diff --git a/advisories/unreviewed/2022/12/GHSA-2pf6-r9w4-v7hm/GHSA-2pf6-r9w4-v7hm.json b/advisories/unreviewed/2022/12/GHSA-2pf6-r9w4-v7hm/GHSA-2pf6-r9w4-v7hm.json
index a1b64239733..1ded0e01b79 100644
--- a/advisories/unreviewed/2022/12/GHSA-2pf6-r9w4-v7hm/GHSA-2pf6-r9w4-v7hm.json
+++ b/advisories/unreviewed/2022/12/GHSA-2pf6-r9w4-v7hm/GHSA-2pf6-r9w4-v7hm.json
@@ -26,7 +26,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-287"
+ "CWE-287",
+ "CWE-306"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2022/12/GHSA-4jqr-r4vf-pqw6/GHSA-4jqr-r4vf-pqw6.json b/advisories/unreviewed/2022/12/GHSA-4jqr-r4vf-pqw6/GHSA-4jqr-r4vf-pqw6.json
index 0a4371949f3..4a18e0b7428 100644
--- a/advisories/unreviewed/2022/12/GHSA-4jqr-r4vf-pqw6/GHSA-4jqr-r4vf-pqw6.json
+++ b/advisories/unreviewed/2022/12/GHSA-4jqr-r4vf-pqw6/GHSA-4jqr-r4vf-pqw6.json
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-200"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/12/GHSA-4xvh-3f9w-p34q/GHSA-4xvh-3f9w-p34q.json b/advisories/unreviewed/2022/12/GHSA-4xvh-3f9w-p34q/GHSA-4xvh-3f9w-p34q.json
index ec4434420f9..cb2728704da 100644
--- a/advisories/unreviewed/2022/12/GHSA-4xvh-3f9w-p34q/GHSA-4xvh-3f9w-p34q.json
+++ b/advisories/unreviewed/2022/12/GHSA-4xvh-3f9w-p34q/GHSA-4xvh-3f9w-p34q.json
@@ -25,7 +25,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-201"
+ ],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/12/GHSA-63qw-7qhm-cxf4/GHSA-63qw-7qhm-cxf4.json b/advisories/unreviewed/2022/12/GHSA-63qw-7qhm-cxf4/GHSA-63qw-7qhm-cxf4.json
index d4c805ca196..2587bdeadbf 100644
--- a/advisories/unreviewed/2022/12/GHSA-63qw-7qhm-cxf4/GHSA-63qw-7qhm-cxf4.json
+++ b/advisories/unreviewed/2022/12/GHSA-63qw-7qhm-cxf4/GHSA-63qw-7qhm-cxf4.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-63qw-7qhm-cxf4",
- "modified": "2023-01-05T00:30:17Z",
+ "modified": "2025-04-14T15:31:38Z",
"published": "2022-12-26T15:30:24Z",
"aliases": [
"CVE-2022-4268"
diff --git a/advisories/unreviewed/2022/12/GHSA-68hv-qf49-hr4m/GHSA-68hv-qf49-hr4m.json b/advisories/unreviewed/2022/12/GHSA-68hv-qf49-hr4m/GHSA-68hv-qf49-hr4m.json
index 0c3f147bca5..9ac6f38de62 100644
--- a/advisories/unreviewed/2022/12/GHSA-68hv-qf49-hr4m/GHSA-68hv-qf49-hr4m.json
+++ b/advisories/unreviewed/2022/12/GHSA-68hv-qf49-hr4m/GHSA-68hv-qf49-hr4m.json
@@ -26,7 +26,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-287"
+ "CWE-287",
+ "CWE-306"
],
"severity": "LOW",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2022/12/GHSA-7jhg-5v84-7gqc/GHSA-7jhg-5v84-7gqc.json b/advisories/unreviewed/2022/12/GHSA-7jhg-5v84-7gqc/GHSA-7jhg-5v84-7gqc.json
index a551d4a61e4..d4e1a170d5c 100644
--- a/advisories/unreviewed/2022/12/GHSA-7jhg-5v84-7gqc/GHSA-7jhg-5v84-7gqc.json
+++ b/advisories/unreviewed/2022/12/GHSA-7jhg-5v84-7gqc/GHSA-7jhg-5v84-7gqc.json
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
+ "CWE-306",
"CWE-522"
],
"severity": "MODERATE",
diff --git a/advisories/unreviewed/2022/12/GHSA-824h-6hr6-ghh3/GHSA-824h-6hr6-ghh3.json b/advisories/unreviewed/2022/12/GHSA-824h-6hr6-ghh3/GHSA-824h-6hr6-ghh3.json
index 212a7c80096..4e8b35dcd38 100644
--- a/advisories/unreviewed/2022/12/GHSA-824h-6hr6-ghh3/GHSA-824h-6hr6-ghh3.json
+++ b/advisories/unreviewed/2022/12/GHSA-824h-6hr6-ghh3/GHSA-824h-6hr6-ghh3.json
@@ -26,7 +26,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-287"
+ "CWE-287",
+ "CWE-770"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2022/12/GHSA-8h49-w326-p6w9/GHSA-8h49-w326-p6w9.json b/advisories/unreviewed/2022/12/GHSA-8h49-w326-p6w9/GHSA-8h49-w326-p6w9.json
index dc65cab638d..b007141c6e9 100644
--- a/advisories/unreviewed/2022/12/GHSA-8h49-w326-p6w9/GHSA-8h49-w326-p6w9.json
+++ b/advisories/unreviewed/2022/12/GHSA-8h49-w326-p6w9/GHSA-8h49-w326-p6w9.json
@@ -30,6 +30,7 @@
],
"database_specific": {
"cwe_ids": [
+ "CWE-1284",
"CWE-400"
],
"severity": "MODERATE",
diff --git a/advisories/unreviewed/2022/12/GHSA-9mqj-rmc8-938f/GHSA-9mqj-rmc8-938f.json b/advisories/unreviewed/2022/12/GHSA-9mqj-rmc8-938f/GHSA-9mqj-rmc8-938f.json
index 9e8c481e943..08f398544f9 100644
--- a/advisories/unreviewed/2022/12/GHSA-9mqj-rmc8-938f/GHSA-9mqj-rmc8-938f.json
+++ b/advisories/unreviewed/2022/12/GHSA-9mqj-rmc8-938f/GHSA-9mqj-rmc8-938f.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9mqj-rmc8-938f",
- "modified": "2023-01-05T18:30:30Z",
+ "modified": "2025-04-14T15:31:38Z",
"published": "2022-12-27T00:30:27Z",
"aliases": [
"CVE-2022-36664"
diff --git a/advisories/unreviewed/2022/12/GHSA-gqwx-q2cx-gx28/GHSA-gqwx-q2cx-gx28.json b/advisories/unreviewed/2022/12/GHSA-gqwx-q2cx-gx28/GHSA-gqwx-q2cx-gx28.json
index 1d42fc9dcf8..bba9bf6f63e 100644
--- a/advisories/unreviewed/2022/12/GHSA-gqwx-q2cx-gx28/GHSA-gqwx-q2cx-gx28.json
+++ b/advisories/unreviewed/2022/12/GHSA-gqwx-q2cx-gx28/GHSA-gqwx-q2cx-gx28.json
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
+ "CWE-306",
"CWE-522"
],
"severity": "HIGH",
diff --git a/advisories/unreviewed/2022/12/GHSA-h9fm-vg9q-642c/GHSA-h9fm-vg9q-642c.json b/advisories/unreviewed/2022/12/GHSA-h9fm-vg9q-642c/GHSA-h9fm-vg9q-642c.json
index bb8bfb3f465..5f5c3ec41c0 100644
--- a/advisories/unreviewed/2022/12/GHSA-h9fm-vg9q-642c/GHSA-h9fm-vg9q-642c.json
+++ b/advisories/unreviewed/2022/12/GHSA-h9fm-vg9q-642c/GHSA-h9fm-vg9q-642c.json
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
+ "CWE-284",
"CWE-863"
],
"severity": "CRITICAL",
diff --git a/advisories/unreviewed/2022/12/GHSA-x9wg-93qj-qhg4/GHSA-x9wg-93qj-qhg4.json b/advisories/unreviewed/2022/12/GHSA-x9wg-93qj-qhg4/GHSA-x9wg-93qj-qhg4.json
index 711dd8c9411..671005a5929 100644
--- a/advisories/unreviewed/2022/12/GHSA-x9wg-93qj-qhg4/GHSA-x9wg-93qj-qhg4.json
+++ b/advisories/unreviewed/2022/12/GHSA-x9wg-93qj-qhg4/GHSA-x9wg-93qj-qhg4.json
@@ -30,6 +30,7 @@
],
"database_specific": {
"cwe_ids": [
+ "CWE-1284",
"CWE-400"
],
"severity": "MODERATE",
diff --git a/advisories/unreviewed/2024/04/GHSA-4xpx-694q-f2wv/GHSA-4xpx-694q-f2wv.json b/advisories/unreviewed/2024/04/GHSA-4xpx-694q-f2wv/GHSA-4xpx-694q-f2wv.json
index 5fee9015317..6fb43428c69 100644
--- a/advisories/unreviewed/2024/04/GHSA-4xpx-694q-f2wv/GHSA-4xpx-694q-f2wv.json
+++ b/advisories/unreviewed/2024/04/GHSA-4xpx-694q-f2wv/GHSA-4xpx-694q-f2wv.json
@@ -25,7 +25,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/04/GHSA-h335-p3x8-932g/GHSA-h335-p3x8-932g.json b/advisories/unreviewed/2024/04/GHSA-h335-p3x8-932g/GHSA-h335-p3x8-932g.json
index 2528f98a6e4..e6082a06dd5 100644
--- a/advisories/unreviewed/2024/04/GHSA-h335-p3x8-932g/GHSA-h335-p3x8-932g.json
+++ b/advisories/unreviewed/2024/04/GHSA-h335-p3x8-932g/GHSA-h335-p3x8-932g.json
@@ -25,7 +25,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/04/GHSA-jjv2-293m-3wrf/GHSA-jjv2-293m-3wrf.json b/advisories/unreviewed/2024/04/GHSA-jjv2-293m-3wrf/GHSA-jjv2-293m-3wrf.json
index fad8ef9e174..9932fb34cb3 100644
--- a/advisories/unreviewed/2024/04/GHSA-jjv2-293m-3wrf/GHSA-jjv2-293m-3wrf.json
+++ b/advisories/unreviewed/2024/04/GHSA-jjv2-293m-3wrf/GHSA-jjv2-293m-3wrf.json
@@ -25,7 +25,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-352"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/04/GHSA-pjpc-v23w-hch2/GHSA-pjpc-v23w-hch2.json b/advisories/unreviewed/2024/04/GHSA-pjpc-v23w-hch2/GHSA-pjpc-v23w-hch2.json
index 9f84ae096d2..a67bc181f2b 100644
--- a/advisories/unreviewed/2024/04/GHSA-pjpc-v23w-hch2/GHSA-pjpc-v23w-hch2.json
+++ b/advisories/unreviewed/2024/04/GHSA-pjpc-v23w-hch2/GHSA-pjpc-v23w-hch2.json
@@ -25,7 +25,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/04/GHSA-qx35-w84c-98jc/GHSA-qx35-w84c-98jc.json b/advisories/unreviewed/2024/04/GHSA-qx35-w84c-98jc/GHSA-qx35-w84c-98jc.json
index ac36626deec..df03200b60e 100644
--- a/advisories/unreviewed/2024/04/GHSA-qx35-w84c-98jc/GHSA-qx35-w84c-98jc.json
+++ b/advisories/unreviewed/2024/04/GHSA-qx35-w84c-98jc/GHSA-qx35-w84c-98jc.json
@@ -25,7 +25,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/09/GHSA-2p9x-h657-5mg3/GHSA-2p9x-h657-5mg3.json b/advisories/unreviewed/2024/09/GHSA-2p9x-h657-5mg3/GHSA-2p9x-h657-5mg3.json
index 994d3dbb2ba..efeb849e66c 100644
--- a/advisories/unreviewed/2024/09/GHSA-2p9x-h657-5mg3/GHSA-2p9x-h657-5mg3.json
+++ b/advisories/unreviewed/2024/09/GHSA-2p9x-h657-5mg3/GHSA-2p9x-h657-5mg3.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2p9x-h657-5mg3",
- "modified": "2024-09-18T18:30:51Z",
+ "modified": "2025-04-14T15:31:49Z",
"published": "2024-09-18T18:30:51Z",
"aliases": [
"CVE-2023-41611"
],
"details": "Victure PC420 1.1.39 was discovered to use a weak and partially hardcoded key to encrypt data.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-798"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-18T18:15:05Z"
diff --git a/advisories/unreviewed/2025/03/GHSA-gg43-xfqw-xwg6/GHSA-gg43-xfqw-xwg6.json b/advisories/unreviewed/2025/03/GHSA-gg43-xfqw-xwg6/GHSA-gg43-xfqw-xwg6.json
index 78f57df4088..d305c218cb3 100644
--- a/advisories/unreviewed/2025/03/GHSA-gg43-xfqw-xwg6/GHSA-gg43-xfqw-xwg6.json
+++ b/advisories/unreviewed/2025/03/GHSA-gg43-xfqw-xwg6/GHSA-gg43-xfqw-xwg6.json
@@ -42,7 +42,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-119"
+ "CWE-119",
+ "CWE-787"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2025/03/GHSA-h8rm-7p58-mx4h/GHSA-h8rm-7p58-mx4h.json b/advisories/unreviewed/2025/03/GHSA-h8rm-7p58-mx4h/GHSA-h8rm-7p58-mx4h.json
index a7e280d02b5..8edb2672fa5 100644
--- a/advisories/unreviewed/2025/03/GHSA-h8rm-7p58-mx4h/GHSA-h8rm-7p58-mx4h.json
+++ b/advisories/unreviewed/2025/03/GHSA-h8rm-7p58-mx4h/GHSA-h8rm-7p58-mx4h.json
@@ -26,7 +26,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-122"
+ "CWE-122",
+ "CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2025/04/GHSA-2h9w-x423-49m5/GHSA-2h9w-x423-49m5.json b/advisories/unreviewed/2025/04/GHSA-2h9w-x423-49m5/GHSA-2h9w-x423-49m5.json
new file mode 100644
index 00000000000..e016a4b1c6c
--- /dev/null
+++ b/advisories/unreviewed/2025/04/GHSA-2h9w-x423-49m5/GHSA-2h9w-x423-49m5.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-2h9w-x423-49m5",
+ "modified": "2025-04-14T15:31:59Z",
+ "published": "2025-04-14T15:31:59Z",
+ "aliases": [
+ "CVE-2025-2160"
+ ],
+ "details": "Pega Platform versions 8.4.3 to Infinity 24.2.1 are affected by an XSS issue with Mashup",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2160"
+ },
+ {
+ "type": "WEB",
+ "url": "https://support.pega.com/support-doc/pega-security-advisory-d25-vulnerability-remediation-note"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-04-14T15:15:24Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/04/GHSA-537h-95q4-66vj/GHSA-537h-95q4-66vj.json b/advisories/unreviewed/2025/04/GHSA-537h-95q4-66vj/GHSA-537h-95q4-66vj.json
new file mode 100644
index 00000000000..d9094bf8974
--- /dev/null
+++ b/advisories/unreviewed/2025/04/GHSA-537h-95q4-66vj/GHSA-537h-95q4-66vj.json
@@ -0,0 +1,25 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-537h-95q4-66vj",
+ "modified": "2025-04-14T15:31:59Z",
+ "published": "2025-04-14T15:31:59Z",
+ "aliases": [
+ "CVE-2025-32930"
+ ],
+ "details": "Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32930"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-04-14T15:15:25Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/04/GHSA-5hq9-4cph-v2w6/GHSA-5hq9-4cph-v2w6.json b/advisories/unreviewed/2025/04/GHSA-5hq9-4cph-v2w6/GHSA-5hq9-4cph-v2w6.json
new file mode 100644
index 00000000000..98fcdac5b9c
--- /dev/null
+++ b/advisories/unreviewed/2025/04/GHSA-5hq9-4cph-v2w6/GHSA-5hq9-4cph-v2w6.json
@@ -0,0 +1,52 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-5hq9-4cph-v2w6",
+ "modified": "2025-04-14T15:32:00Z",
+ "published": "2025-04-14T15:32:00Z",
+ "aliases": [
+ "CVE-2025-3571"
+ ],
+ "details": "A vulnerability was found in Fannuo Enterprise Content Management System 凡诺企业网站管理系统 1.1/4.0. It has been declared as critical. This vulnerability affects unknown code of the file admin/cms_chip.php. The manipulation of the argument del leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
+ },
+ {
+ "type": "CVSS_V4",
+ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3571"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?ctiid.304612"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?id.304612"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?submit.549927"
+ },
+ {
+ "type": "WEB",
+ "url": "https://wiki.shikangsi.com/post/share/c46c50d3-c8d7-46a0-9fed-8d79a64abb44"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-74"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-04-14T15:15:26Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/04/GHSA-5q67-5hpv-7q5r/GHSA-5q67-5hpv-7q5r.json b/advisories/unreviewed/2025/04/GHSA-5q67-5hpv-7q5r/GHSA-5q67-5hpv-7q5r.json
index 278ce328a7e..994aecec222 100644
--- a/advisories/unreviewed/2025/04/GHSA-5q67-5hpv-7q5r/GHSA-5q67-5hpv-7q5r.json
+++ b/advisories/unreviewed/2025/04/GHSA-5q67-5hpv-7q5r/GHSA-5q67-5hpv-7q5r.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5q67-5hpv-7q5r",
- "modified": "2025-04-14T06:30:24Z",
+ "modified": "2025-04-14T15:31:57Z",
"published": "2025-04-14T06:30:24Z",
"aliases": [
"CVE-2024-9230"
],
"details": "The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.9.18 does not sanitise and escape some of its settings when adding a podcast, which could allow author and above users to perform Stored Cross-Site Scripting attacks",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
"affected": [],
"references": [
{
@@ -21,7 +26,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-14T06:15:15Z"
diff --git a/advisories/unreviewed/2025/04/GHSA-65wf-c9wx-f4v7/GHSA-65wf-c9wx-f4v7.json b/advisories/unreviewed/2025/04/GHSA-65wf-c9wx-f4v7/GHSA-65wf-c9wx-f4v7.json
new file mode 100644
index 00000000000..fe221487a2b
--- /dev/null
+++ b/advisories/unreviewed/2025/04/GHSA-65wf-c9wx-f4v7/GHSA-65wf-c9wx-f4v7.json
@@ -0,0 +1,40 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-65wf-c9wx-f4v7",
+ "modified": "2025-04-14T15:31:59Z",
+ "published": "2025-04-14T15:31:59Z",
+ "aliases": [
+ "CVE-2025-32910"
+ ],
+ "details": "A flaw was found in libsoup, where soup_auth_digest_authenticate() is vulnerable to a NULL pointer dereference. This issue may cause the libsoup client to crash.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32910"
+ },
+ {
+ "type": "WEB",
+ "url": "https://access.redhat.com/security/cve/CVE-2025-32910"
+ },
+ {
+ "type": "WEB",
+ "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359354"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-04-14T15:15:25Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/04/GHSA-6j35-rq42-fv6v/GHSA-6j35-rq42-fv6v.json b/advisories/unreviewed/2025/04/GHSA-6j35-rq42-fv6v/GHSA-6j35-rq42-fv6v.json
index 5238c64e7a3..cc673d283b1 100644
--- a/advisories/unreviewed/2025/04/GHSA-6j35-rq42-fv6v/GHSA-6j35-rq42-fv6v.json
+++ b/advisories/unreviewed/2025/04/GHSA-6j35-rq42-fv6v/GHSA-6j35-rq42-fv6v.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6j35-rq42-fv6v",
- "modified": "2025-04-08T15:31:02Z",
+ "modified": "2025-04-14T15:31:56Z",
"published": "2025-04-07T21:32:08Z",
"aliases": [
"CVE-2025-29087"
@@ -22,6 +22,14 @@
{
"type": "WEB",
"url": "https://gist.github.com/ylwango613/a44a29f1ef074fa783e29f04a0afd62a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://sqlite.org/releaselog/3_49_1.html"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.sqlite.org/cves.html"
}
],
"database_specific": {
diff --git a/advisories/unreviewed/2025/04/GHSA-6rqh-8465-2xcw/GHSA-6rqh-8465-2xcw.json b/advisories/unreviewed/2025/04/GHSA-6rqh-8465-2xcw/GHSA-6rqh-8465-2xcw.json
new file mode 100644
index 00000000000..cefaf645080
--- /dev/null
+++ b/advisories/unreviewed/2025/04/GHSA-6rqh-8465-2xcw/GHSA-6rqh-8465-2xcw.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-6rqh-8465-2xcw",
+ "modified": "2025-04-14T15:31:59Z",
+ "published": "2025-04-14T15:31:59Z",
+ "aliases": [
+ "CVE-2025-2475"
+ ],
+ "details": "Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to invalidate the cache when a user account is converted to a bot which allows an attacker to login to the bot exactly one time via normal credentials.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2475"
+ },
+ {
+ "type": "WEB",
+ "url": "https://mattermost.com/security-updates"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-303"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-04-14T15:15:24Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/04/GHSA-6vrq-h789-6x32/GHSA-6vrq-h789-6x32.json b/advisories/unreviewed/2025/04/GHSA-6vrq-h789-6x32/GHSA-6vrq-h789-6x32.json
new file mode 100644
index 00000000000..ebbc5c89e75
--- /dev/null
+++ b/advisories/unreviewed/2025/04/GHSA-6vrq-h789-6x32/GHSA-6vrq-h789-6x32.json
@@ -0,0 +1,52 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-6vrq-h789-6x32",
+ "modified": "2025-04-14T15:31:59Z",
+ "published": "2025-04-14T15:31:59Z",
+ "aliases": [
+ "CVE-2025-3569"
+ ],
+ "details": "A vulnerability was found in JamesZBL/code-projects db-hospital-drug 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file ShiroConfig.java. The manipulation leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
+ },
+ {
+ "type": "CVSS_V4",
+ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3569"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/buluorifu/Vulnerability-recurrence/blob/main/Refer/db-hospital-drug-authority.md"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?ctiid.304610"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?id.304610"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?submit.549920"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-266"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-04-14T14:15:25Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/04/GHSA-7hqq-7crg-xr49/GHSA-7hqq-7crg-xr49.json b/advisories/unreviewed/2025/04/GHSA-7hqq-7crg-xr49/GHSA-7hqq-7crg-xr49.json
new file mode 100644
index 00000000000..0355c364ed0
--- /dev/null
+++ b/advisories/unreviewed/2025/04/GHSA-7hqq-7crg-xr49/GHSA-7hqq-7crg-xr49.json
@@ -0,0 +1,40 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-7hqq-7crg-xr49",
+ "modified": "2025-04-14T15:31:58Z",
+ "published": "2025-04-14T15:31:58Z",
+ "aliases": [
+ "CVE-2025-32908"
+ ],
+ "details": "A flaw was found in libsoup. The HTTP/2 server in libsoup may not fully validate the values of pseudo-headers :scheme, :authority, and :path, which may allow a user to cause a denial of service (DoS).",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32908"
+ },
+ {
+ "type": "WEB",
+ "url": "https://access.redhat.com/security/cve/CVE-2025-32908"
+ },
+ {
+ "type": "WEB",
+ "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359343"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-115"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-04-14T14:15:24Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/04/GHSA-7wfq-7p2f-6344/GHSA-7wfq-7p2f-6344.json b/advisories/unreviewed/2025/04/GHSA-7wfq-7p2f-6344/GHSA-7wfq-7p2f-6344.json
new file mode 100644
index 00000000000..186b12ddb28
--- /dev/null
+++ b/advisories/unreviewed/2025/04/GHSA-7wfq-7p2f-6344/GHSA-7wfq-7p2f-6344.json
@@ -0,0 +1,40 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-7wfq-7p2f-6344",
+ "modified": "2025-04-14T15:31:58Z",
+ "published": "2025-04-14T15:31:58Z",
+ "aliases": [
+ "CVE-2025-32907"
+ ],
+ "details": "A flaw was found in libsoup. The implementation of HTTP range requests is vulnerable to a resource consumption attack. This flaw allows a malicious client to request the same range many times in a single HTTP request, causing the server to use large amounts of memory.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32907"
+ },
+ {
+ "type": "WEB",
+ "url": "https://access.redhat.com/security/cve/CVE-2025-32907"
+ },
+ {
+ "type": "WEB",
+ "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359342"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-1050"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-04-14T14:15:24Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/04/GHSA-895g-hfqv-8mq5/GHSA-895g-hfqv-8mq5.json b/advisories/unreviewed/2025/04/GHSA-895g-hfqv-8mq5/GHSA-895g-hfqv-8mq5.json
new file mode 100644
index 00000000000..e8854ecc224
--- /dev/null
+++ b/advisories/unreviewed/2025/04/GHSA-895g-hfqv-8mq5/GHSA-895g-hfqv-8mq5.json
@@ -0,0 +1,56 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-895g-hfqv-8mq5",
+ "modified": "2025-04-14T15:31:59Z",
+ "published": "2025-04-14T15:31:59Z",
+ "aliases": [
+ "CVE-2025-3568"
+ ],
+ "details": "A vulnerability has been found in Webkul Krayin CRM up to 2.1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/settings/users/edit/ of the component SVG File Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor prepares a fix for the next major release and explains that he does not think therefore that this should qualify for a CVE.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
+ },
+ {
+ "type": "CVSS_V4",
+ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3568"
+ },
+ {
+ "type": "WEB",
+ "url": "https://drive.google.com/file/d/1LMzZyCgloWquJRWzJAV2bpWMTuiMs6Xa/view?usp=sharing"
+ },
+ {
+ "type": "WEB",
+ "url": "https://gist.github.com/shellkraft/a8b1f35d5c3ba313605065889563fb00"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?ctiid.304609"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?id.304609"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?submit.549591"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-04-14T14:15:25Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/04/GHSA-89g2-jrcc-p8r7/GHSA-89g2-jrcc-p8r7.json b/advisories/unreviewed/2025/04/GHSA-89g2-jrcc-p8r7/GHSA-89g2-jrcc-p8r7.json
new file mode 100644
index 00000000000..febc645a8c8
--- /dev/null
+++ b/advisories/unreviewed/2025/04/GHSA-89g2-jrcc-p8r7/GHSA-89g2-jrcc-p8r7.json
@@ -0,0 +1,40 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-89g2-jrcc-p8r7",
+ "modified": "2025-04-14T15:31:59Z",
+ "published": "2025-04-14T15:31:59Z",
+ "aliases": [
+ "CVE-2025-32914"
+ ],
+ "details": "A flaw was found in libsoup, where the soup_multipart_new_from_message() function is vulnerable to an out-of-bounds read. This flaw allows a malicious HTTP client to induce the libsoup server to read out of bounds.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32914"
+ },
+ {
+ "type": "WEB",
+ "url": "https://access.redhat.com/security/cve/CVE-2025-32914"
+ },
+ {
+ "type": "WEB",
+ "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359358"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-125"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-04-14T15:15:25Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/04/GHSA-9589-mpwg-8xq6/GHSA-9589-mpwg-8xq6.json b/advisories/unreviewed/2025/04/GHSA-9589-mpwg-8xq6/GHSA-9589-mpwg-8xq6.json
new file mode 100644
index 00000000000..d8c22e9c028
--- /dev/null
+++ b/advisories/unreviewed/2025/04/GHSA-9589-mpwg-8xq6/GHSA-9589-mpwg-8xq6.json
@@ -0,0 +1,40 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-9589-mpwg-8xq6",
+ "modified": "2025-04-14T15:31:58Z",
+ "published": "2025-04-14T15:31:58Z",
+ "aliases": [
+ "CVE-2025-32913"
+ ],
+ "details": "A flaw was found in libsoup, where the soup_message_headers_get_content_disposition() function is vulnerable to a NULL pointer dereference. This flaw allows a malicious HTTP peer to crash a libsoup client or server that uses this function.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32913"
+ },
+ {
+ "type": "WEB",
+ "url": "https://access.redhat.com/security/cve/CVE-2025-32913"
+ },
+ {
+ "type": "WEB",
+ "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359357"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-04-14T14:15:24Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/04/GHSA-9r58-7qgh-qjq2/GHSA-9r58-7qgh-qjq2.json b/advisories/unreviewed/2025/04/GHSA-9r58-7qgh-qjq2/GHSA-9r58-7qgh-qjq2.json
new file mode 100644
index 00000000000..477dd7c49c7
--- /dev/null
+++ b/advisories/unreviewed/2025/04/GHSA-9r58-7qgh-qjq2/GHSA-9r58-7qgh-qjq2.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-9r58-7qgh-qjq2",
+ "modified": "2025-04-14T15:31:59Z",
+ "published": "2025-04-14T15:31:59Z",
+ "aliases": [
+ "CVE-2024-49825"
+ ],
+ "details": "IBM Robotic Process Automation and Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.20 and 23.0.0 through 23.0.20 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the system.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49825"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.ibm.com/support/pages/node/7230848"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-613"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-04-14T15:15:23Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/04/GHSA-9v7h-vc98-97mp/GHSA-9v7h-vc98-97mp.json b/advisories/unreviewed/2025/04/GHSA-9v7h-vc98-97mp/GHSA-9v7h-vc98-97mp.json
index 193b69b3a54..40158f207d2 100644
--- a/advisories/unreviewed/2025/04/GHSA-9v7h-vc98-97mp/GHSA-9v7h-vc98-97mp.json
+++ b/advisories/unreviewed/2025/04/GHSA-9v7h-vc98-97mp/GHSA-9v7h-vc98-97mp.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9v7h-vc98-97mp",
- "modified": "2025-04-01T18:30:54Z",
+ "modified": "2025-04-14T15:31:54Z",
"published": "2025-04-01T18:30:54Z",
"aliases": [
"CVE-2025-21969"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: Fix slab-use-after-free Read in l2cap_send_cmd\n\nAfter the hci sync command releases l2cap_conn, the hci receive data work\nqueue references the released l2cap_conn when sending to the upper layer.\nAdd hci dev lock to the hci receive data work queue to synchronize the two.\n\n[1]\nBUG: KASAN: slab-use-after-free in l2cap_send_cmd+0x187/0x8d0 net/bluetooth/l2cap_core.c:954\nRead of size 8 at addr ffff8880271a4000 by task kworker/u9:2/5837\n\nCPU: 0 UID: 0 PID: 5837 Comm: kworker/u9:2 Not tainted 6.13.0-rc5-syzkaller-00163-gab75170520d4 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024\nWorkqueue: hci1 hci_rx_work\nCall Trace:\n \n __dump_stack lib/dump_stack.c:94 [inline]\n dump_stack_lvl+0x241/0x360 lib/dump_stack.c:120\n print_address_description mm/kasan/report.c:378 [inline]\n print_report+0x169/0x550 mm/kasan/report.c:489\n kasan_report+0x143/0x180 mm/kasan/report.c:602\n l2cap_build_cmd net/bluetooth/l2cap_core.c:2964 [inline]\n l2cap_send_cmd+0x187/0x8d0 net/bluetooth/l2cap_core.c:954\n l2cap_sig_send_rej net/bluetooth/l2cap_core.c:5502 [inline]\n l2cap_sig_channel net/bluetooth/l2cap_core.c:5538 [inline]\n l2cap_recv_frame+0x221f/0x10db0 net/bluetooth/l2cap_core.c:6817\n hci_acldata_packet net/bluetooth/hci_core.c:3797 [inline]\n hci_rx_work+0x508/0xdb0 net/bluetooth/hci_core.c:4040\n process_one_work kernel/workqueue.c:3229 [inline]\n process_scheduled_works+0xa66/0x1840 kernel/workqueue.c:3310\n worker_thread+0x870/0xd30 kernel/workqueue.c:3391\n kthread+0x2f0/0x390 kernel/kthread.c:389\n ret_from_fork+0x4b/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244\n \n\nAllocated by task 5837:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x3f/0x80 mm/kasan/common.c:68\n poison_kmalloc_redzone mm/kasan/common.c:377 [inline]\n __kasan_kmalloc+0x98/0xb0 mm/kasan/common.c:394\n kasan_kmalloc include/linux/kasan.h:260 [inline]\n __kmalloc_cache_noprof+0x243/0x390 mm/slub.c:4329\n kmalloc_noprof include/linux/slab.h:901 [inline]\n kzalloc_noprof include/linux/slab.h:1037 [inline]\n l2cap_conn_add+0xa9/0x8e0 net/bluetooth/l2cap_core.c:6860\n l2cap_connect_cfm+0x115/0x1090 net/bluetooth/l2cap_core.c:7239\n hci_connect_cfm include/net/bluetooth/hci_core.h:2057 [inline]\n hci_remote_features_evt+0x68e/0xac0 net/bluetooth/hci_event.c:3726\n hci_event_func net/bluetooth/hci_event.c:7473 [inline]\n hci_event_packet+0xac2/0x1540 net/bluetooth/hci_event.c:7525\n hci_rx_work+0x3f3/0xdb0 net/bluetooth/hci_core.c:4035\n process_one_work kernel/workqueue.c:3229 [inline]\n process_scheduled_works+0xa66/0x1840 kernel/workqueue.c:3310\n worker_thread+0x870/0xd30 kernel/workqueue.c:3391\n kthread+0x2f0/0x390 kernel/kthread.c:389\n ret_from_fork+0x4b/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244\n\nFreed by task 54:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x3f/0x80 mm/kasan/common.c:68\n kasan_save_free_info+0x40/0x50 mm/kasan/generic.c:582\n poison_slab_object mm/kasan/common.c:247 [inline]\n __kasan_slab_free+0x59/0x70 mm/kasan/common.c:264\n kasan_slab_free include/linux/kasan.h:233 [inline]\n slab_free_hook mm/slub.c:2353 [inline]\n slab_free mm/slub.c:4613 [inline]\n kfree+0x196/0x430 mm/slub.c:4761\n l2cap_connect_cfm+0xcc/0x1090 net/bluetooth/l2cap_core.c:7235\n hci_connect_cfm include/net/bluetooth/hci_core.h:2057 [inline]\n hci_conn_failed+0x287/0x400 net/bluetooth/hci_conn.c:1266\n hci_abort_conn_sync+0x56c/0x11f0 net/bluetooth/hci_sync.c:5603\n hci_cmd_sync_work+0x22b/0x400 net/bluetooth/hci_sync.c:332\n process_one_work kernel/workqueue.c:3229 [inline]\n process_scheduled_works+0xa66/0x1840 kernel/workqueue.c:3310\n worker_thread+0x870/0xd30 kernel/workqueue.c:3391\n kthread+0x2f0/0x390 kernel/kthread.c:389\n ret_from_fork+0x4b/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entr\n---truncated---",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -32,8 +37,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-01T16:15:28Z"
diff --git a/advisories/unreviewed/2025/04/GHSA-c9rj-rm8x-wf58/GHSA-c9rj-rm8x-wf58.json b/advisories/unreviewed/2025/04/GHSA-c9rj-rm8x-wf58/GHSA-c9rj-rm8x-wf58.json
new file mode 100644
index 00000000000..888d0c300e3
--- /dev/null
+++ b/advisories/unreviewed/2025/04/GHSA-c9rj-rm8x-wf58/GHSA-c9rj-rm8x-wf58.json
@@ -0,0 +1,52 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-c9rj-rm8x-wf58",
+ "modified": "2025-04-14T15:32:00Z",
+ "published": "2025-04-14T15:32:00Z",
+ "aliases": [
+ "CVE-2025-3570"
+ ],
+ "details": "A vulnerability was found in JamesZBL/code-projects db-hospital-drug 1.0. It has been classified as problematic. This affects the function Save of the file ContentController.java. The manipulation of the argument content leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
+ },
+ {
+ "type": "CVSS_V4",
+ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3570"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/buluorifu/Vulnerability-recurrence/blob/main/Refer/db-hospital-drug-xss.md"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?ctiid.304611"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?id.304611"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?submit.549923"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-04-14T15:15:26Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/04/GHSA-cp5g-5x6r-cmw3/GHSA-cp5g-5x6r-cmw3.json b/advisories/unreviewed/2025/04/GHSA-cp5g-5x6r-cmw3/GHSA-cp5g-5x6r-cmw3.json
new file mode 100644
index 00000000000..732892e3795
--- /dev/null
+++ b/advisories/unreviewed/2025/04/GHSA-cp5g-5x6r-cmw3/GHSA-cp5g-5x6r-cmw3.json
@@ -0,0 +1,52 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-cp5g-5x6r-cmw3",
+ "modified": "2025-04-14T15:31:57Z",
+ "published": "2025-04-14T15:31:57Z",
+ "aliases": [
+ "CVE-2025-3567"
+ ],
+ "details": "A vulnerability, which was classified as problematic, was found in veal98 小牛肉 Echo 开源社区系统 4.2. Affected is the function preHandle of the file src/main/java/com/greate/community/controller/interceptor/LoginTicketInterceptor.java of the component Ticket Handler. The manipulation leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
+ },
+ {
+ "type": "CVSS_V4",
+ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3567"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/caigo8/CVE-md/blob/main/Echo/%E4%B8%8D%E5%AE%89%E5%85%A8%E7%9A%84%E6%9D%83%E9%99%90%E6%A0%A1%E9%AA%8C.md"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?ctiid.304608"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?id.304608"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?submit.549537"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-266"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-04-14T13:15:17Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/04/GHSA-f4vp-qjpg-x8wq/GHSA-f4vp-qjpg-x8wq.json b/advisories/unreviewed/2025/04/GHSA-f4vp-qjpg-x8wq/GHSA-f4vp-qjpg-x8wq.json
new file mode 100644
index 00000000000..0c43f51291e
--- /dev/null
+++ b/advisories/unreviewed/2025/04/GHSA-f4vp-qjpg-x8wq/GHSA-f4vp-qjpg-x8wq.json
@@ -0,0 +1,40 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-f4vp-qjpg-x8wq",
+ "modified": "2025-04-14T15:31:58Z",
+ "published": "2025-04-14T15:31:58Z",
+ "aliases": [
+ "CVE-2025-32906"
+ ],
+ "details": "A flaw was found in libsoup, where the soup_headers_parse_request() function may be vulnerable to an out-of-bound read. This flaw allows a malicious user to use a specially crafted HTTP request to crash the HTTP server.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32906"
+ },
+ {
+ "type": "WEB",
+ "url": "https://access.redhat.com/security/cve/CVE-2025-32906"
+ },
+ {
+ "type": "WEB",
+ "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359341"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-125"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-04-14T14:15:24Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/04/GHSA-fmvm-7g4g-75c2/GHSA-fmvm-7g4g-75c2.json b/advisories/unreviewed/2025/04/GHSA-fmvm-7g4g-75c2/GHSA-fmvm-7g4g-75c2.json
new file mode 100644
index 00000000000..fa01fe3ffec
--- /dev/null
+++ b/advisories/unreviewed/2025/04/GHSA-fmvm-7g4g-75c2/GHSA-fmvm-7g4g-75c2.json
@@ -0,0 +1,53 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-fmvm-7g4g-75c2",
+ "modified": "2025-04-14T15:31:57Z",
+ "published": "2025-04-14T15:31:57Z",
+ "aliases": [
+ "CVE-2025-3566"
+ ],
+ "details": "A vulnerability, which was classified as critical, has been found in veal98 小牛肉 Echo 开源社区系统 4.2. This issue affects the function uploadMdPic of the file /discuss/uploadMdPic. The manipulation of the argument editormd-image-file leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
+ },
+ {
+ "type": "CVSS_V4",
+ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3566"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/caigo8/CVE-md/blob/main/Echo/%E6%9C%AA%E6%8E%88%E6%9D%83%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0.md"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?ctiid.304607"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?id.304607"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?submit.549509"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-284",
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-04-14T13:15:17Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/04/GHSA-h9h6-5fw6-j683/GHSA-h9h6-5fw6-j683.json b/advisories/unreviewed/2025/04/GHSA-h9h6-5fw6-j683/GHSA-h9h6-5fw6-j683.json
index 20084e3daaa..270ca5ff692 100644
--- a/advisories/unreviewed/2025/04/GHSA-h9h6-5fw6-j683/GHSA-h9h6-5fw6-j683.json
+++ b/advisories/unreviewed/2025/04/GHSA-h9h6-5fw6-j683/GHSA-h9h6-5fw6-j683.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h9h6-5fw6-j683",
- "modified": "2025-04-10T15:31:44Z",
+ "modified": "2025-04-14T15:31:54Z",
"published": "2025-04-01T18:30:53Z",
"aliases": [
"CVE-2025-21963"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: Fix integer overflow while processing acdirmax mount option\n\nUser-provided mount parameter acdirmax of type u32 is intended to have\nan upper limit, but before it is validated, the value is converted from\nseconds to jiffies which can lead to an integer overflow.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -40,8 +45,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-190"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-01T16:15:27Z"
diff --git a/advisories/unreviewed/2025/04/GHSA-hhmv-6rqc-qrc8/GHSA-hhmv-6rqc-qrc8.json b/advisories/unreviewed/2025/04/GHSA-hhmv-6rqc-qrc8/GHSA-hhmv-6rqc-qrc8.json
new file mode 100644
index 00000000000..e6ddefdc452
--- /dev/null
+++ b/advisories/unreviewed/2025/04/GHSA-hhmv-6rqc-qrc8/GHSA-hhmv-6rqc-qrc8.json
@@ -0,0 +1,40 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-hhmv-6rqc-qrc8",
+ "modified": "2025-04-14T15:31:59Z",
+ "published": "2025-04-14T15:31:59Z",
+ "aliases": [
+ "CVE-2025-32912"
+ ],
+ "details": "A flaw was found in libsoup, where SoupAuthDigest is vulnerable to a NULL pointer dereference. The HTTP server may cause the libsoup client to crash.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32912"
+ },
+ {
+ "type": "WEB",
+ "url": "https://access.redhat.com/security/cve/CVE-2025-32912"
+ },
+ {
+ "type": "WEB",
+ "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359356"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-04-14T15:15:25Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/04/GHSA-hwhh-xm47-jghm/GHSA-hwhh-xm47-jghm.json b/advisories/unreviewed/2025/04/GHSA-hwhh-xm47-jghm/GHSA-hwhh-xm47-jghm.json
index f21408aaf69..09f738b1672 100644
--- a/advisories/unreviewed/2025/04/GHSA-hwhh-xm47-jghm/GHSA-hwhh-xm47-jghm.json
+++ b/advisories/unreviewed/2025/04/GHSA-hwhh-xm47-jghm/GHSA-hwhh-xm47-jghm.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hwhh-xm47-jghm",
- "modified": "2025-04-10T15:31:44Z",
+ "modified": "2025-04-14T15:31:54Z",
"published": "2025-04-01T18:30:53Z",
"aliases": [
"CVE-2025-21959"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_conncount: Fully initialize struct nf_conncount_tuple in insert_tree()\n\nSince commit b36e4523d4d5 (\"netfilter: nf_conncount: fix garbage\ncollection confirm race\"), `cpu` and `jiffies32` were introduced to\nthe struct nf_conncount_tuple.\n\nThe commit made nf_conncount_add() initialize `conn->cpu` and\n`conn->jiffies32` when allocating the struct.\nIn contrast, count_tree() was not changed to initialize them.\n\nBy commit 34848d5c896e (\"netfilter: nf_conncount: Split insert and\ntraversal\"), count_tree() was split and the relevant allocation\ncode now resides in insert_tree().\nInitialize `conn->cpu` and `conn->jiffies32` in insert_tree().\n\nBUG: KMSAN: uninit-value in find_or_evict net/netfilter/nf_conncount.c:117 [inline]\nBUG: KMSAN: uninit-value in __nf_conncount_add+0xd9c/0x2850 net/netfilter/nf_conncount.c:143\n find_or_evict net/netfilter/nf_conncount.c:117 [inline]\n __nf_conncount_add+0xd9c/0x2850 net/netfilter/nf_conncount.c:143\n count_tree net/netfilter/nf_conncount.c:438 [inline]\n nf_conncount_count+0x82f/0x1e80 net/netfilter/nf_conncount.c:521\n connlimit_mt+0x7f6/0xbd0 net/netfilter/xt_connlimit.c:72\n __nft_match_eval net/netfilter/nft_compat.c:403 [inline]\n nft_match_eval+0x1a5/0x300 net/netfilter/nft_compat.c:433\n expr_call_ops_eval net/netfilter/nf_tables_core.c:240 [inline]\n nft_do_chain+0x426/0x2290 net/netfilter/nf_tables_core.c:288\n nft_do_chain_ipv4+0x1a5/0x230 net/netfilter/nft_chain_filter.c:23\n nf_hook_entry_hookfn include/linux/netfilter.h:154 [inline]\n nf_hook_slow+0xf4/0x400 net/netfilter/core.c:626\n nf_hook_slow_list+0x24d/0x860 net/netfilter/core.c:663\n NF_HOOK_LIST include/linux/netfilter.h:350 [inline]\n ip_sublist_rcv+0x17b7/0x17f0 net/ipv4/ip_input.c:633\n ip_list_rcv+0x9ef/0xa40 net/ipv4/ip_input.c:669\n __netif_receive_skb_list_ptype net/core/dev.c:5936 [inline]\n __netif_receive_skb_list_core+0x15c5/0x1670 net/core/dev.c:5983\n __netif_receive_skb_list net/core/dev.c:6035 [inline]\n netif_receive_skb_list_internal+0x1085/0x1700 net/core/dev.c:6126\n netif_receive_skb_list+0x5a/0x460 net/core/dev.c:6178\n xdp_recv_frames net/bpf/test_run.c:280 [inline]\n xdp_test_run_batch net/bpf/test_run.c:361 [inline]\n bpf_test_run_xdp_live+0x2e86/0x3480 net/bpf/test_run.c:390\n bpf_prog_test_run_xdp+0xf1d/0x1ae0 net/bpf/test_run.c:1316\n bpf_prog_test_run+0x5e5/0xa30 kernel/bpf/syscall.c:4407\n __sys_bpf+0x6aa/0xd90 kernel/bpf/syscall.c:5813\n __do_sys_bpf kernel/bpf/syscall.c:5902 [inline]\n __se_sys_bpf kernel/bpf/syscall.c:5900 [inline]\n __ia32_sys_bpf+0xa0/0xe0 kernel/bpf/syscall.c:5900\n ia32_sys_call+0x394d/0x4180 arch/x86/include/generated/asm/syscalls_32.h:358\n do_syscall_32_irqs_on arch/x86/entry/common.c:165 [inline]\n __do_fast_syscall_32+0xb0/0x110 arch/x86/entry/common.c:387\n do_fast_syscall_32+0x38/0x80 arch/x86/entry/common.c:412\n do_SYSENTER_32+0x1f/0x30 arch/x86/entry/common.c:450\n entry_SYSENTER_compat_after_hwframe+0x84/0x8e\n\nUninit was created at:\n slab_post_alloc_hook mm/slub.c:4121 [inline]\n slab_alloc_node mm/slub.c:4164 [inline]\n kmem_cache_alloc_noprof+0x915/0xe10 mm/slub.c:4171\n insert_tree net/netfilter/nf_conncount.c:372 [inline]\n count_tree net/netfilter/nf_conncount.c:450 [inline]\n nf_conncount_count+0x1415/0x1e80 net/netfilter/nf_conncount.c:521\n connlimit_mt+0x7f6/0xbd0 net/netfilter/xt_connlimit.c:72\n __nft_match_eval net/netfilter/nft_compat.c:403 [inline]\n nft_match_eval+0x1a5/0x300 net/netfilter/nft_compat.c:433\n expr_call_ops_eval net/netfilter/nf_tables_core.c:240 [inline]\n nft_do_chain+0x426/0x2290 net/netfilter/nf_tables_core.c:288\n nft_do_chain_ipv4+0x1a5/0x230 net/netfilter/nft_chain_filter.c:23\n nf_hook_entry_hookfn include/linux/netfilter.h:154 [inline]\n nf_hook_slow+0xf4/0x400 net/netfilter/core.c:626\n nf_hook_slow_list+0x24d/0x860 net/netfilter/core.c:663\n NF_HOOK_LIST include/linux/netfilter.h:350 [inline]\n ip_sublist_rcv+0x17b7/0x17f0 net/ipv4/ip_input.c:633\n ip_list_rcv+0x9ef/0xa40 net/ip\n---truncated---",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -48,8 +53,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-908"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-01T16:15:27Z"
diff --git a/advisories/unreviewed/2025/04/GHSA-j3pp-f94x-f42g/GHSA-j3pp-f94x-f42g.json b/advisories/unreviewed/2025/04/GHSA-j3pp-f94x-f42g/GHSA-j3pp-f94x-f42g.json
new file mode 100644
index 00000000000..c14c52d6b8c
--- /dev/null
+++ b/advisories/unreviewed/2025/04/GHSA-j3pp-f94x-f42g/GHSA-j3pp-f94x-f42g.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-j3pp-f94x-f42g",
+ "modified": "2025-04-14T15:31:59Z",
+ "published": "2025-04-14T15:31:59Z",
+ "aliases": [
+ "CVE-2025-2161"
+ ],
+ "details": "Pega Platform versions 7.2.1 to Infinity 24.2.1 are affected by an XSS issue with Mashup",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2161"
+ },
+ {
+ "type": "WEB",
+ "url": "https://support.pega.com/support-doc/pega-security-advisory-d25-vulnerability-remediation-note"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-04-14T15:15:24Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/04/GHSA-jwm2-2q27-v4vh/GHSA-jwm2-2q27-v4vh.json b/advisories/unreviewed/2025/04/GHSA-jwm2-2q27-v4vh/GHSA-jwm2-2q27-v4vh.json
index ba2ad8f0ba7..e0681d0d7ae 100644
--- a/advisories/unreviewed/2025/04/GHSA-jwm2-2q27-v4vh/GHSA-jwm2-2q27-v4vh.json
+++ b/advisories/unreviewed/2025/04/GHSA-jwm2-2q27-v4vh/GHSA-jwm2-2q27-v4vh.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jwm2-2q27-v4vh",
- "modified": "2025-04-03T09:32:14Z",
+ "modified": "2025-04-14T15:31:54Z",
"published": "2025-04-03T09:32:14Z",
"aliases": [
"CVE-2025-21995"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/sched: Fix fence reference count leak\n\nThe last_scheduled fence leaks when an entity is being killed and adding\nthe cleanup callback fails.\n\nDecrement the reference count of prev when dma_fence_add_callback()\nfails, ensuring proper balance.\n\n[phasta: add git tag info for stable kernel]",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -33,7 +38,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-03T08:15:14Z"
diff --git a/advisories/unreviewed/2025/04/GHSA-jxh5-f52q-732j/GHSA-jxh5-f52q-732j.json b/advisories/unreviewed/2025/04/GHSA-jxh5-f52q-732j/GHSA-jxh5-f52q-732j.json
index ad4ad42041c..5e5df09ceff 100644
--- a/advisories/unreviewed/2025/04/GHSA-jxh5-f52q-732j/GHSA-jxh5-f52q-732j.json
+++ b/advisories/unreviewed/2025/04/GHSA-jxh5-f52q-732j/GHSA-jxh5-f52q-732j.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jxh5-f52q-732j",
- "modified": "2025-04-14T06:30:24Z",
+ "modified": "2025-04-14T15:31:57Z",
"published": "2025-04-14T06:30:24Z",
"aliases": [
"CVE-2025-2563"
],
"details": "The User Registration & Membership WordPress plugin before 4.1.2 does not prevent users to set their account role when the Membership Addon is enabled, leading to a privilege escalation issue and allowing unauthenticated users to gain admin privileges",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -21,7 +26,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-14T06:15:16Z"
diff --git a/advisories/unreviewed/2025/04/GHSA-mg5c-fjcx-j5g5/GHSA-mg5c-fjcx-j5g5.json b/advisories/unreviewed/2025/04/GHSA-mg5c-fjcx-j5g5/GHSA-mg5c-fjcx-j5g5.json
index 906ff304f9d..72d58831d00 100644
--- a/advisories/unreviewed/2025/04/GHSA-mg5c-fjcx-j5g5/GHSA-mg5c-fjcx-j5g5.json
+++ b/advisories/unreviewed/2025/04/GHSA-mg5c-fjcx-j5g5/GHSA-mg5c-fjcx-j5g5.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mg5c-fjcx-j5g5",
- "modified": "2025-04-10T15:31:43Z",
+ "modified": "2025-04-14T15:31:54Z",
"published": "2025-04-01T18:30:53Z",
"aliases": [
"CVE-2025-21962"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: Fix integer overflow while processing closetimeo mount option\n\nUser-provided mount parameter closetimeo of type u32 is intended to have\nan upper limit, but before it is validated, the value is converted from\nseconds to jiffies which can lead to an integer overflow.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -40,8 +45,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-190"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-01T16:15:27Z"
diff --git a/advisories/unreviewed/2025/04/GHSA-mj4r-rr6h-q62g/GHSA-mj4r-rr6h-q62g.json b/advisories/unreviewed/2025/04/GHSA-mj4r-rr6h-q62g/GHSA-mj4r-rr6h-q62g.json
index a2f3e2022f8..bffbef7a6dc 100644
--- a/advisories/unreviewed/2025/04/GHSA-mj4r-rr6h-q62g/GHSA-mj4r-rr6h-q62g.json
+++ b/advisories/unreviewed/2025/04/GHSA-mj4r-rr6h-q62g/GHSA-mj4r-rr6h-q62g.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mj4r-rr6h-q62g",
- "modified": "2025-04-11T21:30:36Z",
+ "modified": "2025-04-14T15:31:56Z",
"published": "2025-04-10T15:31:48Z",
"aliases": [
"CVE-2025-29088"
@@ -27,6 +27,14 @@
"type": "WEB",
"url": "https://gist.github.com/ylwango613/d3883fb9f6ba8a78086356779ce88248"
},
+ {
+ "type": "WEB",
+ "url": "https://sqlite.org/forum/forumpost/48f365daec"
+ },
+ {
+ "type": "WEB",
+ "url": "https://sqlite.org/releaselog/3_49_1.html"
+ },
{
"type": "WEB",
"url": "https://www.sqlite.org/cves.html"
@@ -34,6 +42,7 @@
],
"database_specific": {
"cwe_ids": [
+ "CWE-190",
"CWE-400"
],
"severity": "HIGH",
diff --git a/advisories/unreviewed/2025/04/GHSA-mp83-3fxr-m45v/GHSA-mp83-3fxr-m45v.json b/advisories/unreviewed/2025/04/GHSA-mp83-3fxr-m45v/GHSA-mp83-3fxr-m45v.json
index 15ca24a77fc..c92ab6aa4a4 100644
--- a/advisories/unreviewed/2025/04/GHSA-mp83-3fxr-m45v/GHSA-mp83-3fxr-m45v.json
+++ b/advisories/unreviewed/2025/04/GHSA-mp83-3fxr-m45v/GHSA-mp83-3fxr-m45v.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mp83-3fxr-m45v",
- "modified": "2025-04-10T15:31:44Z",
+ "modified": "2025-04-14T15:31:54Z",
"published": "2025-04-01T18:30:53Z",
"aliases": [
"CVE-2025-21964"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: Fix integer overflow while processing acregmax mount option\n\nUser-provided mount parameter acregmax of type u32 is intended to have\nan upper limit, but before it is validated, the value is converted from\nseconds to jiffies which can lead to an integer overflow.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -40,8 +45,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-190"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-01T16:15:27Z"
diff --git a/advisories/unreviewed/2025/04/GHSA-p3jf-39f4-gqr8/GHSA-p3jf-39f4-gqr8.json b/advisories/unreviewed/2025/04/GHSA-p3jf-39f4-gqr8/GHSA-p3jf-39f4-gqr8.json
index 302a7fe9f75..477df54ace8 100644
--- a/advisories/unreviewed/2025/04/GHSA-p3jf-39f4-gqr8/GHSA-p3jf-39f4-gqr8.json
+++ b/advisories/unreviewed/2025/04/GHSA-p3jf-39f4-gqr8/GHSA-p3jf-39f4-gqr8.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p3jf-39f4-gqr8",
- "modified": "2025-04-01T18:30:54Z",
+ "modified": "2025-04-14T15:31:54Z",
"published": "2025-04-01T18:30:53Z",
"aliases": [
"CVE-2025-21967"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix use-after-free in ksmbd_free_work_struct\n\n->interim_entry of ksmbd_work could be deleted after oplock is freed.\nWe don't need to manage it with linked list. The interim request could be\nimmediately sent whenever a oplock break wait is needed.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -32,8 +37,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-01T16:15:27Z"
diff --git a/advisories/unreviewed/2025/04/GHSA-p42v-4mrm-3j3g/GHSA-p42v-4mrm-3j3g.json b/advisories/unreviewed/2025/04/GHSA-p42v-4mrm-3j3g/GHSA-p42v-4mrm-3j3g.json
index 9244e887ade..e88c50938e4 100644
--- a/advisories/unreviewed/2025/04/GHSA-p42v-4mrm-3j3g/GHSA-p42v-4mrm-3j3g.json
+++ b/advisories/unreviewed/2025/04/GHSA-p42v-4mrm-3j3g/GHSA-p42v-4mrm-3j3g.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p42v-4mrm-3j3g",
- "modified": "2025-04-10T15:31:47Z",
+ "modified": "2025-04-14T15:31:55Z",
"published": "2025-04-03T09:32:15Z",
"aliases": [
"CVE-2025-21996"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/radeon: fix uninitialized size issue in radeon_vce_cs_parse()\n\nOn the off chance that command stream passed from userspace via\nioctl() call to radeon_vce_cs_parse() is weirdly crafted and\nfirst command to execute is to encode (case 0x03000001), the function\nin question will attempt to call radeon_vce_cs_reloc() with size\nargument that has not been properly initialized. Specifically, 'size'\nwill point to 'tmp' variable before the latter had a chance to be\nassigned any value.\n\nPlay it safe and init 'tmp' with 0, thus ensuring that\nradeon_vce_cs_reloc() will catch an early error in cases like these.\n\nFound by Linux Verification Center (linuxtesting.org) with static\nanalysis tool SVACE.\n\n(cherry picked from commit 2d52de55f9ee7aaee0e09ac443f77855989c6b68)",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -48,8 +53,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-908"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-03T08:15:15Z"
diff --git a/advisories/unreviewed/2025/04/GHSA-rvg2-pv9x-xxhg/GHSA-rvg2-pv9x-xxhg.json b/advisories/unreviewed/2025/04/GHSA-rvg2-pv9x-xxhg/GHSA-rvg2-pv9x-xxhg.json
index 071c25bf115..d9e034b5412 100644
--- a/advisories/unreviewed/2025/04/GHSA-rvg2-pv9x-xxhg/GHSA-rvg2-pv9x-xxhg.json
+++ b/advisories/unreviewed/2025/04/GHSA-rvg2-pv9x-xxhg/GHSA-rvg2-pv9x-xxhg.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rvg2-pv9x-xxhg",
- "modified": "2025-04-10T15:31:44Z",
+ "modified": "2025-04-14T15:31:54Z",
"published": "2025-04-01T18:30:54Z",
"aliases": [
"CVE-2025-21968"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix slab-use-after-free on hdcp_work\n\n[Why]\nA slab-use-after-free is reported when HDCP is destroyed but the\nproperty_validate_dwork queue is still running.\n\n[How]\nCancel the delayed work when destroying workqueue.\n\n(cherry picked from commit 725a04ba5a95e89c89633d4322430cfbca7ce128)",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -44,8 +49,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-01T16:15:28Z"
diff --git a/advisories/unreviewed/2025/04/GHSA-v974-f78x-v6pq/GHSA-v974-f78x-v6pq.json b/advisories/unreviewed/2025/04/GHSA-v974-f78x-v6pq/GHSA-v974-f78x-v6pq.json
index 93a9779e8ee..024886b5533 100644
--- a/advisories/unreviewed/2025/04/GHSA-v974-f78x-v6pq/GHSA-v974-f78x-v6pq.json
+++ b/advisories/unreviewed/2025/04/GHSA-v974-f78x-v6pq/GHSA-v974-f78x-v6pq.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v974-f78x-v6pq",
- "modified": "2025-04-01T18:30:53Z",
+ "modified": "2025-04-14T15:31:54Z",
"published": "2025-04-01T18:30:53Z",
"aliases": [
"CVE-2025-21961"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\neth: bnxt: fix truesize for mb-xdp-pass case\n\nWhen mb-xdp is set and return is XDP_PASS, packet is converted from\nxdp_buff to sk_buff with xdp_update_skb_shared_info() in\nbnxt_xdp_build_skb().\nbnxt_xdp_build_skb() passes incorrect truesize argument to\nxdp_update_skb_shared_info().\nThe truesize is calculated as BNXT_RX_PAGE_SIZE * sinfo->nr_frags but\nthe skb_shared_info was wiped by napi_build_skb() before.\nSo it stores sinfo->nr_frags before bnxt_xdp_build_skb() and use it\ninstead of getting skb_shared_info from xdp_get_shared_info_from_buff().\n\nSplat looks like:\n ------------[ cut here ]------------\n WARNING: CPU: 2 PID: 0 at net/core/skbuff.c:6072 skb_try_coalesce+0x504/0x590\n Modules linked in: xt_nat xt_tcpudp veth af_packet xt_conntrack nft_chain_nat xt_MASQUERADE nf_conntrack_netlink xfrm_user xt_addrtype nft_coms\n CPU: 2 UID: 0 PID: 0 Comm: swapper/2 Not tainted 6.14.0-rc2+ #3\n RIP: 0010:skb_try_coalesce+0x504/0x590\n Code: 4b fd ff ff 49 8b 34 24 40 80 e6 40 0f 84 3d fd ff ff 49 8b 74 24 48 40 f6 c6 01 0f 84 2e fd ff ff 48 8d 4e ff e9 25 fd ff ff <0f> 0b e99\n RSP: 0018:ffffb62c4120caa8 EFLAGS: 00010287\n RAX: 0000000000000003 RBX: ffffb62c4120cb14 RCX: 0000000000000ec0\n RDX: 0000000000001000 RSI: ffffa06e5d7dc000 RDI: 0000000000000003\n RBP: ffffa06e5d7ddec0 R08: ffffa06e6120a800 R09: ffffa06e7a119900\n R10: 0000000000002310 R11: ffffa06e5d7dcec0 R12: ffffe4360575f740\n R13: ffffe43600000000 R14: 0000000000000002 R15: 0000000000000002\n FS: 0000000000000000(0000) GS:ffffa0755f700000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007f147b76b0f8 CR3: 00000001615d4000 CR4: 00000000007506f0\n PKRU: 55555554\n Call Trace:\n \n ? __warn+0x84/0x130\n ? skb_try_coalesce+0x504/0x590\n ? report_bug+0x18a/0x1a0\n ? handle_bug+0x53/0x90\n ? exc_invalid_op+0x14/0x70\n ? asm_exc_invalid_op+0x16/0x20\n ? skb_try_coalesce+0x504/0x590\n inet_frag_reasm_finish+0x11f/0x2e0\n ip_defrag+0x37a/0x900\n ip_local_deliver+0x51/0x120\n ip_sublist_rcv_finish+0x64/0x70\n ip_sublist_rcv+0x179/0x210\n ip_list_rcv+0xf9/0x130\n\nHow to reproduce:\n\nip link set $interface1 xdp obj xdp_pass.o\nip link set $interface1 mtu 9000 up\nip a a 10.0.0.1/24 dev $interface1\n\nip link set $interfac2 mtu 9000 up\nip a a 10.0.0.2/24 dev $interface2\nping 10.0.0.1 -s 65000\n\nFollowing ping.py patch adds xdp-mb-pass case. so ping.py is going to be\nable to reproduce this issue.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -29,7 +34,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-01T16:15:27Z"
diff --git a/advisories/unreviewed/2025/04/GHSA-w66x-hqgr-vfg4/GHSA-w66x-hqgr-vfg4.json b/advisories/unreviewed/2025/04/GHSA-w66x-hqgr-vfg4/GHSA-w66x-hqgr-vfg4.json
index 9de8474fe43..10b3980ed44 100644
--- a/advisories/unreviewed/2025/04/GHSA-w66x-hqgr-vfg4/GHSA-w66x-hqgr-vfg4.json
+++ b/advisories/unreviewed/2025/04/GHSA-w66x-hqgr-vfg4/GHSA-w66x-hqgr-vfg4.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w66x-hqgr-vfg4",
- "modified": "2025-04-01T18:30:54Z",
+ "modified": "2025-04-14T15:31:54Z",
"published": "2025-04-01T18:30:53Z",
"aliases": [
"CVE-2025-21966"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm-flakey: Fix memory corruption in optional corrupt_bio_byte feature\n\nFix memory corruption due to incorrect parameter being passed to bio_init",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -32,8 +37,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-787"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-01T16:15:27Z"
diff --git a/advisories/unreviewed/2025/04/GHSA-wcmh-fj7m-gv6r/GHSA-wcmh-fj7m-gv6r.json b/advisories/unreviewed/2025/04/GHSA-wcmh-fj7m-gv6r/GHSA-wcmh-fj7m-gv6r.json
new file mode 100644
index 00000000000..ec81d685a64
--- /dev/null
+++ b/advisories/unreviewed/2025/04/GHSA-wcmh-fj7m-gv6r/GHSA-wcmh-fj7m-gv6r.json
@@ -0,0 +1,40 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-wcmh-fj7m-gv6r",
+ "modified": "2025-04-14T15:31:59Z",
+ "published": "2025-04-14T15:31:59Z",
+ "aliases": [
+ "CVE-2025-32909"
+ ],
+ "details": "A flaw was found in libsoup. SoupContentSniffer may be vulnerable to a NULL pointer dereference in the sniff_mp4 function. The HTTP server may cause the libsoup client to crash.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32909"
+ },
+ {
+ "type": "WEB",
+ "url": "https://access.redhat.com/security/cve/CVE-2025-32909"
+ },
+ {
+ "type": "WEB",
+ "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359353"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-04-14T15:15:25Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/04/GHSA-wwhj-pw6h-f8hw/GHSA-wwhj-pw6h-f8hw.json b/advisories/unreviewed/2025/04/GHSA-wwhj-pw6h-f8hw/GHSA-wwhj-pw6h-f8hw.json
new file mode 100644
index 00000000000..e75a45abb1b
--- /dev/null
+++ b/advisories/unreviewed/2025/04/GHSA-wwhj-pw6h-f8hw/GHSA-wwhj-pw6h-f8hw.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-wwhj-pw6h-f8hw",
+ "modified": "2025-04-14T15:31:59Z",
+ "published": "2025-04-14T15:31:59Z",
+ "aliases": [
+ "CVE-2025-2424"
+ ],
+ "details": "Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to check if a file has been deleted when creating a bookmark which allows an attacker who knows the IDs of deleted files to obtain metadata of the files via bookmark creation.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2424"
+ },
+ {
+ "type": "WEB",
+ "url": "https://mattermost.com/security-updates"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-863"
+ ],
+ "severity": "LOW",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-04-14T15:15:24Z"
+ }
+}
\ No newline at end of file