccx2-385m-5g4m.json +++ b/advisories/unreviewed/2024/02/GHSA-ccx2-385m-5g4m/GHSA-ccx2-385m-5g4m.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-g5p5-rhqv-c3qj/GHSA-g5p5-rhqv-c3qj.json b/advisories/unreviewed/2024/02/GHSA-g5p5-rhqv-c3qj/GHSA-g5p5-rhqv-c3qj.json index 3dda171933a..494cbed8350 100644 --- a/advisories/unreviewed/2024/02/GHSA-g5p5-rhqv-c3qj/GHSA-g5p5-rhqv-c3qj.json +++ b/advisories/unreviewed/2024/02/GHSA-g5p5-rhqv-c3qj/GHSA-g5p5-rhqv-c3qj.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-g5p5-rhqv-c3qj", - "modified": "2024-02-03T06:30:24Z", + "modified": "2025-06-03T21:30:33Z", "published": "2024-02-03T06:30:24Z", "aliases": [ "CVE-2023-37528" ], - "details": "A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attack to exploit an application parameter during execution of the Save Report. \n", + "details": "A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attack to exploit an application parameter during execution of the Save Report.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/02/GHSA-j75r-xrr2-rgp6/GHSA-j75r-xrr2-rgp6.json b/advisories/unreviewed/2024/02/GHSA-j75r-xrr2-rgp6/GHSA-j75r-xrr2-rgp6.json index 7fd86147ae0..6dde571555a 100644 --- a/advisories/unreviewed/2024/02/GHSA-j75r-xrr2-rgp6/GHSA-j75r-xrr2-rgp6.json +++ b/advisories/unreviewed/2024/02/GHSA-j75r-xrr2-rgp6/GHSA-j75r-xrr2-rgp6.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-j75r-xrr2-rgp6", - "modified": "2024-02-10T03:30:19Z", + "modified": "2025-06-03T21:30:34Z", "published": "2024-02-10T03:30:19Z", "aliases": [ "CVE-2023-45696" ], - "details": "Sametime is impacted by sensitive fields with autocomplete enabled in the Legacy web chat client. By default, this allows user entered data to be stored by the browser.\n", + "details": "Sametime is impacted by sensitive fields with autocomplete enabled in the Legacy web chat client. By default, this allows user entered data to be stored by the browser.", "severity": [ { "type": "CVSS_V3", @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-524" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-jxrx-5cg2-pj56/GHSA-jxrx-5cg2-pj56.json b/advisories/unreviewed/2024/02/GHSA-jxrx-5cg2-pj56/GHSA-jxrx-5cg2-pj56.json index c428f0ba1ba..7ac97785924 100644 --- a/advisories/unreviewed/2024/02/GHSA-jxrx-5cg2-pj56/GHSA-jxrx-5cg2-pj56.json +++ b/advisories/unreviewed/2024/02/GHSA-jxrx-5cg2-pj56/GHSA-jxrx-5cg2-pj56.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-jxrx-5cg2-pj56", - "modified": "2024-02-02T03:30:32Z", + "modified": "2025-06-03T21:30:33Z", "published": "2024-02-02T03:30:32Z", "aliases": [ "CVE-2023-50933" ], - "details": "IBM PowerSC 1.3, 2.0, and 2.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 275113.\n\n", + "details": "IBM PowerSC 1.3, 2.0, and 2.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 275113.", "severity": [ { "type": "CVSS_V3", @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-79" + "CWE-79", + "CWE-80" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-q58q-2fxh-6w6r/GHSA-q58q-2fxh-6w6r.json b/advisories/unreviewed/2024/02/GHSA-q58q-2fxh-6w6r/GHSA-q58q-2fxh-6w6r.json index 804a3f122da..5c55d238dae 100644 --- a/advisories/unreviewed/2024/02/GHSA-q58q-2fxh-6w6r/GHSA-q58q-2fxh-6w6r.json +++ b/advisories/unreviewed/2024/02/GHSA-q58q-2fxh-6w6r/GHSA-q58q-2fxh-6w6r.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-q58q-2fxh-6w6r", - "modified": "2024-02-10T00:31:59Z", + "modified": "2025-06-03T21:30:33Z", "published": "2024-02-10T00:31:59Z", "aliases": [ "CVE-2023-45716" ], - "details": "Sametime is impacted by sensitive information passed in URL. \n", + "details": "Sametime is impacted by sensitive information passed in URL.", "severity": [ { "type": "CVSS_V3", @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-319" + "CWE-319", + "CWE-598" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-v4cg-mf2j-mwp7/GHSA-v4cg-mf2j-mwp7.json b/advisories/unreviewed/2024/02/GHSA-v4cg-mf2j-mwp7/GHSA-v4cg-mf2j-mwp7.json index 58af018fdbd..da97d700d57 100644 --- a/advisories/unreviewed/2024/02/GHSA-v4cg-mf2j-mwp7/GHSA-v4cg-mf2j-mwp7.json +++ b/advisories/unreviewed/2024/02/GHSA-v4cg-mf2j-mwp7/GHSA-v4cg-mf2j-mwp7.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-v4cg-mf2j-mwp7", - "modified": "2024-02-02T21:31:29Z", + "modified": "2025-06-03T21:30:33Z", "published": "2024-02-02T21:31:29Z", "aliases": [ "CVE-2023-37527" ], - "details": "A reflected cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code in the application session or in database, via remote injection, while rendering content in a web page. \n", + "details": "A reflected cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code in the application session or in database, via remote injection, while rendering content in a web page.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/02/GHSA-xqc9-88mp-rfhw/GHSA-xqc9-88mp-rfhw.json b/advisories/unreviewed/2024/02/GHSA-xqc9-88mp-rfhw/GHSA-xqc9-88mp-rfhw.json index 847b48c5252..7a5d159fad2 100644 --- a/advisories/unreviewed/2024/02/GHSA-xqc9-88mp-rfhw/GHSA-xqc9-88mp-rfhw.json +++ b/advisories/unreviewed/2024/02/GHSA-xqc9-88mp-rfhw/GHSA-xqc9-88mp-rfhw.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-xqc9-88mp-rfhw", - "modified": "2024-02-10T06:30:18Z", + "modified": "2025-06-03T21:30:33Z", "published": "2024-02-06T21:30:26Z", "aliases": [ "CVE-2024-22241" ], - "details": "Aria Operations for Networks contains a cross site scripting vulnerability. A malicious actor with admin privileges can inject a malicious payload into the login banner and takeover the user account.   ", + "details": "Aria Operations for Networks contains a cross site scripting vulnerability. A malicious actor with admin privileges can inject a malicious payload into the login banner and takeover the user account.  ", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2025/04/GHSA-qjrp-xr9r-wmrg/GHSA-qjrp-xr9r-wmrg.json b/advisories/unreviewed/2025/04/GHSA-qjrp-xr9r-wmrg/GHSA-qjrp-xr9r-wmrg.json index 4e7e28be3c5..b9083abfa57 100644 --- a/advisories/unreviewed/2025/04/GHSA-qjrp-xr9r-wmrg/GHSA-qjrp-xr9r-wmrg.json +++ b/advisories/unreviewed/2025/04/GHSA-qjrp-xr9r-wmrg/GHSA-qjrp-xr9r-wmrg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qjrp-xr9r-wmrg", - "modified": "2025-04-25T21:31:33Z", + "modified": "2025-06-03T21:30:35Z", "published": "2025-04-25T21:31:33Z", "aliases": [ "CVE-2025-3935" diff --git a/advisories/unreviewed/2025/06/GHSA-28m4-49gg-78fx/GHSA-28m4-49gg-78fx.json b/advisories/unreviewed/2025/06/GHSA-28m4-49gg-78fx/GHSA-28m4-49gg-78fx.json new file mode 100644 index 00000000000..22ed1b983e1 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-28m4-49gg-78fx/GHSA-28m4-49gg-78fx.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-28m4-49gg-78fx", + "modified": "2025-06-03T21:30:39Z", + "published": "2025-06-03T21:30:39Z", + "aliases": [ + "CVE-2025-5527" + ], + "details": "A vulnerability was found in Tenda RX3 16.03.13.11_multi_TDE01. It has been rated as critical. This issue affects the function save_staticroute_data of the file /goform/SetStaticRouteCfg. The manipulation of the argument list leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5527" + }, + { + "type": "WEB", + "url": "https://github.com/alc9700jmo/CVE/issues/13" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310967" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310967" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.586781" + }, + { + "type": "WEB", + "url": "https://www.tenda.com.cn" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T21:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-2pg8-h2j6-28xm/GHSA-2pg8-h2j6-28xm.json b/advisories/unreviewed/2025/06/GHSA-2pg8-h2j6-28xm/GHSA-2pg8-h2j6-28xm.json index 873e30f3517..061ea51843b 100644 --- a/advisories/unreviewed/2025/06/GHSA-2pg8-h2j6-28xm/GHSA-2pg8-h2j6-28xm.json +++ b/advisories/unreviewed/2025/06/GHSA-2pg8-h2j6-28xm/GHSA-2pg8-h2j6-28xm.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2pg8-h2j6-28xm", - "modified": "2025-06-03T15:31:25Z", + "modified": "2025-06-03T21:30:36Z", "published": "2025-06-03T15:31:25Z", "aliases": [ "CVE-2024-12718" ], "details": "Allows modifying some file metadata (e.g. last modified) with filter=\"data\" or file permissions (chmod) with filter=\"tar\" of files outside the extraction directory.\nYou are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of \"data\" or \"tar\". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter  for more information. Only Python versions 3.12 or later are affected by these vulnerabilities, earlier versions don't include the extraction filter feature.\n\nNote that for Python 3.14 or later the default value of filter= changed from \"no filtering\" to `\"data\", so if you are relying on this new default behavior then your usage is also affected.\n\nNote that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" @@ -31,14 +35,38 @@ "type": "WEB", "url": "https://github.com/python/cpython/pull/135037" }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9" + }, { "type": "WEB", "url": "https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a" }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a" + }, { "type": "WEB", "url": "https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a" }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1" + }, { "type": "WEB", "url": "https://gist.github.com/sethmlarson/52398e33eff261329a0180ac1d54f42f" diff --git a/advisories/unreviewed/2025/06/GHSA-36xg-7wfq-m2jj/GHSA-36xg-7wfq-m2jj.json b/advisories/unreviewed/2025/06/GHSA-36xg-7wfq-m2jj/GHSA-36xg-7wfq-m2jj.json new file mode 100644 index 00000000000..114b439777c --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-36xg-7wfq-m2jj/GHSA-36xg-7wfq-m2jj.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-36xg-7wfq-m2jj", + "modified": "2025-06-03T21:30:38Z", + "published": "2025-06-03T21:30:38Z", + "aliases": [ + "CVE-2025-5523" + ], + "details": "A vulnerability classified as problematic has been found in enilu web-flash 1.0. This affects the function fileService.upload of the file src/main/java/cn/enilu/flash/api/controller/FileController/upload of the component File Upload. The manipulation of the argument File leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5523" + }, + { + "type": "WEB", + "url": "https://gitee.com/enilu/web-flash/issues/ICAXTM" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310959" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310959" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.585342" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T20:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-3jrw-q59w-mpr2/GHSA-3jrw-q59w-mpr2.json b/advisories/unreviewed/2025/06/GHSA-3jrw-q59w-mpr2/GHSA-3jrw-q59w-mpr2.json index c420c783af1..353a6e35444 100644 --- a/advisories/unreviewed/2025/06/GHSA-3jrw-q59w-mpr2/GHSA-3jrw-q59w-mpr2.json +++ b/advisories/unreviewed/2025/06/GHSA-3jrw-q59w-mpr2/GHSA-3jrw-q59w-mpr2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3jrw-q59w-mpr2", - "modified": "2025-06-03T15:31:26Z", + "modified": "2025-06-03T21:30:37Z", "published": "2025-06-03T15:31:26Z", "aliases": [ "CVE-2025-43925" ], "details": "An issue was discovered in Unicom Focal Point 7.6.1. The database is encrypted with a hardcoded key, making it easier to recover the cleartext data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-326" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-03T15:15:58Z" diff --git a/advisories/unreviewed/2025/06/GHSA-4g4g-fqw4-prp2/GHSA-4g4g-fqw4-prp2.json b/advisories/unreviewed/2025/06/GHSA-4g4g-fqw4-prp2/GHSA-4g4g-fqw4-prp2.json index a6a8e416806..f69f197a1db 100644 --- a/advisories/unreviewed/2025/06/GHSA-4g4g-fqw4-prp2/GHSA-4g4g-fqw4-prp2.json +++ b/advisories/unreviewed/2025/06/GHSA-4g4g-fqw4-prp2/GHSA-4g4g-fqw4-prp2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4g4g-fqw4-prp2", - "modified": "2025-06-03T18:30:41Z", + "modified": "2025-06-03T21:30:36Z", "published": "2025-06-03T15:31:25Z", "aliases": [ "CVE-2025-4138" @@ -43,6 +43,10 @@ "type": "WEB", "url": "https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e" }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a" + }, { "type": "WEB", "url": "https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a" @@ -51,6 +55,10 @@ "type": "WEB", "url": "https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01" }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1" + }, { "type": "WEB", "url": "https://gist.github.com/sethmlarson/52398e33eff261329a0180ac1d54f42f" diff --git a/advisories/unreviewed/2025/06/GHSA-5gr5-vmmr-82g6/GHSA-5gr5-vmmr-82g6.json b/advisories/unreviewed/2025/06/GHSA-5gr5-vmmr-82g6/GHSA-5gr5-vmmr-82g6.json index 6e8f0d218c5..908739a7dc9 100644 --- a/advisories/unreviewed/2025/06/GHSA-5gr5-vmmr-82g6/GHSA-5gr5-vmmr-82g6.json +++ b/advisories/unreviewed/2025/06/GHSA-5gr5-vmmr-82g6/GHSA-5gr5-vmmr-82g6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5gr5-vmmr-82g6", - "modified": "2025-06-03T15:31:26Z", + "modified": "2025-06-03T21:30:36Z", "published": "2025-06-03T15:31:26Z", "aliases": [ "CVE-2025-45855" ], "details": "An arbitrary file upload vulnerability in the component /upload/GoodsCategory/image of erupt v1.12.19 allows attackers to execute arbitrary code via uploading a crafted file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-03T14:15:48Z" diff --git a/advisories/unreviewed/2025/06/GHSA-62pm-4mgm-x6wg/GHSA-62pm-4mgm-x6wg.json b/advisories/unreviewed/2025/06/GHSA-62pm-4mgm-x6wg/GHSA-62pm-4mgm-x6wg.json new file mode 100644 index 00000000000..5edd608a691 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-62pm-4mgm-x6wg/GHSA-62pm-4mgm-x6wg.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62pm-4mgm-x6wg", + "modified": "2025-06-03T21:30:39Z", + "published": "2025-06-03T21:30:39Z", + "aliases": [ + "CVE-2025-5525" + ], + "details": "A vulnerability was found in Jrohy trojan up to 2.15.3. It has been declared as critical. This vulnerability affects the function LogChan of the file trojan/util/linux.go. The manipulation of the argument c leads to os command injection. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5525" + }, + { + "type": "WEB", + "url": "https://github.com/Tritium0041/Jrohy-trojan-RCE-POC/blob/main/POC.py" + }, + { + "type": "WEB", + "url": "https://github.com/ainrm/Jrohy-trojan-unauth-poc/blob/main/README.en.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310966" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310966" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.586673" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T20:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-68pj-xrp5-vccj/GHSA-68pj-xrp5-vccj.json b/advisories/unreviewed/2025/06/GHSA-68pj-xrp5-vccj/GHSA-68pj-xrp5-vccj.json index c7d48bc15e0..e1625d57001 100644 --- a/advisories/unreviewed/2025/06/GHSA-68pj-xrp5-vccj/GHSA-68pj-xrp5-vccj.json +++ b/advisories/unreviewed/2025/06/GHSA-68pj-xrp5-vccj/GHSA-68pj-xrp5-vccj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-68pj-xrp5-vccj", - "modified": "2025-06-03T18:30:41Z", + "modified": "2025-06-03T21:30:36Z", "published": "2025-06-03T15:31:25Z", "aliases": [ "CVE-2025-4330" @@ -43,6 +43,10 @@ "type": "WEB", "url": "https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e" }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a" + }, { "type": "WEB", "url": "https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a" @@ -51,6 +55,10 @@ "type": "WEB", "url": "https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01" }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1" + }, { "type": "WEB", "url": "https://gist.github.com/sethmlarson/52398e33eff261329a0180ac1d54f42f" diff --git a/advisories/unreviewed/2025/06/GHSA-6r6c-684h-9j7p/GHSA-6r6c-684h-9j7p.json b/advisories/unreviewed/2025/06/GHSA-6r6c-684h-9j7p/GHSA-6r6c-684h-9j7p.json index 061eeb14dc8..e9cf54ccdc1 100644 --- a/advisories/unreviewed/2025/06/GHSA-6r6c-684h-9j7p/GHSA-6r6c-684h-9j7p.json +++ b/advisories/unreviewed/2025/06/GHSA-6r6c-684h-9j7p/GHSA-6r6c-684h-9j7p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6r6c-684h-9j7p", - "modified": "2025-06-03T18:30:41Z", + "modified": "2025-06-03T21:30:37Z", "published": "2025-06-03T15:31:25Z", "aliases": [ "CVE-2025-4517" @@ -43,6 +43,10 @@ "type": "WEB", "url": "https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e" }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a" + }, { "type": "WEB", "url": "https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a" @@ -51,6 +55,10 @@ "type": "WEB", "url": "https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01" }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1" + }, { "type": "WEB", "url": "https://gist.github.com/sethmlarson/52398e33eff261329a0180ac1d54f42f" diff --git a/advisories/unreviewed/2025/06/GHSA-7fq6-gf52-6m77/GHSA-7fq6-gf52-6m77.json b/advisories/unreviewed/2025/06/GHSA-7fq6-gf52-6m77/GHSA-7fq6-gf52-6m77.json new file mode 100644 index 00000000000..430b089e130 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-7fq6-gf52-6m77/GHSA-7fq6-gf52-6m77.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7fq6-gf52-6m77", + "modified": "2025-06-03T21:30:38Z", + "published": "2025-06-03T21:30:38Z", + "aliases": [ + "CVE-2025-23100" + ], + "details": "An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400. The absence of a NULL check leads to a Denial of Service.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23100" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2025-23100" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T20:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-7v6m-28jr-rg84/GHSA-7v6m-28jr-rg84.json b/advisories/unreviewed/2025/06/GHSA-7v6m-28jr-rg84/GHSA-7v6m-28jr-rg84.json new file mode 100644 index 00000000000..91e7d1fa0e3 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-7v6m-28jr-rg84/GHSA-7v6m-28jr-rg84.json @@ -0,0 +1,88 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7v6m-28jr-rg84", + "modified": "2025-06-03T21:30:39Z", + "published": "2025-06-03T21:30:39Z", + "aliases": [ + "CVE-2025-35036" + ], + "details": "Hibernate Validator before 6.2.0 and 7.0.0, by default and depending how it is used, may interpolate user-supplied input in a constraint violation message with Expression Language. This could allow an attacker to access sensitive information or execute arbitrary Java code. Hibernate Validator as of 6.2.0 and 7.0.0 no longer interpolates custom constraint violation messages with Expression Language and strongly recommends not allowing user-supplied input in constraint violation messages. CVE-2020-5245 and CVE-2025-4428 are examples of related, downstream vulnerabilities involving Expression Language intepolation of user-supplied data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-35036" + }, + { + "type": "WEB", + "url": "https://github.com/hibernate/hibernate-validator/pull/1138" + }, + { + "type": "WEB", + "url": "https://github.com/hibernate/hibernate-validator/commit/05f795bb7cf18856004f40e5042709e550ed0d6e" + }, + { + "type": "WEB", + "url": "https://github.com/hibernate/hibernate-validator/commit/254858d9dcc4e7cd775d1b0f47f482218077c5e1" + }, + { + "type": "WEB", + "url": "https://github.com/hibernate/hibernate-validator/commit/d2db40b9e7d22c7a0b44d7665242dfc7b4d14d78" + }, + { + "type": "WEB", + "url": "https://github.com/hibernate/hibernate-validator/commit/e076293b0ee1bfa97b6e67d05ad9eee1ad77e893" + }, + { + "type": "WEB", + "url": "https://docs.jboss.org/hibernate/stable/validator/reference/en-US/html_single/#section-hibernateconstraintvalidatorcontext" + }, + { + "type": "WEB", + "url": "https://github.com/hibernate/hibernate-validator/compare/6.1.7.Final...6.2.0.Final" + }, + { + "type": "WEB", + "url": "https://hibernate.atlassian.net/browse/HV-1816" + }, + { + "type": "WEB", + "url": "https://hibernate.org/validator/documentation/migration-guide/#6-2-0-cr1" + }, + { + "type": "WEB", + "url": "https://in.relation.to/2021/01/06/hibernate-validator-700-62-final-released/#expression-language" + }, + { + "type": "WEB", + "url": "https://labs.watchtowr.com/expression-payloads-meet-mayhem-cve-2025-4427-and-cve-2025-4428" + }, + { + "type": "WEB", + "url": "https://www.cve.org/CVERecord?id=CVE-2020-5245" + }, + { + "type": "WEB", + "url": "https://www.cve.org/CVERecord?id=CVE-2025-4428" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T20:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-7wc4-mx57-5w73/GHSA-7wc4-mx57-5w73.json b/advisories/unreviewed/2025/06/GHSA-7wc4-mx57-5w73/GHSA-7wc4-mx57-5w73.json new file mode 100644 index 00000000000..f76c81037e6 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-7wc4-mx57-5w73/GHSA-7wc4-mx57-5w73.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7wc4-mx57-5w73", + "modified": "2025-06-03T21:30:38Z", + "published": "2025-06-03T21:30:38Z", + "aliases": [ + "CVE-2025-23098" + ], + "details": "An issue was discovered in Samsung Mobile Processor Exynos 980, 990, 1080, 2100, 1280, 2200, 1380. A Use-After-Free in the mobile processor leads to privilege escalation.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23098" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2025-23098" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T20:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-8v33-w22p-qf3q/GHSA-8v33-w22p-qf3q.json b/advisories/unreviewed/2025/06/GHSA-8v33-w22p-qf3q/GHSA-8v33-w22p-qf3q.json new file mode 100644 index 00000000000..0ed16069959 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-8v33-w22p-qf3q/GHSA-8v33-w22p-qf3q.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8v33-w22p-qf3q", + "modified": "2025-06-03T21:30:38Z", + "published": "2025-06-03T21:30:38Z", + "aliases": [ + "CVE-2025-5521" + ], + "details": "A vulnerability was found in WuKongOpenSource WukongCRM 9.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /system/user/updataPassword. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5521" + }, + { + "type": "WEB", + "url": "https://github.com/Aiyakami/CVE-1/issues/6" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310957" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310957" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.584636" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T19:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-p72v-37h5-753v/GHSA-p72v-37h5-753v.json b/advisories/unreviewed/2025/06/GHSA-p72v-37h5-753v/GHSA-p72v-37h5-753v.json index ac87b5c0d42..ed743743734 100644 --- a/advisories/unreviewed/2025/06/GHSA-p72v-37h5-753v/GHSA-p72v-37h5-753v.json +++ b/advisories/unreviewed/2025/06/GHSA-p72v-37h5-753v/GHSA-p72v-37h5-753v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p72v-37h5-753v", - "modified": "2025-06-03T18:30:41Z", + "modified": "2025-06-03T21:30:36Z", "published": "2025-06-03T15:31:25Z", "aliases": [ "CVE-2025-4435" @@ -43,6 +43,10 @@ "type": "WEB", "url": "https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e" }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a" + }, { "type": "WEB", "url": "https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a" @@ -51,6 +55,10 @@ "type": "WEB", "url": "https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01" }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1" + }, { "type": "WEB", "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG" diff --git a/advisories/unreviewed/2025/06/GHSA-rxpg-c894-3g4j/GHSA-rxpg-c894-3g4j.json b/advisories/unreviewed/2025/06/GHSA-rxpg-c894-3g4j/GHSA-rxpg-c894-3g4j.json new file mode 100644 index 00000000000..61e9bf7c6f6 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-rxpg-c894-3g4j/GHSA-rxpg-c894-3g4j.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rxpg-c894-3g4j", + "modified": "2025-06-03T21:30:38Z", + "published": "2025-06-03T21:30:38Z", + "aliases": [ + "CVE-2025-23097" + ], + "details": "An issue was discovered in Samsung Mobile Processor Exynos 1380. The lack of a length check leads to out-of-bounds writes.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23097" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2025-23097" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T20:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-wrc6-3hf5-f858/GHSA-wrc6-3hf5-f858.json b/advisories/unreviewed/2025/06/GHSA-wrc6-3hf5-f858/GHSA-wrc6-3hf5-f858.json new file mode 100644 index 00000000000..66f3968dc7b --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-wrc6-3hf5-f858/GHSA-wrc6-3hf5-f858.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wrc6-3hf5-f858", + "modified": "2025-06-03T21:30:37Z", + "published": "2025-06-03T21:30:37Z", + "aliases": [ + "CVE-2025-23102" + ], + "details": "An issue was discovered in Samsung Mobile Processor Exynos 9820, 9825, 980, 990, 1080, 2100, 1280, 2200, and 1380. A Double Free in the mobile processor leads to privilege escalation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23102" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2025-23102" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-415" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T19:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-x7cg-3x6g-hghf/GHSA-x7cg-3x6g-hghf.json b/advisories/unreviewed/2025/06/GHSA-x7cg-3x6g-hghf/GHSA-x7cg-3x6g-hghf.json new file mode 100644 index 00000000000..d2773d7ba84 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-x7cg-3x6g-hghf/GHSA-x7cg-3x6g-hghf.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x7cg-3x6g-hghf", + "modified": "2025-06-03T21:30:38Z", + "published": "2025-06-03T21:30:38Z", + "aliases": [ + "CVE-2025-5522" + ], + "details": "A vulnerability was found in jack0240 魏 bskms 蓝天幼儿园管理系统 up to dffe6640b5b54d8e29da6f060e0493fea74b3fad. It has been rated as critical. Affected by this issue is some unknown functionality of the file /sa/addUser of the component User Creation Handler. The manipulation leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5522" + }, + { + "type": "WEB", + "url": "https://gitee.com/jack0240/bskms/issues/ICAOOU" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310958" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310958" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.584986" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T19:15:40Z" + } +} \ No newline at end of file