diff --git a/advisories/unreviewed/2024/02/GHSA-ch34-vwch-58hx/GHSA-ch34-vwch-58hx.json b/advisories/unreviewed/2024/02/GHSA-ch34-vwch-58hx/GHSA-ch34-vwch-58hx.json index af557335233..510a34e2967 100644 --- a/advisories/unreviewed/2024/02/GHSA-ch34-vwch-58hx/GHSA-ch34-vwch-58hx.json +++ b/advisories/unreviewed/2024/02/GHSA-ch34-vwch-58hx/GHSA-ch34-vwch-58hx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ch34-vwch-58hx", - "modified": "2024-11-01T21:31:45Z", + "modified": "2025-06-10T21:31:18Z", "published": "2024-02-29T03:33:17Z", "aliases": [ "CVE-2024-22251" diff --git a/advisories/unreviewed/2024/02/GHSA-j2p9-482v-5wj6/GHSA-j2p9-482v-5wj6.json b/advisories/unreviewed/2024/02/GHSA-j2p9-482v-5wj6/GHSA-j2p9-482v-5wj6.json index d2f9a9b727c..244e3b23e50 100644 --- a/advisories/unreviewed/2024/02/GHSA-j2p9-482v-5wj6/GHSA-j2p9-482v-5wj6.json +++ b/advisories/unreviewed/2024/02/GHSA-j2p9-482v-5wj6/GHSA-j2p9-482v-5wj6.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-j2p9-482v-5wj6", - "modified": "2024-02-09T06:32:24Z", + "modified": "2025-06-10T21:31:18Z", "published": "2024-02-09T06:32:24Z", "aliases": [ "CVE-2023-51761" ], - "details": "\n\n\n\n\nIn Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could bypass authentication and acquire admin capabilities.\n\n\n\n\n\n", + "details": "In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could bypass authentication and acquire admin capabilities.", "severity": [ { "type": "CVSS_V3", @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-863" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-qx4x-jg45-h572/GHSA-qx4x-jg45-h572.json b/advisories/unreviewed/2024/02/GHSA-qx4x-jg45-h572/GHSA-qx4x-jg45-h572.json index 0320b670ee1..88d2993a8f4 100644 --- a/advisories/unreviewed/2024/02/GHSA-qx4x-jg45-h572/GHSA-qx4x-jg45-h572.json +++ b/advisories/unreviewed/2024/02/GHSA-qx4x-jg45-h572/GHSA-qx4x-jg45-h572.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-qx4x-jg45-h572", - "modified": "2024-02-09T06:32:23Z", + "modified": "2025-06-10T21:31:18Z", "published": "2024-02-09T06:32:23Z", "aliases": [ "CVE-2023-43609" ], - "details": "\n\n\n\n\n\n\nIn Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could obtain access to sensitive information or cause a denial-of-service condition.\n\n\n\n\n\n\n\n", + "details": "In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could obtain access to sensitive information or cause a denial-of-service condition.", "severity": [ { "type": "CVSS_V3", @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-285" + "CWE-285", + "CWE-863" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-27jg-5m5x-f2g4/GHSA-27jg-5m5x-f2g4.json b/advisories/unreviewed/2025/05/GHSA-27jg-5m5x-f2g4/GHSA-27jg-5m5x-f2g4.json index b5faeafc357..8d98a8294ff 100644 --- a/advisories/unreviewed/2025/05/GHSA-27jg-5m5x-f2g4/GHSA-27jg-5m5x-f2g4.json +++ b/advisories/unreviewed/2025/05/GHSA-27jg-5m5x-f2g4/GHSA-27jg-5m5x-f2g4.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-94" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-9q78-jg46-rwj6/GHSA-9q78-jg46-rwj6.json b/advisories/unreviewed/2025/05/GHSA-9q78-jg46-rwj6/GHSA-9q78-jg46-rwj6.json index 536f98eb568..83bd13b0558 100644 --- a/advisories/unreviewed/2025/05/GHSA-9q78-jg46-rwj6/GHSA-9q78-jg46-rwj6.json +++ b/advisories/unreviewed/2025/05/GHSA-9q78-jg46-rwj6/GHSA-9q78-jg46-rwj6.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-c8hr-6m27-p6qr/GHSA-c8hr-6m27-p6qr.json b/advisories/unreviewed/2025/05/GHSA-c8hr-6m27-p6qr/GHSA-c8hr-6m27-p6qr.json index 67c34683a8c..5a5f9cee07d 100644 --- a/advisories/unreviewed/2025/05/GHSA-c8hr-6m27-p6qr/GHSA-c8hr-6m27-p6qr.json +++ b/advisories/unreviewed/2025/05/GHSA-c8hr-6m27-p6qr/GHSA-c8hr-6m27-p6qr.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-cmg2-pjgm-gcrp/GHSA-cmg2-pjgm-gcrp.json b/advisories/unreviewed/2025/05/GHSA-cmg2-pjgm-gcrp/GHSA-cmg2-pjgm-gcrp.json index a97ab4fd716..284b4b17d85 100644 --- a/advisories/unreviewed/2025/05/GHSA-cmg2-pjgm-gcrp/GHSA-cmg2-pjgm-gcrp.json +++ b/advisories/unreviewed/2025/05/GHSA-cmg2-pjgm-gcrp/GHSA-cmg2-pjgm-gcrp.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/06/GHSA-23fj-6rwp-5rq6/GHSA-23fj-6rwp-5rq6.json b/advisories/unreviewed/2025/06/GHSA-23fj-6rwp-5rq6/GHSA-23fj-6rwp-5rq6.json new file mode 100644 index 00000000000..990d46bbd29 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-23fj-6rwp-5rq6/GHSA-23fj-6rwp-5rq6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23fj-6rwp-5rq6", + "modified": "2025-06-10T21:31:22Z", + "published": "2025-06-10T21:31:22Z", + "aliases": [ + "CVE-2025-43576" + ], + "details": "Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43576" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/acrobat/apsb25-57.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T19:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-25px-qwqc-5cg6/GHSA-25px-qwqc-5cg6.json b/advisories/unreviewed/2025/06/GHSA-25px-qwqc-5cg6/GHSA-25px-qwqc-5cg6.json new file mode 100644 index 00000000000..a90f330f251 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-25px-qwqc-5cg6/GHSA-25px-qwqc-5cg6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-25px-qwqc-5cg6", + "modified": "2025-06-10T21:31:22Z", + "published": "2025-06-10T21:31:22Z", + "aliases": [ + "CVE-2025-30327" + ], + "details": "InCopy versions 20.2, 19.5.3 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30327" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/incopy/apsb25-41.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T19:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-2xg5-8frj-h6pm/GHSA-2xg5-8frj-h6pm.json b/advisories/unreviewed/2025/06/GHSA-2xg5-8frj-h6pm/GHSA-2xg5-8frj-h6pm.json index 1d6ddb1a47f..69e325043c5 100644 --- a/advisories/unreviewed/2025/06/GHSA-2xg5-8frj-h6pm/GHSA-2xg5-8frj-h6pm.json +++ b/advisories/unreviewed/2025/06/GHSA-2xg5-8frj-h6pm/GHSA-2xg5-8frj-h6pm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2xg5-8frj-h6pm", - "modified": "2025-06-10T18:32:26Z", + "modified": "2025-06-10T21:31:22Z", "published": "2025-06-10T18:32:26Z", "aliases": [ "CVE-2025-44044" ], "details": "Keyoti SearchUnit prior to 9.0.0. is vulnerable to XML External Entity (XXE). An attacker who can force a vulnerable SearchUnit host into parsing maliciously crafted XML and/or DTD files can exfiltrate some files from the underlying operating system.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-611" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-10T16:15:40Z" diff --git a/advisories/unreviewed/2025/06/GHSA-3fxc-2crv-fg9x/GHSA-3fxc-2crv-fg9x.json b/advisories/unreviewed/2025/06/GHSA-3fxc-2crv-fg9x/GHSA-3fxc-2crv-fg9x.json index bc5b1eb3f1e..01fa1188ca9 100644 --- a/advisories/unreviewed/2025/06/GHSA-3fxc-2crv-fg9x/GHSA-3fxc-2crv-fg9x.json +++ b/advisories/unreviewed/2025/06/GHSA-3fxc-2crv-fg9x/GHSA-3fxc-2crv-fg9x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3fxc-2crv-fg9x", - "modified": "2025-06-10T18:32:32Z", + "modified": "2025-06-10T21:31:22Z", "published": "2025-06-10T18:32:32Z", "aliases": [ "CVE-2025-2884" @@ -21,6 +21,14 @@ { "type": "WEB", "url": "https://trustedcomputinggroup.org/wp-content/uploads/TPM2.0-Library-Spec-v1.83-Errata_v1_pub.pdf" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01209.html" + }, + { + "type": "WEB", + "url": "https://www.kb.cert.org/vuls/id/282450" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/06/GHSA-4mm2-j594-64h8/GHSA-4mm2-j594-64h8.json b/advisories/unreviewed/2025/06/GHSA-4mm2-j594-64h8/GHSA-4mm2-j594-64h8.json new file mode 100644 index 00000000000..fc253008c79 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-4mm2-j594-64h8/GHSA-4mm2-j594-64h8.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4mm2-j594-64h8", + "modified": "2025-06-10T21:31:24Z", + "published": "2025-06-10T21:31:24Z", + "aliases": [ + "CVE-2025-5977" + ], + "details": "A vulnerability was found in code-projects School Fees Payment System 1.0 and classified as critical. This issue affects some unknown processing of the file /datatable.php. The manipulation of the argument sSortDir_0 leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5977" + }, + { + "type": "WEB", + "url": "https://github.com/jiangffffd/cve/issues/1" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311855" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311855" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.592458" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T20:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-57x8-g7cj-crwq/GHSA-57x8-g7cj-crwq.json b/advisories/unreviewed/2025/06/GHSA-57x8-g7cj-crwq/GHSA-57x8-g7cj-crwq.json new file mode 100644 index 00000000000..9dbd97f0d53 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-57x8-g7cj-crwq/GHSA-57x8-g7cj-crwq.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-57x8-g7cj-crwq", + "modified": "2025-06-10T21:31:23Z", + "published": "2025-06-10T21:31:23Z", + "aliases": [ + "CVE-2024-41504" + ], + "details": "Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS). In the \"Oportunidades\" (opportunities) section of the application when creating or editing an \"Atividade\" (activity), the form field \"Descrico\" allows injection of JavaScript.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41504" + }, + { + "type": "WEB", + "url": "https://github.com/rafaelbaldasso/CVE-2024-41504" + }, + { + "type": "WEB", + "url": "http://jetimob.com" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T20:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-5wcp-x98w-p534/GHSA-5wcp-x98w-p534.json b/advisories/unreviewed/2025/06/GHSA-5wcp-x98w-p534/GHSA-5wcp-x98w-p534.json new file mode 100644 index 00000000000..781bc5348a1 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-5wcp-x98w-p534/GHSA-5wcp-x98w-p534.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5wcp-x98w-p534", + "modified": "2025-06-10T21:31:24Z", + "published": "2025-06-10T21:31:24Z", + "aliases": [ + "CVE-2025-35940" + ], + "details": "The ArchiverSpaApi ASP.NET application uses a hard-coded JWT signing key. An unauthenticated remote attacker can generate and use a verifiable JWT token to access protected ArchiverSpaApi URL endpoints.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-35940" + }, + { + "type": "WEB", + "url": "https://www.tenable.com/security/research/tra-2025-17" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-798" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T21:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-639h-q5mc-2xjf/GHSA-639h-q5mc-2xjf.json b/advisories/unreviewed/2025/06/GHSA-639h-q5mc-2xjf/GHSA-639h-q5mc-2xjf.json index 355816adc12..7095b4a8b1e 100644 --- a/advisories/unreviewed/2025/06/GHSA-639h-q5mc-2xjf/GHSA-639h-q5mc-2xjf.json +++ b/advisories/unreviewed/2025/06/GHSA-639h-q5mc-2xjf/GHSA-639h-q5mc-2xjf.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/06/GHSA-66jr-c3x5-vxxr/GHSA-66jr-c3x5-vxxr.json b/advisories/unreviewed/2025/06/GHSA-66jr-c3x5-vxxr/GHSA-66jr-c3x5-vxxr.json new file mode 100644 index 00000000000..1e1b2366f43 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-66jr-c3x5-vxxr/GHSA-66jr-c3x5-vxxr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-66jr-c3x5-vxxr", + "modified": "2025-06-10T21:31:23Z", + "published": "2025-06-10T21:31:23Z", + "aliases": [ + "CVE-2025-47111" + ], + "details": "Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing a disruption in service. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47111" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/acrobat/apsb25-57.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T19:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-6fpm-c38x-hr9h/GHSA-6fpm-c38x-hr9h.json b/advisories/unreviewed/2025/06/GHSA-6fpm-c38x-hr9h/GHSA-6fpm-c38x-hr9h.json new file mode 100644 index 00000000000..b3ce4d6ebf2 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-6fpm-c38x-hr9h/GHSA-6fpm-c38x-hr9h.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6fpm-c38x-hr9h", + "modified": "2025-06-10T21:31:23Z", + "published": "2025-06-10T21:31:23Z", + "aliases": [ + "CVE-2024-41503" + ], + "details": "Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS) in the field \"Ttulo\" (title) inside the filter Save option in the \"Busca\" (search) function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41503" + }, + { + "type": "WEB", + "url": "https://github.com/rafaelbaldasso/CVE-2024-41503" + }, + { + "type": "WEB", + "url": "http://jetimob.com" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T20:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-6g24-6w3x-338j/GHSA-6g24-6w3x-338j.json b/advisories/unreviewed/2025/06/GHSA-6g24-6w3x-338j/GHSA-6g24-6w3x-338j.json new file mode 100644 index 00000000000..1988a435faa --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-6g24-6w3x-338j/GHSA-6g24-6w3x-338j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6g24-6w3x-338j", + "modified": "2025-06-10T21:31:22Z", + "published": "2025-06-10T21:31:22Z", + "aliases": [ + "CVE-2025-43575" + ], + "details": "Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43575" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/acrobat/apsb25-57.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T19:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-6mvj-rxp7-39x3/GHSA-6mvj-rxp7-39x3.json b/advisories/unreviewed/2025/06/GHSA-6mvj-rxp7-39x3/GHSA-6mvj-rxp7-39x3.json new file mode 100644 index 00000000000..273b54c74d3 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-6mvj-rxp7-39x3/GHSA-6mvj-rxp7-39x3.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6mvj-rxp7-39x3", + "modified": "2025-06-10T21:31:23Z", + "published": "2025-06-10T21:31:23Z", + "aliases": [ + "CVE-2024-41505" + ], + "details": "Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS) in the \"Pessoas\" (persons) section via the field \"Profisso\" (professor).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41505" + }, + { + "type": "WEB", + "url": "https://github.com/rafaelbaldasso/CVE-2024-41505" + }, + { + "type": "WEB", + "url": "http://jetimob.com" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T20:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-7v3j-qcv2-4wc4/GHSA-7v3j-qcv2-4wc4.json b/advisories/unreviewed/2025/06/GHSA-7v3j-qcv2-4wc4/GHSA-7v3j-qcv2-4wc4.json index cf4ea08e56f..12f0d4cd359 100644 --- a/advisories/unreviewed/2025/06/GHSA-7v3j-qcv2-4wc4/GHSA-7v3j-qcv2-4wc4.json +++ b/advisories/unreviewed/2025/06/GHSA-7v3j-qcv2-4wc4/GHSA-7v3j-qcv2-4wc4.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-77" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/06/GHSA-8388-575x-9wmq/GHSA-8388-575x-9wmq.json b/advisories/unreviewed/2025/06/GHSA-8388-575x-9wmq/GHSA-8388-575x-9wmq.json index a3bf27871c2..71dce3a9a7a 100644 --- a/advisories/unreviewed/2025/06/GHSA-8388-575x-9wmq/GHSA-8388-575x-9wmq.json +++ b/advisories/unreviewed/2025/06/GHSA-8388-575x-9wmq/GHSA-8388-575x-9wmq.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/06/GHSA-8jmh-8q7v-83gf/GHSA-8jmh-8q7v-83gf.json b/advisories/unreviewed/2025/06/GHSA-8jmh-8q7v-83gf/GHSA-8jmh-8q7v-83gf.json new file mode 100644 index 00000000000..a360a1092c6 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-8jmh-8q7v-83gf/GHSA-8jmh-8q7v-83gf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8jmh-8q7v-83gf", + "modified": "2025-06-10T21:31:23Z", + "published": "2025-06-10T21:31:23Z", + "aliases": [ + "CVE-2025-43578" + ], + "details": "Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43578" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/acrobat/apsb25-57.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T19:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-96g4-w779-w67g/GHSA-96g4-w779-w67g.json b/advisories/unreviewed/2025/06/GHSA-96g4-w779-w67g/GHSA-96g4-w779-w67g.json new file mode 100644 index 00000000000..bd4fbb39764 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-96g4-w779-w67g/GHSA-96g4-w779-w67g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-96g4-w779-w67g", + "modified": "2025-06-10T21:31:22Z", + "published": "2025-06-10T21:31:22Z", + "aliases": [ + "CVE-2025-43574" + ], + "details": "Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43574" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/acrobat/apsb25-57.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T19:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-9fg6-655w-rjj5/GHSA-9fg6-655w-rjj5.json b/advisories/unreviewed/2025/06/GHSA-9fg6-655w-rjj5/GHSA-9fg6-655w-rjj5.json new file mode 100644 index 00000000000..6bbac22203e --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-9fg6-655w-rjj5/GHSA-9fg6-655w-rjj5.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9fg6-655w-rjj5", + "modified": "2025-06-10T21:31:24Z", + "published": "2025-06-10T21:31:24Z", + "aliases": [ + "CVE-2025-5976" + ], + "details": "A vulnerability has been found in PHPGurukul Rail Pass Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /admin/add-pass.php. The manipulation of the argument fullname leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5976" + }, + { + "type": "WEB", + "url": "https://github.com/kakalalaww/CVE/issues/10" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311854" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311854" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.592442" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T20:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-cx36-hwm9-j7v8/GHSA-cx36-hwm9-j7v8.json b/advisories/unreviewed/2025/06/GHSA-cx36-hwm9-j7v8/GHSA-cx36-hwm9-j7v8.json new file mode 100644 index 00000000000..3f44356d2ae --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-cx36-hwm9-j7v8/GHSA-cx36-hwm9-j7v8.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cx36-hwm9-j7v8", + "modified": "2025-06-10T21:31:24Z", + "published": "2025-06-10T21:31:24Z", + "aliases": [ + "CVE-2025-5975" + ], + "details": "A vulnerability, which was classified as problematic, was found in PHPGurukul Rail Pass Management System 1.0. This affects an unknown part of the file /rpms/download-pass.php. The manipulation of the argument searchdata leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5975" + }, + { + "type": "WEB", + "url": "https://github.com/kakalalaww/CVE/issues/9" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311853" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311853" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.592440" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T20:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-gccm-j8cw-3hcg/GHSA-gccm-j8cw-3hcg.json b/advisories/unreviewed/2025/06/GHSA-gccm-j8cw-3hcg/GHSA-gccm-j8cw-3hcg.json index 02f929426b2..fa814031f75 100644 --- a/advisories/unreviewed/2025/06/GHSA-gccm-j8cw-3hcg/GHSA-gccm-j8cw-3hcg.json +++ b/advisories/unreviewed/2025/06/GHSA-gccm-j8cw-3hcg/GHSA-gccm-j8cw-3hcg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gccm-j8cw-3hcg", - "modified": "2025-06-10T06:31:38Z", + "modified": "2025-06-10T21:31:21Z", "published": "2025-06-10T06:31:38Z", "aliases": [ "CVE-2025-4840" ], "details": "The inprosysmedia-likes-dislikes-post WordPress plugin through 1.0.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-10T06:15:22Z" diff --git a/advisories/unreviewed/2025/06/GHSA-gp97-h73h-crr6/GHSA-gp97-h73h-crr6.json b/advisories/unreviewed/2025/06/GHSA-gp97-h73h-crr6/GHSA-gp97-h73h-crr6.json new file mode 100644 index 00000000000..654a5255949 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-gp97-h73h-crr6/GHSA-gp97-h73h-crr6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gp97-h73h-crr6", + "modified": "2025-06-10T21:31:23Z", + "published": "2025-06-10T21:31:23Z", + "aliases": [ + "CVE-2025-43579" + ], + "details": "Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by an Information Exposure vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to gain unauthorized access to sensitive information. Exploitation of this issue does not require user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43579" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/acrobat/apsb25-57.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T19:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-gxgp-r84x-ph9x/GHSA-gxgp-r84x-ph9x.json b/advisories/unreviewed/2025/06/GHSA-gxgp-r84x-ph9x/GHSA-gxgp-r84x-ph9x.json new file mode 100644 index 00000000000..c9bd2e87c0a --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-gxgp-r84x-ph9x/GHSA-gxgp-r84x-ph9x.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gxgp-r84x-ph9x", + "modified": "2025-06-10T21:31:23Z", + "published": "2025-06-10T21:31:23Z", + "aliases": [ + "CVE-2024-41502" + ], + "details": "Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS) via the form field \"Observaces\" (observances) in the \"Pessoas\" (persons) section when creating or editing either a legal or a natural person.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41502" + }, + { + "type": "WEB", + "url": "https://github.com/rafaelbaldasso/CVE-2024-41502" + }, + { + "type": "WEB", + "url": "http://jetimob.com" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T20:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-h6m7-5g9v-g97c/GHSA-h6m7-5g9v-g97c.json b/advisories/unreviewed/2025/06/GHSA-h6m7-5g9v-g97c/GHSA-h6m7-5g9v-g97c.json new file mode 100644 index 00000000000..cf1407820e1 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-h6m7-5g9v-g97c/GHSA-h6m7-5g9v-g97c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h6m7-5g9v-g97c", + "modified": "2025-06-10T21:31:22Z", + "published": "2025-06-10T21:31:22Z", + "aliases": [ + "CVE-2025-43550" + ], + "details": "Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43550" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/acrobat/apsb25-57.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T19:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-hw43-jx4x-7g84/GHSA-hw43-jx4x-7g84.json b/advisories/unreviewed/2025/06/GHSA-hw43-jx4x-7g84/GHSA-hw43-jx4x-7g84.json new file mode 100644 index 00000000000..420037c4656 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-hw43-jx4x-7g84/GHSA-hw43-jx4x-7g84.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hw43-jx4x-7g84", + "modified": "2025-06-10T21:31:24Z", + "published": "2025-06-10T21:31:24Z", + "aliases": [ + "CVE-2025-5979" + ], + "details": "A vulnerability classified as critical has been found in code-projects School Fees Payment System 1.0. This affects an unknown part of the file /branch.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5979" + }, + { + "type": "WEB", + "url": "https://github.com/jiangffffd/cve/issues/2" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311859" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311859" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.592463" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T21:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-jpxg-f4wp-2h3x/GHSA-jpxg-f4wp-2h3x.json b/advisories/unreviewed/2025/06/GHSA-jpxg-f4wp-2h3x/GHSA-jpxg-f4wp-2h3x.json new file mode 100644 index 00000000000..5d849429219 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-jpxg-f4wp-2h3x/GHSA-jpxg-f4wp-2h3x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jpxg-f4wp-2h3x", + "modified": "2025-06-10T21:31:23Z", + "published": "2025-06-10T21:31:23Z", + "aliases": [ + "CVE-2025-47107" + ], + "details": "InCopy versions 20.2, 19.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47107" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/incopy/apsb25-41.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T19:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-p23m-2c93-c3j5/GHSA-p23m-2c93-c3j5.json b/advisories/unreviewed/2025/06/GHSA-p23m-2c93-c3j5/GHSA-p23m-2c93-c3j5.json new file mode 100644 index 00000000000..9a6069dd10d --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-p23m-2c93-c3j5/GHSA-p23m-2c93-c3j5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p23m-2c93-c3j5", + "modified": "2025-06-10T21:31:22Z", + "published": "2025-06-10T21:31:22Z", + "aliases": [ + "CVE-2025-43573" + ], + "details": "Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43573" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/acrobat/apsb25-57.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T19:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-q4rv-v64c-3hff/GHSA-q4rv-v64c-3hff.json b/advisories/unreviewed/2025/06/GHSA-q4rv-v64c-3hff/GHSA-q4rv-v64c-3hff.json new file mode 100644 index 00000000000..976e14373dc --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-q4rv-v64c-3hff/GHSA-q4rv-v64c-3hff.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q4rv-v64c-3hff", + "modified": "2025-06-10T21:31:23Z", + "published": "2025-06-10T21:31:23Z", + "aliases": [ + "CVE-2025-3052" + ], + "details": "An arbitrary write vulnerability in Microsoft signed UEFI firmware allows for code execution of untrusted software. This allows an attacker to control its value, leading to arbitrary memory writes, including modification of critical firmware settings stored in NVRAM. Exploiting this vulnerability could enable security bypasses, persistence mechanisms, or full system compromise.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3052" + }, + { + "type": "WEB", + "url": "https://uefi.org/specs/UEFI/2.10/32_Secure_Boot_and_Driver_Signing.html" + }, + { + "type": "WEB", + "url": "https://www.binarly.io/advisories/brly-dva-2025-001" + }, + { + "type": "WEB", + "url": "https://www.kb.cert.org/vuls/id/806555" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T20:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-q932-m5f2-f55f/GHSA-q932-m5f2-f55f.json b/advisories/unreviewed/2025/06/GHSA-q932-m5f2-f55f/GHSA-q932-m5f2-f55f.json new file mode 100644 index 00000000000..4a56145aa5a --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-q932-m5f2-f55f/GHSA-q932-m5f2-f55f.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q932-m5f2-f55f", + "modified": "2025-06-10T21:31:24Z", + "published": "2025-06-10T21:31:24Z", + "aliases": [ + "CVE-2025-5980" + ], + "details": "A vulnerability classified as critical was found in code-projects Restaurant Order System 1.0. This vulnerability affects unknown code of the file /order.php. The manipulation of the argument tabidNoti leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5980" + }, + { + "type": "WEB", + "url": "https://github.com/jiangffffd/cve/issues/3" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311860" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311860" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.592467" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T21:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-qq9h-6xm2-q77v/GHSA-qq9h-6xm2-q77v.json b/advisories/unreviewed/2025/06/GHSA-qq9h-6xm2-q77v/GHSA-qq9h-6xm2-q77v.json new file mode 100644 index 00000000000..3357d8ee901 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-qq9h-6xm2-q77v/GHSA-qq9h-6xm2-q77v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qq9h-6xm2-q77v", + "modified": "2025-06-10T21:31:23Z", + "published": "2025-06-10T21:31:23Z", + "aliases": [ + "CVE-2025-47112" + ], + "details": "Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47112" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/acrobat/apsb25-57.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T19:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-rhf9-f348-g9j3/GHSA-rhf9-f348-g9j3.json b/advisories/unreviewed/2025/06/GHSA-rhf9-f348-g9j3/GHSA-rhf9-f348-g9j3.json new file mode 100644 index 00000000000..5bc6b96b0c3 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-rhf9-f348-g9j3/GHSA-rhf9-f348-g9j3.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rhf9-f348-g9j3", + "modified": "2025-06-10T21:31:23Z", + "published": "2025-06-10T21:31:23Z", + "aliases": [ + "CVE-2025-5973" + ], + "details": "A vulnerability classified as problematic was found in PHPGurukul Restaurant Table Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/add-table.php. The manipulation of the argument tableno leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5973" + }, + { + "type": "WEB", + "url": "https://github.com/kakalalaww/CVE/issues/6" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311851" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311851" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.592343" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T19:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-rp42-8rq2-m4vq/GHSA-rp42-8rq2-m4vq.json b/advisories/unreviewed/2025/06/GHSA-rp42-8rq2-m4vq/GHSA-rp42-8rq2-m4vq.json new file mode 100644 index 00000000000..e55b295fec7 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-rp42-8rq2-m4vq/GHSA-rp42-8rq2-m4vq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rp42-8rq2-m4vq", + "modified": "2025-06-10T21:31:22Z", + "published": "2025-06-10T21:31:22Z", + "aliases": [ + "CVE-2025-43577" + ], + "details": "Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43577" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/acrobat/apsb25-57.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T19:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-rrr2-jcr8-7q3x/GHSA-rrr2-jcr8-7q3x.json b/advisories/unreviewed/2025/06/GHSA-rrr2-jcr8-7q3x/GHSA-rrr2-jcr8-7q3x.json new file mode 100644 index 00000000000..50332fc3877 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-rrr2-jcr8-7q3x/GHSA-rrr2-jcr8-7q3x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rrr2-jcr8-7q3x", + "modified": "2025-06-10T21:31:23Z", + "published": "2025-06-10T21:31:23Z", + "aliases": [ + "CVE-2025-36852" + ], + "details": "A critical security vulnerability exists in remote cache extensions for common build systems utilizing bucket-based remote cache (such as those using Amazon S3, Google Cloud Storage, or similar object storage) that allows any contributor with pull request privileges to inject compromised artifacts from an untrusted environment into trusted production environments without detection. \n\n\n\n\nThe vulnerability exploits a fundamental design flaw in the \"first-to-cache wins\" principle, where artifacts built in untrusted environments (feature branches, pull requests) can poison the cache used by trusted environments (protected branches, production deployments). \n\n\n\n\nThis attack bypasses all traditional security measures including encryption, access controls, and checksum validation because the poisoning occurs during the artifact construction phase, before any security measures are applied.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:U/V:C/RE:M/U:Red" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-36852" + }, + { + "type": "WEB", + "url": "https://nx.app/files/cve-2025-06" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-829" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T20:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-w6rq-5ggq-m372/GHSA-w6rq-5ggq-m372.json b/advisories/unreviewed/2025/06/GHSA-w6rq-5ggq-m372/GHSA-w6rq-5ggq-m372.json index ee8f7aa7d5c..6a16b21bde7 100644 --- a/advisories/unreviewed/2025/06/GHSA-w6rq-5ggq-m372/GHSA-w6rq-5ggq-m372.json +++ b/advisories/unreviewed/2025/06/GHSA-w6rq-5ggq-m372/GHSA-w6rq-5ggq-m372.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w6rq-5ggq-m372", - "modified": "2025-06-09T06:30:22Z", + "modified": "2025-06-10T21:31:21Z", "published": "2025-06-09T06:30:22Z", "aliases": [ "CVE-2025-4652" ], "details": "The Broadstreet WordPress plugin before 1.51.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-09T06:15:25Z" diff --git a/advisories/unreviewed/2025/06/GHSA-x7pm-2wpr-q9mh/GHSA-x7pm-2wpr-q9mh.json b/advisories/unreviewed/2025/06/GHSA-x7pm-2wpr-q9mh/GHSA-x7pm-2wpr-q9mh.json new file mode 100644 index 00000000000..807ba24c688 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-x7pm-2wpr-q9mh/GHSA-x7pm-2wpr-q9mh.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x7pm-2wpr-q9mh", + "modified": "2025-06-10T21:31:23Z", + "published": "2025-06-10T21:31:23Z", + "aliases": [ + "CVE-2025-5972" + ], + "details": "A vulnerability classified as problematic has been found in PHPGurukul Restaurant Table Booking System 1.0. Affected is an unknown function of the file /admin/manage-subadmins.php. The manipulation of the argument fullname leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5972" + }, + { + "type": "WEB", + "url": "https://github.com/kakalalaww/CVE/issues/5" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311850" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311850" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.592340" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T19:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-x9cf-p29j-c3gc/GHSA-x9cf-p29j-c3gc.json b/advisories/unreviewed/2025/06/GHSA-x9cf-p29j-c3gc/GHSA-x9cf-p29j-c3gc.json new file mode 100644 index 00000000000..bca41effb92 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-x9cf-p29j-c3gc/GHSA-x9cf-p29j-c3gc.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x9cf-p29j-c3gc", + "modified": "2025-06-10T21:31:24Z", + "published": "2025-06-10T21:31:24Z", + "aliases": [ + "CVE-2025-5974" + ], + "details": "A vulnerability, which was classified as problematic, has been found in PHPGurukul Restaurant Table Booking System 1.0. Affected by this issue is some unknown functionality of the file /check-status.php. The manipulation of the argument searchdata leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5974" + }, + { + "type": "WEB", + "url": "https://github.com/kakalalaww/CVE/issues/8" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311852" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311852" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.592357" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T20:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-xm3q-vf5j-mg52/GHSA-xm3q-vf5j-mg52.json b/advisories/unreviewed/2025/06/GHSA-xm3q-vf5j-mg52/GHSA-xm3q-vf5j-mg52.json index 720bafb2b22..e140d237f70 100644 --- a/advisories/unreviewed/2025/06/GHSA-xm3q-vf5j-mg52/GHSA-xm3q-vf5j-mg52.json +++ b/advisories/unreviewed/2025/06/GHSA-xm3q-vf5j-mg52/GHSA-xm3q-vf5j-mg52.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/06/GHSA-xwv7-xr8f-pf75/GHSA-xwv7-xr8f-pf75.json b/advisories/unreviewed/2025/06/GHSA-xwv7-xr8f-pf75/GHSA-xwv7-xr8f-pf75.json new file mode 100644 index 00000000000..efe4b8992f1 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-xwv7-xr8f-pf75/GHSA-xwv7-xr8f-pf75.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xwv7-xr8f-pf75", + "modified": "2025-06-10T21:31:24Z", + "published": "2025-06-10T21:31:24Z", + "aliases": [ + "CVE-2025-5978" + ], + "details": "A vulnerability was found in Tenda FH1202 1.2.0.14. It has been classified as critical. Affected is the function fromVirtualSer of the file /goform/VirtualSer. The manipulation of the argument page leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5978" + }, + { + "type": "WEB", + "url": "https://lavender-bicycle-a5a.notion.site/Tenda-FH1202-fromVirtualSer-20b53a41781f80b7a6c7e727f93d7d9f?source=copy_link" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311856" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311856" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.592462" + }, + { + "type": "WEB", + "url": "https://www.tenda.com.cn" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T21:15:22Z" + } +} \ No newline at end of file