diff --git a/advisories/github-reviewed/2025/05/GHSA-5rjg-fvgr-3xxf/GHSA-5rjg-fvgr-3xxf.json b/advisories/github-reviewed/2025/05/GHSA-5rjg-fvgr-3xxf/GHSA-5rjg-fvgr-3xxf.json index 47d07509f32..37f7e3e6ba2 100644 --- a/advisories/github-reviewed/2025/05/GHSA-5rjg-fvgr-3xxf/GHSA-5rjg-fvgr-3xxf.json +++ b/advisories/github-reviewed/2025/05/GHSA-5rjg-fvgr-3xxf/GHSA-5rjg-fvgr-3xxf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5rjg-fvgr-3xxf", - "modified": "2025-05-19T16:52:43Z", + "modified": "2025-05-28T15:34:05Z", "published": "2025-05-19T16:52:43Z", "aliases": [ "CVE-2025-47273" @@ -59,6 +59,10 @@ { "type": "WEB", "url": "https://github.com/pypa/setuptools/blob/6ead555c5fb29bc57fe6105b1bffc163f56fd558/setuptools/package_index.py#L810C1-L825C88" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00035.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/05/GHSA-36vw-58gr-fvfc/GHSA-36vw-58gr-fvfc.json b/advisories/unreviewed/2022/05/GHSA-36vw-58gr-fvfc/GHSA-36vw-58gr-fvfc.json index a5992837c2b..77f850caa3c 100644 --- a/advisories/unreviewed/2022/05/GHSA-36vw-58gr-fvfc/GHSA-36vw-58gr-fvfc.json +++ b/advisories/unreviewed/2022/05/GHSA-36vw-58gr-fvfc/GHSA-36vw-58gr-fvfc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-36vw-58gr-fvfc", - "modified": "2022-05-24T17:18:57Z", + "modified": "2025-05-28T15:33:50Z", "published": "2022-05-24T17:18:57Z", "aliases": [ "CVE-2019-11843" ], "details": "The MailPoet plugin before 3.23.2 for WordPress allows remote attackers to inject arbitrary web script or HTML using extra parameters in the URL (Reflective Server-Side XSS).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -28,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-37cj-9g83-7692/GHSA-37cj-9g83-7692.json b/advisories/unreviewed/2022/09/GHSA-37cj-9g83-7692/GHSA-37cj-9g83-7692.json index 4fd2cf82a5c..ce4840cec9a 100644 --- a/advisories/unreviewed/2022/09/GHSA-37cj-9g83-7692/GHSA-37cj-9g83-7692.json +++ b/advisories/unreviewed/2022/09/GHSA-37cj-9g83-7692/GHSA-37cj-9g83-7692.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-37cj-9g83-7692", - "modified": "2022-09-25T00:00:20Z", + "modified": "2025-05-28T15:33:54Z", "published": "2022-09-22T00:00:23Z", "aliases": [ "CVE-2022-29800" diff --git a/advisories/unreviewed/2022/09/GHSA-8wrc-9xqr-5ph9/GHSA-8wrc-9xqr-5ph9.json b/advisories/unreviewed/2022/09/GHSA-8wrc-9xqr-5ph9/GHSA-8wrc-9xqr-5ph9.json index c857fd4217f..8996e8a577f 100644 --- a/advisories/unreviewed/2022/09/GHSA-8wrc-9xqr-5ph9/GHSA-8wrc-9xqr-5ph9.json +++ b/advisories/unreviewed/2022/09/GHSA-8wrc-9xqr-5ph9/GHSA-8wrc-9xqr-5ph9.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-88" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/09/GHSA-m8ph-q5j2-m8w7/GHSA-m8ph-q5j2-m8w7.json b/advisories/unreviewed/2022/09/GHSA-m8ph-q5j2-m8w7/GHSA-m8ph-q5j2-m8w7.json index f905f0e850c..4ccf13a587b 100644 --- a/advisories/unreviewed/2022/09/GHSA-m8ph-q5j2-m8w7/GHSA-m8ph-q5j2-m8w7.json +++ b/advisories/unreviewed/2022/09/GHSA-m8ph-q5j2-m8w7/GHSA-m8ph-q5j2-m8w7.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-7w5v-94w3-9cq7/GHSA-7w5v-94w3-9cq7.json b/advisories/unreviewed/2023/01/GHSA-7w5v-94w3-9cq7/GHSA-7w5v-94w3-9cq7.json index 206eaae5ea9..04863f382ff 100644 --- a/advisories/unreviewed/2023/01/GHSA-7w5v-94w3-9cq7/GHSA-7w5v-94w3-9cq7.json +++ b/advisories/unreviewed/2023/01/GHSA-7w5v-94w3-9cq7/GHSA-7w5v-94w3-9cq7.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/12/GHSA-34vj-g8wc-6443/GHSA-34vj-g8wc-6443.json b/advisories/unreviewed/2023/12/GHSA-34vj-g8wc-6443/GHSA-34vj-g8wc-6443.json index 6309e82ff62..f4696f9019d 100644 --- a/advisories/unreviewed/2023/12/GHSA-34vj-g8wc-6443/GHSA-34vj-g8wc-6443.json +++ b/advisories/unreviewed/2023/12/GHSA-34vj-g8wc-6443/GHSA-34vj-g8wc-6443.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-34vj-g8wc-6443", - "modified": "2023-12-12T18:31:33Z", + "modified": "2025-05-28T15:33:55Z", "published": "2023-12-07T09:30:44Z", "aliases": [ "CVE-2023-49225" diff --git a/advisories/unreviewed/2024/04/GHSA-f8q2-j8xf-7xhh/GHSA-f8q2-j8xf-7xhh.json b/advisories/unreviewed/2024/04/GHSA-f8q2-j8xf-7xhh/GHSA-f8q2-j8xf-7xhh.json index ba8fcd9831f..d5cdd432013 100644 --- a/advisories/unreviewed/2024/04/GHSA-f8q2-j8xf-7xhh/GHSA-f8q2-j8xf-7xhh.json +++ b/advisories/unreviewed/2024/04/GHSA-f8q2-j8xf-7xhh/GHSA-f8q2-j8xf-7xhh.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-79r7-4mh7-v639/GHSA-79r7-4mh7-v639.json b/advisories/unreviewed/2024/12/GHSA-79r7-4mh7-v639/GHSA-79r7-4mh7-v639.json index 7f911781d3b..60a0c22a1e8 100644 --- a/advisories/unreviewed/2024/12/GHSA-79r7-4mh7-v639/GHSA-79r7-4mh7-v639.json +++ b/advisories/unreviewed/2024/12/GHSA-79r7-4mh7-v639/GHSA-79r7-4mh7-v639.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-79r7-4mh7-v639", - "modified": "2024-12-04T12:31:45Z", + "modified": "2025-05-28T15:33:56Z", "published": "2024-12-04T12:31:45Z", "aliases": [ "CVE-2024-52274" ], "details": "Stack-based Buffer Overflow vulnerability in Shenzhen Tenda Technology Co Tenda AC6V2 (setDoubleL2tpConfig->guest_ip_check(overflow arg: mask) modules) allows Overflow Buffers.This issue affects Tenda AC6V2: through 15.03.06.50", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" @@ -26,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-9446-54vc-3xw5/GHSA-9446-54vc-3xw5.json b/advisories/unreviewed/2024/12/GHSA-9446-54vc-3xw5/GHSA-9446-54vc-3xw5.json index eb86cbbcfad..f4d2c140612 100644 --- a/advisories/unreviewed/2024/12/GHSA-9446-54vc-3xw5/GHSA-9446-54vc-3xw5.json +++ b/advisories/unreviewed/2024/12/GHSA-9446-54vc-3xw5/GHSA-9446-54vc-3xw5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9446-54vc-3xw5", - "modified": "2024-12-19T21:31:11Z", + "modified": "2025-05-28T15:33:57Z", "published": "2024-12-19T21:31:11Z", "aliases": [ "CVE-2024-7138" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://community.silabs.com/068Vm00000F9zre" + }, + { + "type": "WEB", + "url": "https://community.silabs.com/068Vm00000I5mjD" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/12/GHSA-jv22-j23g-5gfv/GHSA-jv22-j23g-5gfv.json b/advisories/unreviewed/2024/12/GHSA-jv22-j23g-5gfv/GHSA-jv22-j23g-5gfv.json index 5448b1f0fc2..7f649c89bab 100644 --- a/advisories/unreviewed/2024/12/GHSA-jv22-j23g-5gfv/GHSA-jv22-j23g-5gfv.json +++ b/advisories/unreviewed/2024/12/GHSA-jv22-j23g-5gfv/GHSA-jv22-j23g-5gfv.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jv22-j23g-5gfv", - "modified": "2024-12-04T12:31:45Z", + "modified": "2025-05-28T15:33:56Z", "published": "2024-12-04T12:31:45Z", "aliases": [ "CVE-2024-52273" ], "details": "Stack-based Buffer Overflow vulnerability in Shenzhen Tenda Technology Co Tenda AC6V2 (setDoublePppoeConfig->guest_ip_check(overflow arg: mask) modules) allows Overflow Buffers.This issue affects Tenda AC6V2: through 15.03.06.50", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" @@ -26,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-m2wv-vgv6-f4hv/GHSA-m2wv-vgv6-f4hv.json b/advisories/unreviewed/2024/12/GHSA-m2wv-vgv6-f4hv/GHSA-m2wv-vgv6-f4hv.json index 20b2f94deda..96b2dc62b3e 100644 --- a/advisories/unreviewed/2024/12/GHSA-m2wv-vgv6-f4hv/GHSA-m2wv-vgv6-f4hv.json +++ b/advisories/unreviewed/2024/12/GHSA-m2wv-vgv6-f4hv/GHSA-m2wv-vgv6-f4hv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m2wv-vgv6-f4hv", - "modified": "2024-12-19T21:31:11Z", + "modified": "2025-05-28T15:33:57Z", "published": "2024-12-19T21:31:11Z", "aliases": [ "CVE-2024-7139" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://community.silabs.com/068Vm00000F9zre" + }, + { + "type": "WEB", + "url": "https://community.silabs.com/068Vm00000I5mjD" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/12/GHSA-mwxc-q3ch-vfhx/GHSA-mwxc-q3ch-vfhx.json b/advisories/unreviewed/2024/12/GHSA-mwxc-q3ch-vfhx/GHSA-mwxc-q3ch-vfhx.json index 8823027c29d..6620e250830 100644 --- a/advisories/unreviewed/2024/12/GHSA-mwxc-q3ch-vfhx/GHSA-mwxc-q3ch-vfhx.json +++ b/advisories/unreviewed/2024/12/GHSA-mwxc-q3ch-vfhx/GHSA-mwxc-q3ch-vfhx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mwxc-q3ch-vfhx", - "modified": "2024-12-19T21:31:11Z", + "modified": "2025-05-28T15:33:56Z", "published": "2024-12-19T21:31:11Z", "aliases": [ "CVE-2024-7137" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://community.silabs.com/068Vm00000F9zre" + }, + { + "type": "WEB", + "url": "https://community.silabs.com/068Vm00000I5mjD" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/12/GHSA-p2hx-7wmw-x3vv/GHSA-p2hx-7wmw-x3vv.json b/advisories/unreviewed/2024/12/GHSA-p2hx-7wmw-x3vv/GHSA-p2hx-7wmw-x3vv.json index 7cdf3fb8799..a950bda12bc 100644 --- a/advisories/unreviewed/2024/12/GHSA-p2hx-7wmw-x3vv/GHSA-p2hx-7wmw-x3vv.json +++ b/advisories/unreviewed/2024/12/GHSA-p2hx-7wmw-x3vv/GHSA-p2hx-7wmw-x3vv.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p2hx-7wmw-x3vv", - "modified": "2024-12-04T12:31:45Z", + "modified": "2025-05-28T15:33:56Z", "published": "2024-12-04T12:31:45Z", "aliases": [ "CVE-2024-52272" ], "details": "Stack-based Buffer Overflow vulnerability in Shenzhen Tenda Technology Co Tenda AC6V2 (fromAdvSetLanip(overflow arg:lanMask) modules) allows Overflow Buffers.This issue affects Tenda AC6V2: through 15.03.06.50", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" @@ -26,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-wv6h-2w59-v7m9/GHSA-wv6h-2w59-v7m9.json b/advisories/unreviewed/2024/12/GHSA-wv6h-2w59-v7m9/GHSA-wv6h-2w59-v7m9.json index 0df87c1d5af..ca6ac890527 100644 --- a/advisories/unreviewed/2024/12/GHSA-wv6h-2w59-v7m9/GHSA-wv6h-2w59-v7m9.json +++ b/advisories/unreviewed/2024/12/GHSA-wv6h-2w59-v7m9/GHSA-wv6h-2w59-v7m9.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wv6h-2w59-v7m9", - "modified": "2024-12-04T12:31:45Z", + "modified": "2025-05-28T15:33:56Z", "published": "2024-12-04T12:31:45Z", "aliases": [ "CVE-2024-52275" ], "details": "Stack-based Buffer Overflow vulnerability in Shenzhen Tenda Technology Co Tenda AC6V2 (fromWizardHandle modules) allows Overflow Buffers.This issue affects Tenda AC6V2: through 15.03.06.50.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" @@ -34,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-jj49-w25f-3wxj/GHSA-jj49-w25f-3wxj.json b/advisories/unreviewed/2025/01/GHSA-jj49-w25f-3wxj/GHSA-jj49-w25f-3wxj.json index 31906fd81fd..fa10d5bd1ea 100644 --- a/advisories/unreviewed/2025/01/GHSA-jj49-w25f-3wxj/GHSA-jj49-w25f-3wxj.json +++ b/advisories/unreviewed/2025/01/GHSA-jj49-w25f-3wxj/GHSA-jj49-w25f-3wxj.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-78" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-3h28-663g-h6cx/GHSA-3h28-663g-h6cx.json b/advisories/unreviewed/2025/03/GHSA-3h28-663g-h6cx/GHSA-3h28-663g-h6cx.json index 79a70ae4a4d..c61c0542d10 100644 --- a/advisories/unreviewed/2025/03/GHSA-3h28-663g-h6cx/GHSA-3h28-663g-h6cx.json +++ b/advisories/unreviewed/2025/03/GHSA-3h28-663g-h6cx/GHSA-3h28-663g-h6cx.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-8j69-hcq4-p2fc/GHSA-8j69-hcq4-p2fc.json b/advisories/unreviewed/2025/03/GHSA-8j69-hcq4-p2fc/GHSA-8j69-hcq4-p2fc.json index da6a8058c43..7693f64c057 100644 --- a/advisories/unreviewed/2025/03/GHSA-8j69-hcq4-p2fc/GHSA-8j69-hcq4-p2fc.json +++ b/advisories/unreviewed/2025/03/GHSA-8j69-hcq4-p2fc/GHSA-8j69-hcq4-p2fc.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-hv6q-2vcj-wx97/GHSA-hv6q-2vcj-wx97.json b/advisories/unreviewed/2025/03/GHSA-hv6q-2vcj-wx97/GHSA-hv6q-2vcj-wx97.json index 58f004a1b48..03e3c84df17 100644 --- a/advisories/unreviewed/2025/03/GHSA-hv6q-2vcj-wx97/GHSA-hv6q-2vcj-wx97.json +++ b/advisories/unreviewed/2025/03/GHSA-hv6q-2vcj-wx97/GHSA-hv6q-2vcj-wx97.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-v9vj-4w4v-xqvj/GHSA-v9vj-4w4v-xqvj.json b/advisories/unreviewed/2025/03/GHSA-v9vj-4w4v-xqvj/GHSA-v9vj-4w4v-xqvj.json index 05128c63b98..d35d45a9a39 100644 --- a/advisories/unreviewed/2025/03/GHSA-v9vj-4w4v-xqvj/GHSA-v9vj-4w4v-xqvj.json +++ b/advisories/unreviewed/2025/03/GHSA-v9vj-4w4v-xqvj/GHSA-v9vj-4w4v-xqvj.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-wjw9-vpcj-v7j3/GHSA-wjw9-vpcj-v7j3.json b/advisories/unreviewed/2025/03/GHSA-wjw9-vpcj-v7j3/GHSA-wjw9-vpcj-v7j3.json index 4e9f0c0e7cc..510f8ba6ac6 100644 --- a/advisories/unreviewed/2025/03/GHSA-wjw9-vpcj-v7j3/GHSA-wjw9-vpcj-v7j3.json +++ b/advisories/unreviewed/2025/03/GHSA-wjw9-vpcj-v7j3/GHSA-wjw9-vpcj-v7j3.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-5jfr-9rr4-m9qm/GHSA-5jfr-9rr4-m9qm.json b/advisories/unreviewed/2025/04/GHSA-5jfr-9rr4-m9qm/GHSA-5jfr-9rr4-m9qm.json index 08d8ab97f0f..e61b36c1e5a 100644 --- a/advisories/unreviewed/2025/04/GHSA-5jfr-9rr4-m9qm/GHSA-5jfr-9rr4-m9qm.json +++ b/advisories/unreviewed/2025/04/GHSA-5jfr-9rr4-m9qm/GHSA-5jfr-9rr4-m9qm.json @@ -54,7 +54,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-125" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-hj96-872g-wqc5/GHSA-hj96-872g-wqc5.json b/advisories/unreviewed/2025/04/GHSA-hj96-872g-wqc5/GHSA-hj96-872g-wqc5.json index 48a0fbed11d..6ebff732142 100644 --- a/advisories/unreviewed/2025/04/GHSA-hj96-872g-wqc5/GHSA-hj96-872g-wqc5.json +++ b/advisories/unreviewed/2025/04/GHSA-hj96-872g-wqc5/GHSA-hj96-872g-wqc5.json @@ -50,7 +50,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-345f-895w-jg76/GHSA-345f-895w-jg76.json b/advisories/unreviewed/2025/05/GHSA-345f-895w-jg76/GHSA-345f-895w-jg76.json index 6b161798bce..4ef6706d41f 100644 --- a/advisories/unreviewed/2025/05/GHSA-345f-895w-jg76/GHSA-345f-895w-jg76.json +++ b/advisories/unreviewed/2025/05/GHSA-345f-895w-jg76/GHSA-345f-895w-jg76.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-3h37-cc2v-wm7x/GHSA-3h37-cc2v-wm7x.json b/advisories/unreviewed/2025/05/GHSA-3h37-cc2v-wm7x/GHSA-3h37-cc2v-wm7x.json index 654b5b3cb1f..699de5ceb1c 100644 --- a/advisories/unreviewed/2025/05/GHSA-3h37-cc2v-wm7x/GHSA-3h37-cc2v-wm7x.json +++ b/advisories/unreviewed/2025/05/GHSA-3h37-cc2v-wm7x/GHSA-3h37-cc2v-wm7x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3h37-cc2v-wm7x", - "modified": "2025-05-02T09:30:35Z", + "modified": "2025-05-28T15:33:59Z", "published": "2025-05-02T09:30:35Z", "aliases": [ "CVE-2025-2812" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2812" }, + { + "type": "WEB", + "url": "https://github.com/sahici/CVE-2025-2812" + }, { "type": "WEB", "url": "https://www.usom.gov.tr/bildirim/tr-25-0099" diff --git a/advisories/unreviewed/2025/05/GHSA-42jj-4cc5-rm9v/GHSA-42jj-4cc5-rm9v.json b/advisories/unreviewed/2025/05/GHSA-42jj-4cc5-rm9v/GHSA-42jj-4cc5-rm9v.json index cbfbda78225..6b311b1cd3f 100644 --- a/advisories/unreviewed/2025/05/GHSA-42jj-4cc5-rm9v/GHSA-42jj-4cc5-rm9v.json +++ b/advisories/unreviewed/2025/05/GHSA-42jj-4cc5-rm9v/GHSA-42jj-4cc5-rm9v.json @@ -46,6 +46,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-548" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/05/GHSA-45cr-hmqj-f6p9/GHSA-45cr-hmqj-f6p9.json b/advisories/unreviewed/2025/05/GHSA-45cr-hmqj-f6p9/GHSA-45cr-hmqj-f6p9.json index c02e0946e83..5fb83dc2109 100644 --- a/advisories/unreviewed/2025/05/GHSA-45cr-hmqj-f6p9/GHSA-45cr-hmqj-f6p9.json +++ b/advisories/unreviewed/2025/05/GHSA-45cr-hmqj-f6p9/GHSA-45cr-hmqj-f6p9.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-4g9c-v26v-gp27/GHSA-4g9c-v26v-gp27.json b/advisories/unreviewed/2025/05/GHSA-4g9c-v26v-gp27/GHSA-4g9c-v26v-gp27.json index ae4c0e57407..a86bd683afa 100644 --- a/advisories/unreviewed/2025/05/GHSA-4g9c-v26v-gp27/GHSA-4g9c-v26v-gp27.json +++ b/advisories/unreviewed/2025/05/GHSA-4g9c-v26v-gp27/GHSA-4g9c-v26v-gp27.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4g9c-v26v-gp27", - "modified": "2025-05-27T21:32:16Z", + "modified": "2025-05-28T15:34:28Z", "published": "2025-05-27T21:32:16Z", "aliases": [ "CVE-2025-5064" ], "details": "Inappropriate implementation in Background Fetch API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-27T21:15:22Z" diff --git a/advisories/unreviewed/2025/05/GHSA-5474-xcxr-hq89/GHSA-5474-xcxr-hq89.json b/advisories/unreviewed/2025/05/GHSA-5474-xcxr-hq89/GHSA-5474-xcxr-hq89.json index c68f55e6590..eb016d94a9e 100644 --- a/advisories/unreviewed/2025/05/GHSA-5474-xcxr-hq89/GHSA-5474-xcxr-hq89.json +++ b/advisories/unreviewed/2025/05/GHSA-5474-xcxr-hq89/GHSA-5474-xcxr-hq89.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-5qj4-xfp4-j9m4/GHSA-5qj4-xfp4-j9m4.json b/advisories/unreviewed/2025/05/GHSA-5qj4-xfp4-j9m4/GHSA-5qj4-xfp4-j9m4.json index a31bce4d820..aca0851c6bf 100644 --- a/advisories/unreviewed/2025/05/GHSA-5qj4-xfp4-j9m4/GHSA-5qj4-xfp4-j9m4.json +++ b/advisories/unreviewed/2025/05/GHSA-5qj4-xfp4-j9m4/GHSA-5qj4-xfp4-j9m4.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-6jfj-hxvq-rv4x/GHSA-6jfj-hxvq-rv4x.json b/advisories/unreviewed/2025/05/GHSA-6jfj-hxvq-rv4x/GHSA-6jfj-hxvq-rv4x.json index 5bc8172365b..517f1549611 100644 --- a/advisories/unreviewed/2025/05/GHSA-6jfj-hxvq-rv4x/GHSA-6jfj-hxvq-rv4x.json +++ b/advisories/unreviewed/2025/05/GHSA-6jfj-hxvq-rv4x/GHSA-6jfj-hxvq-rv4x.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-6vq9-m5rh-wvx5/GHSA-6vq9-m5rh-wvx5.json b/advisories/unreviewed/2025/05/GHSA-6vq9-m5rh-wvx5/GHSA-6vq9-m5rh-wvx5.json index a43ed7d39d3..14a68eb7f90 100644 --- a/advisories/unreviewed/2025/05/GHSA-6vq9-m5rh-wvx5/GHSA-6vq9-m5rh-wvx5.json +++ b/advisories/unreviewed/2025/05/GHSA-6vq9-m5rh-wvx5/GHSA-6vq9-m5rh-wvx5.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-434" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-78gr-w2ph-m22p/GHSA-78gr-w2ph-m22p.json b/advisories/unreviewed/2025/05/GHSA-78gr-w2ph-m22p/GHSA-78gr-w2ph-m22p.json index c8d7c994859..1d571e33e47 100644 --- a/advisories/unreviewed/2025/05/GHSA-78gr-w2ph-m22p/GHSA-78gr-w2ph-m22p.json +++ b/advisories/unreviewed/2025/05/GHSA-78gr-w2ph-m22p/GHSA-78gr-w2ph-m22p.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-78m4-4wrg-v443/GHSA-78m4-4wrg-v443.json b/advisories/unreviewed/2025/05/GHSA-78m4-4wrg-v443/GHSA-78m4-4wrg-v443.json index fb5101740c9..cf35d2b2550 100644 --- a/advisories/unreviewed/2025/05/GHSA-78m4-4wrg-v443/GHSA-78m4-4wrg-v443.json +++ b/advisories/unreviewed/2025/05/GHSA-78m4-4wrg-v443/GHSA-78m4-4wrg-v443.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-78m4-4wrg-v443", - "modified": "2025-05-27T21:32:16Z", + "modified": "2025-05-28T15:34:29Z", "published": "2025-05-27T21:32:16Z", "aliases": [ "CVE-2025-5065" ], "details": "Inappropriate implementation in FileSystemAccess API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-451" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-27T21:15:22Z" diff --git a/advisories/unreviewed/2025/05/GHSA-7fvh-65xr-g9fx/GHSA-7fvh-65xr-g9fx.json b/advisories/unreviewed/2025/05/GHSA-7fvh-65xr-g9fx/GHSA-7fvh-65xr-g9fx.json index 516c66776ae..bd5553bd27d 100644 --- a/advisories/unreviewed/2025/05/GHSA-7fvh-65xr-g9fx/GHSA-7fvh-65xr-g9fx.json +++ b/advisories/unreviewed/2025/05/GHSA-7fvh-65xr-g9fx/GHSA-7fvh-65xr-g9fx.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-7gvx-rvmq-cw57/GHSA-7gvx-rvmq-cw57.json b/advisories/unreviewed/2025/05/GHSA-7gvx-rvmq-cw57/GHSA-7gvx-rvmq-cw57.json index a33863f1d5b..3c81d17fce5 100644 --- a/advisories/unreviewed/2025/05/GHSA-7gvx-rvmq-cw57/GHSA-7gvx-rvmq-cw57.json +++ b/advisories/unreviewed/2025/05/GHSA-7gvx-rvmq-cw57/GHSA-7gvx-rvmq-cw57.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-548" + "CWE-548", + "CWE-552" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-89cv-jc38-p2qw/GHSA-89cv-jc38-p2qw.json b/advisories/unreviewed/2025/05/GHSA-89cv-jc38-p2qw/GHSA-89cv-jc38-p2qw.json index 31d0674c2fa..fc382f22b5d 100644 --- a/advisories/unreviewed/2025/05/GHSA-89cv-jc38-p2qw/GHSA-89cv-jc38-p2qw.json +++ b/advisories/unreviewed/2025/05/GHSA-89cv-jc38-p2qw/GHSA-89cv-jc38-p2qw.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-8fmf-wf4h-2xc8/GHSA-8fmf-wf4h-2xc8.json b/advisories/unreviewed/2025/05/GHSA-8fmf-wf4h-2xc8/GHSA-8fmf-wf4h-2xc8.json index de94bebdea6..3340ee2eff2 100644 --- a/advisories/unreviewed/2025/05/GHSA-8fmf-wf4h-2xc8/GHSA-8fmf-wf4h-2xc8.json +++ b/advisories/unreviewed/2025/05/GHSA-8fmf-wf4h-2xc8/GHSA-8fmf-wf4h-2xc8.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-434" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-8jf4-jjhg-xf85/GHSA-8jf4-jjhg-xf85.json b/advisories/unreviewed/2025/05/GHSA-8jf4-jjhg-xf85/GHSA-8jf4-jjhg-xf85.json index 9a313f9ac6e..02660ee03e7 100644 --- a/advisories/unreviewed/2025/05/GHSA-8jf4-jjhg-xf85/GHSA-8jf4-jjhg-xf85.json +++ b/advisories/unreviewed/2025/05/GHSA-8jf4-jjhg-xf85/GHSA-8jf4-jjhg-xf85.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-8xp4-g6hr-p494/GHSA-8xp4-g6hr-p494.json b/advisories/unreviewed/2025/05/GHSA-8xp4-g6hr-p494/GHSA-8xp4-g6hr-p494.json index c2976327c0f..1912b540034 100644 --- a/advisories/unreviewed/2025/05/GHSA-8xp4-g6hr-p494/GHSA-8xp4-g6hr-p494.json +++ b/advisories/unreviewed/2025/05/GHSA-8xp4-g6hr-p494/GHSA-8xp4-g6hr-p494.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-955v-h2r9-q4cw/GHSA-955v-h2r9-q4cw.json b/advisories/unreviewed/2025/05/GHSA-955v-h2r9-q4cw/GHSA-955v-h2r9-q4cw.json index 203a89ec605..8619124a74f 100644 --- a/advisories/unreviewed/2025/05/GHSA-955v-h2r9-q4cw/GHSA-955v-h2r9-q4cw.json +++ b/advisories/unreviewed/2025/05/GHSA-955v-h2r9-q4cw/GHSA-955v-h2r9-q4cw.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-95xc-5cxv-mp93/GHSA-95xc-5cxv-mp93.json b/advisories/unreviewed/2025/05/GHSA-95xc-5cxv-mp93/GHSA-95xc-5cxv-mp93.json index cdd5f1a00fa..36d176cdb32 100644 --- a/advisories/unreviewed/2025/05/GHSA-95xc-5cxv-mp93/GHSA-95xc-5cxv-mp93.json +++ b/advisories/unreviewed/2025/05/GHSA-95xc-5cxv-mp93/GHSA-95xc-5cxv-mp93.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-989c-235q-c52g/GHSA-989c-235q-c52g.json b/advisories/unreviewed/2025/05/GHSA-989c-235q-c52g/GHSA-989c-235q-c52g.json index a49be2391f2..ee0b91d7af7 100644 --- a/advisories/unreviewed/2025/05/GHSA-989c-235q-c52g/GHSA-989c-235q-c52g.json +++ b/advisories/unreviewed/2025/05/GHSA-989c-235q-c52g/GHSA-989c-235q-c52g.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-9c4g-4r76-5rq7/GHSA-9c4g-4r76-5rq7.json b/advisories/unreviewed/2025/05/GHSA-9c4g-4r76-5rq7/GHSA-9c4g-4r76-5rq7.json index d2f6d4292f4..15e82079fd7 100644 --- a/advisories/unreviewed/2025/05/GHSA-9c4g-4r76-5rq7/GHSA-9c4g-4r76-5rq7.json +++ b/advisories/unreviewed/2025/05/GHSA-9c4g-4r76-5rq7/GHSA-9c4g-4r76-5rq7.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-9hcm-55mc-5fmj/GHSA-9hcm-55mc-5fmj.json b/advisories/unreviewed/2025/05/GHSA-9hcm-55mc-5fmj/GHSA-9hcm-55mc-5fmj.json new file mode 100644 index 00000000000..3f49b47043e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9hcm-55mc-5fmj/GHSA-9hcm-55mc-5fmj.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9hcm-55mc-5fmj", + "modified": "2025-05-28T15:34:33Z", + "published": "2025-05-28T15:34:33Z", + "aliases": [ + "CVE-2025-45997" + ], + "details": "Sourcecodester Web-based Pharmacy Product Management System v.1.0 has a file upload vulnerability. An attacker can upload a PHP file disguised as an image by modifying the Content-Type header to image/jpg.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45997" + }, + { + "type": "WEB", + "url": "https://github.com/litsasuk/CVE-POC/blob/main/CVE-2025-45997.md" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com/php/17883/web-based-product-alert-system.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T14:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9x5p-gmqf-87ww/GHSA-9x5p-gmqf-87ww.json b/advisories/unreviewed/2025/05/GHSA-9x5p-gmqf-87ww/GHSA-9x5p-gmqf-87ww.json index babd84a22d8..33b699f96c4 100644 --- a/advisories/unreviewed/2025/05/GHSA-9x5p-gmqf-87ww/GHSA-9x5p-gmqf-87ww.json +++ b/advisories/unreviewed/2025/05/GHSA-9x5p-gmqf-87ww/GHSA-9x5p-gmqf-87ww.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-c82m-4wjj-w8fw/GHSA-c82m-4wjj-w8fw.json b/advisories/unreviewed/2025/05/GHSA-c82m-4wjj-w8fw/GHSA-c82m-4wjj-w8fw.json index bd49a60cae5..ab4f8f49144 100644 --- a/advisories/unreviewed/2025/05/GHSA-c82m-4wjj-w8fw/GHSA-c82m-4wjj-w8fw.json +++ b/advisories/unreviewed/2025/05/GHSA-c82m-4wjj-w8fw/GHSA-c82m-4wjj-w8fw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c82m-4wjj-w8fw", - "modified": "2025-05-27T21:32:17Z", + "modified": "2025-05-28T15:34:29Z", "published": "2025-05-27T21:32:17Z", "aliases": [ "CVE-2025-5280" ], "details": "Out of bounds write in V8 in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-27T21:15:23Z" diff --git a/advisories/unreviewed/2025/05/GHSA-cj5g-8945-q3rg/GHSA-cj5g-8945-q3rg.json b/advisories/unreviewed/2025/05/GHSA-cj5g-8945-q3rg/GHSA-cj5g-8945-q3rg.json new file mode 100644 index 00000000000..e4d2bd0d708 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-cj5g-8945-q3rg/GHSA-cj5g-8945-q3rg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cj5g-8945-q3rg", + "modified": "2025-05-28T15:34:34Z", + "published": "2025-05-28T15:34:34Z", + "aliases": [ + "CVE-2025-4134" + ], + "details": "Lack of file validation in do_update_vps in Avast Business Antivirus for Linux 4.5 on Linux allows local user to spoof or tamper with the update file via an unverified file write.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4134" + }, + { + "type": "WEB", + "url": "https://www.gendigital.com/us/en/contact-us/security-advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-552" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T14:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-f5w7-cjpw-qq45/GHSA-f5w7-cjpw-qq45.json b/advisories/unreviewed/2025/05/GHSA-f5w7-cjpw-qq45/GHSA-f5w7-cjpw-qq45.json new file mode 100644 index 00000000000..6f6b5651fbf --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-f5w7-cjpw-qq45/GHSA-f5w7-cjpw-qq45.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f5w7-cjpw-qq45", + "modified": "2025-05-28T15:34:34Z", + "published": "2025-05-28T15:34:34Z", + "aliases": [ + "CVE-2025-3357" + ], + "details": "IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 19 could allow a remote attacker to execute arbitrary code due to improper validation of an index value of a dynamically allocated array.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3357" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7234923" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1285" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T15:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fwg2-cw8q-4fc7/GHSA-fwg2-cw8q-4fc7.json b/advisories/unreviewed/2025/05/GHSA-fwg2-cw8q-4fc7/GHSA-fwg2-cw8q-4fc7.json index a42c3c6b5cd..70104ea1ea8 100644 --- a/advisories/unreviewed/2025/05/GHSA-fwg2-cw8q-4fc7/GHSA-fwg2-cw8q-4fc7.json +++ b/advisories/unreviewed/2025/05/GHSA-fwg2-cw8q-4fc7/GHSA-fwg2-cw8q-4fc7.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-g3gr-c6vj-5j9j/GHSA-g3gr-c6vj-5j9j.json b/advisories/unreviewed/2025/05/GHSA-g3gr-c6vj-5j9j/GHSA-g3gr-c6vj-5j9j.json index 3afbce1a609..9639869534d 100644 --- a/advisories/unreviewed/2025/05/GHSA-g3gr-c6vj-5j9j/GHSA-g3gr-c6vj-5j9j.json +++ b/advisories/unreviewed/2025/05/GHSA-g3gr-c6vj-5j9j/GHSA-g3gr-c6vj-5j9j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g3gr-c6vj-5j9j", - "modified": "2025-05-27T21:32:17Z", + "modified": "2025-05-28T15:34:29Z", "published": "2025-05-27T21:32:17Z", "aliases": [ "CVE-2025-5066" ], "details": "Inappropriate implementation in Messages in Google Chrome on Android prior to 137.0.7151.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-451" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-27T21:15:22Z" diff --git a/advisories/unreviewed/2025/05/GHSA-g8h9-5wwm-pj6c/GHSA-g8h9-5wwm-pj6c.json b/advisories/unreviewed/2025/05/GHSA-g8h9-5wwm-pj6c/GHSA-g8h9-5wwm-pj6c.json index 8c63c0a1aaf..c622b843ad0 100644 --- a/advisories/unreviewed/2025/05/GHSA-g8h9-5wwm-pj6c/GHSA-g8h9-5wwm-pj6c.json +++ b/advisories/unreviewed/2025/05/GHSA-g8h9-5wwm-pj6c/GHSA-g8h9-5wwm-pj6c.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-gffr-g4h9-f8x5/GHSA-gffr-g4h9-f8x5.json b/advisories/unreviewed/2025/05/GHSA-gffr-g4h9-f8x5/GHSA-gffr-g4h9-f8x5.json new file mode 100644 index 00000000000..5e2b0f1c143 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gffr-g4h9-f8x5/GHSA-gffr-g4h9-f8x5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gffr-g4h9-f8x5", + "modified": "2025-05-28T15:34:33Z", + "published": "2025-05-28T15:34:33Z", + "aliases": [ + "CVE-2025-4493" + ], + "details": "Improper privilege assignment in PAM JIT privilege sets in Devolutions \nServer allows a PAM user to perform PAM JIT \nrequests on unauthorized groups by exploiting a user interface issue.\n\n\nThis issue affects the following versions : \n\n * Devolutions Server 2025.1.3.0 through 2025.1.7.0\n * Devolutions Server 2024.3.15.0 and earlier", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4493" + }, + { + "type": "WEB", + "url": "https://devolutions.net/security/advisories/DEVO-2025-0008" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T13:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gvh9-8j24-6gg5/GHSA-gvh9-8j24-6gg5.json b/advisories/unreviewed/2025/05/GHSA-gvh9-8j24-6gg5/GHSA-gvh9-8j24-6gg5.json new file mode 100644 index 00000000000..acfe8070836 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gvh9-8j24-6gg5/GHSA-gvh9-8j24-6gg5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gvh9-8j24-6gg5", + "modified": "2025-05-28T15:34:33Z", + "published": "2025-05-28T15:34:33Z", + "aliases": [ + "CVE-2025-40651" + ], + "details": "Reflected Cross-Site Scripting (XSS) vulnerability in Real Easy Store. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the keyword parameter in /index.php?a=search. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40651" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/reflected-cross-site-scripting-xss-real-easy-store" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T14:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hqjf-gj2q-64ch/GHSA-hqjf-gj2q-64ch.json b/advisories/unreviewed/2025/05/GHSA-hqjf-gj2q-64ch/GHSA-hqjf-gj2q-64ch.json index df525ca1355..a6bb0738e4a 100644 --- a/advisories/unreviewed/2025/05/GHSA-hqjf-gj2q-64ch/GHSA-hqjf-gj2q-64ch.json +++ b/advisories/unreviewed/2025/05/GHSA-hqjf-gj2q-64ch/GHSA-hqjf-gj2q-64ch.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hqjf-gj2q-64ch", - "modified": "2025-05-27T21:32:17Z", + "modified": "2025-05-28T15:34:28Z", "published": "2025-05-27T21:32:17Z", "aliases": [ "CVE-2025-5281" ], "details": "Inappropriate implementation in BFCache in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially obtain user information via a crafted HTML page. (Chromium security severity: Medium)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-27T21:15:23Z" diff --git a/advisories/unreviewed/2025/05/GHSA-j2rh-9hjf-9v46/GHSA-j2rh-9hjf-9v46.json b/advisories/unreviewed/2025/05/GHSA-j2rh-9hjf-9v46/GHSA-j2rh-9hjf-9v46.json index f08b4c08972..dfc95077ce6 100644 --- a/advisories/unreviewed/2025/05/GHSA-j2rh-9hjf-9v46/GHSA-j2rh-9hjf-9v46.json +++ b/advisories/unreviewed/2025/05/GHSA-j2rh-9hjf-9v46/GHSA-j2rh-9hjf-9v46.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-121" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-j442-3j4w-vh9f/GHSA-j442-3j4w-vh9f.json b/advisories/unreviewed/2025/05/GHSA-j442-3j4w-vh9f/GHSA-j442-3j4w-vh9f.json index cc5aeed3fa9..b4875620de4 100644 --- a/advisories/unreviewed/2025/05/GHSA-j442-3j4w-vh9f/GHSA-j442-3j4w-vh9f.json +++ b/advisories/unreviewed/2025/05/GHSA-j442-3j4w-vh9f/GHSA-j442-3j4w-vh9f.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-j84v-78j2-55gh/GHSA-j84v-78j2-55gh.json b/advisories/unreviewed/2025/05/GHSA-j84v-78j2-55gh/GHSA-j84v-78j2-55gh.json index ae54acbe511..2ef144fbc08 100644 --- a/advisories/unreviewed/2025/05/GHSA-j84v-78j2-55gh/GHSA-j84v-78j2-55gh.json +++ b/advisories/unreviewed/2025/05/GHSA-j84v-78j2-55gh/GHSA-j84v-78j2-55gh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j84v-78j2-55gh", - "modified": "2025-05-27T21:32:18Z", + "modified": "2025-05-28T15:34:29Z", "published": "2025-05-27T21:32:18Z", "aliases": [ "CVE-2025-5283" ], "details": "Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-27T21:15:23Z" diff --git a/advisories/unreviewed/2025/05/GHSA-jgrx-7c84-m3h2/GHSA-jgrx-7c84-m3h2.json b/advisories/unreviewed/2025/05/GHSA-jgrx-7c84-m3h2/GHSA-jgrx-7c84-m3h2.json index be102b39f6e..24e9056cd83 100644 --- a/advisories/unreviewed/2025/05/GHSA-jgrx-7c84-m3h2/GHSA-jgrx-7c84-m3h2.json +++ b/advisories/unreviewed/2025/05/GHSA-jgrx-7c84-m3h2/GHSA-jgrx-7c84-m3h2.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-jqh7-h346-vm4j/GHSA-jqh7-h346-vm4j.json b/advisories/unreviewed/2025/05/GHSA-jqh7-h346-vm4j/GHSA-jqh7-h346-vm4j.json index ca492152dbf..5932ae4755c 100644 --- a/advisories/unreviewed/2025/05/GHSA-jqh7-h346-vm4j/GHSA-jqh7-h346-vm4j.json +++ b/advisories/unreviewed/2025/05/GHSA-jqh7-h346-vm4j/GHSA-jqh7-h346-vm4j.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-mjmf-7vj6-xw78/GHSA-mjmf-7vj6-xw78.json b/advisories/unreviewed/2025/05/GHSA-mjmf-7vj6-xw78/GHSA-mjmf-7vj6-xw78.json index ac9dcd6104b..655dd1638a9 100644 --- a/advisories/unreviewed/2025/05/GHSA-mjmf-7vj6-xw78/GHSA-mjmf-7vj6-xw78.json +++ b/advisories/unreviewed/2025/05/GHSA-mjmf-7vj6-xw78/GHSA-mjmf-7vj6-xw78.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-p5gc-747c-w32p/GHSA-p5gc-747c-w32p.json b/advisories/unreviewed/2025/05/GHSA-p5gc-747c-w32p/GHSA-p5gc-747c-w32p.json index b4078f05019..7ed422328a2 100644 --- a/advisories/unreviewed/2025/05/GHSA-p5gc-747c-w32p/GHSA-p5gc-747c-w32p.json +++ b/advisories/unreviewed/2025/05/GHSA-p5gc-747c-w32p/GHSA-p5gc-747c-w32p.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-p745-hrr6-rg8c/GHSA-p745-hrr6-rg8c.json b/advisories/unreviewed/2025/05/GHSA-p745-hrr6-rg8c/GHSA-p745-hrr6-rg8c.json index 1c3d03fa525..706e5060a42 100644 --- a/advisories/unreviewed/2025/05/GHSA-p745-hrr6-rg8c/GHSA-p745-hrr6-rg8c.json +++ b/advisories/unreviewed/2025/05/GHSA-p745-hrr6-rg8c/GHSA-p745-hrr6-rg8c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p745-hrr6-rg8c", - "modified": "2025-05-28T00:30:35Z", + "modified": "2025-05-28T15:34:29Z", "published": "2025-05-28T00:30:35Z", "aliases": [ "CVE-2025-40911" ], "details": "Net::CIDR::Set versions 0.10 through 0.13 for Perl does not properly handle leading zero characters in IP CIDR address strings, which could allow attackers to bypass access control that is based on IP addresses.\n\nLeading zeros are used to indicate octal numbers, which can confuse users who are intentionally using octal notation, as well as users who believe they are using decimal notation.\n\nNet::CIDR::Set used code from Net::CIDR::Lite, which had a similar vulnerability CVE-2021-47154.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -31,7 +36,7 @@ "cwe_ids": [ "CWE-1287" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-27T22:15:22Z" diff --git a/advisories/unreviewed/2025/05/GHSA-phj4-6g5f-vqcj/GHSA-phj4-6g5f-vqcj.json b/advisories/unreviewed/2025/05/GHSA-phj4-6g5f-vqcj/GHSA-phj4-6g5f-vqcj.json index aba7f71739c..d3a75676c34 100644 --- a/advisories/unreviewed/2025/05/GHSA-phj4-6g5f-vqcj/GHSA-phj4-6g5f-vqcj.json +++ b/advisories/unreviewed/2025/05/GHSA-phj4-6g5f-vqcj/GHSA-phj4-6g5f-vqcj.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-ppfq-jg49-mqj4/GHSA-ppfq-jg49-mqj4.json b/advisories/unreviewed/2025/05/GHSA-ppfq-jg49-mqj4/GHSA-ppfq-jg49-mqj4.json index f623ce24163..da0659a6aac 100644 --- a/advisories/unreviewed/2025/05/GHSA-ppfq-jg49-mqj4/GHSA-ppfq-jg49-mqj4.json +++ b/advisories/unreviewed/2025/05/GHSA-ppfq-jg49-mqj4/GHSA-ppfq-jg49-mqj4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-ppfq-jg49-mqj4", - "modified": "2025-05-28T09:31:26Z", + "modified": "2025-05-28T15:34:32Z", "published": "2025-05-28T09:31:26Z", "aliases": [ "CVE-2025-4947" ], "details": "libcurl accidentally skips the certificate verification for QUIC connections when connecting to a host specified as an IP address in the URL. Therefore, it does not detect impostors or man-in-the-middle attacks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -33,7 +38,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-28T07:15:24Z" diff --git a/advisories/unreviewed/2025/05/GHSA-pwcm-729c-fvpf/GHSA-pwcm-729c-fvpf.json b/advisories/unreviewed/2025/05/GHSA-pwcm-729c-fvpf/GHSA-pwcm-729c-fvpf.json index 2db6a81bf44..5046cb6c88e 100644 --- a/advisories/unreviewed/2025/05/GHSA-pwcm-729c-fvpf/GHSA-pwcm-729c-fvpf.json +++ b/advisories/unreviewed/2025/05/GHSA-pwcm-729c-fvpf/GHSA-pwcm-729c-fvpf.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-q4w4-v939-f8rm/GHSA-q4w4-v939-f8rm.json b/advisories/unreviewed/2025/05/GHSA-q4w4-v939-f8rm/GHSA-q4w4-v939-f8rm.json index 29aabe57e99..c325a851233 100644 --- a/advisories/unreviewed/2025/05/GHSA-q4w4-v939-f8rm/GHSA-q4w4-v939-f8rm.json +++ b/advisories/unreviewed/2025/05/GHSA-q4w4-v939-f8rm/GHSA-q4w4-v939-f8rm.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-r2m3-qfw3-6wmj/GHSA-r2m3-qfw3-6wmj.json b/advisories/unreviewed/2025/05/GHSA-r2m3-qfw3-6wmj/GHSA-r2m3-qfw3-6wmj.json index a11d08d1698..0b1189a7736 100644 --- a/advisories/unreviewed/2025/05/GHSA-r2m3-qfw3-6wmj/GHSA-r2m3-qfw3-6wmj.json +++ b/advisories/unreviewed/2025/05/GHSA-r2m3-qfw3-6wmj/GHSA-r2m3-qfw3-6wmj.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-r9cm-p538-hxc8/GHSA-r9cm-p538-hxc8.json b/advisories/unreviewed/2025/05/GHSA-r9cm-p538-hxc8/GHSA-r9cm-p538-hxc8.json index 7aa956c575a..273d250687b 100644 --- a/advisories/unreviewed/2025/05/GHSA-r9cm-p538-hxc8/GHSA-r9cm-p538-hxc8.json +++ b/advisories/unreviewed/2025/05/GHSA-r9cm-p538-hxc8/GHSA-r9cm-p538-hxc8.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-rp49-qh64-pw4x/GHSA-rp49-qh64-pw4x.json b/advisories/unreviewed/2025/05/GHSA-rp49-qh64-pw4x/GHSA-rp49-qh64-pw4x.json index 605817e92a3..bb7daf3a91a 100644 --- a/advisories/unreviewed/2025/05/GHSA-rp49-qh64-pw4x/GHSA-rp49-qh64-pw4x.json +++ b/advisories/unreviewed/2025/05/GHSA-rp49-qh64-pw4x/GHSA-rp49-qh64-pw4x.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-v69c-p4g4-vw22/GHSA-v69c-p4g4-vw22.json b/advisories/unreviewed/2025/05/GHSA-v69c-p4g4-vw22/GHSA-v69c-p4g4-vw22.json index 3cf73e3cf49..39bc5004e87 100644 --- a/advisories/unreviewed/2025/05/GHSA-v69c-p4g4-vw22/GHSA-v69c-p4g4-vw22.json +++ b/advisories/unreviewed/2025/05/GHSA-v69c-p4g4-vw22/GHSA-v69c-p4g4-vw22.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-vcfj-m4g8-j8jv/GHSA-vcfj-m4g8-j8jv.json b/advisories/unreviewed/2025/05/GHSA-vcfj-m4g8-j8jv/GHSA-vcfj-m4g8-j8jv.json index 33c1bcb504a..ef55287899b 100644 --- a/advisories/unreviewed/2025/05/GHSA-vcfj-m4g8-j8jv/GHSA-vcfj-m4g8-j8jv.json +++ b/advisories/unreviewed/2025/05/GHSA-vcfj-m4g8-j8jv/GHSA-vcfj-m4g8-j8jv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vcfj-m4g8-j8jv", - "modified": "2025-05-27T21:32:17Z", + "modified": "2025-05-28T15:34:29Z", "published": "2025-05-27T21:32:17Z", "aliases": [ "CVE-2025-5067" ], "details": "Inappropriate implementation in Tab Strip in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-290" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-27T21:15:22Z" diff --git a/advisories/unreviewed/2025/05/GHSA-vh6r-wx95-v75w/GHSA-vh6r-wx95-v75w.json b/advisories/unreviewed/2025/05/GHSA-vh6r-wx95-v75w/GHSA-vh6r-wx95-v75w.json index abed30ecbea..5727eaf55f6 100644 --- a/advisories/unreviewed/2025/05/GHSA-vh6r-wx95-v75w/GHSA-vh6r-wx95-v75w.json +++ b/advisories/unreviewed/2025/05/GHSA-vh6r-wx95-v75w/GHSA-vh6r-wx95-v75w.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-w87c-v4h6-r3wj/GHSA-w87c-v4h6-r3wj.json b/advisories/unreviewed/2025/05/GHSA-w87c-v4h6-r3wj/GHSA-w87c-v4h6-r3wj.json index 99149e34411..83201cf582c 100644 --- a/advisories/unreviewed/2025/05/GHSA-w87c-v4h6-r3wj/GHSA-w87c-v4h6-r3wj.json +++ b/advisories/unreviewed/2025/05/GHSA-w87c-v4h6-r3wj/GHSA-w87c-v4h6-r3wj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w87c-v4h6-r3wj", - "modified": "2025-05-27T21:32:16Z", + "modified": "2025-05-28T15:34:28Z", "published": "2025-05-27T21:32:16Z", "aliases": [ "CVE-2025-5063" ], "details": "Use after free in Compositing in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-27T21:15:22Z" diff --git a/advisories/unreviewed/2025/05/GHSA-wcp5-vgqm-h42v/GHSA-wcp5-vgqm-h42v.json b/advisories/unreviewed/2025/05/GHSA-wcp5-vgqm-h42v/GHSA-wcp5-vgqm-h42v.json index 220665a118b..28bbd9b3972 100644 --- a/advisories/unreviewed/2025/05/GHSA-wcp5-vgqm-h42v/GHSA-wcp5-vgqm-h42v.json +++ b/advisories/unreviewed/2025/05/GHSA-wcp5-vgqm-h42v/GHSA-wcp5-vgqm-h42v.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-wxr5-93ph-8wr9/GHSA-wxr5-93ph-8wr9.json b/advisories/unreviewed/2025/05/GHSA-wxr5-93ph-8wr9/GHSA-wxr5-93ph-8wr9.json new file mode 100644 index 00000000000..ca138a9ecab --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wxr5-93ph-8wr9/GHSA-wxr5-93ph-8wr9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wxr5-93ph-8wr9", + "modified": "2025-05-28T15:34:34Z", + "published": "2025-05-28T15:34:34Z", + "aliases": [ + "CVE-2025-48734" + ], + "details": "Improper Access Control vulnerability in Apache Commons.\n\n\n\nA special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default.\n\n\n\n\n\nReleases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty().\nStarting in versions 1.11.0 and 2.0.0-M2 a special BeanIntrospector suppresses the “declaredClass” property. Note that this new BeanIntrospector is enabled by default, but you can disable it to regain the old behavior; see section 2.5 of the user's guide and the unit tests.\n\nThis issue affects Apache Commons BeanUtils 1.x before 1.11.0, and 2.x before 2.0.0-M2.Users of the artifact commons-beanutils:commons-beanutils\n\n 1.x are recommended to upgrade to version 1.11.0, which fixes the issue.\n\n\nUsers of the artifact org.apache.commons:commons-beanutils2\n\n 2.x are recommended to upgrade to version 2.0.0-M2, which fixes the issue.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48734" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/s0hb3jkfj5f3ryx6c57zqtfohb0of1g9" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T14:15:34Z" + } +} \ No newline at end of file