diff --git a/advisories/unreviewed/2022/10/GHSA-45x6-9f7m-559p/GHSA-45x6-9f7m-559p.json b/advisories/unreviewed/2022/10/GHSA-45x6-9f7m-559p/GHSA-45x6-9f7m-559p.json index 022b9d25a27..88f5ae75319 100644 --- a/advisories/unreviewed/2022/10/GHSA-45x6-9f7m-559p/GHSA-45x6-9f7m-559p.json +++ b/advisories/unreviewed/2022/10/GHSA-45x6-9f7m-559p/GHSA-45x6-9f7m-559p.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-285" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-579p-3xv7-xhp3/GHSA-579p-3xv7-xhp3.json b/advisories/unreviewed/2022/10/GHSA-579p-3xv7-xhp3/GHSA-579p-3xv7-xhp3.json index 766ecdcd778..ae7e57d657d 100644 --- a/advisories/unreviewed/2022/10/GHSA-579p-3xv7-xhp3/GHSA-579p-3xv7-xhp3.json +++ b/advisories/unreviewed/2022/10/GHSA-579p-3xv7-xhp3/GHSA-579p-3xv7-xhp3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-579p-3xv7-xhp3", - "modified": "2023-01-21T03:30:28Z", + "modified": "2025-05-07T21:31:36Z", "published": "2022-10-21T19:01:14Z", "aliases": [ "CVE-2022-3597" diff --git a/advisories/unreviewed/2022/10/GHSA-6cg2-4798-gw4g/GHSA-6cg2-4798-gw4g.json b/advisories/unreviewed/2022/10/GHSA-6cg2-4798-gw4g/GHSA-6cg2-4798-gw4g.json index c5267d0452b..b8fb84c9897 100644 --- a/advisories/unreviewed/2022/10/GHSA-6cg2-4798-gw4g/GHSA-6cg2-4798-gw4g.json +++ b/advisories/unreviewed/2022/10/GHSA-6cg2-4798-gw4g/GHSA-6cg2-4798-gw4g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6cg2-4798-gw4g", - "modified": "2023-01-21T03:30:28Z", + "modified": "2025-05-07T21:31:36Z", "published": "2022-10-21T19:01:14Z", "aliases": [ "CVE-2022-3599" diff --git a/advisories/unreviewed/2022/10/GHSA-jpmh-qrhq-g32f/GHSA-jpmh-qrhq-g32f.json b/advisories/unreviewed/2022/10/GHSA-jpmh-qrhq-g32f/GHSA-jpmh-qrhq-g32f.json index 8e65d342cd6..afe79271e72 100644 --- a/advisories/unreviewed/2022/10/GHSA-jpmh-qrhq-g32f/GHSA-jpmh-qrhq-g32f.json +++ b/advisories/unreviewed/2022/10/GHSA-jpmh-qrhq-g32f/GHSA-jpmh-qrhq-g32f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jpmh-qrhq-g32f", - "modified": "2022-10-27T19:00:38Z", + "modified": "2025-05-07T21:31:37Z", "published": "2022-10-25T19:00:28Z", "aliases": [ "CVE-2022-36783" diff --git a/advisories/unreviewed/2022/10/GHSA-r9r4-j5ch-84qf/GHSA-r9r4-j5ch-84qf.json b/advisories/unreviewed/2022/10/GHSA-r9r4-j5ch-84qf/GHSA-r9r4-j5ch-84qf.json index a3c2fc4d846..ae3fb2d8c20 100644 --- a/advisories/unreviewed/2022/10/GHSA-r9r4-j5ch-84qf/GHSA-r9r4-j5ch-84qf.json +++ b/advisories/unreviewed/2022/10/GHSA-r9r4-j5ch-84qf/GHSA-r9r4-j5ch-84qf.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-306", "CWE-319" ], "severity": "LOW", diff --git a/advisories/unreviewed/2022/10/GHSA-w3vw-h42p-vjw6/GHSA-w3vw-h42p-vjw6.json b/advisories/unreviewed/2022/10/GHSA-w3vw-h42p-vjw6/GHSA-w3vw-h42p-vjw6.json index 205afbf8dd9..b8aefe1153c 100644 --- a/advisories/unreviewed/2022/10/GHSA-w3vw-h42p-vjw6/GHSA-w3vw-h42p-vjw6.json +++ b/advisories/unreviewed/2022/10/GHSA-w3vw-h42p-vjw6/GHSA-w3vw-h42p-vjw6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w3vw-h42p-vjw6", - "modified": "2023-01-21T03:30:28Z", + "modified": "2025-05-07T21:31:35Z", "published": "2022-10-21T19:01:14Z", "aliases": [ "CVE-2022-3570" diff --git a/advisories/unreviewed/2022/10/GHSA-w5jf-pq96-6w7c/GHSA-w5jf-pq96-6w7c.json b/advisories/unreviewed/2022/10/GHSA-w5jf-pq96-6w7c/GHSA-w5jf-pq96-6w7c.json index ad019df3819..3e35b55610a 100644 --- a/advisories/unreviewed/2022/10/GHSA-w5jf-pq96-6w7c/GHSA-w5jf-pq96-6w7c.json +++ b/advisories/unreviewed/2022/10/GHSA-w5jf-pq96-6w7c/GHSA-w5jf-pq96-6w7c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w5jf-pq96-6w7c", - "modified": "2022-10-28T19:00:42Z", + "modified": "2025-05-07T21:31:37Z", "published": "2022-10-26T12:00:31Z", "aliases": [ "CVE-2022-33178" diff --git a/advisories/unreviewed/2022/10/GHSA-wvgj-4785-cm7h/GHSA-wvgj-4785-cm7h.json b/advisories/unreviewed/2022/10/GHSA-wvgj-4785-cm7h/GHSA-wvgj-4785-cm7h.json index 4fafab8eba5..4118a918d75 100644 --- a/advisories/unreviewed/2022/10/GHSA-wvgj-4785-cm7h/GHSA-wvgj-4785-cm7h.json +++ b/advisories/unreviewed/2022/10/GHSA-wvgj-4785-cm7h/GHSA-wvgj-4785-cm7h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wvgj-4785-cm7h", - "modified": "2022-10-29T12:00:48Z", + "modified": "2025-05-07T21:31:38Z", "published": "2022-10-27T12:00:27Z", "aliases": [ "CVE-2022-2782" diff --git a/advisories/unreviewed/2022/10/GHSA-xqqh-8g96-r9wj/GHSA-xqqh-8g96-r9wj.json b/advisories/unreviewed/2022/10/GHSA-xqqh-8g96-r9wj/GHSA-xqqh-8g96-r9wj.json index 4dd262cbfb9..874ac7b32d6 100644 --- a/advisories/unreviewed/2022/10/GHSA-xqqh-8g96-r9wj/GHSA-xqqh-8g96-r9wj.json +++ b/advisories/unreviewed/2022/10/GHSA-xqqh-8g96-r9wj/GHSA-xqqh-8g96-r9wj.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-285" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-xqrw-f62h-4ff2/GHSA-xqrw-f62h-4ff2.json b/advisories/unreviewed/2022/10/GHSA-xqrw-f62h-4ff2/GHSA-xqrw-f62h-4ff2.json index 6dfb0862626..d476e57e218 100644 --- a/advisories/unreviewed/2022/10/GHSA-xqrw-f62h-4ff2/GHSA-xqrw-f62h-4ff2.json +++ b/advisories/unreviewed/2022/10/GHSA-xqrw-f62h-4ff2/GHSA-xqrw-f62h-4ff2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xqrw-f62h-4ff2", - "modified": "2022-10-31T19:00:36Z", + "modified": "2025-05-07T21:31:37Z", "published": "2022-10-26T12:00:39Z", "aliases": [ "CVE-2022-38162" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://www.withsecure.com/en/support/security-advisories" }, + { + "type": "WEB", + "url": "https://www.withsecure.com/en/support/security-advisories/cve-2022-38162?_gl=1%2Adtq2t3%2A_up%2AMQ..%2A_ga%2AMTMxOTM1OTA2MC4xNjY2NzIxMjQ0%2A_ga_B5SG5Y2DHS%2AMTY2NjcyMTI0MS4xLjAuMTY2NjcyMTI0MS4wLjAuMA.." + }, { "type": "WEB", "url": "https://www.withsecure.com/en/support/security-advisories/cve-2022-38162?_gl=1*dtq2t3*_up*MQ..*_ga*MTMxOTM1OTA2MC4xNjY2NzIxMjQ0*_ga_B5SG5Y2DHS*MTY2NjcyMTI0MS4xLjAuMTY2NjcyMTI0MS4wLjAuMA.." diff --git a/advisories/unreviewed/2023/07/GHSA-c65j-wcvh-77gc/GHSA-c65j-wcvh-77gc.json b/advisories/unreviewed/2023/07/GHSA-c65j-wcvh-77gc/GHSA-c65j-wcvh-77gc.json index 022fb5ffdaa..298d668a3df 100644 --- a/advisories/unreviewed/2023/07/GHSA-c65j-wcvh-77gc/GHSA-c65j-wcvh-77gc.json +++ b/advisories/unreviewed/2023/07/GHSA-c65j-wcvh-77gc/GHSA-c65j-wcvh-77gc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c65j-wcvh-77gc", - "modified": "2024-04-04T05:29:45Z", + "modified": "2025-05-07T21:31:36Z", "published": "2023-07-06T19:24:02Z", "aliases": [ "CVE-2022-35739" diff --git a/advisories/unreviewed/2023/12/GHSA-42rj-c8ww-p58f/GHSA-42rj-c8ww-p58f.json b/advisories/unreviewed/2023/12/GHSA-42rj-c8ww-p58f/GHSA-42rj-c8ww-p58f.json index 930c7b5193d..3f9d34623d7 100644 --- a/advisories/unreviewed/2023/12/GHSA-42rj-c8ww-p58f/GHSA-42rj-c8ww-p58f.json +++ b/advisories/unreviewed/2023/12/GHSA-42rj-c8ww-p58f/GHSA-42rj-c8ww-p58f.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-288" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/12/GHSA-8c4w-xw52-85px/GHSA-8c4w-xw52-85px.json b/advisories/unreviewed/2023/12/GHSA-8c4w-xw52-85px/GHSA-8c4w-xw52-85px.json index 4de12a6a350..ce0434c1008 100644 --- a/advisories/unreviewed/2023/12/GHSA-8c4w-xw52-85px/GHSA-8c4w-xw52-85px.json +++ b/advisories/unreviewed/2023/12/GHSA-8c4w-xw52-85px/GHSA-8c4w-xw52-85px.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8c4w-xw52-85px", - "modified": "2023-12-22T12:31:46Z", + "modified": "2025-05-07T21:31:38Z", "published": "2023-12-19T15:30:30Z", "aliases": [ "CVE-2023-6869" diff --git a/advisories/unreviewed/2023/12/GHSA-cm9x-r8m9-x222/GHSA-cm9x-r8m9-x222.json b/advisories/unreviewed/2023/12/GHSA-cm9x-r8m9-x222/GHSA-cm9x-r8m9-x222.json index 8e3d5b23549..5a98413f974 100644 --- a/advisories/unreviewed/2023/12/GHSA-cm9x-r8m9-x222/GHSA-cm9x-r8m9-x222.json +++ b/advisories/unreviewed/2023/12/GHSA-cm9x-r8m9-x222/GHSA-cm9x-r8m9-x222.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cm9x-r8m9-x222", - "modified": "2023-12-22T12:31:46Z", + "modified": "2025-05-07T21:31:38Z", "published": "2023-12-19T15:30:30Z", "aliases": [ "CVE-2023-6858" diff --git a/advisories/unreviewed/2024/01/GHSA-fc9w-pqjw-8r96/GHSA-fc9w-pqjw-8r96.json b/advisories/unreviewed/2024/01/GHSA-fc9w-pqjw-8r96/GHSA-fc9w-pqjw-8r96.json index 4f0fff64ad2..abd4b6d45a2 100644 --- a/advisories/unreviewed/2024/01/GHSA-fc9w-pqjw-8r96/GHSA-fc9w-pqjw-8r96.json +++ b/advisories/unreviewed/2024/01/GHSA-fc9w-pqjw-8r96/GHSA-fc9w-pqjw-8r96.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-fc9w-pqjw-8r96", - "modified": "2024-03-13T03:31:05Z", + "modified": "2025-05-07T21:31:38Z", "published": "2024-01-16T18:31:09Z", "aliases": [ "CVE-2023-45230" ], - "details": " EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. This\n vulnerability can be exploited by an attacker to gain unauthorized \naccess and potentially lead to a loss of Confidentiality, Integrity and/or Availability.\n\n", + "details": "EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. This\n vulnerability can be exploited by an attacker to gain unauthorized \naccess and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/02/GHSA-f9xc-7r8v-hf32/GHSA-f9xc-7r8v-hf32.json b/advisories/unreviewed/2024/02/GHSA-f9xc-7r8v-hf32/GHSA-f9xc-7r8v-hf32.json index 24687afa1df..8319ab1d72f 100644 --- a/advisories/unreviewed/2024/02/GHSA-f9xc-7r8v-hf32/GHSA-f9xc-7r8v-hf32.json +++ b/advisories/unreviewed/2024/02/GHSA-f9xc-7r8v-hf32/GHSA-f9xc-7r8v-hf32.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-434" + "CWE-434", + "CWE-502" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-x4gq-xcr8-xwp7/GHSA-x4gq-xcr8-xwp7.json b/advisories/unreviewed/2024/02/GHSA-x4gq-xcr8-xwp7/GHSA-x4gq-xcr8-xwp7.json index 4ad41500249..08f21cbcbc4 100644 --- a/advisories/unreviewed/2024/02/GHSA-x4gq-xcr8-xwp7/GHSA-x4gq-xcr8-xwp7.json +++ b/advisories/unreviewed/2024/02/GHSA-x4gq-xcr8-xwp7/GHSA-x4gq-xcr8-xwp7.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-22" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-6876-c4r3-53ww/GHSA-6876-c4r3-53ww.json b/advisories/unreviewed/2025/01/GHSA-6876-c4r3-53ww/GHSA-6876-c4r3-53ww.json index 0065665a983..6cd3ca61cf3 100644 --- a/advisories/unreviewed/2025/01/GHSA-6876-c4r3-53ww/GHSA-6876-c4r3-53ww.json +++ b/advisories/unreviewed/2025/01/GHSA-6876-c4r3-53ww/GHSA-6876-c4r3-53ww.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-69jp-7vgw-2cgr/GHSA-69jp-7vgw-2cgr.json b/advisories/unreviewed/2025/01/GHSA-69jp-7vgw-2cgr/GHSA-69jp-7vgw-2cgr.json index ef1e248e96b..d9a4daf1f4d 100644 --- a/advisories/unreviewed/2025/01/GHSA-69jp-7vgw-2cgr/GHSA-69jp-7vgw-2cgr.json +++ b/advisories/unreviewed/2025/01/GHSA-69jp-7vgw-2cgr/GHSA-69jp-7vgw-2cgr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-c33j-w5w4-w9q4/GHSA-c33j-w5w4-w9q4.json b/advisories/unreviewed/2025/01/GHSA-c33j-w5w4-w9q4/GHSA-c33j-w5w4-w9q4.json index d0b570e3921..c8970939acf 100644 --- a/advisories/unreviewed/2025/01/GHSA-c33j-w5w4-w9q4/GHSA-c33j-w5w4-w9q4.json +++ b/advisories/unreviewed/2025/01/GHSA-c33j-w5w4-w9q4/GHSA-c33j-w5w4-w9q4.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-c75v-42g3-xvcr/GHSA-c75v-42g3-xvcr.json b/advisories/unreviewed/2025/01/GHSA-c75v-42g3-xvcr/GHSA-c75v-42g3-xvcr.json index 79bb40f0da6..246ce8bb6a5 100644 --- a/advisories/unreviewed/2025/01/GHSA-c75v-42g3-xvcr/GHSA-c75v-42g3-xvcr.json +++ b/advisories/unreviewed/2025/01/GHSA-c75v-42g3-xvcr/GHSA-c75v-42g3-xvcr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-f5ph-j9m6-qjqc/GHSA-f5ph-j9m6-qjqc.json b/advisories/unreviewed/2025/01/GHSA-f5ph-j9m6-qjqc/GHSA-f5ph-j9m6-qjqc.json index b92981039a0..a2aafd7480a 100644 --- a/advisories/unreviewed/2025/01/GHSA-f5ph-j9m6-qjqc/GHSA-f5ph-j9m6-qjqc.json +++ b/advisories/unreviewed/2025/01/GHSA-f5ph-j9m6-qjqc/GHSA-f5ph-j9m6-qjqc.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-v9f7-mhwh-hfh9/GHSA-v9f7-mhwh-hfh9.json b/advisories/unreviewed/2025/01/GHSA-v9f7-mhwh-hfh9/GHSA-v9f7-mhwh-hfh9.json index dbf6697ce15..a20ed15a5c1 100644 --- a/advisories/unreviewed/2025/01/GHSA-v9f7-mhwh-hfh9/GHSA-v9f7-mhwh-hfh9.json +++ b/advisories/unreviewed/2025/01/GHSA-v9f7-mhwh-hfh9/GHSA-v9f7-mhwh-hfh9.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-644c-37wg-x7m6/GHSA-644c-37wg-x7m6.json b/advisories/unreviewed/2025/02/GHSA-644c-37wg-x7m6/GHSA-644c-37wg-x7m6.json index 5def3681645..a705f242e5c 100644 --- a/advisories/unreviewed/2025/02/GHSA-644c-37wg-x7m6/GHSA-644c-37wg-x7m6.json +++ b/advisories/unreviewed/2025/02/GHSA-644c-37wg-x7m6/GHSA-644c-37wg-x7m6.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-7fgp-fc75-5g7h/GHSA-7fgp-fc75-5g7h.json b/advisories/unreviewed/2025/02/GHSA-7fgp-fc75-5g7h/GHSA-7fgp-fc75-5g7h.json index 33739f34b7e..e8a1f01e8f2 100644 --- a/advisories/unreviewed/2025/02/GHSA-7fgp-fc75-5g7h/GHSA-7fgp-fc75-5g7h.json +++ b/advisories/unreviewed/2025/02/GHSA-7fgp-fc75-5g7h/GHSA-7fgp-fc75-5g7h.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-cfr2-48g6-c7rv/GHSA-cfr2-48g6-c7rv.json b/advisories/unreviewed/2025/02/GHSA-cfr2-48g6-c7rv/GHSA-cfr2-48g6-c7rv.json index 735d4fc6d23..a946666b44b 100644 --- a/advisories/unreviewed/2025/02/GHSA-cfr2-48g6-c7rv/GHSA-cfr2-48g6-c7rv.json +++ b/advisories/unreviewed/2025/02/GHSA-cfr2-48g6-c7rv/GHSA-cfr2-48g6-c7rv.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-cp9x-c42q-mmfp/GHSA-cp9x-c42q-mmfp.json b/advisories/unreviewed/2025/02/GHSA-cp9x-c42q-mmfp/GHSA-cp9x-c42q-mmfp.json index 046649903c2..b1fa1063d76 100644 --- a/advisories/unreviewed/2025/02/GHSA-cp9x-c42q-mmfp/GHSA-cp9x-c42q-mmfp.json +++ b/advisories/unreviewed/2025/02/GHSA-cp9x-c42q-mmfp/GHSA-cp9x-c42q-mmfp.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-v6qj-7vmr-f46c/GHSA-v6qj-7vmr-f46c.json b/advisories/unreviewed/2025/02/GHSA-v6qj-7vmr-f46c/GHSA-v6qj-7vmr-f46c.json index 8be53b728fd..b3bf3512138 100644 --- a/advisories/unreviewed/2025/02/GHSA-v6qj-7vmr-f46c/GHSA-v6qj-7vmr-f46c.json +++ b/advisories/unreviewed/2025/02/GHSA-v6qj-7vmr-f46c/GHSA-v6qj-7vmr-f46c.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-vhvv-g6wq-54gp/GHSA-vhvv-g6wq-54gp.json b/advisories/unreviewed/2025/02/GHSA-vhvv-g6wq-54gp/GHSA-vhvv-g6wq-54gp.json index 8ea90d3cb91..6787fa7aa2e 100644 --- a/advisories/unreviewed/2025/02/GHSA-vhvv-g6wq-54gp/GHSA-vhvv-g6wq-54gp.json +++ b/advisories/unreviewed/2025/02/GHSA-vhvv-g6wq-54gp/GHSA-vhvv-g6wq-54gp.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-3fhq-6hpj-6xr8/GHSA-3fhq-6hpj-6xr8.json b/advisories/unreviewed/2025/04/GHSA-3fhq-6hpj-6xr8/GHSA-3fhq-6hpj-6xr8.json index 5c100dd0922..e049de62dcc 100644 --- a/advisories/unreviewed/2025/04/GHSA-3fhq-6hpj-6xr8/GHSA-3fhq-6hpj-6xr8.json +++ b/advisories/unreviewed/2025/04/GHSA-3fhq-6hpj-6xr8/GHSA-3fhq-6hpj-6xr8.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-4jrh-22g5-5pwg/GHSA-4jrh-22g5-5pwg.json b/advisories/unreviewed/2025/04/GHSA-4jrh-22g5-5pwg/GHSA-4jrh-22g5-5pwg.json index 877c680f3cc..2f6a8996eec 100644 --- a/advisories/unreviewed/2025/04/GHSA-4jrh-22g5-5pwg/GHSA-4jrh-22g5-5pwg.json +++ b/advisories/unreviewed/2025/04/GHSA-4jrh-22g5-5pwg/GHSA-4jrh-22g5-5pwg.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-59gw-jx9x-fx7m/GHSA-59gw-jx9x-fx7m.json b/advisories/unreviewed/2025/04/GHSA-59gw-jx9x-fx7m/GHSA-59gw-jx9x-fx7m.json index 4d45780f9fc..dd1f60df78c 100644 --- a/advisories/unreviewed/2025/04/GHSA-59gw-jx9x-fx7m/GHSA-59gw-jx9x-fx7m.json +++ b/advisories/unreviewed/2025/04/GHSA-59gw-jx9x-fx7m/GHSA-59gw-jx9x-fx7m.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-77" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-66m2-9rhm-5rrv/GHSA-66m2-9rhm-5rrv.json b/advisories/unreviewed/2025/04/GHSA-66m2-9rhm-5rrv/GHSA-66m2-9rhm-5rrv.json index 2f64ea76cbd..fbaf6856d35 100644 --- a/advisories/unreviewed/2025/04/GHSA-66m2-9rhm-5rrv/GHSA-66m2-9rhm-5rrv.json +++ b/advisories/unreviewed/2025/04/GHSA-66m2-9rhm-5rrv/GHSA-66m2-9rhm-5rrv.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-9h3x-g96g-wcqp/GHSA-9h3x-g96g-wcqp.json b/advisories/unreviewed/2025/04/GHSA-9h3x-g96g-wcqp/GHSA-9h3x-g96g-wcqp.json index 058bc1e37ad..f72a247202e 100644 --- a/advisories/unreviewed/2025/04/GHSA-9h3x-g96g-wcqp/GHSA-9h3x-g96g-wcqp.json +++ b/advisories/unreviewed/2025/04/GHSA-9h3x-g96g-wcqp/GHSA-9h3x-g96g-wcqp.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-680" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/04/GHSA-c68w-vfvr-6rg8/GHSA-c68w-vfvr-6rg8.json b/advisories/unreviewed/2025/04/GHSA-c68w-vfvr-6rg8/GHSA-c68w-vfvr-6rg8.json index f2cf490305b..f526951c05c 100644 --- a/advisories/unreviewed/2025/04/GHSA-c68w-vfvr-6rg8/GHSA-c68w-vfvr-6rg8.json +++ b/advisories/unreviewed/2025/04/GHSA-c68w-vfvr-6rg8/GHSA-c68w-vfvr-6rg8.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-fr6v-2rhg-84h3/GHSA-fr6v-2rhg-84h3.json b/advisories/unreviewed/2025/04/GHSA-fr6v-2rhg-84h3/GHSA-fr6v-2rhg-84h3.json index c256e3ca600..5960b0b8366 100644 --- a/advisories/unreviewed/2025/04/GHSA-fr6v-2rhg-84h3/GHSA-fr6v-2rhg-84h3.json +++ b/advisories/unreviewed/2025/04/GHSA-fr6v-2rhg-84h3/GHSA-fr6v-2rhg-84h3.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-grgf-jm3x-9rcf/GHSA-grgf-jm3x-9rcf.json b/advisories/unreviewed/2025/04/GHSA-grgf-jm3x-9rcf/GHSA-grgf-jm3x-9rcf.json index 362ae125dde..a9440cde4b0 100644 --- a/advisories/unreviewed/2025/04/GHSA-grgf-jm3x-9rcf/GHSA-grgf-jm3x-9rcf.json +++ b/advisories/unreviewed/2025/04/GHSA-grgf-jm3x-9rcf/GHSA-grgf-jm3x-9rcf.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-22" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-h3qf-q3hj-98c2/GHSA-h3qf-q3hj-98c2.json b/advisories/unreviewed/2025/04/GHSA-h3qf-q3hj-98c2/GHSA-h3qf-q3hj-98c2.json index 8a159c99852..7472f12a04f 100644 --- a/advisories/unreviewed/2025/04/GHSA-h3qf-q3hj-98c2/GHSA-h3qf-q3hj-98c2.json +++ b/advisories/unreviewed/2025/04/GHSA-h3qf-q3hj-98c2/GHSA-h3qf-q3hj-98c2.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-q746-mv6h-3fx6/GHSA-q746-mv6h-3fx6.json b/advisories/unreviewed/2025/04/GHSA-q746-mv6h-3fx6/GHSA-q746-mv6h-3fx6.json index 9de10c12166..e1e6a6501c9 100644 --- a/advisories/unreviewed/2025/04/GHSA-q746-mv6h-3fx6/GHSA-q746-mv6h-3fx6.json +++ b/advisories/unreviewed/2025/04/GHSA-q746-mv6h-3fx6/GHSA-q746-mv6h-3fx6.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-qp3g-mq2p-x532/GHSA-qp3g-mq2p-x532.json b/advisories/unreviewed/2025/04/GHSA-qp3g-mq2p-x532/GHSA-qp3g-mq2p-x532.json index b304b663220..3e6f050ba9c 100644 --- a/advisories/unreviewed/2025/04/GHSA-qp3g-mq2p-x532/GHSA-qp3g-mq2p-x532.json +++ b/advisories/unreviewed/2025/04/GHSA-qp3g-mq2p-x532/GHSA-qp3g-mq2p-x532.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-26wx-r897-chcf/GHSA-26wx-r897-chcf.json b/advisories/unreviewed/2025/05/GHSA-26wx-r897-chcf/GHSA-26wx-r897-chcf.json index df88983fb50..fbadc92c4ea 100644 --- a/advisories/unreviewed/2025/05/GHSA-26wx-r897-chcf/GHSA-26wx-r897-chcf.json +++ b/advisories/unreviewed/2025/05/GHSA-26wx-r897-chcf/GHSA-26wx-r897-chcf.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-2vq3-r375-cjhg/GHSA-2vq3-r375-cjhg.json b/advisories/unreviewed/2025/05/GHSA-2vq3-r375-cjhg/GHSA-2vq3-r375-cjhg.json index f9cb789925d..b8086e8f99e 100644 --- a/advisories/unreviewed/2025/05/GHSA-2vq3-r375-cjhg/GHSA-2vq3-r375-cjhg.json +++ b/advisories/unreviewed/2025/05/GHSA-2vq3-r375-cjhg/GHSA-2vq3-r375-cjhg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2vq3-r375-cjhg", - "modified": "2025-05-07T00:31:34Z", + "modified": "2025-05-07T21:31:44Z", "published": "2025-05-07T00:31:34Z", "aliases": [ "CVE-2025-4372" ], "details": "Use after free in WebAudio in Google Chrome prior to 136.0.7103.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-06T22:15:17Z" diff --git a/advisories/unreviewed/2025/05/GHSA-3h4v-p542-7xmc/GHSA-3h4v-p542-7xmc.json b/advisories/unreviewed/2025/05/GHSA-3h4v-p542-7xmc/GHSA-3h4v-p542-7xmc.json new file mode 100644 index 00000000000..2d04cbda6df --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3h4v-p542-7xmc/GHSA-3h4v-p542-7xmc.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3h4v-p542-7xmc", + "modified": "2025-05-07T21:31:45Z", + "published": "2025-05-07T21:31:45Z", + "aliases": [ + "CVE-2025-26169" + ], + "details": "IXON VPN Client before 1.4.4 on Windows allows Local Privilege Escalation to SYSTEM because there is code execution from a configuration file that can be controlled by a low-privileged user. There is a race condition in which a temporary configuration file, in a world-writable directory, can be overwritten.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26169" + }, + { + "type": "WEB", + "url": "https://ixon-cloud.my.salesforce.com/sfc/p/#1t000000vlSF/a/TX000000DQmH/WRGwuYg2iMsKX6NAIK3MygCUOlg0SPQ..YvGWrwfNeM" + }, + { + "type": "WEB", + "url": "https://support.ixon.cloud/s/article/VPN-Client-installation-and-uninstallation" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T19:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3m2w-69h3-vmv2/GHSA-3m2w-69h3-vmv2.json b/advisories/unreviewed/2025/05/GHSA-3m2w-69h3-vmv2/GHSA-3m2w-69h3-vmv2.json index eabaa1013d1..840694a49e3 100644 --- a/advisories/unreviewed/2025/05/GHSA-3m2w-69h3-vmv2/GHSA-3m2w-69h3-vmv2.json +++ b/advisories/unreviewed/2025/05/GHSA-3m2w-69h3-vmv2/GHSA-3m2w-69h3-vmv2.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-3pqj-q5j3-4r5q/GHSA-3pqj-q5j3-4r5q.json b/advisories/unreviewed/2025/05/GHSA-3pqj-q5j3-4r5q/GHSA-3pqj-q5j3-4r5q.json new file mode 100644 index 00000000000..608753a6bda --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3pqj-q5j3-4r5q/GHSA-3pqj-q5j3-4r5q.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3pqj-q5j3-4r5q", + "modified": "2025-05-07T21:31:46Z", + "published": "2025-05-07T21:31:46Z", + "aliases": [ + "CVE-2025-3925" + ], + "details": "BrightSign players running BrightSign OS series 4 prior to v8.5.53.1 or \nseries 5 prior to v9.0.166 contain an execution with unnecessary \nprivileges vulnerability, allowing for privilege escalation on the \ndevice once code execution has been obtained.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3925" + }, + { + "type": "WEB", + "url": "https://www.brightsign.biz/resources/software-downloads" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-126-03" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-250" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T21:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3r5v-gmfp-3mh9/GHSA-3r5v-gmfp-3mh9.json b/advisories/unreviewed/2025/05/GHSA-3r5v-gmfp-3mh9/GHSA-3r5v-gmfp-3mh9.json index 6a2b41f7b57..543a3ec3b4b 100644 --- a/advisories/unreviewed/2025/05/GHSA-3r5v-gmfp-3mh9/GHSA-3r5v-gmfp-3mh9.json +++ b/advisories/unreviewed/2025/05/GHSA-3r5v-gmfp-3mh9/GHSA-3r5v-gmfp-3mh9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3r5v-gmfp-3mh9", - "modified": "2025-05-03T12:30:25Z", + "modified": "2025-05-07T21:31:44Z", "published": "2025-05-03T12:30:25Z", "aliases": [ "CVE-2024-58135" ], "details": "Mojolicious versions from 7.28 through 9.39 for Perl may generate weak HMAC session secrets.\n\nWhen creating a default app with the \"mojo generate app\" tool, a weak secret is written to the application's configuration file using the insecure rand() function, and used for authenticating and protecting the integrity of the application's sessions. This may allow an attacker to brute force the application's session keys.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -47,7 +52,7 @@ "cwe_ids": [ "CWE-338" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-03T11:15:48Z" diff --git a/advisories/unreviewed/2025/05/GHSA-3x2x-rqjh-c8vg/GHSA-3x2x-rqjh-c8vg.json b/advisories/unreviewed/2025/05/GHSA-3x2x-rqjh-c8vg/GHSA-3x2x-rqjh-c8vg.json index b6f2bfc6659..07b16c42cb9 100644 --- a/advisories/unreviewed/2025/05/GHSA-3x2x-rqjh-c8vg/GHSA-3x2x-rqjh-c8vg.json +++ b/advisories/unreviewed/2025/05/GHSA-3x2x-rqjh-c8vg/GHSA-3x2x-rqjh-c8vg.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-5gp3-3rvx-qhx2/GHSA-5gp3-3rvx-qhx2.json b/advisories/unreviewed/2025/05/GHSA-5gp3-3rvx-qhx2/GHSA-5gp3-3rvx-qhx2.json index 3d1e9e9b4d1..7be9df2e760 100644 --- a/advisories/unreviewed/2025/05/GHSA-5gp3-3rvx-qhx2/GHSA-5gp3-3rvx-qhx2.json +++ b/advisories/unreviewed/2025/05/GHSA-5gp3-3rvx-qhx2/GHSA-5gp3-3rvx-qhx2.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-5qcr-g689-6g4f/GHSA-5qcr-g689-6g4f.json b/advisories/unreviewed/2025/05/GHSA-5qcr-g689-6g4f/GHSA-5qcr-g689-6g4f.json index 92f979e20c1..d1d2974ae87 100644 --- a/advisories/unreviewed/2025/05/GHSA-5qcr-g689-6g4f/GHSA-5qcr-g689-6g4f.json +++ b/advisories/unreviewed/2025/05/GHSA-5qcr-g689-6g4f/GHSA-5qcr-g689-6g4f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5qcr-g689-6g4f", - "modified": "2025-05-05T15:30:53Z", + "modified": "2025-05-07T21:31:44Z", "published": "2025-05-05T15:30:53Z", "aliases": [ "CVE-2025-4316" ], "details": "Improper access control in PAM feature in Devolutions Server 2025.1.6.0 and earlier allows a PAM user to self approve their PAM requests even if disallowed by the configured policy via specific user interface actions.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-284" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-05T14:15:29Z" diff --git a/advisories/unreviewed/2025/05/GHSA-5vm6-hp43-q7fh/GHSA-5vm6-hp43-q7fh.json b/advisories/unreviewed/2025/05/GHSA-5vm6-hp43-q7fh/GHSA-5vm6-hp43-q7fh.json new file mode 100644 index 00000000000..a7741f1e8f9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5vm6-hp43-q7fh/GHSA-5vm6-hp43-q7fh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5vm6-hp43-q7fh", + "modified": "2025-05-07T21:31:45Z", + "published": "2025-05-07T21:31:45Z", + "aliases": [ + "CVE-2025-3272" + ], + "details": "Incorrect Authorization vulnerability in OpenText™ Operations Bridge Manager. \n\nThe vulnerability could allow authenticated users to change their password without providing their old password.\n\nThis issue affects Operations Bridge Manager: 24.2, 24.4.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:L/U:Green" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3272" + }, + { + "type": "WEB", + "url": "https://portal.microfocus.com/s/article/KM000040405" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T19:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6hw7-xhgx-5vfp/GHSA-6hw7-xhgx-5vfp.json b/advisories/unreviewed/2025/05/GHSA-6hw7-xhgx-5vfp/GHSA-6hw7-xhgx-5vfp.json index 828b872571d..fffd9200ada 100644 --- a/advisories/unreviewed/2025/05/GHSA-6hw7-xhgx-5vfp/GHSA-6hw7-xhgx-5vfp.json +++ b/advisories/unreviewed/2025/05/GHSA-6hw7-xhgx-5vfp/GHSA-6hw7-xhgx-5vfp.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-822v-v9px-p668/GHSA-822v-v9px-p668.json b/advisories/unreviewed/2025/05/GHSA-822v-v9px-p668/GHSA-822v-v9px-p668.json index 82ae01e591a..008abc93214 100644 --- a/advisories/unreviewed/2025/05/GHSA-822v-v9px-p668/GHSA-822v-v9px-p668.json +++ b/advisories/unreviewed/2025/05/GHSA-822v-v9px-p668/GHSA-822v-v9px-p668.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-8242-q5jq-p64w/GHSA-8242-q5jq-p64w.json b/advisories/unreviewed/2025/05/GHSA-8242-q5jq-p64w/GHSA-8242-q5jq-p64w.json new file mode 100644 index 00000000000..bfc3f8dd4d6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8242-q5jq-p64w/GHSA-8242-q5jq-p64w.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8242-q5jq-p64w", + "modified": "2025-05-07T21:31:45Z", + "published": "2025-05-07T21:31:45Z", + "aliases": [ + "CVE-2025-4043" + ], + "details": "An admin user can gain unauthorized write access to the /etc/rc.local file on the device, which is executed on a system boot.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4043" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-126-02" + }, + { + "type": "WEB", + "url": "https://www.milesight.com/iot/resources/download-center/#firmware-ug65" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1274" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T21:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-f4mm-pxc8-94h7/GHSA-f4mm-pxc8-94h7.json b/advisories/unreviewed/2025/05/GHSA-f4mm-pxc8-94h7/GHSA-f4mm-pxc8-94h7.json new file mode 100644 index 00000000000..4979a5e2e62 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-f4mm-pxc8-94h7/GHSA-f4mm-pxc8-94h7.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f4mm-pxc8-94h7", + "modified": "2025-05-07T21:31:45Z", + "published": "2025-05-07T21:31:45Z", + "aliases": [ + "CVE-2025-26168" + ], + "details": "IXON VPN Client before 1.4.4 on Linux and macOS allows Local Privilege Escalation to root because there is code execution from a configuration file that can be controlled by a low-privileged user. There is a race condition in which a temporary configuration file, in a world-writable directory, can be overwritten.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26168" + }, + { + "type": "WEB", + "url": "https://ixon-cloud.my.salesforce.com/sfc/p/#1t000000vlSF/a/TX000000DQmH/WRGwuYg2iMsKX6NAIK3MygCUOlg0SPQ..YvGWrwfNeM" + }, + { + "type": "WEB", + "url": "https://support.ixon.cloud/s/article/VPN-Client-installation-and-uninstallation" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T19:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fqr4-2vmh-phgq/GHSA-fqr4-2vmh-phgq.json b/advisories/unreviewed/2025/05/GHSA-fqr4-2vmh-phgq/GHSA-fqr4-2vmh-phgq.json new file mode 100644 index 00000000000..fc4542314da --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fqr4-2vmh-phgq/GHSA-fqr4-2vmh-phgq.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fqr4-2vmh-phgq", + "modified": "2025-05-07T21:31:45Z", + "published": "2025-05-07T21:31:45Z", + "aliases": [ + "CVE-2025-45514" + ], + "details": "Tenda FH451 V1.0.0.9 has a stack overflow vulnerability in the function.frmL7ImForm.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45514" + }, + { + "type": "WEB", + "url": "https://github.com/Eu21ka/cve_report/blob/master/The_router_Tenda_FH451_V1.0.0.9_of_Shenzhen_Jixiang_Tenda_Technology_Co.%2C_Ltd._has_a_stack_overflow_vulnerability_2.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T19:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fxvx-gfmr-5xfj/GHSA-fxvx-gfmr-5xfj.json b/advisories/unreviewed/2025/05/GHSA-fxvx-gfmr-5xfj/GHSA-fxvx-gfmr-5xfj.json new file mode 100644 index 00000000000..5f155fce613 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fxvx-gfmr-5xfj/GHSA-fxvx-gfmr-5xfj.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fxvx-gfmr-5xfj", + "modified": "2025-05-07T21:31:45Z", + "published": "2025-05-07T21:31:45Z", + "aliases": [ + "CVE-2025-29746" + ], + "details": "Cross Site Scripting vulnerability in Koillection v.1.6.10 allows a remote attacker to escalate privileges via the collection, Wishlist and album components", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29746" + }, + { + "type": "WEB", + "url": "https://github.com/benjaminjonard/koillection/issues/1329" + }, + { + "type": "WEB", + "url": "https://gist.github.com/unklerunkle/73e2ab58d1a5b9129be5de55765ea4fe" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T19:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hjrw-9jmp-vr8q/GHSA-hjrw-9jmp-vr8q.json b/advisories/unreviewed/2025/05/GHSA-hjrw-9jmp-vr8q/GHSA-hjrw-9jmp-vr8q.json index a5fb038be08..89457f10aa7 100644 --- a/advisories/unreviewed/2025/05/GHSA-hjrw-9jmp-vr8q/GHSA-hjrw-9jmp-vr8q.json +++ b/advisories/unreviewed/2025/05/GHSA-hjrw-9jmp-vr8q/GHSA-hjrw-9jmp-vr8q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hjrw-9jmp-vr8q", - "modified": "2025-05-07T18:30:50Z", + "modified": "2025-05-07T21:31:44Z", "published": "2025-05-07T18:30:50Z", "aliases": [ "CVE-2025-32820" ], "details": "A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges can inject a path traversal sequence to make any directory on the SMA appliance writable.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-07T18:15:42Z" diff --git a/advisories/unreviewed/2025/05/GHSA-jqcw-jj5v-2h9g/GHSA-jqcw-jj5v-2h9g.json b/advisories/unreviewed/2025/05/GHSA-jqcw-jj5v-2h9g/GHSA-jqcw-jj5v-2h9g.json index 0da4ce65b58..372aefa2d81 100644 --- a/advisories/unreviewed/2025/05/GHSA-jqcw-jj5v-2h9g/GHSA-jqcw-jj5v-2h9g.json +++ b/advisories/unreviewed/2025/05/GHSA-jqcw-jj5v-2h9g/GHSA-jqcw-jj5v-2h9g.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-mwp5-6mcm-q9cq/GHSA-mwp5-6mcm-q9cq.json b/advisories/unreviewed/2025/05/GHSA-mwp5-6mcm-q9cq/GHSA-mwp5-6mcm-q9cq.json index 04787b2a445..ddcf2e4e064 100644 --- a/advisories/unreviewed/2025/05/GHSA-mwp5-6mcm-q9cq/GHSA-mwp5-6mcm-q9cq.json +++ b/advisories/unreviewed/2025/05/GHSA-mwp5-6mcm-q9cq/GHSA-mwp5-6mcm-q9cq.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-q787-4mx6-96qg/GHSA-q787-4mx6-96qg.json b/advisories/unreviewed/2025/05/GHSA-q787-4mx6-96qg/GHSA-q787-4mx6-96qg.json new file mode 100644 index 00000000000..a45d4c743aa --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q787-4mx6-96qg/GHSA-q787-4mx6-96qg.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q787-4mx6-96qg", + "modified": "2025-05-07T21:31:45Z", + "published": "2025-05-07T21:31:45Z", + "aliases": [ + "CVE-2025-45388" + ], + "details": "Wagtail CMS 6.4.1 is vulnerable to a Stored Cross-Site Scripting (XSS) in the document upload functionality. Attackers can inject malicious code inside a PDF file. When a user clicks the document in the CMS interface, the payload executes.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45388" + }, + { + "type": "WEB", + "url": "https://github.com/echoBRT/Wagtail-CMS-XSS" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T19:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w76x-4q27-ffmh/GHSA-w76x-4q27-ffmh.json b/advisories/unreviewed/2025/05/GHSA-w76x-4q27-ffmh/GHSA-w76x-4q27-ffmh.json new file mode 100644 index 00000000000..5bdf029dca8 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w76x-4q27-ffmh/GHSA-w76x-4q27-ffmh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w76x-4q27-ffmh", + "modified": "2025-05-07T21:31:45Z", + "published": "2025-05-07T21:31:45Z", + "aliases": [ + "CVE-2025-3476" + ], + "details": "Incorrect Authorization vulnerability in OpenText™ Operations Bridge Manager. The vulnerability could allows privilege escalation by authenticated users.This issue affects Operations Bridge Manager: 2023.05, 23.4, 24.2, 24.4.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:H/U:Red" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3476" + }, + { + "type": "WEB", + "url": "https://portal.microfocus.com/s/article/KM000040406?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T19:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-x9rr-xwxc-jcjf/GHSA-x9rr-xwxc-jcjf.json b/advisories/unreviewed/2025/05/GHSA-x9rr-xwxc-jcjf/GHSA-x9rr-xwxc-jcjf.json index 3b9b19a9d4f..c832795e4ea 100644 --- a/advisories/unreviewed/2025/05/GHSA-x9rr-xwxc-jcjf/GHSA-x9rr-xwxc-jcjf.json +++ b/advisories/unreviewed/2025/05/GHSA-x9rr-xwxc-jcjf/GHSA-x9rr-xwxc-jcjf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x9rr-xwxc-jcjf", - "modified": "2025-05-05T15:30:53Z", + "modified": "2025-05-07T21:31:45Z", "published": "2025-05-05T15:30:53Z", "aliases": [ "CVE-2025-28168" ], "details": "Outsystems Multiple File Upload < 3.1.0 is vulnerable to Unrestricted File Upload. The vulnerability is because file extension and size validations are enforced solely on the client side. An attacker can intercept the upload request and modify the parameter to bypass extension restrictions and upload arbitrary files.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-05T14:15:28Z" diff --git a/advisories/unreviewed/2025/05/GHSA-xjcf-jhr2-9x97/GHSA-xjcf-jhr2-9x97.json b/advisories/unreviewed/2025/05/GHSA-xjcf-jhr2-9x97/GHSA-xjcf-jhr2-9x97.json new file mode 100644 index 00000000000..0de0b766948 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xjcf-jhr2-9x97/GHSA-xjcf-jhr2-9x97.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xjcf-jhr2-9x97", + "modified": "2025-05-07T21:31:45Z", + "published": "2025-05-07T21:31:45Z", + "aliases": [ + "CVE-2025-31177" + ], + "details": "gnuplot is affected by a heap buffer overflow at function utf8_copy_one.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31177" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-31177" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2355342" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T21:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xv34-vpcm-23p2/GHSA-xv34-vpcm-23p2.json b/advisories/unreviewed/2025/05/GHSA-xv34-vpcm-23p2/GHSA-xv34-vpcm-23p2.json index a8a9a8ddf64..32a56e18b73 100644 --- a/advisories/unreviewed/2025/05/GHSA-xv34-vpcm-23p2/GHSA-xv34-vpcm-23p2.json +++ b/advisories/unreviewed/2025/05/GHSA-xv34-vpcm-23p2/GHSA-xv34-vpcm-23p2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xv34-vpcm-23p2", - "modified": "2025-05-07T18:30:50Z", + "modified": "2025-05-07T21:31:45Z", "published": "2025-05-07T18:30:50Z", "aliases": [ "CVE-2025-32821" ], "details": "A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN admin privileges can with admin privileges can inject shell command arguments to upload a file on the appliance.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-07T18:15:42Z"