diff --git a/advisories/unreviewed/2022/09/GHSA-c6mf-qfg4-63q6/GHSA-c6mf-qfg4-63q6.json b/advisories/unreviewed/2022/09/GHSA-c6mf-qfg4-63q6/GHSA-c6mf-qfg4-63q6.json index 18555e38768..7823cbe34f6 100644 --- a/advisories/unreviewed/2022/09/GHSA-c6mf-qfg4-63q6/GHSA-c6mf-qfg4-63q6.json +++ b/advisories/unreviewed/2022/09/GHSA-c6mf-qfg4-63q6/GHSA-c6mf-qfg4-63q6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c6mf-qfg4-63q6", - "modified": "2022-09-22T00:00:32Z", + "modified": "2025-06-03T18:30:29Z", "published": "2022-09-17T00:00:33Z", "aliases": [ "CVE-2022-39001" diff --git a/advisories/unreviewed/2022/09/GHSA-gch9-mhrp-q35m/GHSA-gch9-mhrp-q35m.json b/advisories/unreviewed/2022/09/GHSA-gch9-mhrp-q35m/GHSA-gch9-mhrp-q35m.json index f59ba7d771f..9edb32b8de6 100644 --- a/advisories/unreviewed/2022/09/GHSA-gch9-mhrp-q35m/GHSA-gch9-mhrp-q35m.json +++ b/advisories/unreviewed/2022/09/GHSA-gch9-mhrp-q35m/GHSA-gch9-mhrp-q35m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gch9-mhrp-q35m", - "modified": "2022-09-22T00:00:31Z", + "modified": "2025-06-03T18:30:29Z", "published": "2022-09-17T00:00:33Z", "aliases": [ "CVE-2022-39007" @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-269", "CWE-287" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2022/09/GHSA-hff6-mv2f-62rw/GHSA-hff6-mv2f-62rw.json b/advisories/unreviewed/2022/09/GHSA-hff6-mv2f-62rw/GHSA-hff6-mv2f-62rw.json index 8f299459e24..8c80300ef86 100644 --- a/advisories/unreviewed/2022/09/GHSA-hff6-mv2f-62rw/GHSA-hff6-mv2f-62rw.json +++ b/advisories/unreviewed/2022/09/GHSA-hff6-mv2f-62rw/GHSA-hff6-mv2f-62rw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hff6-mv2f-62rw", - "modified": "2022-09-22T00:00:31Z", + "modified": "2025-06-03T18:30:29Z", "published": "2022-09-17T00:00:33Z", "aliases": [ "CVE-2022-39008" diff --git a/advisories/unreviewed/2024/01/GHSA-xx65-34vr-mqrj/GHSA-xx65-34vr-mqrj.json b/advisories/unreviewed/2024/01/GHSA-xx65-34vr-mqrj/GHSA-xx65-34vr-mqrj.json index 82c821c67fa..0f8dacdfe09 100644 --- a/advisories/unreviewed/2024/01/GHSA-xx65-34vr-mqrj/GHSA-xx65-34vr-mqrj.json +++ b/advisories/unreviewed/2024/01/GHSA-xx65-34vr-mqrj/GHSA-xx65-34vr-mqrj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xx65-34vr-mqrj", - "modified": "2024-02-05T15:30:23Z", + "modified": "2025-06-03T18:30:29Z", "published": "2024-01-26T09:30:23Z", "aliases": [ "CVE-2024-23388" diff --git a/advisories/unreviewed/2024/08/GHSA-5gxm-744m-qfgp/GHSA-5gxm-744m-qfgp.json b/advisories/unreviewed/2024/08/GHSA-5gxm-744m-qfgp/GHSA-5gxm-744m-qfgp.json index 0456ab76786..ea6c5400882 100644 --- a/advisories/unreviewed/2024/08/GHSA-5gxm-744m-qfgp/GHSA-5gxm-744m-qfgp.json +++ b/advisories/unreviewed/2024/08/GHSA-5gxm-744m-qfgp/GHSA-5gxm-744m-qfgp.json @@ -50,7 +50,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-37pp-xmcw-vg4w/GHSA-37pp-xmcw-vg4w.json b/advisories/unreviewed/2025/02/GHSA-37pp-xmcw-vg4w/GHSA-37pp-xmcw-vg4w.json index 934d4e9d03f..3ee7798269d 100644 --- a/advisories/unreviewed/2025/02/GHSA-37pp-xmcw-vg4w/GHSA-37pp-xmcw-vg4w.json +++ b/advisories/unreviewed/2025/02/GHSA-37pp-xmcw-vg4w/GHSA-37pp-xmcw-vg4w.json @@ -50,7 +50,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-24xc-5f2v-5mc5/GHSA-24xc-5f2v-5mc5.json b/advisories/unreviewed/2025/05/GHSA-24xc-5f2v-5mc5/GHSA-24xc-5f2v-5mc5.json index 8210bbfab05..1b6ae216e48 100644 --- a/advisories/unreviewed/2025/05/GHSA-24xc-5f2v-5mc5/GHSA-24xc-5f2v-5mc5.json +++ b/advisories/unreviewed/2025/05/GHSA-24xc-5f2v-5mc5/GHSA-24xc-5f2v-5mc5.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-2x3r-7c7j-hfjv/GHSA-2x3r-7c7j-hfjv.json b/advisories/unreviewed/2025/05/GHSA-2x3r-7c7j-hfjv/GHSA-2x3r-7c7j-hfjv.json index d539133d20e..6fff8aae31d 100644 --- a/advisories/unreviewed/2025/05/GHSA-2x3r-7c7j-hfjv/GHSA-2x3r-7c7j-hfjv.json +++ b/advisories/unreviewed/2025/05/GHSA-2x3r-7c7j-hfjv/GHSA-2x3r-7c7j-hfjv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2x3r-7c7j-hfjv", - "modified": "2025-05-26T12:30:30Z", + "modified": "2025-06-03T18:30:35Z", "published": "2025-05-26T12:30:30Z", "aliases": [ "CVE-2025-5179" diff --git a/advisories/unreviewed/2025/05/GHSA-3ff9-v8g6-rg9q/GHSA-3ff9-v8g6-rg9q.json b/advisories/unreviewed/2025/05/GHSA-3ff9-v8g6-rg9q/GHSA-3ff9-v8g6-rg9q.json index 7bd7bfcd966..4758a1e580b 100644 --- a/advisories/unreviewed/2025/05/GHSA-3ff9-v8g6-rg9q/GHSA-3ff9-v8g6-rg9q.json +++ b/advisories/unreviewed/2025/05/GHSA-3ff9-v8g6-rg9q/GHSA-3ff9-v8g6-rg9q.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-45cf-9mc2-p552/GHSA-45cf-9mc2-p552.json b/advisories/unreviewed/2025/05/GHSA-45cf-9mc2-p552/GHSA-45cf-9mc2-p552.json index 0c0426303b8..38bb98afba7 100644 --- a/advisories/unreviewed/2025/05/GHSA-45cf-9mc2-p552/GHSA-45cf-9mc2-p552.json +++ b/advisories/unreviewed/2025/05/GHSA-45cf-9mc2-p552/GHSA-45cf-9mc2-p552.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-55g9-6c2x-gf8q/GHSA-55g9-6c2x-gf8q.json b/advisories/unreviewed/2025/05/GHSA-55g9-6c2x-gf8q/GHSA-55g9-6c2x-gf8q.json index 95bd008c44b..fdac1c264c1 100644 --- a/advisories/unreviewed/2025/05/GHSA-55g9-6c2x-gf8q/GHSA-55g9-6c2x-gf8q.json +++ b/advisories/unreviewed/2025/05/GHSA-55g9-6c2x-gf8q/GHSA-55g9-6c2x-gf8q.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-502" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-5gc6-2564-mq66/GHSA-5gc6-2564-mq66.json b/advisories/unreviewed/2025/05/GHSA-5gc6-2564-mq66/GHSA-5gc6-2564-mq66.json index 9ce86dd0c38..b0349eec91e 100644 --- a/advisories/unreviewed/2025/05/GHSA-5gc6-2564-mq66/GHSA-5gc6-2564-mq66.json +++ b/advisories/unreviewed/2025/05/GHSA-5gc6-2564-mq66/GHSA-5gc6-2564-mq66.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-5wpj-mx2x-hx72/GHSA-5wpj-mx2x-hx72.json b/advisories/unreviewed/2025/05/GHSA-5wpj-mx2x-hx72/GHSA-5wpj-mx2x-hx72.json index f03fa4ec9a7..bbad2297a41 100644 --- a/advisories/unreviewed/2025/05/GHSA-5wpj-mx2x-hx72/GHSA-5wpj-mx2x-hx72.json +++ b/advisories/unreviewed/2025/05/GHSA-5wpj-mx2x-hx72/GHSA-5wpj-mx2x-hx72.json @@ -50,7 +50,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-125" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-6h7w-j6pv-9qgw/GHSA-6h7w-j6pv-9qgw.json b/advisories/unreviewed/2025/05/GHSA-6h7w-j6pv-9qgw/GHSA-6h7w-j6pv-9qgw.json index 116696ed41a..0566cfebe9c 100644 --- a/advisories/unreviewed/2025/05/GHSA-6h7w-j6pv-9qgw/GHSA-6h7w-j6pv-9qgw.json +++ b/advisories/unreviewed/2025/05/GHSA-6h7w-j6pv-9qgw/GHSA-6h7w-j6pv-9qgw.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-6q5v-v3c3-5mrp/GHSA-6q5v-v3c3-5mrp.json b/advisories/unreviewed/2025/05/GHSA-6q5v-v3c3-5mrp/GHSA-6q5v-v3c3-5mrp.json index f28193a8f65..703be0de932 100644 --- a/advisories/unreviewed/2025/05/GHSA-6q5v-v3c3-5mrp/GHSA-6q5v-v3c3-5mrp.json +++ b/advisories/unreviewed/2025/05/GHSA-6q5v-v3c3-5mrp/GHSA-6q5v-v3c3-5mrp.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-73j9-hwpp-f466/GHSA-73j9-hwpp-f466.json b/advisories/unreviewed/2025/05/GHSA-73j9-hwpp-f466/GHSA-73j9-hwpp-f466.json index ce52b623537..721a3708e58 100644 --- a/advisories/unreviewed/2025/05/GHSA-73j9-hwpp-f466/GHSA-73j9-hwpp-f466.json +++ b/advisories/unreviewed/2025/05/GHSA-73j9-hwpp-f466/GHSA-73j9-hwpp-f466.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-434" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-829c-hx47-67xw/GHSA-829c-hx47-67xw.json b/advisories/unreviewed/2025/05/GHSA-829c-hx47-67xw/GHSA-829c-hx47-67xw.json index a4969073cb6..f0894ec3848 100644 --- a/advisories/unreviewed/2025/05/GHSA-829c-hx47-67xw/GHSA-829c-hx47-67xw.json +++ b/advisories/unreviewed/2025/05/GHSA-829c-hx47-67xw/GHSA-829c-hx47-67xw.json @@ -50,7 +50,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-125" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-8pj5-84fx-c3xh/GHSA-8pj5-84fx-c3xh.json b/advisories/unreviewed/2025/05/GHSA-8pj5-84fx-c3xh/GHSA-8pj5-84fx-c3xh.json index 1b62ad7d4fc..7662bc76044 100644 --- a/advisories/unreviewed/2025/05/GHSA-8pj5-84fx-c3xh/GHSA-8pj5-84fx-c3xh.json +++ b/advisories/unreviewed/2025/05/GHSA-8pj5-84fx-c3xh/GHSA-8pj5-84fx-c3xh.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-f3xf-ch76-j4mw/GHSA-f3xf-ch76-j4mw.json b/advisories/unreviewed/2025/05/GHSA-f3xf-ch76-j4mw/GHSA-f3xf-ch76-j4mw.json index 81aade80b35..8db58e09d5b 100644 --- a/advisories/unreviewed/2025/05/GHSA-f3xf-ch76-j4mw/GHSA-f3xf-ch76-j4mw.json +++ b/advisories/unreviewed/2025/05/GHSA-f3xf-ch76-j4mw/GHSA-f3xf-ch76-j4mw.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-fgxx-mq9w-h6mc/GHSA-fgxx-mq9w-h6mc.json b/advisories/unreviewed/2025/05/GHSA-fgxx-mq9w-h6mc/GHSA-fgxx-mq9w-h6mc.json index c60a1a12ff2..85d83ae95b2 100644 --- a/advisories/unreviewed/2025/05/GHSA-fgxx-mq9w-h6mc/GHSA-fgxx-mq9w-h6mc.json +++ b/advisories/unreviewed/2025/05/GHSA-fgxx-mq9w-h6mc/GHSA-fgxx-mq9w-h6mc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fgxx-mq9w-h6mc", - "modified": "2025-05-26T09:30:35Z", + "modified": "2025-06-03T18:30:35Z", "published": "2025-05-26T09:30:35Z", "aliases": [ "CVE-2025-5176" @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-fp8j-jjxv-2295/GHSA-fp8j-jjxv-2295.json b/advisories/unreviewed/2025/05/GHSA-fp8j-jjxv-2295/GHSA-fp8j-jjxv-2295.json index 404c860f09a..f5eff9dcb91 100644 --- a/advisories/unreviewed/2025/05/GHSA-fp8j-jjxv-2295/GHSA-fp8j-jjxv-2295.json +++ b/advisories/unreviewed/2025/05/GHSA-fp8j-jjxv-2295/GHSA-fp8j-jjxv-2295.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-hfpp-xwvh-4mcc/GHSA-hfpp-xwvh-4mcc.json b/advisories/unreviewed/2025/05/GHSA-hfpp-xwvh-4mcc/GHSA-hfpp-xwvh-4mcc.json index d06044ada46..3b92ee74d12 100644 --- a/advisories/unreviewed/2025/05/GHSA-hfpp-xwvh-4mcc/GHSA-hfpp-xwvh-4mcc.json +++ b/advisories/unreviewed/2025/05/GHSA-hfpp-xwvh-4mcc/GHSA-hfpp-xwvh-4mcc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hfpp-xwvh-4mcc", - "modified": "2025-05-26T12:30:30Z", + "modified": "2025-06-03T18:30:35Z", "published": "2025-05-26T12:30:30Z", "aliases": [ "CVE-2025-5177" diff --git a/advisories/unreviewed/2025/05/GHSA-hvj4-qf24-vggm/GHSA-hvj4-qf24-vggm.json b/advisories/unreviewed/2025/05/GHSA-hvj4-qf24-vggm/GHSA-hvj4-qf24-vggm.json index 731518f1e76..385f970ec79 100644 --- a/advisories/unreviewed/2025/05/GHSA-hvj4-qf24-vggm/GHSA-hvj4-qf24-vggm.json +++ b/advisories/unreviewed/2025/05/GHSA-hvj4-qf24-vggm/GHSA-hvj4-qf24-vggm.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-jg2v-6g6x-hx35/GHSA-jg2v-6g6x-hx35.json b/advisories/unreviewed/2025/05/GHSA-jg2v-6g6x-hx35/GHSA-jg2v-6g6x-hx35.json index 9622239665d..c9af51d3cdc 100644 --- a/advisories/unreviewed/2025/05/GHSA-jg2v-6g6x-hx35/GHSA-jg2v-6g6x-hx35.json +++ b/advisories/unreviewed/2025/05/GHSA-jg2v-6g6x-hx35/GHSA-jg2v-6g6x-hx35.json @@ -50,7 +50,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-125" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-jv59-53f5-37p7/GHSA-jv59-53f5-37p7.json b/advisories/unreviewed/2025/05/GHSA-jv59-53f5-37p7/GHSA-jv59-53f5-37p7.json index 776a4d34872..e5e0e96d602 100644 --- a/advisories/unreviewed/2025/05/GHSA-jv59-53f5-37p7/GHSA-jv59-53f5-37p7.json +++ b/advisories/unreviewed/2025/05/GHSA-jv59-53f5-37p7/GHSA-jv59-53f5-37p7.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-426" + "CWE-426", + "CWE-427" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-mhg6-w3h6-f286/GHSA-mhg6-w3h6-f286.json b/advisories/unreviewed/2025/05/GHSA-mhg6-w3h6-f286/GHSA-mhg6-w3h6-f286.json index caef246af5b..d49b72709b8 100644 --- a/advisories/unreviewed/2025/05/GHSA-mhg6-w3h6-f286/GHSA-mhg6-w3h6-f286.json +++ b/advisories/unreviewed/2025/05/GHSA-mhg6-w3h6-f286/GHSA-mhg6-w3h6-f286.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-p64m-3pg6-g8pq/GHSA-p64m-3pg6-g8pq.json b/advisories/unreviewed/2025/05/GHSA-p64m-3pg6-g8pq/GHSA-p64m-3pg6-g8pq.json index 62925d472e1..6fae74a3f67 100644 --- a/advisories/unreviewed/2025/05/GHSA-p64m-3pg6-g8pq/GHSA-p64m-3pg6-g8pq.json +++ b/advisories/unreviewed/2025/05/GHSA-p64m-3pg6-g8pq/GHSA-p64m-3pg6-g8pq.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-p79q-2vjx-gr7p/GHSA-p79q-2vjx-gr7p.json b/advisories/unreviewed/2025/05/GHSA-p79q-2vjx-gr7p/GHSA-p79q-2vjx-gr7p.json index 98fe3f30153..89abd74894e 100644 --- a/advisories/unreviewed/2025/05/GHSA-p79q-2vjx-gr7p/GHSA-p79q-2vjx-gr7p.json +++ b/advisories/unreviewed/2025/05/GHSA-p79q-2vjx-gr7p/GHSA-p79q-2vjx-gr7p.json @@ -50,7 +50,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-125" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-p84j-ggc3-5x2h/GHSA-p84j-ggc3-5x2h.json b/advisories/unreviewed/2025/05/GHSA-p84j-ggc3-5x2h/GHSA-p84j-ggc3-5x2h.json index c220445be50..cb5e8f8ed02 100644 --- a/advisories/unreviewed/2025/05/GHSA-p84j-ggc3-5x2h/GHSA-p84j-ggc3-5x2h.json +++ b/advisories/unreviewed/2025/05/GHSA-p84j-ggc3-5x2h/GHSA-p84j-ggc3-5x2h.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-q22v-8f6w-43w8/GHSA-q22v-8f6w-43w8.json b/advisories/unreviewed/2025/05/GHSA-q22v-8f6w-43w8/GHSA-q22v-8f6w-43w8.json index 855c2be19ed..5f52ef4d484 100644 --- a/advisories/unreviewed/2025/05/GHSA-q22v-8f6w-43w8/GHSA-q22v-8f6w-43w8.json +++ b/advisories/unreviewed/2025/05/GHSA-q22v-8f6w-43w8/GHSA-q22v-8f6w-43w8.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-798" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-q55x-cgc8-49xh/GHSA-q55x-cgc8-49xh.json b/advisories/unreviewed/2025/05/GHSA-q55x-cgc8-49xh/GHSA-q55x-cgc8-49xh.json index dcd449cbfa8..e7114457738 100644 --- a/advisories/unreviewed/2025/05/GHSA-q55x-cgc8-49xh/GHSA-q55x-cgc8-49xh.json +++ b/advisories/unreviewed/2025/05/GHSA-q55x-cgc8-49xh/GHSA-q55x-cgc8-49xh.json @@ -50,7 +50,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-125" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-qjfw-6989-7pvv/GHSA-qjfw-6989-7pvv.json b/advisories/unreviewed/2025/05/GHSA-qjfw-6989-7pvv/GHSA-qjfw-6989-7pvv.json index 1e9803e3774..7caa46bce9d 100644 --- a/advisories/unreviewed/2025/05/GHSA-qjfw-6989-7pvv/GHSA-qjfw-6989-7pvv.json +++ b/advisories/unreviewed/2025/05/GHSA-qjfw-6989-7pvv/GHSA-qjfw-6989-7pvv.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-434" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-qw9v-w977-pp2h/GHSA-qw9v-w977-pp2h.json b/advisories/unreviewed/2025/05/GHSA-qw9v-w977-pp2h/GHSA-qw9v-w977-pp2h.json index 2461961c742..3c042b34a6e 100644 --- a/advisories/unreviewed/2025/05/GHSA-qw9v-w977-pp2h/GHSA-qw9v-w977-pp2h.json +++ b/advisories/unreviewed/2025/05/GHSA-qw9v-w977-pp2h/GHSA-qw9v-w977-pp2h.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-rjv6-gj2v-mh9h/GHSA-rjv6-gj2v-mh9h.json b/advisories/unreviewed/2025/05/GHSA-rjv6-gj2v-mh9h/GHSA-rjv6-gj2v-mh9h.json index 4f8deb0b9cb..5322ffcf376 100644 --- a/advisories/unreviewed/2025/05/GHSA-rjv6-gj2v-mh9h/GHSA-rjv6-gj2v-mh9h.json +++ b/advisories/unreviewed/2025/05/GHSA-rjv6-gj2v-mh9h/GHSA-rjv6-gj2v-mh9h.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-285" + "CWE-285", + "CWE-639" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-rmgg-7vrg-pg6w/GHSA-rmgg-7vrg-pg6w.json b/advisories/unreviewed/2025/05/GHSA-rmgg-7vrg-pg6w/GHSA-rmgg-7vrg-pg6w.json index 999f037299f..bdbfb1d87de 100644 --- a/advisories/unreviewed/2025/05/GHSA-rmgg-7vrg-pg6w/GHSA-rmgg-7vrg-pg6w.json +++ b/advisories/unreviewed/2025/05/GHSA-rmgg-7vrg-pg6w/GHSA-rmgg-7vrg-pg6w.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-vqh7-q5w4-vwr6/GHSA-vqh7-q5w4-vwr6.json b/advisories/unreviewed/2025/05/GHSA-vqh7-q5w4-vwr6/GHSA-vqh7-q5w4-vwr6.json index 10e8e3d2983..d7a2d944224 100644 --- a/advisories/unreviewed/2025/05/GHSA-vqh7-q5w4-vwr6/GHSA-vqh7-q5w4-vwr6.json +++ b/advisories/unreviewed/2025/05/GHSA-vqh7-q5w4-vwr6/GHSA-vqh7-q5w4-vwr6.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-434" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-wcrv-5jp3-rmqr/GHSA-wcrv-5jp3-rmqr.json b/advisories/unreviewed/2025/05/GHSA-wcrv-5jp3-rmqr/GHSA-wcrv-5jp3-rmqr.json index b4e802086b2..b91f5c11273 100644 --- a/advisories/unreviewed/2025/05/GHSA-wcrv-5jp3-rmqr/GHSA-wcrv-5jp3-rmqr.json +++ b/advisories/unreviewed/2025/05/GHSA-wcrv-5jp3-rmqr/GHSA-wcrv-5jp3-rmqr.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-434" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-x94g-xwgg-g5h7/GHSA-x94g-xwgg-g5h7.json b/advisories/unreviewed/2025/05/GHSA-x94g-xwgg-g5h7/GHSA-x94g-xwgg-g5h7.json index 31f1a3e1522..f8b8b8774a1 100644 --- a/advisories/unreviewed/2025/05/GHSA-x94g-xwgg-g5h7/GHSA-x94g-xwgg-g5h7.json +++ b/advisories/unreviewed/2025/05/GHSA-x94g-xwgg-g5h7/GHSA-x94g-xwgg-g5h7.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-x9c5-wggq-jw83/GHSA-x9c5-wggq-jw83.json b/advisories/unreviewed/2025/05/GHSA-x9c5-wggq-jw83/GHSA-x9c5-wggq-jw83.json index 311e97af35c..0b8da48be59 100644 --- a/advisories/unreviewed/2025/05/GHSA-x9c5-wggq-jw83/GHSA-x9c5-wggq-jw83.json +++ b/advisories/unreviewed/2025/05/GHSA-x9c5-wggq-jw83/GHSA-x9c5-wggq-jw83.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/06/GHSA-24gp-26hm-9h7f/GHSA-24gp-26hm-9h7f.json b/advisories/unreviewed/2025/06/GHSA-24gp-26hm-9h7f/GHSA-24gp-26hm-9h7f.json new file mode 100644 index 00000000000..58c8e91ec10 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-24gp-26hm-9h7f/GHSA-24gp-26hm-9h7f.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-24gp-26hm-9h7f", + "modified": "2025-06-03T18:30:41Z", + "published": "2025-06-03T18:30:41Z", + "aliases": [ + "CVE-2025-23107" + ], + "details": "An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The lack of a length check leads to out-of-bounds writes.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23107" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2025-23107" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T17:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-2wgg-6f6v-vvvx/GHSA-2wgg-6f6v-vvvx.json b/advisories/unreviewed/2025/06/GHSA-2wgg-6f6v-vvvx/GHSA-2wgg-6f6v-vvvx.json new file mode 100644 index 00000000000..c9796fdd9e0 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-2wgg-6f6v-vvvx/GHSA-2wgg-6f6v-vvvx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2wgg-6f6v-vvvx", + "modified": "2025-06-03T18:30:41Z", + "published": "2025-06-03T18:30:41Z", + "aliases": [ + "CVE-2025-25019" + ], + "details": "IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 does not invalidate session after a logout which could allow a user to impersonate another user on the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25019" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7235432" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-613" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-3q79-wmhj-39pr/GHSA-3q79-wmhj-39pr.json b/advisories/unreviewed/2025/06/GHSA-3q79-wmhj-39pr/GHSA-3q79-wmhj-39pr.json index 5dda189d35b..90f43eb2c52 100644 --- a/advisories/unreviewed/2025/06/GHSA-3q79-wmhj-39pr/GHSA-3q79-wmhj-39pr.json +++ b/advisories/unreviewed/2025/06/GHSA-3q79-wmhj-39pr/GHSA-3q79-wmhj-39pr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3q79-wmhj-39pr", - "modified": "2025-06-03T06:31:15Z", + "modified": "2025-06-03T18:30:40Z", "published": "2025-06-03T06:31:15Z", "aliases": [ "CVE-2025-3662" ], "details": "The FancyBox for WordPress plugin before 3.3.6 does not escape captions and titles attributes before using them to populate galleries' caption fields. The issue was received as a Contributor+ Stored XSS, however one of our researcher (Marc Montpas) escalated it to an Unauthenticated Stored XSS", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-03T06:15:27Z" diff --git a/advisories/unreviewed/2025/06/GHSA-4g4g-fqw4-prp2/GHSA-4g4g-fqw4-prp2.json b/advisories/unreviewed/2025/06/GHSA-4g4g-fqw4-prp2/GHSA-4g4g-fqw4-prp2.json index 6c8caa9c102..a6a8e416806 100644 --- a/advisories/unreviewed/2025/06/GHSA-4g4g-fqw4-prp2/GHSA-4g4g-fqw4-prp2.json +++ b/advisories/unreviewed/2025/06/GHSA-4g4g-fqw4-prp2/GHSA-4g4g-fqw4-prp2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4g4g-fqw4-prp2", - "modified": "2025-06-03T15:31:25Z", + "modified": "2025-06-03T18:30:41Z", "published": "2025-06-03T15:31:25Z", "aliases": [ "CVE-2025-4138" @@ -31,10 +31,18 @@ "type": "WEB", "url": "https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da" }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9" + }, { "type": "WEB", "url": "https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a" }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e" + }, { "type": "WEB", "url": "https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a" diff --git a/advisories/unreviewed/2025/06/GHSA-4rgj-78j5-635j/GHSA-4rgj-78j5-635j.json b/advisories/unreviewed/2025/06/GHSA-4rgj-78j5-635j/GHSA-4rgj-78j5-635j.json index 8d566c47871..776fff5da0f 100644 --- a/advisories/unreviewed/2025/06/GHSA-4rgj-78j5-635j/GHSA-4rgj-78j5-635j.json +++ b/advisories/unreviewed/2025/06/GHSA-4rgj-78j5-635j/GHSA-4rgj-78j5-635j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4rgj-78j5-635j", - "modified": "2025-06-03T06:31:15Z", + "modified": "2025-06-03T18:30:40Z", "published": "2025-06-03T06:31:15Z", "aliases": [ "CVE-2025-4567" ], "details": "The Post Slider and Post Carousel with Post Vertical Scrolling Widget WordPress plugin before 3.2.10 does not validate and escape some of its Widget options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-03T06:15:27Z" diff --git a/advisories/unreviewed/2025/06/GHSA-65w5-5qgg-4h59/GHSA-65w5-5qgg-4h59.json b/advisories/unreviewed/2025/06/GHSA-65w5-5qgg-4h59/GHSA-65w5-5qgg-4h59.json index 090b745311e..3aebb026648 100644 --- a/advisories/unreviewed/2025/06/GHSA-65w5-5qgg-4h59/GHSA-65w5-5qgg-4h59.json +++ b/advisories/unreviewed/2025/06/GHSA-65w5-5qgg-4h59/GHSA-65w5-5qgg-4h59.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-77" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/06/GHSA-68pj-xrp5-vccj/GHSA-68pj-xrp5-vccj.json b/advisories/unreviewed/2025/06/GHSA-68pj-xrp5-vccj/GHSA-68pj-xrp5-vccj.json index 0275fc504e2..c7d48bc15e0 100644 --- a/advisories/unreviewed/2025/06/GHSA-68pj-xrp5-vccj/GHSA-68pj-xrp5-vccj.json +++ b/advisories/unreviewed/2025/06/GHSA-68pj-xrp5-vccj/GHSA-68pj-xrp5-vccj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-68pj-xrp5-vccj", - "modified": "2025-06-03T15:31:25Z", + "modified": "2025-06-03T18:30:41Z", "published": "2025-06-03T15:31:25Z", "aliases": [ "CVE-2025-4330" @@ -31,10 +31,18 @@ "type": "WEB", "url": "https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da" }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9" + }, { "type": "WEB", "url": "https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a" }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e" + }, { "type": "WEB", "url": "https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a" diff --git a/advisories/unreviewed/2025/06/GHSA-6p39-gq6w-rwhx/GHSA-6p39-gq6w-rwhx.json b/advisories/unreviewed/2025/06/GHSA-6p39-gq6w-rwhx/GHSA-6p39-gq6w-rwhx.json index 435e163e0cd..9de49e67fa9 100644 --- a/advisories/unreviewed/2025/06/GHSA-6p39-gq6w-rwhx/GHSA-6p39-gq6w-rwhx.json +++ b/advisories/unreviewed/2025/06/GHSA-6p39-gq6w-rwhx/GHSA-6p39-gq6w-rwhx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6p39-gq6w-rwhx", - "modified": "2025-06-03T06:31:15Z", + "modified": "2025-06-03T18:30:40Z", "published": "2025-06-03T06:31:15Z", "aliases": [ "CVE-2025-3584" ], "details": "The Newsletter WordPress plugin before 8.8.2 does not sanitise and escape some of its Subscription settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-03T06:15:27Z" diff --git a/advisories/unreviewed/2025/06/GHSA-6r6c-684h-9j7p/GHSA-6r6c-684h-9j7p.json b/advisories/unreviewed/2025/06/GHSA-6r6c-684h-9j7p/GHSA-6r6c-684h-9j7p.json index 15cb5d5e572..061eeb14dc8 100644 --- a/advisories/unreviewed/2025/06/GHSA-6r6c-684h-9j7p/GHSA-6r6c-684h-9j7p.json +++ b/advisories/unreviewed/2025/06/GHSA-6r6c-684h-9j7p/GHSA-6r6c-684h-9j7p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6r6c-684h-9j7p", - "modified": "2025-06-03T15:31:25Z", + "modified": "2025-06-03T18:30:41Z", "published": "2025-06-03T15:31:25Z", "aliases": [ "CVE-2025-4517" @@ -31,10 +31,18 @@ "type": "WEB", "url": "https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da" }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9" + }, { "type": "WEB", "url": "https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a" }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e" + }, { "type": "WEB", "url": "https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a" diff --git a/advisories/unreviewed/2025/06/GHSA-73rm-fmgw-mwv5/GHSA-73rm-fmgw-mwv5.json b/advisories/unreviewed/2025/06/GHSA-73rm-fmgw-mwv5/GHSA-73rm-fmgw-mwv5.json new file mode 100644 index 00000000000..1fc6c0fe5f2 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-73rm-fmgw-mwv5/GHSA-73rm-fmgw-mwv5.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-73rm-fmgw-mwv5", + "modified": "2025-06-03T18:30:41Z", + "published": "2025-06-03T18:30:41Z", + "aliases": [ + "CVE-2025-5512" + ], + "details": "A vulnerability, which was classified as critical, was found in quequnlong shiyi-blog up to 1.2.1. Affected is an unknown function of the file /api/sys/user/verifyPassword/ of the component Administrator Backend. The manipulation leads to improper authentication. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5512" + }, + { + "type": "WEB", + "url": "https://github.com/uglory-gll/javasec/blob/main/shiyi-blog.md" + }, + { + "type": "WEB", + "url": "https://github.com/uglory-gll/javasec/blob/main/shiyi-blog.md#32attackers-can-bypass-screen-lock-to-access-the-backend" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310926" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310926" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.584491" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T17:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-7pcg-pjpf-rf23/GHSA-7pcg-pjpf-rf23.json b/advisories/unreviewed/2025/06/GHSA-7pcg-pjpf-rf23/GHSA-7pcg-pjpf-rf23.json new file mode 100644 index 00000000000..dedc10a6f63 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-7pcg-pjpf-rf23/GHSA-7pcg-pjpf-rf23.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7pcg-pjpf-rf23", + "modified": "2025-06-03T18:30:42Z", + "published": "2025-06-03T18:30:42Z", + "aliases": [ + "CVE-2025-5515" + ], + "details": "A vulnerability, which was classified as critical, has been found in TOTOLINK X2000R 1.0.0-B20230726.1108. Affected by this issue is some unknown functionality of the file /boafrm/formMapDel. The manipulation of the argument devicemac1 leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5515" + }, + { + "type": "WEB", + "url": "https://github.com/fizz-is-on-the-way/Iot_vuls/blob/main/X2000R/RCE_formMapDel/RCE_formMapDel.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310952" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310952" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.584653" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T18:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-82rr-6r42-9rg4/GHSA-82rr-6r42-9rg4.json b/advisories/unreviewed/2025/06/GHSA-82rr-6r42-9rg4/GHSA-82rr-6r42-9rg4.json new file mode 100644 index 00000000000..72faf1a8fbf --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-82rr-6r42-9rg4/GHSA-82rr-6r42-9rg4.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-82rr-6r42-9rg4", + "modified": "2025-06-03T18:30:41Z", + "published": "2025-06-03T18:30:41Z", + "aliases": [ + "CVE-2025-23103" + ], + "details": "An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The lack of a length check leads to out-of-bounds writes.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23103" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2025-23103" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-8gw9-w5qj-8xvr/GHSA-8gw9-w5qj-8xvr.json b/advisories/unreviewed/2025/06/GHSA-8gw9-w5qj-8xvr/GHSA-8gw9-w5qj-8xvr.json new file mode 100644 index 00000000000..e2ce3362b6c --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-8gw9-w5qj-8xvr/GHSA-8gw9-w5qj-8xvr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8gw9-w5qj-8xvr", + "modified": "2025-06-03T18:30:41Z", + "published": "2025-06-03T18:30:41Z", + "aliases": [ + "CVE-2025-25021" + ], + "details": "IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow a privileged execute code in case management script creation due to the improper generation of code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25021" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7235432" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-8wx4-4fr5-g6r8/GHSA-8wx4-4fr5-g6r8.json b/advisories/unreviewed/2025/06/GHSA-8wx4-4fr5-g6r8/GHSA-8wx4-4fr5-g6r8.json new file mode 100644 index 00000000000..7c4c767be23 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-8wx4-4fr5-g6r8/GHSA-8wx4-4fr5-g6r8.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8wx4-4fr5-g6r8", + "modified": "2025-06-03T18:30:41Z", + "published": "2025-06-03T18:30:41Z", + "aliases": [ + "CVE-2025-5510" + ], + "details": "A vulnerability classified as critical was found in quequnlong shiyi-blog up to 1.2.1. This vulnerability affects unknown code of the file /app/sys/article/optimize. The manipulation of the argument url leads to server-side request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5510" + }, + { + "type": "WEB", + "url": "https://github.com/uglory-gll/javasec/blob/main/shiyi-blog.md" + }, + { + "type": "WEB", + "url": "https://github.com/uglory-gll/javasec/blob/main/shiyi-blog.md#2ssrf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310924" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310924" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.584489" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T17:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-99j9-vp2v-228j/GHSA-99j9-vp2v-228j.json b/advisories/unreviewed/2025/06/GHSA-99j9-vp2v-228j/GHSA-99j9-vp2v-228j.json index 1ecf2f55656..34dd48d3c8a 100644 --- a/advisories/unreviewed/2025/06/GHSA-99j9-vp2v-228j/GHSA-99j9-vp2v-228j.json +++ b/advisories/unreviewed/2025/06/GHSA-99j9-vp2v-228j/GHSA-99j9-vp2v-228j.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-120" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/06/GHSA-9qvj-rpj8-v5c8/GHSA-9qvj-rpj8-v5c8.json b/advisories/unreviewed/2025/06/GHSA-9qvj-rpj8-v5c8/GHSA-9qvj-rpj8-v5c8.json index de5d4aa4576..038bf287c5f 100644 --- a/advisories/unreviewed/2025/06/GHSA-9qvj-rpj8-v5c8/GHSA-9qvj-rpj8-v5c8.json +++ b/advisories/unreviewed/2025/06/GHSA-9qvj-rpj8-v5c8/GHSA-9qvj-rpj8-v5c8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9qvj-rpj8-v5c8", - "modified": "2025-06-03T15:31:27Z", + "modified": "2025-06-03T18:30:41Z", "published": "2025-06-03T15:31:27Z", "aliases": [ "CVE-2025-46548" @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://lists.apache.org/thread/tnd84hj9w0ggjcft6cp12q67d5jzhp66" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/06/03/7" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/06/GHSA-c6r7-xfw8-p583/GHSA-c6r7-xfw8-p583.json b/advisories/unreviewed/2025/06/GHSA-c6r7-xfw8-p583/GHSA-c6r7-xfw8-p583.json new file mode 100644 index 00000000000..add745c651c --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-c6r7-xfw8-p583/GHSA-c6r7-xfw8-p583.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c6r7-xfw8-p583", + "modified": "2025-06-03T18:30:42Z", + "published": "2025-06-03T18:30:41Z", + "aliases": [ + "CVE-2025-5513" + ], + "details": "A vulnerability has been found in quequnlong shiyi-blog up to 1.2.1 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /dev-api/api/comment/add. The manipulation of the argument content leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5513" + }, + { + "type": "WEB", + "url": "https://github.com/uglory-gll/javasec/blob/main/shiyi-blog.md" + }, + { + "type": "WEB", + "url": "https://github.com/uglory-gll/javasec/blob/main/shiyi-blog.md#4stored-cross-site-scripting" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310927" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310927" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.584492" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T18:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-fpff-3qmf-f6fg/GHSA-fpff-3qmf-f6fg.json b/advisories/unreviewed/2025/06/GHSA-fpff-3qmf-f6fg/GHSA-fpff-3qmf-f6fg.json new file mode 100644 index 00000000000..fe62b1eef3e --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-fpff-3qmf-f6fg/GHSA-fpff-3qmf-f6fg.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fpff-3qmf-f6fg", + "modified": "2025-06-03T18:30:41Z", + "published": "2025-06-03T18:30:41Z", + "aliases": [ + "CVE-2025-5509" + ], + "details": "A vulnerability classified as critical has been found in quequnlong shiyi-blog up to 1.2.1. This affects an unknown part of the file /api/file/upload. The manipulation of the argument file/source leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5509" + }, + { + "type": "WEB", + "url": "https://github.com/uglory-gll/javasec/blob/main/shiyi-blog.md" + }, + { + "type": "WEB", + "url": "https://github.com/uglory-gll/javasec/blob/main/shiyi-blog.md#1file-path-traversal" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310923" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310923" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.584488" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-g3c7-95hc-gv66/GHSA-g3c7-95hc-gv66.json b/advisories/unreviewed/2025/06/GHSA-g3c7-95hc-gv66/GHSA-g3c7-95hc-gv66.json new file mode 100644 index 00000000000..7e698dd05e5 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-g3c7-95hc-gv66/GHSA-g3c7-95hc-gv66.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g3c7-95hc-gv66", + "modified": "2025-06-03T18:30:41Z", + "published": "2025-06-03T18:30:41Z", + "aliases": [ + "CVE-2025-45854" + ], + "details": "An arbitrary file upload vulnerability in the component /server/executeExec of JEHC-BPM v2.0.1 allows attackers to execute arbitrary code via uploading a crafted file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45854" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Cafe-Tea/bc14b38f4bfd951de2979a24c3358460" + }, + { + "type": "WEB", + "url": "https://gitee.com/jehc/JEHC-BPM" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-g6gr-6rr9-69jw/GHSA-g6gr-6rr9-69jw.json b/advisories/unreviewed/2025/06/GHSA-g6gr-6rr9-69jw/GHSA-g6gr-6rr9-69jw.json index d0e37143c6a..bc2a0e4590d 100644 --- a/advisories/unreviewed/2025/06/GHSA-g6gr-6rr9-69jw/GHSA-g6gr-6rr9-69jw.json +++ b/advisories/unreviewed/2025/06/GHSA-g6gr-6rr9-69jw/GHSA-g6gr-6rr9-69jw.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-476" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/06/GHSA-ggcg-qqqw-c8ff/GHSA-ggcg-qqqw-c8ff.json b/advisories/unreviewed/2025/06/GHSA-ggcg-qqqw-c8ff/GHSA-ggcg-qqqw-c8ff.json new file mode 100644 index 00000000000..b6c653a8732 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-ggcg-qqqw-c8ff/GHSA-ggcg-qqqw-c8ff.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ggcg-qqqw-c8ff", + "modified": "2025-06-03T18:30:41Z", + "published": "2025-06-03T18:30:41Z", + "aliases": [ + "CVE-2025-1334" + ], + "details": "IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 allows web pages to be stored locally which can be read by another user on the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1334" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7235432" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-525" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T16:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-hx4r-v9cq-h9mg/GHSA-hx4r-v9cq-h9mg.json b/advisories/unreviewed/2025/06/GHSA-hx4r-v9cq-h9mg/GHSA-hx4r-v9cq-h9mg.json index b4e60139531..74da0542e42 100644 --- a/advisories/unreviewed/2025/06/GHSA-hx4r-v9cq-h9mg/GHSA-hx4r-v9cq-h9mg.json +++ b/advisories/unreviewed/2025/06/GHSA-hx4r-v9cq-h9mg/GHSA-hx4r-v9cq-h9mg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hx4r-v9cq-h9mg", - "modified": "2025-06-02T03:30:24Z", + "modified": "2025-06-03T18:30:40Z", "published": "2025-06-02T03:30:24Z", "aliases": [ "CVE-2025-20677" ], "details": "In Bluetooth driver, there is a possible system crash due to an uncaught exception. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00412256; Issue ID: MSV-3284.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-02T03:15:25Z" diff --git a/advisories/unreviewed/2025/06/GHSA-hx7r-89vp-x3gj/GHSA-hx7r-89vp-x3gj.json b/advisories/unreviewed/2025/06/GHSA-hx7r-89vp-x3gj/GHSA-hx7r-89vp-x3gj.json new file mode 100644 index 00000000000..52cba736909 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-hx7r-89vp-x3gj/GHSA-hx7r-89vp-x3gj.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hx7r-89vp-x3gj", + "modified": "2025-06-03T18:30:41Z", + "published": "2025-06-03T18:30:41Z", + "aliases": [ + "CVE-2025-32106" + ], + "details": "In Audiocodes Mediapack MP-11x through 6.60A.369.002, a crafted POST request request may result in an unauthenticated remote user's ability to execute unauthorized code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32106" + }, + { + "type": "WEB", + "url": "https://Audiocodes.com" + }, + { + "type": "WEB", + "url": "https://github.com/austin2111/papers/blob/main/Software_Vulnerabilities_in_Telecommunications_Hardware.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T17:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-jqjr-322m-7mjw/GHSA-jqjr-322m-7mjw.json b/advisories/unreviewed/2025/06/GHSA-jqjr-322m-7mjw/GHSA-jqjr-322m-7mjw.json new file mode 100644 index 00000000000..7eefd0f297e --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-jqjr-322m-7mjw/GHSA-jqjr-322m-7mjw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jqjr-322m-7mjw", + "modified": "2025-06-03T18:30:41Z", + "published": "2025-06-03T18:30:41Z", + "aliases": [ + "CVE-2025-25022" + ], + "details": "IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow an unauthenticated user in the environment to obtain highly sensitive information in configuration files.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25022" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7235432" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-260" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-jvhv-7727-rf3v/GHSA-jvhv-7727-rf3v.json b/advisories/unreviewed/2025/06/GHSA-jvhv-7727-rf3v/GHSA-jvhv-7727-rf3v.json index 8785f8103ff..a1905cba5cf 100644 --- a/advisories/unreviewed/2025/06/GHSA-jvhv-7727-rf3v/GHSA-jvhv-7727-rf3v.json +++ b/advisories/unreviewed/2025/06/GHSA-jvhv-7727-rf3v/GHSA-jvhv-7727-rf3v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jvhv-7727-rf3v", - "modified": "2025-06-02T18:30:52Z", + "modified": "2025-06-03T18:30:40Z", "published": "2025-06-02T18:30:52Z", "aliases": [ "CVE-2025-45542" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://medium.com/@sanjay70023/cve-2025-45542-time-based-blind-sql-injection-in-cloudclassroom-php-project-v1-0-1fa0efc8a94a" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2025/Jun/12" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/06/GHSA-mcvh-wcmh-927v/GHSA-mcvh-wcmh-927v.json b/advisories/unreviewed/2025/06/GHSA-mcvh-wcmh-927v/GHSA-mcvh-wcmh-927v.json new file mode 100644 index 00000000000..a7d0962632f --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-mcvh-wcmh-927v/GHSA-mcvh-wcmh-927v.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mcvh-wcmh-927v", + "modified": "2025-06-03T18:30:41Z", + "published": "2025-06-03T18:30:41Z", + "aliases": [ + "CVE-2025-44148" + ], + "details": "Cross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via the failure.aspx component", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44148" + }, + { + "type": "WEB", + "url": "https://github.com/barisbaydur/CVE-2025-44148" + }, + { + "type": "WEB", + "url": "http://mailenable.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-mjq6-f642-426f/GHSA-mjq6-f642-426f.json b/advisories/unreviewed/2025/06/GHSA-mjq6-f642-426f/GHSA-mjq6-f642-426f.json new file mode 100644 index 00000000000..ef52d871633 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-mjq6-f642-426f/GHSA-mjq6-f642-426f.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mjq6-f642-426f", + "modified": "2025-06-03T18:30:42Z", + "published": "2025-06-03T18:30:41Z", + "aliases": [ + "CVE-2025-5511" + ], + "details": "A vulnerability, which was classified as critical, has been found in quequnlong shiyi-blog up to 1.2.1. This issue affects some unknown processing of the file /dev api/app/album/photos/. The manipulation leads to improper authorization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5511" + }, + { + "type": "WEB", + "url": "https://github.com/uglory-gll/javasec/blob/main/shiyi-blog.md" + }, + { + "type": "WEB", + "url": "https://github.com/uglory-gll/javasec/blob/main/shiyi-blog.md#31bypass-password-verification-and-directly-view-photo-albums" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310925" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310925" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.584490" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T17:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-mqmr-5x7c-pxxx/GHSA-mqmr-5x7c-pxxx.json b/advisories/unreviewed/2025/06/GHSA-mqmr-5x7c-pxxx/GHSA-mqmr-5x7c-pxxx.json new file mode 100644 index 00000000000..ce86d389de6 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-mqmr-5x7c-pxxx/GHSA-mqmr-5x7c-pxxx.json @@ -0,0 +1,64 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mqmr-5x7c-pxxx", + "modified": "2025-06-03T18:30:42Z", + "published": "2025-06-03T18:30:42Z", + "aliases": [ + "CVE-2025-5520" + ], + "details": "A vulnerability was found in Open5GS up to 2.7.3. It has been classified as problematic. Affected is the function gmm_state_authentication/emm_state_authentication of the component AMF/MME. The manipulation leads to reachable assertion. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 9f5d133657850e6167231527514ee1364d37a884. It is recommended to apply a patch to fix this issue. This is a different issue than CVE-2025-1893.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5520" + }, + { + "type": "WEB", + "url": "https://github.com/open5gs/open5gs/issues/3910" + }, + { + "type": "WEB", + "url": "https://github.com/open5gs/open5gs/issues/3910#issuecomment-2926719317" + }, + { + "type": "WEB", + "url": "https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884" + }, + { + "type": "WEB", + "url": "https://github.com/user-attachments/files/20362243/Problematic.handover.required.process.zip" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310956" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310956" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.582269" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-617" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T18:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-p72v-37h5-753v/GHSA-p72v-37h5-753v.json b/advisories/unreviewed/2025/06/GHSA-p72v-37h5-753v/GHSA-p72v-37h5-753v.json index 300043402e8..ac87b5c0d42 100644 --- a/advisories/unreviewed/2025/06/GHSA-p72v-37h5-753v/GHSA-p72v-37h5-753v.json +++ b/advisories/unreviewed/2025/06/GHSA-p72v-37h5-753v/GHSA-p72v-37h5-753v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p72v-37h5-753v", - "modified": "2025-06-03T15:31:25Z", + "modified": "2025-06-03T18:30:41Z", "published": "2025-06-03T15:31:25Z", "aliases": [ "CVE-2025-4435" @@ -31,10 +31,18 @@ "type": "WEB", "url": "https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da" }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9" + }, { "type": "WEB", "url": "https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a" }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e" + }, { "type": "WEB", "url": "https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a" diff --git a/advisories/unreviewed/2025/06/GHSA-pggq-8qg7-4m9m/GHSA-pggq-8qg7-4m9m.json b/advisories/unreviewed/2025/06/GHSA-pggq-8qg7-4m9m/GHSA-pggq-8qg7-4m9m.json new file mode 100644 index 00000000000..e3b93575c4f --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-pggq-8qg7-4m9m/GHSA-pggq-8qg7-4m9m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pggq-8qg7-4m9m", + "modified": "2025-06-03T18:30:41Z", + "published": "2025-06-03T18:30:41Z", + "aliases": [ + "CVE-2025-32105" + ], + "details": "A buffer overflow in the the Sangoma IMG2020 HTTP server through 2.3.9.6 allows an unauthenticated user to achieve remote code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32105" + }, + { + "type": "WEB", + "url": "https://github.com/austin2111/papers/blob/main/Software_Vulnerabilities_in_Telecommunications_Hardware.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T17:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-q3q3-r499-2w2w/GHSA-q3q3-r499-2w2w.json b/advisories/unreviewed/2025/06/GHSA-q3q3-r499-2w2w/GHSA-q3q3-r499-2w2w.json new file mode 100644 index 00000000000..a650669a806 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-q3q3-r499-2w2w/GHSA-q3q3-r499-2w2w.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q3q3-r499-2w2w", + "modified": "2025-06-03T18:30:41Z", + "published": "2025-06-03T18:30:41Z", + "aliases": [ + "CVE-2025-5508" + ], + "details": "A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011. It has been rated as problematic. Affected by this issue is some unknown functionality of the component IP Port Filtering Page. The manipulation of the argument Comment leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5508" + }, + { + "type": "WEB", + "url": "https://github.com/fizz-is-on-the-way/Iot_vuls/tree/main/A3002RU_V2/XSS_IP_Port_Filtering" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310922" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310922" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.584671" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-r8gp-c62w-m7jr/GHSA-r8gp-c62w-m7jr.json b/advisories/unreviewed/2025/06/GHSA-r8gp-c62w-m7jr/GHSA-r8gp-c62w-m7jr.json new file mode 100644 index 00000000000..f174391a4c4 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-r8gp-c62w-m7jr/GHSA-r8gp-c62w-m7jr.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r8gp-c62w-m7jr", + "modified": "2025-06-03T18:30:42Z", + "published": "2025-06-03T18:30:42Z", + "aliases": [ + "CVE-2025-5516" + ], + "details": "A vulnerability, which was classified as problematic, was found in TOTOLINK X2000R 1.0.0-B20230726.1108. This affects an unknown part of the file /boafrm/formFilter of the component URL Filtering Page. The manipulation of the argument URL Address leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5516" + }, + { + "type": "WEB", + "url": "https://github.com/fizz-is-on-the-way/Iot_vuls/tree/main/X2000R/XSS_url_filtering" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310953" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310953" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.584661" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T18:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-rw7v-mvq9-wxc3/GHSA-rw7v-mvq9-wxc3.json b/advisories/unreviewed/2025/06/GHSA-rw7v-mvq9-wxc3/GHSA-rw7v-mvq9-wxc3.json new file mode 100644 index 00000000000..7cd86e67a72 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-rw7v-mvq9-wxc3/GHSA-rw7v-mvq9-wxc3.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rw7v-mvq9-wxc3", + "modified": "2025-06-03T18:30:41Z", + "published": "2025-06-03T18:30:41Z", + "aliases": [ + "CVE-2025-5507" + ], + "details": "A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component MAC Filtering Page. The manipulation of the argument Comment leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5507" + }, + { + "type": "WEB", + "url": "https://github.com/fizz-is-on-the-way/Iot_vuls/tree/main/A3002RU_V2/XSS_Mac_filtering" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310921" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310921" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.584664" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-v7wr-69gh-4wh3/GHSA-v7wr-69gh-4wh3.json b/advisories/unreviewed/2025/06/GHSA-v7wr-69gh-4wh3/GHSA-v7wr-69gh-4wh3.json index 17276dc3305..faf6a43026b 100644 --- a/advisories/unreviewed/2025/06/GHSA-v7wr-69gh-4wh3/GHSA-v7wr-69gh-4wh3.json +++ b/advisories/unreviewed/2025/06/GHSA-v7wr-69gh-4wh3/GHSA-v7wr-69gh-4wh3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v7wr-69gh-4wh3", - "modified": "2025-06-02T03:30:24Z", + "modified": "2025-06-03T18:30:40Z", "published": "2025-06-02T03:30:23Z", "aliases": [ "CVE-2025-20676" ], "details": "In wlan STA driver, there is a possible system crash due to an uncaught exception. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00412240; Issue ID: MSV-3293.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-02T03:15:24Z" diff --git a/advisories/unreviewed/2025/06/GHSA-wmgq-6qjq-p9j6/GHSA-wmgq-6qjq-p9j6.json b/advisories/unreviewed/2025/06/GHSA-wmgq-6qjq-p9j6/GHSA-wmgq-6qjq-p9j6.json new file mode 100644 index 00000000000..6b1c58893ae --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-wmgq-6qjq-p9j6/GHSA-wmgq-6qjq-p9j6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wmgq-6qjq-p9j6", + "modified": "2025-06-03T18:30:41Z", + "published": "2025-06-03T18:30:41Z", + "aliases": [ + "CVE-2025-25020" + ], + "details": "IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow an authenticated user to cause a denial of service due to improperly validating API data input.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25020" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7235432" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T16:15:24Z" + } +} \ No newline at end of file