From 3788dc6a4ae16f0e006bb80c23f7d6f8fa68ed7b Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 8 Apr 2025 18:36:04 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-4w2r-hhr3-c2wv.json | 4 ++- .../GHSA-58wq-p76f-6qjh.json | 2 +- .../GHSA-6fr8-22pf-g32x.json | 2 +- .../GHSA-mp4c-w7j9-95f4.json | 10 +++++- .../GHSA-wv3p-jvhj-v4jc.json | 10 +++++- .../GHSA-327x-6c4p-8g25.json | 4 +-- .../GHSA-3vqf-26wq-v77m.json | 4 +-- .../GHSA-4gwg-56fg-39pf.json | 4 +-- .../GHSA-539g-ppw2-7c4r.json | 4 +-- .../GHSA-c7mc-vqjx-hc9c.json | 4 +-- .../GHSA-jr8p-29pq-j5wf.json | 4 +-- .../GHSA-p2c5-vphq-jrxg.json | 4 +-- .../GHSA-pr9j-p6wx-p73x.json | 4 +-- .../GHSA-qw72-jmvh-wj6r.json | 4 +-- .../GHSA-qxgj-php7-wrw3.json | 4 +-- .../GHSA-vxq6-3hh5-mcjj.json | 4 +-- .../GHSA-27w6-8m77-x3qf.json | 4 +-- .../GHSA-3m3j-g6jr-6c5m.json | 1 + .../GHSA-c4qr-mpj2-hxhr.json | 4 +-- .../GHSA-chwx-r397-6ww4.json | 4 +-- .../GHSA-cqgx-qm2w-88qc.json | 4 +-- .../GHSA-f525-qqcm-4ww9.json | 4 +-- .../GHSA-gv6g-p8pg-jx2h.json | 4 +-- .../GHSA-p939-fx2c-j96p.json | 4 ++- .../GHSA-rrpg-fwx7-jf88.json | 4 +-- .../GHSA-xq4m-hfgr-r2x5.json | 4 ++- .../GHSA-556r-646r-vxjp.json | 4 ++- .../GHSA-5jv6-7953-598p.json | 4 ++- .../GHSA-22fq-gxhw-m8h5.json | 36 +++++++++++++++++++ .../GHSA-23cx-98wc-24qg.json | 3 +- .../GHSA-2453-p5w4-2rh4.json | 36 +++++++++++++++++++ .../GHSA-25m2-7f7f-p53m.json | 36 +++++++++++++++++++ .../GHSA-2f5r-r4jx-hh42.json | 36 +++++++++++++++++++ .../GHSA-2gwg-wcpq-6h7g.json | 36 +++++++++++++++++++ .../GHSA-2hgf-545p-qvj7.json | 36 +++++++++++++++++++ .../GHSA-2hrp-x9mq-5qp2.json | 36 +++++++++++++++++++ .../GHSA-2j6p-wf3v-2mvp.json | 36 +++++++++++++++++++ .../GHSA-35q9-q5hh-hmc4.json | 36 +++++++++++++++++++ .../GHSA-386h-wcf4-977x.json | 36 +++++++++++++++++++ .../GHSA-3pxq-xg4j-rgqx.json | 15 +++++--- .../GHSA-3w3r-78f2-2x8v.json | 36 +++++++++++++++++++ .../GHSA-429q-ccqc-32wq.json | 36 +++++++++++++++++++ .../GHSA-437f-4378-pmh4.json | 36 +++++++++++++++++++ .../GHSA-443w-gf2f-8h6x.json | 36 +++++++++++++++++++ .../GHSA-44v2-prcf-pc3m.json | 31 ++++++++++++++++ .../GHSA-46hp-9p3c-5jgh.json | 36 +++++++++++++++++++ .../GHSA-473g-6pv5-56gc.json | 36 +++++++++++++++++++ .../GHSA-47qr-4ffm-5qm9.json | 36 +++++++++++++++++++ .../GHSA-47xw-2q7j-49hw.json | 36 +++++++++++++++++++ .../GHSA-4f3f-qmwc-952f.json | 36 +++++++++++++++++++ .../GHSA-4f8x-f25f-pp6r.json | 36 +++++++++++++++++++ .../GHSA-4j9p-mgjx-whjq.json | 36 +++++++++++++++++++ .../GHSA-4x7q-6v7j-m3g9.json | 36 +++++++++++++++++++ .../GHSA-523j-7w3w-4hch.json | 3 +- .../GHSA-58gq-7w24-hj3p.json | 36 +++++++++++++++++++ .../GHSA-59vw-wx25-6mxm.json | 36 +++++++++++++++++++ .../GHSA-5px6-qr34-v59r.json | 3 +- .../GHSA-5v5h-mr5g-h898.json | 36 +++++++++++++++++++ .../GHSA-5vwc-px2m-7jxg.json | 36 +++++++++++++++++++ .../GHSA-5xm9-x7x4-4j5x.json | 36 +++++++++++++++++++ .../GHSA-5xwr-vwvm-vhh2.json | 36 +++++++++++++++++++ .../GHSA-6423-85cc-8gf6.json | 31 ++++++++++++++++ .../GHSA-6fgm-cc65-9jj3.json | 36 +++++++++++++++++++ .../GHSA-6hhr-6xwm-4f6j.json | 36 +++++++++++++++++++ .../GHSA-6mpr-rpj5-q557.json | 36 +++++++++++++++++++ .../GHSA-6v62-cvf7-mpv3.json | 36 +++++++++++++++++++ .../GHSA-6vg9-pg49-5fg4.json | 36 +++++++++++++++++++ .../GHSA-74mq-6c57-fxpx.json | 36 +++++++++++++++++++ .../GHSA-76h8-9q54-37cc.json | 36 +++++++++++++++++++ .../GHSA-76qh-8gv2-726j.json | 36 +++++++++++++++++++ .../GHSA-7883-gj3f-26q9.json | 36 +++++++++++++++++++ .../GHSA-79xr-cjjw-p6f2.json | 36 +++++++++++++++++++ .../GHSA-7fqc-4xq7-ghg5.json | 36 +++++++++++++++++++ .../GHSA-7px8-2cr8-7p32.json | 36 +++++++++++++++++++ .../GHSA-7q5w-7fpv-35wj.json | 36 +++++++++++++++++++ .../GHSA-7qv7-c4h7-rw9m.json | 36 +++++++++++++++++++ .../GHSA-7r63-qvqc-2fch.json | 36 +++++++++++++++++++ .../GHSA-7wj9-rggf-4prj.json | 36 +++++++++++++++++++ .../GHSA-82xw-6f7x-r595.json | 36 +++++++++++++++++++ .../GHSA-8844-88f7-3mwf.json | 36 +++++++++++++++++++ .../GHSA-89pp-mprf-p328.json | 36 +++++++++++++++++++ .../GHSA-8h2h-4x77-6crv.json | 36 +++++++++++++++++++ .../GHSA-8vjw-ghh4-xxg8.json | 36 +++++++++++++++++++ .../GHSA-8wgx-9672-jj5j.json | 36 +++++++++++++++++++ .../GHSA-923v-g26h-29fj.json | 36 +++++++++++++++++++ .../GHSA-944c-wq2v-7wrg.json | 36 +++++++++++++++++++ .../GHSA-959p-rfmc-j2w3.json | 36 +++++++++++++++++++ .../GHSA-95rc-q9jr-6jhg.json | 36 +++++++++++++++++++ .../GHSA-96vc-522p-f5f2.json | 36 +++++++++++++++++++ .../GHSA-9c5m-4mvh-2p3v.json | 36 +++++++++++++++++++ .../GHSA-9hqh-j935-cc49.json | 36 +++++++++++++++++++ .../GHSA-9mm4-w3m4-jvj3.json | 36 +++++++++++++++++++ .../GHSA-9qjc-6fwg-p54r.json | 36 +++++++++++++++++++ .../GHSA-9qpr-rvwc-j2wc.json | 36 +++++++++++++++++++ .../GHSA-c3xg-4h7v-p83w.json | 36 +++++++++++++++++++ .../GHSA-c4pv-p44r-9xfc.json | 36 +++++++++++++++++++ .../GHSA-c538-wc2q-4rmx.json | 36 +++++++++++++++++++ .../GHSA-c57f-m24w-hf5p.json | 3 +- .../GHSA-c6h2-xp45-96cv.json | 36 +++++++++++++++++++ .../GHSA-c8q9-g877-5qr3.json | 36 +++++++++++++++++++ .../GHSA-ccjx-w7qv-vvc6.json | 34 ++++++++++++++++++ .../GHSA-ccvc-x2m3-pqg3.json | 36 +++++++++++++++++++ .../GHSA-ccx5-jh35-2p3c.json | 36 +++++++++++++++++++ .../GHSA-ch4m-2996-7xpv.json | 2 +- .../GHSA-cj54-rxfj-2qp3.json | 36 +++++++++++++++++++ .../GHSA-cp6c-ff57-294g.json | 36 +++++++++++++++++++ .../GHSA-cppr-qmr8-4r9j.json | 36 +++++++++++++++++++ .../GHSA-cv6v-q3qg-36vr.json | 36 +++++++++++++++++++ .../GHSA-cvhq-cvvf-jw9r.json | 36 +++++++++++++++++++ .../GHSA-cw83-5fh9-w7xx.json | 36 +++++++++++++++++++ .../GHSA-cwwx-grqm-7hjh.json | 36 +++++++++++++++++++ .../GHSA-f4pv-mh4w-365x.json | 36 +++++++++++++++++++ .../GHSA-f5m3-pwfc-3wq8.json | 36 +++++++++++++++++++ .../GHSA-f5p6-vmgq-f9qw.json | 36 +++++++++++++++++++ .../GHSA-f687-cpxh-93rh.json | 36 +++++++++++++++++++ .../GHSA-f69r-g2v6-6r6h.json | 36 +++++++++++++++++++ .../GHSA-f6cf-jwhc-p8rr.json | 36 +++++++++++++++++++ .../GHSA-f777-q5j9-qjx5.json | 36 +++++++++++++++++++ .../GHSA-f88r-vjvm-q77m.json | 36 +++++++++++++++++++ .../GHSA-ffww-3j7j-g93q.json | 36 +++++++++++++++++++ .../GHSA-fg42-rvmc-ccpv.json | 36 +++++++++++++++++++ .../GHSA-fh3v-p8r7-f9p8.json | 36 +++++++++++++++++++ .../GHSA-fhf5-q9qm-767w.json | 36 +++++++++++++++++++ .../GHSA-fwcf-6vhv-fhqj.json | 36 +++++++++++++++++++ .../GHSA-g3jg-gq9w-rmh8.json | 36 +++++++++++++++++++ .../GHSA-g453-6hhw-8qx3.json | 36 +++++++++++++++++++ .../GHSA-g954-x6px-fjvv.json | 36 +++++++++++++++++++ .../GHSA-gf2r-7cq8-xww9.json | 36 +++++++++++++++++++ .../GHSA-ggqx-jcf7-78x8.json | 36 +++++++++++++++++++ .../GHSA-ghfh-p92w-j4mg.json | 36 +++++++++++++++++++ .../GHSA-ghmp-5866-2jgf.json | 36 +++++++++++++++++++ .../GHSA-gjc7-752x-rr86.json | 36 +++++++++++++++++++ .../GHSA-gr4c-v8p7-98x2.json | 36 +++++++++++++++++++ .../GHSA-h78g-f5x3-jrm2.json | 34 ++++++++++++++++++ .../GHSA-h78m-4g6h-334g.json | 34 ++++++++++++++++++ .../GHSA-h7rc-mcrm-p3mh.json | 36 +++++++++++++++++++ .../GHSA-h8h5-8pv5-88g9.json | 36 +++++++++++++++++++ .../GHSA-h9r9-jmq5-x5wh.json | 36 +++++++++++++++++++ .../GHSA-hgp6-f396-gg6v.json | 36 +++++++++++++++++++ .../GHSA-hrxg-42v2-hfvm.json | 36 +++++++++++++++++++ .../GHSA-hwrv-xj84-453c.json | 36 +++++++++++++++++++ .../GHSA-j233-wqrg-q9v9.json | 36 +++++++++++++++++++ .../GHSA-j5q7-6x8m-99jx.json | 36 +++++++++++++++++++ .../GHSA-j7wg-vqfq-fh3f.json | 34 ++++++++++++++++++ .../GHSA-j882-wwwr-7r6q.json | 1 + .../GHSA-j923-xmpp-p4g8.json | 36 +++++++++++++++++++ .../GHSA-jc9x-pxc5-cq7f.json | 36 +++++++++++++++++++ .../GHSA-jghh-64fm-ph6v.json | 3 +- .../GHSA-jjwr-7vqh-8gf4.json | 36 +++++++++++++++++++ .../GHSA-jpmv-9x86-xvwc.json | 36 +++++++++++++++++++ .../GHSA-jrp5-65w7-pcg2.json | 36 +++++++++++++++++++ .../GHSA-m46h-3mqp-xh9w.json | 36 +++++++++++++++++++ .../GHSA-m8g5-jr5h-6c6f.json | 36 +++++++++++++++++++ .../GHSA-m8qx-v899-58w7.json | 36 +++++++++++++++++++ .../GHSA-mrrv-j79h-j3g7.json | 3 +- .../GHSA-mx35-q7v3-5rh9.json | 36 +++++++++++++++++++ .../GHSA-p24p-f3hr-cw49.json | 36 +++++++++++++++++++ .../GHSA-p2fq-4w5w-2ccm.json | 36 +++++++++++++++++++ .../GHSA-p34p-m244-f7pp.json | 36 +++++++++++++++++++ .../GHSA-p5rh-8pxf-mm32.json | 36 +++++++++++++++++++ .../GHSA-p5vq-38hr-952c.json | 36 +++++++++++++++++++ .../GHSA-p9qw-h5h2-6vw8.json | 36 +++++++++++++++++++ .../GHSA-pcvm-gp76-hqvq.json | 36 +++++++++++++++++++ .../GHSA-pf7h-9fm5-wgv6.json | 36 +++++++++++++++++++ .../GHSA-pgr8-v8gq-7h3m.json | 36 +++++++++++++++++++ .../GHSA-pjr7-76vx-55xq.json | 36 +++++++++++++++++++ .../GHSA-pqgf-8vrh-rr46.json | 36 +++++++++++++++++++ .../GHSA-pxr7-h23v-3wv6.json | 36 +++++++++++++++++++ .../GHSA-q7p5-2w2c-9c56.json | 34 ++++++++++++++++++ .../GHSA-q84m-7mh3-gvhw.json | 36 +++++++++++++++++++ .../GHSA-qjm7-f9mj-293h.json | 36 +++++++++++++++++++ .../GHSA-qm95-22pj-qx7v.json | 36 +++++++++++++++++++ .../GHSA-qp8f-6pj7-98h4.json | 36 +++++++++++++++++++ .../GHSA-r9m4-84qp-v455.json | 36 +++++++++++++++++++ .../GHSA-rfqv-r3rp-j8mm.json | 36 +++++++++++++++++++ .../GHSA-rr38-x2xx-vwr5.json | 36 +++++++++++++++++++ .../GHSA-v269-fhhx-vf6j.json | 36 +++++++++++++++++++ .../GHSA-v2ph-qcjx-gh8g.json | 36 +++++++++++++++++++ .../GHSA-v3mw-3vwm-c6c7.json | 36 +++++++++++++++++++ .../GHSA-v4v5-73p4-rg59.json | 36 +++++++++++++++++++ .../GHSA-vg4c-j58p-8f66.json | 36 +++++++++++++++++++ .../GHSA-vg94-crh4-qq4x.json | 36 +++++++++++++++++++ .../GHSA-vm5w-p85f-gq6r.json | 36 +++++++++++++++++++ .../GHSA-vq2r-vj3j-964w.json | 36 +++++++++++++++++++ .../GHSA-vxc2-qxc2-pw67.json | 36 +++++++++++++++++++ .../GHSA-w3h4-x33c-8cc8.json | 36 +++++++++++++++++++ .../GHSA-w4rq-mvcf-xc7h.json | 36 +++++++++++++++++++ .../GHSA-w5wx-73w5-58mw.json | 36 +++++++++++++++++++ .../GHSA-w84w-59g8-pmg9.json | 36 +++++++++++++++++++ .../GHSA-w87f-mr23-wrp9.json | 36 +++++++++++++++++++ .../GHSA-w9x5-m47g-3gx6.json | 36 +++++++++++++++++++ .../GHSA-wjr6-rfwf-wx2f.json | 36 +++++++++++++++++++ .../GHSA-wm96-jrv9-gggq.json | 3 +- .../GHSA-wq4m-7cp4-8jgg.json | 36 +++++++++++++++++++ .../GHSA-wr29-5553-rrh3.json | 36 +++++++++++++++++++ .../GHSA-wvg7-cvgq-hhh3.json | 36 +++++++++++++++++++ .../GHSA-x27v-pq4m-wch6.json | 36 +++++++++++++++++++ .../GHSA-x599-jjw8-g5vw.json | 36 +++++++++++++++++++ .../GHSA-x65v-wxjf-f672.json | 36 +++++++++++++++++++ .../GHSA-x7g5-wpm2-r3jm.json | 36 +++++++++++++++++++ .../GHSA-x998-4j8c-4fq3.json | 36 +++++++++++++++++++ .../GHSA-xc3h-9j86-jpjh.json | 36 +++++++++++++++++++ .../GHSA-xcw6-8574-9qv2.json | 36 +++++++++++++++++++ .../GHSA-xmq2-8hhc-7629.json | 3 +- .../GHSA-xp88-vp78-mqm7.json | 36 +++++++++++++++++++ .../GHSA-xr7q-639h-425q.json | 36 +++++++++++++++++++ .../GHSA-xrg8-r4mg-6g2x.json | 36 +++++++++++++++++++ .../GHSA-xwxw-9gfj-g2c9.json | 36 +++++++++++++++++++ 208 files changed, 6165 insertions(+), 58 deletions(-) create mode 100644 advisories/unreviewed/2025/04/GHSA-22fq-gxhw-m8h5/GHSA-22fq-gxhw-m8h5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-2453-p5w4-2rh4/GHSA-2453-p5w4-2rh4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-25m2-7f7f-p53m/GHSA-25m2-7f7f-p53m.json create mode 100644 advisories/unreviewed/2025/04/GHSA-2f5r-r4jx-hh42/GHSA-2f5r-r4jx-hh42.json create mode 100644 advisories/unreviewed/2025/04/GHSA-2gwg-wcpq-6h7g/GHSA-2gwg-wcpq-6h7g.json create mode 100644 advisories/unreviewed/2025/04/GHSA-2hgf-545p-qvj7/GHSA-2hgf-545p-qvj7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-2hrp-x9mq-5qp2/GHSA-2hrp-x9mq-5qp2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-2j6p-wf3v-2mvp/GHSA-2j6p-wf3v-2mvp.json create mode 100644 advisories/unreviewed/2025/04/GHSA-35q9-q5hh-hmc4/GHSA-35q9-q5hh-hmc4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-386h-wcf4-977x/GHSA-386h-wcf4-977x.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3w3r-78f2-2x8v/GHSA-3w3r-78f2-2x8v.json create mode 100644 advisories/unreviewed/2025/04/GHSA-429q-ccqc-32wq/GHSA-429q-ccqc-32wq.json create mode 100644 advisories/unreviewed/2025/04/GHSA-437f-4378-pmh4/GHSA-437f-4378-pmh4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-443w-gf2f-8h6x/GHSA-443w-gf2f-8h6x.json create mode 100644 advisories/unreviewed/2025/04/GHSA-44v2-prcf-pc3m/GHSA-44v2-prcf-pc3m.json create mode 100644 advisories/unreviewed/2025/04/GHSA-46hp-9p3c-5jgh/GHSA-46hp-9p3c-5jgh.json create mode 100644 advisories/unreviewed/2025/04/GHSA-473g-6pv5-56gc/GHSA-473g-6pv5-56gc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-47qr-4ffm-5qm9/GHSA-47qr-4ffm-5qm9.json create mode 100644 advisories/unreviewed/2025/04/GHSA-47xw-2q7j-49hw/GHSA-47xw-2q7j-49hw.json create mode 100644 advisories/unreviewed/2025/04/GHSA-4f3f-qmwc-952f/GHSA-4f3f-qmwc-952f.json create mode 100644 advisories/unreviewed/2025/04/GHSA-4f8x-f25f-pp6r/GHSA-4f8x-f25f-pp6r.json create mode 100644 advisories/unreviewed/2025/04/GHSA-4j9p-mgjx-whjq/GHSA-4j9p-mgjx-whjq.json create mode 100644 advisories/unreviewed/2025/04/GHSA-4x7q-6v7j-m3g9/GHSA-4x7q-6v7j-m3g9.json create mode 100644 advisories/unreviewed/2025/04/GHSA-58gq-7w24-hj3p/GHSA-58gq-7w24-hj3p.json create mode 100644 advisories/unreviewed/2025/04/GHSA-59vw-wx25-6mxm/GHSA-59vw-wx25-6mxm.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5v5h-mr5g-h898/GHSA-5v5h-mr5g-h898.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5vwc-px2m-7jxg/GHSA-5vwc-px2m-7jxg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5xm9-x7x4-4j5x/GHSA-5xm9-x7x4-4j5x.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5xwr-vwvm-vhh2/GHSA-5xwr-vwvm-vhh2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-6423-85cc-8gf6/GHSA-6423-85cc-8gf6.json create mode 100644 advisories/unreviewed/2025/04/GHSA-6fgm-cc65-9jj3/GHSA-6fgm-cc65-9jj3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-6hhr-6xwm-4f6j/GHSA-6hhr-6xwm-4f6j.json create mode 100644 advisories/unreviewed/2025/04/GHSA-6mpr-rpj5-q557/GHSA-6mpr-rpj5-q557.json create mode 100644 advisories/unreviewed/2025/04/GHSA-6v62-cvf7-mpv3/GHSA-6v62-cvf7-mpv3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-6vg9-pg49-5fg4/GHSA-6vg9-pg49-5fg4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-74mq-6c57-fxpx/GHSA-74mq-6c57-fxpx.json create mode 100644 advisories/unreviewed/2025/04/GHSA-76h8-9q54-37cc/GHSA-76h8-9q54-37cc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-76qh-8gv2-726j/GHSA-76qh-8gv2-726j.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7883-gj3f-26q9/GHSA-7883-gj3f-26q9.json create mode 100644 advisories/unreviewed/2025/04/GHSA-79xr-cjjw-p6f2/GHSA-79xr-cjjw-p6f2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7fqc-4xq7-ghg5/GHSA-7fqc-4xq7-ghg5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7px8-2cr8-7p32/GHSA-7px8-2cr8-7p32.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7q5w-7fpv-35wj/GHSA-7q5w-7fpv-35wj.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7qv7-c4h7-rw9m/GHSA-7qv7-c4h7-rw9m.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7r63-qvqc-2fch/GHSA-7r63-qvqc-2fch.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7wj9-rggf-4prj/GHSA-7wj9-rggf-4prj.json create mode 100644 advisories/unreviewed/2025/04/GHSA-82xw-6f7x-r595/GHSA-82xw-6f7x-r595.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8844-88f7-3mwf/GHSA-8844-88f7-3mwf.json create mode 100644 advisories/unreviewed/2025/04/GHSA-89pp-mprf-p328/GHSA-89pp-mprf-p328.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8h2h-4x77-6crv/GHSA-8h2h-4x77-6crv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8vjw-ghh4-xxg8/GHSA-8vjw-ghh4-xxg8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8wgx-9672-jj5j/GHSA-8wgx-9672-jj5j.json create mode 100644 advisories/unreviewed/2025/04/GHSA-923v-g26h-29fj/GHSA-923v-g26h-29fj.json create mode 100644 advisories/unreviewed/2025/04/GHSA-944c-wq2v-7wrg/GHSA-944c-wq2v-7wrg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-959p-rfmc-j2w3/GHSA-959p-rfmc-j2w3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-95rc-q9jr-6jhg/GHSA-95rc-q9jr-6jhg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-96vc-522p-f5f2/GHSA-96vc-522p-f5f2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-9c5m-4mvh-2p3v/GHSA-9c5m-4mvh-2p3v.json create mode 100644 advisories/unreviewed/2025/04/GHSA-9hqh-j935-cc49/GHSA-9hqh-j935-cc49.json create mode 100644 advisories/unreviewed/2025/04/GHSA-9mm4-w3m4-jvj3/GHSA-9mm4-w3m4-jvj3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-9qjc-6fwg-p54r/GHSA-9qjc-6fwg-p54r.json create mode 100644 advisories/unreviewed/2025/04/GHSA-9qpr-rvwc-j2wc/GHSA-9qpr-rvwc-j2wc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-c3xg-4h7v-p83w/GHSA-c3xg-4h7v-p83w.json create mode 100644 advisories/unreviewed/2025/04/GHSA-c4pv-p44r-9xfc/GHSA-c4pv-p44r-9xfc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-c538-wc2q-4rmx/GHSA-c538-wc2q-4rmx.json create mode 100644 advisories/unreviewed/2025/04/GHSA-c6h2-xp45-96cv/GHSA-c6h2-xp45-96cv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-c8q9-g877-5qr3/GHSA-c8q9-g877-5qr3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-ccjx-w7qv-vvc6/GHSA-ccjx-w7qv-vvc6.json create mode 100644 advisories/unreviewed/2025/04/GHSA-ccvc-x2m3-pqg3/GHSA-ccvc-x2m3-pqg3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-ccx5-jh35-2p3c/GHSA-ccx5-jh35-2p3c.json create mode 100644 advisories/unreviewed/2025/04/GHSA-cj54-rxfj-2qp3/GHSA-cj54-rxfj-2qp3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-cp6c-ff57-294g/GHSA-cp6c-ff57-294g.json create mode 100644 advisories/unreviewed/2025/04/GHSA-cppr-qmr8-4r9j/GHSA-cppr-qmr8-4r9j.json create mode 100644 advisories/unreviewed/2025/04/GHSA-cv6v-q3qg-36vr/GHSA-cv6v-q3qg-36vr.json create mode 100644 advisories/unreviewed/2025/04/GHSA-cvhq-cvvf-jw9r/GHSA-cvhq-cvvf-jw9r.json create mode 100644 advisories/unreviewed/2025/04/GHSA-cw83-5fh9-w7xx/GHSA-cw83-5fh9-w7xx.json create mode 100644 advisories/unreviewed/2025/04/GHSA-cwwx-grqm-7hjh/GHSA-cwwx-grqm-7hjh.json create mode 100644 advisories/unreviewed/2025/04/GHSA-f4pv-mh4w-365x/GHSA-f4pv-mh4w-365x.json create mode 100644 advisories/unreviewed/2025/04/GHSA-f5m3-pwfc-3wq8/GHSA-f5m3-pwfc-3wq8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-f5p6-vmgq-f9qw/GHSA-f5p6-vmgq-f9qw.json create mode 100644 advisories/unreviewed/2025/04/GHSA-f687-cpxh-93rh/GHSA-f687-cpxh-93rh.json create mode 100644 advisories/unreviewed/2025/04/GHSA-f69r-g2v6-6r6h/GHSA-f69r-g2v6-6r6h.json create mode 100644 advisories/unreviewed/2025/04/GHSA-f6cf-jwhc-p8rr/GHSA-f6cf-jwhc-p8rr.json create mode 100644 advisories/unreviewed/2025/04/GHSA-f777-q5j9-qjx5/GHSA-f777-q5j9-qjx5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-f88r-vjvm-q77m/GHSA-f88r-vjvm-q77m.json create mode 100644 advisories/unreviewed/2025/04/GHSA-ffww-3j7j-g93q/GHSA-ffww-3j7j-g93q.json create mode 100644 advisories/unreviewed/2025/04/GHSA-fg42-rvmc-ccpv/GHSA-fg42-rvmc-ccpv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-fh3v-p8r7-f9p8/GHSA-fh3v-p8r7-f9p8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-fhf5-q9qm-767w/GHSA-fhf5-q9qm-767w.json create mode 100644 advisories/unreviewed/2025/04/GHSA-fwcf-6vhv-fhqj/GHSA-fwcf-6vhv-fhqj.json create mode 100644 advisories/unreviewed/2025/04/GHSA-g3jg-gq9w-rmh8/GHSA-g3jg-gq9w-rmh8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-g453-6hhw-8qx3/GHSA-g453-6hhw-8qx3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-g954-x6px-fjvv/GHSA-g954-x6px-fjvv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-gf2r-7cq8-xww9/GHSA-gf2r-7cq8-xww9.json create mode 100644 advisories/unreviewed/2025/04/GHSA-ggqx-jcf7-78x8/GHSA-ggqx-jcf7-78x8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-ghfh-p92w-j4mg/GHSA-ghfh-p92w-j4mg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-ghmp-5866-2jgf/GHSA-ghmp-5866-2jgf.json create mode 100644 advisories/unreviewed/2025/04/GHSA-gjc7-752x-rr86/GHSA-gjc7-752x-rr86.json create mode 100644 advisories/unreviewed/2025/04/GHSA-gr4c-v8p7-98x2/GHSA-gr4c-v8p7-98x2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-h78g-f5x3-jrm2/GHSA-h78g-f5x3-jrm2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-h78m-4g6h-334g/GHSA-h78m-4g6h-334g.json create mode 100644 advisories/unreviewed/2025/04/GHSA-h7rc-mcrm-p3mh/GHSA-h7rc-mcrm-p3mh.json create mode 100644 advisories/unreviewed/2025/04/GHSA-h8h5-8pv5-88g9/GHSA-h8h5-8pv5-88g9.json create mode 100644 advisories/unreviewed/2025/04/GHSA-h9r9-jmq5-x5wh/GHSA-h9r9-jmq5-x5wh.json create mode 100644 advisories/unreviewed/2025/04/GHSA-hgp6-f396-gg6v/GHSA-hgp6-f396-gg6v.json create mode 100644 advisories/unreviewed/2025/04/GHSA-hrxg-42v2-hfvm/GHSA-hrxg-42v2-hfvm.json create mode 100644 advisories/unreviewed/2025/04/GHSA-hwrv-xj84-453c/GHSA-hwrv-xj84-453c.json create mode 100644 advisories/unreviewed/2025/04/GHSA-j233-wqrg-q9v9/GHSA-j233-wqrg-q9v9.json create mode 100644 advisories/unreviewed/2025/04/GHSA-j5q7-6x8m-99jx/GHSA-j5q7-6x8m-99jx.json create mode 100644 advisories/unreviewed/2025/04/GHSA-j7wg-vqfq-fh3f/GHSA-j7wg-vqfq-fh3f.json create mode 100644 advisories/unreviewed/2025/04/GHSA-j923-xmpp-p4g8/GHSA-j923-xmpp-p4g8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-jc9x-pxc5-cq7f/GHSA-jc9x-pxc5-cq7f.json create mode 100644 advisories/unreviewed/2025/04/GHSA-jjwr-7vqh-8gf4/GHSA-jjwr-7vqh-8gf4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-jpmv-9x86-xvwc/GHSA-jpmv-9x86-xvwc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-jrp5-65w7-pcg2/GHSA-jrp5-65w7-pcg2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-m46h-3mqp-xh9w/GHSA-m46h-3mqp-xh9w.json create mode 100644 advisories/unreviewed/2025/04/GHSA-m8g5-jr5h-6c6f/GHSA-m8g5-jr5h-6c6f.json create mode 100644 advisories/unreviewed/2025/04/GHSA-m8qx-v899-58w7/GHSA-m8qx-v899-58w7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-mx35-q7v3-5rh9/GHSA-mx35-q7v3-5rh9.json create mode 100644 advisories/unreviewed/2025/04/GHSA-p24p-f3hr-cw49/GHSA-p24p-f3hr-cw49.json create mode 100644 advisories/unreviewed/2025/04/GHSA-p2fq-4w5w-2ccm/GHSA-p2fq-4w5w-2ccm.json create mode 100644 advisories/unreviewed/2025/04/GHSA-p34p-m244-f7pp/GHSA-p34p-m244-f7pp.json create mode 100644 advisories/unreviewed/2025/04/GHSA-p5rh-8pxf-mm32/GHSA-p5rh-8pxf-mm32.json create mode 100644 advisories/unreviewed/2025/04/GHSA-p5vq-38hr-952c/GHSA-p5vq-38hr-952c.json create mode 100644 advisories/unreviewed/2025/04/GHSA-p9qw-h5h2-6vw8/GHSA-p9qw-h5h2-6vw8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-pcvm-gp76-hqvq/GHSA-pcvm-gp76-hqvq.json create mode 100644 advisories/unreviewed/2025/04/GHSA-pf7h-9fm5-wgv6/GHSA-pf7h-9fm5-wgv6.json create mode 100644 advisories/unreviewed/2025/04/GHSA-pgr8-v8gq-7h3m/GHSA-pgr8-v8gq-7h3m.json create mode 100644 advisories/unreviewed/2025/04/GHSA-pjr7-76vx-55xq/GHSA-pjr7-76vx-55xq.json create mode 100644 advisories/unreviewed/2025/04/GHSA-pqgf-8vrh-rr46/GHSA-pqgf-8vrh-rr46.json create mode 100644 advisories/unreviewed/2025/04/GHSA-pxr7-h23v-3wv6/GHSA-pxr7-h23v-3wv6.json create mode 100644 advisories/unreviewed/2025/04/GHSA-q7p5-2w2c-9c56/GHSA-q7p5-2w2c-9c56.json create mode 100644 advisories/unreviewed/2025/04/GHSA-q84m-7mh3-gvhw/GHSA-q84m-7mh3-gvhw.json create mode 100644 advisories/unreviewed/2025/04/GHSA-qjm7-f9mj-293h/GHSA-qjm7-f9mj-293h.json create mode 100644 advisories/unreviewed/2025/04/GHSA-qm95-22pj-qx7v/GHSA-qm95-22pj-qx7v.json create mode 100644 advisories/unreviewed/2025/04/GHSA-qp8f-6pj7-98h4/GHSA-qp8f-6pj7-98h4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-r9m4-84qp-v455/GHSA-r9m4-84qp-v455.json create mode 100644 advisories/unreviewed/2025/04/GHSA-rfqv-r3rp-j8mm/GHSA-rfqv-r3rp-j8mm.json create mode 100644 advisories/unreviewed/2025/04/GHSA-rr38-x2xx-vwr5/GHSA-rr38-x2xx-vwr5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-v269-fhhx-vf6j/GHSA-v269-fhhx-vf6j.json create mode 100644 advisories/unreviewed/2025/04/GHSA-v2ph-qcjx-gh8g/GHSA-v2ph-qcjx-gh8g.json create mode 100644 advisories/unreviewed/2025/04/GHSA-v3mw-3vwm-c6c7/GHSA-v3mw-3vwm-c6c7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-v4v5-73p4-rg59/GHSA-v4v5-73p4-rg59.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vg4c-j58p-8f66/GHSA-vg4c-j58p-8f66.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vg94-crh4-qq4x/GHSA-vg94-crh4-qq4x.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vm5w-p85f-gq6r/GHSA-vm5w-p85f-gq6r.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vq2r-vj3j-964w/GHSA-vq2r-vj3j-964w.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vxc2-qxc2-pw67/GHSA-vxc2-qxc2-pw67.json create mode 100644 advisories/unreviewed/2025/04/GHSA-w3h4-x33c-8cc8/GHSA-w3h4-x33c-8cc8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-w4rq-mvcf-xc7h/GHSA-w4rq-mvcf-xc7h.json create mode 100644 advisories/unreviewed/2025/04/GHSA-w5wx-73w5-58mw/GHSA-w5wx-73w5-58mw.json create mode 100644 advisories/unreviewed/2025/04/GHSA-w84w-59g8-pmg9/GHSA-w84w-59g8-pmg9.json create mode 100644 advisories/unreviewed/2025/04/GHSA-w87f-mr23-wrp9/GHSA-w87f-mr23-wrp9.json create mode 100644 advisories/unreviewed/2025/04/GHSA-w9x5-m47g-3gx6/GHSA-w9x5-m47g-3gx6.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wjr6-rfwf-wx2f/GHSA-wjr6-rfwf-wx2f.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wq4m-7cp4-8jgg/GHSA-wq4m-7cp4-8jgg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wr29-5553-rrh3/GHSA-wr29-5553-rrh3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wvg7-cvgq-hhh3/GHSA-wvg7-cvgq-hhh3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-x27v-pq4m-wch6/GHSA-x27v-pq4m-wch6.json create mode 100644 advisories/unreviewed/2025/04/GHSA-x599-jjw8-g5vw/GHSA-x599-jjw8-g5vw.json create mode 100644 advisories/unreviewed/2025/04/GHSA-x65v-wxjf-f672/GHSA-x65v-wxjf-f672.json create mode 100644 advisories/unreviewed/2025/04/GHSA-x7g5-wpm2-r3jm/GHSA-x7g5-wpm2-r3jm.json create mode 100644 advisories/unreviewed/2025/04/GHSA-x998-4j8c-4fq3/GHSA-x998-4j8c-4fq3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-xc3h-9j86-jpjh/GHSA-xc3h-9j86-jpjh.json create mode 100644 advisories/unreviewed/2025/04/GHSA-xcw6-8574-9qv2/GHSA-xcw6-8574-9qv2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-xp88-vp78-mqm7/GHSA-xp88-vp78-mqm7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-xr7q-639h-425q/GHSA-xr7q-639h-425q.json create mode 100644 advisories/unreviewed/2025/04/GHSA-xrg8-r4mg-6g2x/GHSA-xrg8-r4mg-6g2x.json create mode 100644 advisories/unreviewed/2025/04/GHSA-xwxw-9gfj-g2c9/GHSA-xwxw-9gfj-g2c9.json diff --git a/advisories/unreviewed/2023/01/GHSA-4w2r-hhr3-c2wv/GHSA-4w2r-hhr3-c2wv.json b/advisories/unreviewed/2023/01/GHSA-4w2r-hhr3-c2wv/GHSA-4w2r-hhr3-c2wv.json index 94f8b227493..a3e2471fdd6 100644 --- a/advisories/unreviewed/2023/01/GHSA-4w2r-hhr3-c2wv/GHSA-4w2r-hhr3-c2wv.json +++ b/advisories/unreviewed/2023/01/GHSA-4w2r-hhr3-c2wv/GHSA-4w2r-hhr3-c2wv.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-58wq-p76f-6qjh/GHSA-58wq-p76f-6qjh.json b/advisories/unreviewed/2023/01/GHSA-58wq-p76f-6qjh/GHSA-58wq-p76f-6qjh.json index fdd61f7ec4a..60f724f035c 100644 --- a/advisories/unreviewed/2023/01/GHSA-58wq-p76f-6qjh/GHSA-58wq-p76f-6qjh.json +++ b/advisories/unreviewed/2023/01/GHSA-58wq-p76f-6qjh/GHSA-58wq-p76f-6qjh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-58wq-p76f-6qjh", - "modified": "2023-01-20T21:30:28Z", + "modified": "2025-04-08T18:34:05Z", "published": "2023-01-12T15:30:24Z", "aliases": [ "CVE-2022-3515" diff --git a/advisories/unreviewed/2023/01/GHSA-6fr8-22pf-g32x/GHSA-6fr8-22pf-g32x.json b/advisories/unreviewed/2023/01/GHSA-6fr8-22pf-g32x/GHSA-6fr8-22pf-g32x.json index 9935cca9882..0b8a16eab4e 100644 --- a/advisories/unreviewed/2023/01/GHSA-6fr8-22pf-g32x/GHSA-6fr8-22pf-g32x.json +++ b/advisories/unreviewed/2023/01/GHSA-6fr8-22pf-g32x/GHSA-6fr8-22pf-g32x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6fr8-22pf-g32x", - "modified": "2023-01-23T15:30:33Z", + "modified": "2025-04-08T18:34:05Z", "published": "2023-01-12T21:30:30Z", "aliases": [ "CVE-2022-3977" diff --git a/advisories/unreviewed/2023/01/GHSA-mp4c-w7j9-95f4/GHSA-mp4c-w7j9-95f4.json b/advisories/unreviewed/2023/01/GHSA-mp4c-w7j9-95f4/GHSA-mp4c-w7j9-95f4.json index 49dd1387926..80b52dd4497 100644 --- a/advisories/unreviewed/2023/01/GHSA-mp4c-w7j9-95f4/GHSA-mp4c-w7j9-95f4.json +++ b/advisories/unreviewed/2023/01/GHSA-mp4c-w7j9-95f4/GHSA-mp4c-w7j9-95f4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mp4c-w7j9-95f4", - "modified": "2023-01-20T21:30:29Z", + "modified": "2025-04-08T18:34:04Z", "published": "2023-01-12T06:30:24Z", "aliases": [ "CVE-2022-4345" @@ -27,6 +27,14 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/02/msg00007.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RDZMWIKH3L5JQZC6GSVOJ3N5UXNQPJGQ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGWIW6K64PKC375YAONYXKIVT2FDEDV3" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RDZMWIKH3L5JQZC6GSVOJ3N5UXNQPJGQ" diff --git a/advisories/unreviewed/2023/01/GHSA-wv3p-jvhj-v4jc/GHSA-wv3p-jvhj-v4jc.json b/advisories/unreviewed/2023/01/GHSA-wv3p-jvhj-v4jc/GHSA-wv3p-jvhj-v4jc.json index 5ff783df45d..4ae0e00da2d 100644 --- a/advisories/unreviewed/2023/01/GHSA-wv3p-jvhj-v4jc/GHSA-wv3p-jvhj-v4jc.json +++ b/advisories/unreviewed/2023/01/GHSA-wv3p-jvhj-v4jc/GHSA-wv3p-jvhj-v4jc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wv3p-jvhj-v4jc", - "modified": "2023-01-20T15:30:27Z", + "modified": "2025-04-08T18:34:04Z", "published": "2023-01-12T06:30:23Z", "aliases": [ "CVE-2022-47927" @@ -23,10 +23,18 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/07/msg00011.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AP65YEN762IBNQPOYGUVLTQIDLM5XD2A" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AP65YEN762IBNQPOYGUVLTQIDLM5XD2A" }, + { + "type": "WEB", + "url": "https://lists.wikimedia.org/hyperkitty/list/mediawiki-announce%40lists.wikimedia.org/thread/UEMW64LVEH3BEXCJV43CVS6XPYURKWU3" + }, { "type": "WEB", "url": "https://lists.wikimedia.org/hyperkitty/list/mediawiki-announce@lists.wikimedia.org/thread/UEMW64LVEH3BEXCJV43CVS6XPYURKWU3" diff --git a/advisories/unreviewed/2024/03/GHSA-327x-6c4p-8g25/GHSA-327x-6c4p-8g25.json b/advisories/unreviewed/2024/03/GHSA-327x-6c4p-8g25/GHSA-327x-6c4p-8g25.json index 14d0c5e1322..25ab0bff86d 100644 --- a/advisories/unreviewed/2024/03/GHSA-327x-6c4p-8g25/GHSA-327x-6c4p-8g25.json +++ b/advisories/unreviewed/2024/03/GHSA-327x-6c4p-8g25/GHSA-327x-6c4p-8g25.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-327x-6c4p-8g25", - "modified": "2024-03-29T15:30:28Z", + "modified": "2025-04-08T18:34:07Z", "published": "2024-03-29T15:30:28Z", "aliases": [ "CVE-2024-30503" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EverPress Mailster allows Reflected XSS.This issue affects Mailster: from n/a through 4.0.6.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EverPress Mailster allows Reflected XSS.This issue affects Mailster: from n/a through 4.0.6.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-3vqf-26wq-v77m/GHSA-3vqf-26wq-v77m.json b/advisories/unreviewed/2024/03/GHSA-3vqf-26wq-v77m/GHSA-3vqf-26wq-v77m.json index c10e7a7c17b..32f89e4054a 100644 --- a/advisories/unreviewed/2024/03/GHSA-3vqf-26wq-v77m/GHSA-3vqf-26wq-v77m.json +++ b/advisories/unreviewed/2024/03/GHSA-3vqf-26wq-v77m/GHSA-3vqf-26wq-v77m.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-3vqf-26wq-v77m", - "modified": "2024-03-28T06:30:46Z", + "modified": "2025-04-08T18:34:06Z", "published": "2024-03-28T06:30:46Z", "aliases": [ "CVE-2024-30230" ], - "details": "Deserialization of Untrusted Data vulnerability in Acowebs PDF Invoices and Packing Slips For WooCommerce.This issue affects PDF Invoices and Packing Slips For WooCommerce: from n/a through 1.3.7.\n\n", + "details": "Deserialization of Untrusted Data vulnerability in Acowebs PDF Invoices and Packing Slips For WooCommerce.This issue affects PDF Invoices and Packing Slips For WooCommerce: from n/a through 1.3.7.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-4gwg-56fg-39pf/GHSA-4gwg-56fg-39pf.json b/advisories/unreviewed/2024/03/GHSA-4gwg-56fg-39pf/GHSA-4gwg-56fg-39pf.json index 98232e7dbb8..4bdca971040 100644 --- a/advisories/unreviewed/2024/03/GHSA-4gwg-56fg-39pf/GHSA-4gwg-56fg-39pf.json +++ b/advisories/unreviewed/2024/03/GHSA-4gwg-56fg-39pf/GHSA-4gwg-56fg-39pf.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-4gwg-56fg-39pf", - "modified": "2024-03-27T09:30:40Z", + "modified": "2025-04-08T18:34:06Z", "published": "2024-03-27T09:30:40Z", "aliases": [ "CVE-2024-30194" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Sunshine Sunshine Photo Cart allows Reflected XSS.This issue affects Sunshine Photo Cart: from n/a through 3.1.1.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Sunshine Sunshine Photo Cart allows Reflected XSS.This issue affects Sunshine Photo Cart: from n/a through 3.1.1.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-539g-ppw2-7c4r/GHSA-539g-ppw2-7c4r.json b/advisories/unreviewed/2024/03/GHSA-539g-ppw2-7c4r/GHSA-539g-ppw2-7c4r.json index 80589a343a8..014074ec181 100644 --- a/advisories/unreviewed/2024/03/GHSA-539g-ppw2-7c4r/GHSA-539g-ppw2-7c4r.json +++ b/advisories/unreviewed/2024/03/GHSA-539g-ppw2-7c4r/GHSA-539g-ppw2-7c4r.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-539g-ppw2-7c4r", - "modified": "2024-03-28T06:30:47Z", + "modified": "2025-04-08T18:34:07Z", "published": "2024-03-28T06:30:47Z", "aliases": [ "CVE-2024-29100" ], - "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 2.1.4.\n\n", + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 2.1.4.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-c7mc-vqjx-hc9c/GHSA-c7mc-vqjx-hc9c.json b/advisories/unreviewed/2024/03/GHSA-c7mc-vqjx-hc9c/GHSA-c7mc-vqjx-hc9c.json index a23e8c9667c..69b19789f95 100644 --- a/advisories/unreviewed/2024/03/GHSA-c7mc-vqjx-hc9c/GHSA-c7mc-vqjx-hc9c.json +++ b/advisories/unreviewed/2024/03/GHSA-c7mc-vqjx-hc9c/GHSA-c7mc-vqjx-hc9c.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-c7mc-vqjx-hc9c", - "modified": "2024-03-28T06:30:46Z", + "modified": "2025-04-08T18:34:06Z", "published": "2024-03-28T06:30:46Z", "aliases": [ "CVE-2024-30224" ], - "details": "Deserialization of Untrusted Data vulnerability in Wholesale Team WholesaleX.This issue affects WholesaleX: from n/a through 1.3.2.\n\n", + "details": "Deserialization of Untrusted Data vulnerability in Wholesale Team WholesaleX.This issue affects WholesaleX: from n/a through 1.3.2.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-jr8p-29pq-j5wf/GHSA-jr8p-29pq-j5wf.json b/advisories/unreviewed/2024/03/GHSA-jr8p-29pq-j5wf/GHSA-jr8p-29pq-j5wf.json index 00f23b4a213..d9edf93febe 100644 --- a/advisories/unreviewed/2024/03/GHSA-jr8p-29pq-j5wf/GHSA-jr8p-29pq-j5wf.json +++ b/advisories/unreviewed/2024/03/GHSA-jr8p-29pq-j5wf/GHSA-jr8p-29pq-j5wf.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-jr8p-29pq-j5wf", - "modified": "2024-03-29T15:30:28Z", + "modified": "2025-04-08T18:34:08Z", "published": "2024-03-29T15:30:28Z", "aliases": [ "CVE-2024-30520" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Labib Ahmed Carousel Anything For WPBakery Page Builder allows Stored XSS.This issue affects Carousel Anything For WPBakery Page Builder: from n/a through 2.1.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Labib Ahmed Carousel Anything For WPBakery Page Builder allows Stored XSS.This issue affects Carousel Anything For WPBakery Page Builder: from n/a through 2.1.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-p2c5-vphq-jrxg/GHSA-p2c5-vphq-jrxg.json b/advisories/unreviewed/2024/03/GHSA-p2c5-vphq-jrxg/GHSA-p2c5-vphq-jrxg.json index efc8a892e1f..24f100071a8 100644 --- a/advisories/unreviewed/2024/03/GHSA-p2c5-vphq-jrxg/GHSA-p2c5-vphq-jrxg.json +++ b/advisories/unreviewed/2024/03/GHSA-p2c5-vphq-jrxg/GHSA-p2c5-vphq-jrxg.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-p2c5-vphq-jrxg", - "modified": "2024-03-29T15:30:31Z", + "modified": "2025-04-08T18:34:08Z", "published": "2024-03-29T15:30:31Z", "aliases": [ "CVE-2024-30488" ], - "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Katie Seaborn Zotpress.This issue affects Zotpress: from n/a through 7.3.7.\n\n", + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Katie Seaborn Zotpress.This issue affects Zotpress: from n/a through 7.3.7.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-pr9j-p6wx-p73x/GHSA-pr9j-p6wx-p73x.json b/advisories/unreviewed/2024/03/GHSA-pr9j-p6wx-p73x/GHSA-pr9j-p6wx-p73x.json index e2300f862a2..183b2544374 100644 --- a/advisories/unreviewed/2024/03/GHSA-pr9j-p6wx-p73x/GHSA-pr9j-p6wx-p73x.json +++ b/advisories/unreviewed/2024/03/GHSA-pr9j-p6wx-p73x/GHSA-pr9j-p6wx-p73x.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-pr9j-p6wx-p73x", - "modified": "2024-03-28T06:30:47Z", + "modified": "2025-04-08T18:34:07Z", "published": "2024-03-28T06:30:47Z", "aliases": [ "CVE-2024-30221" ], - "details": "Deserialization of Untrusted Data vulnerability in WP Sunshine Sunshine Photo Cart.This issue affects Sunshine Photo Cart: from n/a through 3.1.1.\n\n", + "details": "Deserialization of Untrusted Data vulnerability in WP Sunshine Sunshine Photo Cart.This issue affects Sunshine Photo Cart: from n/a through 3.1.1.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-qw72-jmvh-wj6r/GHSA-qw72-jmvh-wj6r.json b/advisories/unreviewed/2024/03/GHSA-qw72-jmvh-wj6r/GHSA-qw72-jmvh-wj6r.json index 724cff9e997..c525f882ef7 100644 --- a/advisories/unreviewed/2024/03/GHSA-qw72-jmvh-wj6r/GHSA-qw72-jmvh-wj6r.json +++ b/advisories/unreviewed/2024/03/GHSA-qw72-jmvh-wj6r/GHSA-qw72-jmvh-wj6r.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-qw72-jmvh-wj6r", - "modified": "2024-03-28T06:30:46Z", + "modified": "2025-04-08T18:34:06Z", "published": "2024-03-28T06:30:46Z", "aliases": [ "CVE-2024-30236" ], - "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Contest Gallery.This issue affects Contest Gallery: from n/a through 21.3.4.\n\n", + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Contest Gallery.This issue affects Contest Gallery: from n/a through 21.3.4.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-qxgj-php7-wrw3/GHSA-qxgj-php7-wrw3.json b/advisories/unreviewed/2024/03/GHSA-qxgj-php7-wrw3/GHSA-qxgj-php7-wrw3.json index a9de900601f..451bb1b3bf1 100644 --- a/advisories/unreviewed/2024/03/GHSA-qxgj-php7-wrw3/GHSA-qxgj-php7-wrw3.json +++ b/advisories/unreviewed/2024/03/GHSA-qxgj-php7-wrw3/GHSA-qxgj-php7-wrw3.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-qxgj-php7-wrw3", - "modified": "2024-03-29T15:30:28Z", + "modified": "2025-04-08T18:34:07Z", "published": "2024-03-29T15:30:28Z", "aliases": [ "CVE-2024-30483" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Simple Sponsorships Sponsors allows Stored XSS.This issue affects Sponsors: from n/a through 3.5.1.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Simple Sponsorships Sponsors allows Stored XSS.This issue affects Sponsors: from n/a through 3.5.1.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-vxq6-3hh5-mcjj/GHSA-vxq6-3hh5-mcjj.json b/advisories/unreviewed/2024/03/GHSA-vxq6-3hh5-mcjj/GHSA-vxq6-3hh5-mcjj.json index 9c196efb109..01705e02a18 100644 --- a/advisories/unreviewed/2024/03/GHSA-vxq6-3hh5-mcjj/GHSA-vxq6-3hh5-mcjj.json +++ b/advisories/unreviewed/2024/03/GHSA-vxq6-3hh5-mcjj/GHSA-vxq6-3hh5-mcjj.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-vxq6-3hh5-mcjj", - "modified": "2024-03-29T15:30:28Z", + "modified": "2025-04-08T18:34:07Z", "published": "2024-03-29T15:30:28Z", "aliases": [ "CVE-2024-30519" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lordicon Lordicon Animated Icons allows Stored XSS.This issue affects Lordicon Animated Icons: from n/a through 2.0.1.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lordicon Lordicon Animated Icons allows Stored XSS.This issue affects Lordicon Animated Icons: from n/a through 2.0.1.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-27w6-8m77-x3qf/GHSA-27w6-8m77-x3qf.json b/advisories/unreviewed/2024/04/GHSA-27w6-8m77-x3qf/GHSA-27w6-8m77-x3qf.json index b91f0cceb5e..bf1d719f976 100644 --- a/advisories/unreviewed/2024/04/GHSA-27w6-8m77-x3qf/GHSA-27w6-8m77-x3qf.json +++ b/advisories/unreviewed/2024/04/GHSA-27w6-8m77-x3qf/GHSA-27w6-8m77-x3qf.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-27w6-8m77-x3qf", - "modified": "2024-04-10T18:30:47Z", + "modified": "2025-04-08T18:34:11Z", "published": "2024-04-10T18:30:47Z", "aliases": [ "CVE-2024-31254" ], - "details": "Insertion of Sensitive Information into Log File vulnerability in WebToffee WordPress Backup & Migration.This issue affects WordPress Backup & Migration: from n/a through 1.4.7.\n\n", + "details": "Insertion of Sensitive Information into Log File vulnerability in WebToffee WordPress Backup & Migration.This issue affects WordPress Backup & Migration: from n/a through 1.4.7.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-3m3j-g6jr-6c5m/GHSA-3m3j-g6jr-6c5m.json b/advisories/unreviewed/2024/04/GHSA-3m3j-g6jr-6c5m/GHSA-3m3j-g6jr-6c5m.json index a53ecbd3fce..f07963af05b 100644 --- a/advisories/unreviewed/2024/04/GHSA-3m3j-g6jr-6c5m/GHSA-3m3j-g6jr-6c5m.json +++ b/advisories/unreviewed/2024/04/GHSA-3m3j-g6jr-6c5m/GHSA-3m3j-g6jr-6c5m.json @@ -38,6 +38,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-24" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/04/GHSA-c4qr-mpj2-hxhr/GHSA-c4qr-mpj2-hxhr.json b/advisories/unreviewed/2024/04/GHSA-c4qr-mpj2-hxhr/GHSA-c4qr-mpj2-hxhr.json index 4a8be41a8ef..db4c752c0b8 100644 --- a/advisories/unreviewed/2024/04/GHSA-c4qr-mpj2-hxhr/GHSA-c4qr-mpj2-hxhr.json +++ b/advisories/unreviewed/2024/04/GHSA-c4qr-mpj2-hxhr/GHSA-c4qr-mpj2-hxhr.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-c4qr-mpj2-hxhr", - "modified": "2024-04-12T15:37:21Z", + "modified": "2025-04-08T18:34:11Z", "published": "2024-04-12T15:37:21Z", "aliases": [ "CVE-2023-51409" ], - "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 1.9.98.\n\n", + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 1.9.98.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-chwx-r397-6ww4/GHSA-chwx-r397-6ww4.json b/advisories/unreviewed/2024/04/GHSA-chwx-r397-6ww4/GHSA-chwx-r397-6ww4.json index 3f95321ba86..a023b1db4ca 100644 --- a/advisories/unreviewed/2024/04/GHSA-chwx-r397-6ww4/GHSA-chwx-r397-6ww4.json +++ b/advisories/unreviewed/2024/04/GHSA-chwx-r397-6ww4/GHSA-chwx-r397-6ww4.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-chwx-r397-6ww4", - "modified": "2024-04-10T18:30:47Z", + "modified": "2025-04-08T18:34:11Z", "published": "2024-04-10T18:30:47Z", "aliases": [ "CVE-2024-31245" ], - "details": "Insertion of Sensitive Information into Log File vulnerability in ConvertKit.This issue affects ConvertKit: from n/a through 2.4.5.\n\n", + "details": "Insertion of Sensitive Information into Log File vulnerability in ConvertKit.This issue affects ConvertKit: from n/a through 2.4.5.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-cqgx-qm2w-88qc/GHSA-cqgx-qm2w-88qc.json b/advisories/unreviewed/2024/04/GHSA-cqgx-qm2w-88qc/GHSA-cqgx-qm2w-88qc.json index 1f9732f7610..c56f640c7db 100644 --- a/advisories/unreviewed/2024/04/GHSA-cqgx-qm2w-88qc/GHSA-cqgx-qm2w-88qc.json +++ b/advisories/unreviewed/2024/04/GHSA-cqgx-qm2w-88qc/GHSA-cqgx-qm2w-88qc.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-cqgx-qm2w-88qc", - "modified": "2024-04-10T18:30:47Z", + "modified": "2025-04-08T18:34:11Z", "published": "2024-04-10T18:30:47Z", "aliases": [ "CVE-2024-31240" ], - "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in InfoTheme WP Poll Maker.This issue affects WP Poll Maker: from n/a through 3.1.\n\n", + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in InfoTheme WP Poll Maker.This issue affects WP Poll Maker: from n/a through 3.1.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-f525-qqcm-4ww9/GHSA-f525-qqcm-4ww9.json b/advisories/unreviewed/2024/04/GHSA-f525-qqcm-4ww9/GHSA-f525-qqcm-4ww9.json index c01c82a8da1..30de25efb8f 100644 --- a/advisories/unreviewed/2024/04/GHSA-f525-qqcm-4ww9/GHSA-f525-qqcm-4ww9.json +++ b/advisories/unreviewed/2024/04/GHSA-f525-qqcm-4ww9/GHSA-f525-qqcm-4ww9.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-f525-qqcm-4ww9", - "modified": "2024-04-10T18:30:47Z", + "modified": "2025-04-08T18:34:11Z", "published": "2024-04-10T18:30:47Z", "aliases": [ "CVE-2024-31249" ], - "details": "Insertion of Sensitive Information into Log File vulnerability in WPKube Subscribe To Comments Reloaded.This issue affects Subscribe To Comments Reloaded: from n/a through 220725.\n\n", + "details": "Insertion of Sensitive Information into Log File vulnerability in WPKube Subscribe To Comments Reloaded.This issue affects Subscribe To Comments Reloaded: from n/a through 220725.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-gv6g-p8pg-jx2h/GHSA-gv6g-p8pg-jx2h.json b/advisories/unreviewed/2024/04/GHSA-gv6g-p8pg-jx2h/GHSA-gv6g-p8pg-jx2h.json index 9c71a7f3d3c..3f0130442ab 100644 --- a/advisories/unreviewed/2024/04/GHSA-gv6g-p8pg-jx2h/GHSA-gv6g-p8pg-jx2h.json +++ b/advisories/unreviewed/2024/04/GHSA-gv6g-p8pg-jx2h/GHSA-gv6g-p8pg-jx2h.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-gv6g-p8pg-jx2h", - "modified": "2024-04-10T18:30:47Z", + "modified": "2025-04-08T18:34:11Z", "published": "2024-04-10T18:30:47Z", "aliases": [ "CVE-2024-31247" ], - "details": "Insertion of Sensitive Information into Log File vulnerability in Frédéric GILLES FG Drupal to WordPress.This issue affects FG Drupal to WordPress: from n/a through 3.70.3.\n\n", + "details": "Insertion of Sensitive Information into Log File vulnerability in Frédéric GILLES FG Drupal to WordPress.This issue affects FG Drupal to WordPress: from n/a through 3.70.3.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-p939-fx2c-j96p/GHSA-p939-fx2c-j96p.json b/advisories/unreviewed/2024/04/GHSA-p939-fx2c-j96p/GHSA-p939-fx2c-j96p.json index f6b21374fd6..18aa08db71f 100644 --- a/advisories/unreviewed/2024/04/GHSA-p939-fx2c-j96p/GHSA-p939-fx2c-j96p.json +++ b/advisories/unreviewed/2024/04/GHSA-p939-fx2c-j96p/GHSA-p939-fx2c-j96p.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-362" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-rrpg-fwx7-jf88/GHSA-rrpg-fwx7-jf88.json b/advisories/unreviewed/2024/04/GHSA-rrpg-fwx7-jf88/GHSA-rrpg-fwx7-jf88.json index a478790b2ac..44b58d179bb 100644 --- a/advisories/unreviewed/2024/04/GHSA-rrpg-fwx7-jf88/GHSA-rrpg-fwx7-jf88.json +++ b/advisories/unreviewed/2024/04/GHSA-rrpg-fwx7-jf88/GHSA-rrpg-fwx7-jf88.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-rrpg-fwx7-jf88", - "modified": "2024-04-10T18:30:47Z", + "modified": "2025-04-08T18:34:11Z", "published": "2024-04-10T18:30:47Z", "aliases": [ "CVE-2024-31253" ], - "details": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in WP OAuth Server OAuth Server.This issue affects OAuth Server: from n/a through 4.3.3.\n\n", + "details": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in WP OAuth Server OAuth Server.This issue affects OAuth Server: from n/a through 4.3.3.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-xq4m-hfgr-r2x5/GHSA-xq4m-hfgr-r2x5.json b/advisories/unreviewed/2024/04/GHSA-xq4m-hfgr-r2x5/GHSA-xq4m-hfgr-r2x5.json index f5a1d4b99b0..a0477d45e2d 100644 --- a/advisories/unreviewed/2024/04/GHSA-xq4m-hfgr-r2x5/GHSA-xq4m-hfgr-r2x5.json +++ b/advisories/unreviewed/2024/04/GHSA-xq4m-hfgr-r2x5/GHSA-xq4m-hfgr-r2x5.json @@ -61,7 +61,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-556r-646r-vxjp/GHSA-556r-646r-vxjp.json b/advisories/unreviewed/2024/05/GHSA-556r-646r-vxjp/GHSA-556r-646r-vxjp.json index 9baa15dc362..78171cc27a7 100644 --- a/advisories/unreviewed/2024/05/GHSA-556r-646r-vxjp/GHSA-556r-646r-vxjp.json +++ b/advisories/unreviewed/2024/05/GHSA-556r-646r-vxjp/GHSA-556r-646r-vxjp.json @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-416" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-5jv6-7953-598p/GHSA-5jv6-7953-598p.json b/advisories/unreviewed/2024/05/GHSA-5jv6-7953-598p/GHSA-5jv6-7953-598p.json index 3f5dc84eb07..fa11e8dbf49 100644 --- a/advisories/unreviewed/2024/05/GHSA-5jv6-7953-598p/GHSA-5jv6-7953-598p.json +++ b/advisories/unreviewed/2024/05/GHSA-5jv6-7953-598p/GHSA-5jv6-7953-598p.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-401" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-22fq-gxhw-m8h5/GHSA-22fq-gxhw-m8h5.json b/advisories/unreviewed/2025/04/GHSA-22fq-gxhw-m8h5/GHSA-22fq-gxhw-m8h5.json new file mode 100644 index 00000000000..18d9591435d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-22fq-gxhw-m8h5/GHSA-22fq-gxhw-m8h5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-22fq-gxhw-m8h5", + "modified": "2025-04-08T18:34:42Z", + "published": "2025-04-08T18:34:42Z", + "aliases": [ + "CVE-2025-2286" + ], + "details": "A local code execution vulnerability exists in the Rockwell Automation Arena®  due to an uninitialized pointer. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerability a legitimate user must open a malicious DOE file.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2286" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1726.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-457" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-23cx-98wc-24qg/GHSA-23cx-98wc-24qg.json b/advisories/unreviewed/2025/04/GHSA-23cx-98wc-24qg/GHSA-23cx-98wc-24qg.json index cb2aaf3c289..8d871550ac8 100644 --- a/advisories/unreviewed/2025/04/GHSA-23cx-98wc-24qg/GHSA-23cx-98wc-24qg.json +++ b/advisories/unreviewed/2025/04/GHSA-23cx-98wc-24qg/GHSA-23cx-98wc-24qg.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-2453-p5w4-2rh4/GHSA-2453-p5w4-2rh4.json b/advisories/unreviewed/2025/04/GHSA-2453-p5w4-2rh4/GHSA-2453-p5w4-2rh4.json new file mode 100644 index 00000000000..e22ccbdc034 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2453-p5w4-2rh4/GHSA-2453-p5w4-2rh4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2453-p5w4-2rh4", + "modified": "2025-04-08T18:34:43Z", + "published": "2025-04-08T18:34:43Z", + "aliases": [ + "CVE-2025-27441" + ], + "details": "Cross site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via adjacent network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27441" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-25013" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T17:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-25m2-7f7f-p53m/GHSA-25m2-7f7f-p53m.json b/advisories/unreviewed/2025/04/GHSA-25m2-7f7f-p53m/GHSA-25m2-7f7f-p53m.json new file mode 100644 index 00000000000..8afb9bbad37 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-25m2-7f7f-p53m/GHSA-25m2-7f7f-p53m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-25m2-7f7f-p53m", + "modified": "2025-04-08T18:34:50Z", + "published": "2025-04-08T18:34:50Z", + "aliases": [ + "CVE-2025-27471" + ], + "details": "Sensitive data storage in improperly locked memory in Microsoft Streaming Service allows an unauthorized attacker to deny service over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27471" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27471" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-591" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2f5r-r4jx-hh42/GHSA-2f5r-r4jx-hh42.json b/advisories/unreviewed/2025/04/GHSA-2f5r-r4jx-hh42/GHSA-2f5r-r4jx-hh42.json new file mode 100644 index 00000000000..728a4d84ee8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2f5r-r4jx-hh42/GHSA-2f5r-r4jx-hh42.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2f5r-r4jx-hh42", + "modified": "2025-04-08T18:34:45Z", + "published": "2025-04-08T18:34:45Z", + "aliases": [ + "CVE-2025-26644" + ], + "details": "Automated recognition mechanism with inadequate detection or handling of adversarial input perturbations in Windows Hello allows an unauthorized attacker to perform spoofing locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26644" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26644" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1039" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2gwg-wcpq-6h7g/GHSA-2gwg-wcpq-6h7g.json b/advisories/unreviewed/2025/04/GHSA-2gwg-wcpq-6h7g/GHSA-2gwg-wcpq-6h7g.json new file mode 100644 index 00000000000..1867b36b6f9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2gwg-wcpq-6h7g/GHSA-2gwg-wcpq-6h7g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2gwg-wcpq-6h7g", + "modified": "2025-04-08T18:34:44Z", + "published": "2025-04-08T18:34:44Z", + "aliases": [ + "CVE-2025-24060" + ], + "details": "Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24060" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24060" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2hgf-545p-qvj7/GHSA-2hgf-545p-qvj7.json b/advisories/unreviewed/2025/04/GHSA-2hgf-545p-qvj7/GHSA-2hgf-545p-qvj7.json new file mode 100644 index 00000000000..7e4e4433520 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2hgf-545p-qvj7/GHSA-2hgf-545p-qvj7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2hgf-545p-qvj7", + "modified": "2025-04-08T18:34:50Z", + "published": "2025-04-08T18:34:50Z", + "aliases": [ + "CVE-2025-27474" + ], + "details": "Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27474" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27474" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-908" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2hrp-x9mq-5qp2/GHSA-2hrp-x9mq-5qp2.json b/advisories/unreviewed/2025/04/GHSA-2hrp-x9mq-5qp2/GHSA-2hrp-x9mq-5qp2.json new file mode 100644 index 00000000000..4edcd23fca0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2hrp-x9mq-5qp2/GHSA-2hrp-x9mq-5qp2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2hrp-x9mq-5qp2", + "modified": "2025-04-08T18:34:44Z", + "published": "2025-04-08T18:34:44Z", + "aliases": [ + "CVE-2025-21205" + ], + "details": "Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21205" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21205" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2j6p-wf3v-2mvp/GHSA-2j6p-wf3v-2mvp.json b/advisories/unreviewed/2025/04/GHSA-2j6p-wf3v-2mvp/GHSA-2j6p-wf3v-2mvp.json new file mode 100644 index 00000000000..97655c72cce --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2j6p-wf3v-2mvp/GHSA-2j6p-wf3v-2mvp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2j6p-wf3v-2mvp", + "modified": "2025-04-08T18:34:51Z", + "published": "2025-04-08T18:34:51Z", + "aliases": [ + "CVE-2025-27478" + ], + "details": "Heap-based buffer overflow in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27478" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27478" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-35q9-q5hh-hmc4/GHSA-35q9-q5hh-hmc4.json b/advisories/unreviewed/2025/04/GHSA-35q9-q5hh-hmc4/GHSA-35q9-q5hh-hmc4.json new file mode 100644 index 00000000000..11463a08186 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-35q9-q5hh-hmc4/GHSA-35q9-q5hh-hmc4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-35q9-q5hh-hmc4", + "modified": "2025-04-08T18:34:44Z", + "published": "2025-04-08T18:34:44Z", + "aliases": [ + "CVE-2025-21197" + ], + "details": "Improper access control in Windows NTFS allows an authorized attacker to disclose file path information under a folder where the attacker doesn't have permission to list content.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21197" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21197" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-386h-wcf4-977x/GHSA-386h-wcf4-977x.json b/advisories/unreviewed/2025/04/GHSA-386h-wcf4-977x/GHSA-386h-wcf4-977x.json new file mode 100644 index 00000000000..3faacdf78a8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-386h-wcf4-977x/GHSA-386h-wcf4-977x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-386h-wcf4-977x", + "modified": "2025-04-08T18:34:57Z", + "published": "2025-04-08T18:34:57Z", + "aliases": [ + "CVE-2025-29821" + ], + "details": "Improper input validation in Dynamics Business Central allows an authorized attacker to disclose information locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29821" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29821" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3pxq-xg4j-rgqx/GHSA-3pxq-xg4j-rgqx.json b/advisories/unreviewed/2025/04/GHSA-3pxq-xg4j-rgqx/GHSA-3pxq-xg4j-rgqx.json index a41599d246f..2c7d22945be 100644 --- a/advisories/unreviewed/2025/04/GHSA-3pxq-xg4j-rgqx/GHSA-3pxq-xg4j-rgqx.json +++ b/advisories/unreviewed/2025/04/GHSA-3pxq-xg4j-rgqx/GHSA-3pxq-xg4j-rgqx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3pxq-xg4j-rgqx", - "modified": "2025-04-07T18:30:48Z", + "modified": "2025-04-08T18:34:21Z", "published": "2025-04-07T18:30:48Z", "aliases": [ "CVE-2025-28413" ], "details": "An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the SysDictTypeController component", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-07T16:15:25Z" diff --git a/advisories/unreviewed/2025/04/GHSA-3w3r-78f2-2x8v/GHSA-3w3r-78f2-2x8v.json b/advisories/unreviewed/2025/04/GHSA-3w3r-78f2-2x8v/GHSA-3w3r-78f2-2x8v.json new file mode 100644 index 00000000000..b9867e42d87 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3w3r-78f2-2x8v/GHSA-3w3r-78f2-2x8v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3w3r-78f2-2x8v", + "modified": "2025-04-08T18:34:52Z", + "published": "2025-04-08T18:34:52Z", + "aliases": [ + "CVE-2025-27728" + ], + "details": "Out-of-bounds read in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27728" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27728" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-429q-ccqc-32wq/GHSA-429q-ccqc-32wq.json b/advisories/unreviewed/2025/04/GHSA-429q-ccqc-32wq/GHSA-429q-ccqc-32wq.json new file mode 100644 index 00000000000..1ad9f013454 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-429q-ccqc-32wq/GHSA-429q-ccqc-32wq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-429q-ccqc-32wq", + "modified": "2025-04-08T18:34:44Z", + "published": "2025-04-08T18:34:44Z", + "aliases": [ + "CVE-2025-21204" + ], + "details": "Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21204" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21204" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-437f-4378-pmh4/GHSA-437f-4378-pmh4.json b/advisories/unreviewed/2025/04/GHSA-437f-4378-pmh4/GHSA-437f-4378-pmh4.json new file mode 100644 index 00000000000..b9585e290f2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-437f-4378-pmh4/GHSA-437f-4378-pmh4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-437f-4378-pmh4", + "modified": "2025-04-08T18:34:57Z", + "published": "2025-04-08T18:34:57Z", + "aliases": [ + "CVE-2025-29819" + ], + "details": "External control of file name or path in Azure Portal Windows Admin Center allows an unauthorized attacker to disclose information locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29819" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29819" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-73" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-443w-gf2f-8h6x/GHSA-443w-gf2f-8h6x.json b/advisories/unreviewed/2025/04/GHSA-443w-gf2f-8h6x/GHSA-443w-gf2f-8h6x.json new file mode 100644 index 00000000000..17955855532 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-443w-gf2f-8h6x/GHSA-443w-gf2f-8h6x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-443w-gf2f-8h6x", + "modified": "2025-04-08T18:34:57Z", + "published": "2025-04-08T18:34:57Z", + "aliases": [ + "CVE-2025-29812" + ], + "details": "Untrusted pointer dereference in Windows Kernel Memory allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29812" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29812" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-822" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-44v2-prcf-pc3m/GHSA-44v2-prcf-pc3m.json b/advisories/unreviewed/2025/04/GHSA-44v2-prcf-pc3m/GHSA-44v2-prcf-pc3m.json new file mode 100644 index 00000000000..9d9522d1f22 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-44v2-prcf-pc3m/GHSA-44v2-prcf-pc3m.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-44v2-prcf-pc3m", + "modified": "2025-04-08T18:34:43Z", + "published": "2025-04-08T18:34:43Z", + "aliases": [ + "CVE-2025-25226" + ], + "details": "Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the vulnerability in question can not be exploited when using the original database class. However, classes extending the affected class might be affected, if the vulnerable method is used.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25226" + }, + { + "type": "WEB", + "url": "https://developer.joomla.org/security-centre/963-20250401-framework-sql-injection-vulnerability-in-quotenamestr-method-of-database-package.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T17:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-46hp-9p3c-5jgh/GHSA-46hp-9p3c-5jgh.json b/advisories/unreviewed/2025/04/GHSA-46hp-9p3c-5jgh/GHSA-46hp-9p3c-5jgh.json new file mode 100644 index 00000000000..d6636ac217d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-46hp-9p3c-5jgh/GHSA-46hp-9p3c-5jgh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-46hp-9p3c-5jgh", + "modified": "2025-04-08T18:34:50Z", + "published": "2025-04-08T18:34:50Z", + "aliases": [ + "CVE-2025-27481" + ], + "details": "Stack-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27481" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27481" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-473g-6pv5-56gc/GHSA-473g-6pv5-56gc.json b/advisories/unreviewed/2025/04/GHSA-473g-6pv5-56gc/GHSA-473g-6pv5-56gc.json new file mode 100644 index 00000000000..e0c0bb7dc65 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-473g-6pv5-56gc/GHSA-473g-6pv5-56gc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-473g-6pv5-56gc", + "modified": "2025-04-08T18:34:44Z", + "published": "2025-04-08T18:34:44Z", + "aliases": [ + "CVE-2025-21222" + ], + "details": "Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21222" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21222" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-47qr-4ffm-5qm9/GHSA-47qr-4ffm-5qm9.json b/advisories/unreviewed/2025/04/GHSA-47qr-4ffm-5qm9/GHSA-47qr-4ffm-5qm9.json new file mode 100644 index 00000000000..46c9ab7ceb6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-47qr-4ffm-5qm9/GHSA-47qr-4ffm-5qm9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-47qr-4ffm-5qm9", + "modified": "2025-04-08T18:34:46Z", + "published": "2025-04-08T18:34:46Z", + "aliases": [ + "CVE-2025-26651" + ], + "details": "Exposed dangerous method or function in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26651" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26651" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-749" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-47xw-2q7j-49hw/GHSA-47xw-2q7j-49hw.json b/advisories/unreviewed/2025/04/GHSA-47xw-2q7j-49hw/GHSA-47xw-2q7j-49hw.json new file mode 100644 index 00000000000..efd3639b63d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-47xw-2q7j-49hw/GHSA-47xw-2q7j-49hw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-47xw-2q7j-49hw", + "modified": "2025-04-08T18:34:50Z", + "published": "2025-04-08T18:34:50Z", + "aliases": [ + "CVE-2025-27467" + ], + "details": "Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27467" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27467" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4f3f-qmwc-952f/GHSA-4f3f-qmwc-952f.json b/advisories/unreviewed/2025/04/GHSA-4f3f-qmwc-952f/GHSA-4f3f-qmwc-952f.json new file mode 100644 index 00000000000..ca9a48ff3f2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4f3f-qmwc-952f/GHSA-4f3f-qmwc-952f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4f3f-qmwc-952f", + "modified": "2025-04-08T18:34:47Z", + "published": "2025-04-08T18:34:47Z", + "aliases": [ + "CVE-2025-26679" + ], + "details": "Use after free in RPC Endpoint Mapper Service allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26679" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26679" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4f8x-f25f-pp6r/GHSA-4f8x-f25f-pp6r.json b/advisories/unreviewed/2025/04/GHSA-4f8x-f25f-pp6r/GHSA-4f8x-f25f-pp6r.json new file mode 100644 index 00000000000..ee213647868 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4f8x-f25f-pp6r/GHSA-4f8x-f25f-pp6r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4f8x-f25f-pp6r", + "modified": "2025-04-08T18:34:57Z", + "published": "2025-04-08T18:34:57Z", + "aliases": [ + "CVE-2025-29809" + ], + "details": "Insecure storage of sensitive information in Windows Kerberos allows an authorized attacker to bypass a security feature locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29809" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29809" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-922" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4j9p-mgjx-whjq/GHSA-4j9p-mgjx-whjq.json b/advisories/unreviewed/2025/04/GHSA-4j9p-mgjx-whjq/GHSA-4j9p-mgjx-whjq.json new file mode 100644 index 00000000000..7835f5782b4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4j9p-mgjx-whjq/GHSA-4j9p-mgjx-whjq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4j9p-mgjx-whjq", + "modified": "2025-04-08T18:34:49Z", + "published": "2025-04-08T18:34:49Z", + "aliases": [ + "CVE-2025-26688" + ], + "details": "Stack-based buffer overflow in Microsoft Virtual Hard Drive allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26688" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26688" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4x7q-6v7j-m3g9/GHSA-4x7q-6v7j-m3g9.json b/advisories/unreviewed/2025/04/GHSA-4x7q-6v7j-m3g9/GHSA-4x7q-6v7j-m3g9.json new file mode 100644 index 00000000000..e56db9f5c41 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4x7q-6v7j-m3g9/GHSA-4x7q-6v7j-m3g9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4x7q-6v7j-m3g9", + "modified": "2025-04-08T18:34:50Z", + "published": "2025-04-08T18:34:50Z", + "aliases": [ + "CVE-2025-27476" + ], + "details": "Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27476" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27476" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-523j-7w3w-4hch/GHSA-523j-7w3w-4hch.json b/advisories/unreviewed/2025/04/GHSA-523j-7w3w-4hch/GHSA-523j-7w3w-4hch.json index 100fb3f602d..940e72a7e64 100644 --- a/advisories/unreviewed/2025/04/GHSA-523j-7w3w-4hch/GHSA-523j-7w3w-4hch.json +++ b/advisories/unreviewed/2025/04/GHSA-523j-7w3w-4hch/GHSA-523j-7w3w-4hch.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-58gq-7w24-hj3p/GHSA-58gq-7w24-hj3p.json b/advisories/unreviewed/2025/04/GHSA-58gq-7w24-hj3p/GHSA-58gq-7w24-hj3p.json new file mode 100644 index 00000000000..fc1d01ab494 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-58gq-7w24-hj3p/GHSA-58gq-7w24-hj3p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-58gq-7w24-hj3p", + "modified": "2025-04-08T18:34:49Z", + "published": "2025-04-08T18:34:49Z", + "aliases": [ + "CVE-2025-27193" + ], + "details": "Bridge versions 14.1.5, 15.0.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27193" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/bridge/apsb25-25.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-59vw-wx25-6mxm/GHSA-59vw-wx25-6mxm.json b/advisories/unreviewed/2025/04/GHSA-59vw-wx25-6mxm/GHSA-59vw-wx25-6mxm.json new file mode 100644 index 00000000000..bb69fcf76eb --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-59vw-wx25-6mxm/GHSA-59vw-wx25-6mxm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-59vw-wx25-6mxm", + "modified": "2025-04-08T18:34:49Z", + "published": "2025-04-08T18:34:49Z", + "aliases": [ + "CVE-2025-27194" + ], + "details": "Media Encoder versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27194" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/media-encoder/apsb25-24.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5px6-qr34-v59r/GHSA-5px6-qr34-v59r.json b/advisories/unreviewed/2025/04/GHSA-5px6-qr34-v59r/GHSA-5px6-qr34-v59r.json index b3b848ffec3..0e587bf0c46 100644 --- a/advisories/unreviewed/2025/04/GHSA-5px6-qr34-v59r/GHSA-5px6-qr34-v59r.json +++ b/advisories/unreviewed/2025/04/GHSA-5px6-qr34-v59r/GHSA-5px6-qr34-v59r.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-5v5h-mr5g-h898/GHSA-5v5h-mr5g-h898.json b/advisories/unreviewed/2025/04/GHSA-5v5h-mr5g-h898/GHSA-5v5h-mr5g-h898.json new file mode 100644 index 00000000000..41e794bef25 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5v5h-mr5g-h898/GHSA-5v5h-mr5g-h898.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5v5h-mr5g-h898", + "modified": "2025-04-08T18:34:50Z", + "published": "2025-04-08T18:34:50Z", + "aliases": [ + "CVE-2025-27479" + ], + "details": "Insufficient resource pool in Windows Kerberos allows an unauthorized attacker to deny service over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27479" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27479" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-410" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5vwc-px2m-7jxg/GHSA-5vwc-px2m-7jxg.json b/advisories/unreviewed/2025/04/GHSA-5vwc-px2m-7jxg/GHSA-5vwc-px2m-7jxg.json new file mode 100644 index 00000000000..4f730fdfe20 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5vwc-px2m-7jxg/GHSA-5vwc-px2m-7jxg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5vwc-px2m-7jxg", + "modified": "2025-04-08T18:34:56Z", + "published": "2025-04-08T18:34:56Z", + "aliases": [ + "CVE-2025-27749" + ], + "details": "Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27749" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27749" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5xm9-x7x4-4j5x/GHSA-5xm9-x7x4-4j5x.json b/advisories/unreviewed/2025/04/GHSA-5xm9-x7x4-4j5x/GHSA-5xm9-x7x4-4j5x.json new file mode 100644 index 00000000000..cf99efccfdf --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5xm9-x7x4-4j5x/GHSA-5xm9-x7x4-4j5x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5xm9-x7x4-4j5x", + "modified": "2025-04-08T18:34:43Z", + "published": "2025-04-08T18:34:43Z", + "aliases": [ + "CVE-2024-52981" + ], + "details": "An issue was discovered in Elasticsearch, where a large recursion using the Well-KnownText formatted string with nested GeometryCollection objects could cause a stackoverflow.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52981" + }, + { + "type": "WEB", + "url": "https://discuss.elastic.co/t/elasticsearch-7-17-24-and-8-15-1-security-update-esa-2024-37/376924" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T17:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5xwr-vwvm-vhh2/GHSA-5xwr-vwvm-vhh2.json b/advisories/unreviewed/2025/04/GHSA-5xwr-vwvm-vhh2/GHSA-5xwr-vwvm-vhh2.json new file mode 100644 index 00000000000..39e23eca672 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5xwr-vwvm-vhh2/GHSA-5xwr-vwvm-vhh2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5xwr-vwvm-vhh2", + "modified": "2025-04-08T18:34:42Z", + "published": "2025-04-08T18:34:42Z", + "aliases": [ + "CVE-2025-3287" + ], + "details": "A local code execution vulnerability exists in the Rockwell Automation Arena® due to a stack-based memory buffer overflow. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerability a legitimate user must open a malicious DOE file.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3287" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1726.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6423-85cc-8gf6/GHSA-6423-85cc-8gf6.json b/advisories/unreviewed/2025/04/GHSA-6423-85cc-8gf6/GHSA-6423-85cc-8gf6.json new file mode 100644 index 00000000000..4d1dee757e0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6423-85cc-8gf6/GHSA-6423-85cc-8gf6.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6423-85cc-8gf6", + "modified": "2025-04-08T18:34:43Z", + "published": "2025-04-08T18:34:43Z", + "aliases": [ + "CVE-2025-25227" + ], + "details": "Insufficient state checks lead to a vector that allows to bypass 2FA checks.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25227" + }, + { + "type": "WEB", + "url": "https://developer.joomla.org/security-centre/964-20250402-core-mfa-authentication-bypass.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T17:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6fgm-cc65-9jj3/GHSA-6fgm-cc65-9jj3.json b/advisories/unreviewed/2025/04/GHSA-6fgm-cc65-9jj3/GHSA-6fgm-cc65-9jj3.json new file mode 100644 index 00000000000..96ae89e0f8a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6fgm-cc65-9jj3/GHSA-6fgm-cc65-9jj3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6fgm-cc65-9jj3", + "modified": "2025-04-08T18:34:46Z", + "published": "2025-04-08T18:34:46Z", + "aliases": [ + "CVE-2025-26666" + ], + "details": "Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26666" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26666" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6hhr-6xwm-4f6j/GHSA-6hhr-6xwm-4f6j.json b/advisories/unreviewed/2025/04/GHSA-6hhr-6xwm-4f6j/GHSA-6hhr-6xwm-4f6j.json new file mode 100644 index 00000000000..bbd7a92a7eb --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6hhr-6xwm-4f6j/GHSA-6hhr-6xwm-4f6j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6hhr-6xwm-4f6j", + "modified": "2025-04-08T18:34:57Z", + "published": "2025-04-08T18:34:57Z", + "aliases": [ + "CVE-2025-29810" + ], + "details": "Improper access control in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29810" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29810" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6mpr-rpj5-q557/GHSA-6mpr-rpj5-q557.json b/advisories/unreviewed/2025/04/GHSA-6mpr-rpj5-q557/GHSA-6mpr-rpj5-q557.json new file mode 100644 index 00000000000..0bfff94a849 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6mpr-rpj5-q557/GHSA-6mpr-rpj5-q557.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6mpr-rpj5-q557", + "modified": "2025-04-08T18:34:51Z", + "published": "2025-04-08T18:34:51Z", + "aliases": [ + "CVE-2025-27484" + ], + "details": "Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27484" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27484" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-591" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6v62-cvf7-mpv3/GHSA-6v62-cvf7-mpv3.json b/advisories/unreviewed/2025/04/GHSA-6v62-cvf7-mpv3/GHSA-6v62-cvf7-mpv3.json new file mode 100644 index 00000000000..454a0e1de82 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6v62-cvf7-mpv3/GHSA-6v62-cvf7-mpv3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6v62-cvf7-mpv3", + "modified": "2025-04-08T18:34:57Z", + "published": "2025-04-08T18:34:56Z", + "aliases": [ + "CVE-2025-29808" + ], + "details": "Use of a cryptographic primitive with a risky implementation in Windows Cryptographic Services allows an authorized attacker to disclose information locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29808" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29808" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1240" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6vg9-pg49-5fg4/GHSA-6vg9-pg49-5fg4.json b/advisories/unreviewed/2025/04/GHSA-6vg9-pg49-5fg4/GHSA-6vg9-pg49-5fg4.json new file mode 100644 index 00000000000..b67dc7a2154 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6vg9-pg49-5fg4/GHSA-6vg9-pg49-5fg4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6vg9-pg49-5fg4", + "modified": "2025-04-08T18:34:55Z", + "published": "2025-04-08T18:34:55Z", + "aliases": [ + "CVE-2025-27743" + ], + "details": "Untrusted search path in System Center allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27743" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27743" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-426" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-74mq-6c57-fxpx/GHSA-74mq-6c57-fxpx.json b/advisories/unreviewed/2025/04/GHSA-74mq-6c57-fxpx/GHSA-74mq-6c57-fxpx.json new file mode 100644 index 00000000000..246ad29aff8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-74mq-6c57-fxpx/GHSA-74mq-6c57-fxpx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-74mq-6c57-fxpx", + "modified": "2025-04-08T18:34:57Z", + "published": "2025-04-08T18:34:57Z", + "aliases": [ + "CVE-2025-29824" + ], + "details": "Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29824" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29824" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-76h8-9q54-37cc/GHSA-76h8-9q54-37cc.json b/advisories/unreviewed/2025/04/GHSA-76h8-9q54-37cc/GHSA-76h8-9q54-37cc.json new file mode 100644 index 00000000000..acc85f3816d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-76h8-9q54-37cc/GHSA-76h8-9q54-37cc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-76h8-9q54-37cc", + "modified": "2025-04-08T18:34:45Z", + "published": "2025-04-08T18:34:45Z", + "aliases": [ + "CVE-2025-26637" + ], + "details": "Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26637" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26637" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-693" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-76qh-8gv2-726j/GHSA-76qh-8gv2-726j.json b/advisories/unreviewed/2025/04/GHSA-76qh-8gv2-726j/GHSA-76qh-8gv2-726j.json new file mode 100644 index 00000000000..23d9d729a89 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-76qh-8gv2-726j/GHSA-76qh-8gv2-726j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-76qh-8gv2-726j", + "modified": "2025-04-08T18:34:42Z", + "published": "2025-04-08T18:34:42Z", + "aliases": [ + "CVE-2025-3286" + ], + "details": "A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data.  If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerability a legitimate user must open a malicious DOE file.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3286" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1726.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7883-gj3f-26q9/GHSA-7883-gj3f-26q9.json b/advisories/unreviewed/2025/04/GHSA-7883-gj3f-26q9/GHSA-7883-gj3f-26q9.json new file mode 100644 index 00000000000..860b8d38993 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7883-gj3f-26q9/GHSA-7883-gj3f-26q9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7883-gj3f-26q9", + "modified": "2025-04-08T18:34:57Z", + "published": "2025-04-08T18:34:57Z", + "aliases": [ + "CVE-2025-29823" + ], + "details": "Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29823" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29823" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-79xr-cjjw-p6f2/GHSA-79xr-cjjw-p6f2.json b/advisories/unreviewed/2025/04/GHSA-79xr-cjjw-p6f2/GHSA-79xr-cjjw-p6f2.json new file mode 100644 index 00000000000..7c17ed90af2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-79xr-cjjw-p6f2/GHSA-79xr-cjjw-p6f2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-79xr-cjjw-p6f2", + "modified": "2025-04-08T18:34:50Z", + "published": "2025-04-08T18:34:50Z", + "aliases": [ + "CVE-2025-27480" + ], + "details": "Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27480" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27480" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7fqc-4xq7-ghg5/GHSA-7fqc-4xq7-ghg5.json b/advisories/unreviewed/2025/04/GHSA-7fqc-4xq7-ghg5/GHSA-7fqc-4xq7-ghg5.json new file mode 100644 index 00000000000..36880305232 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7fqc-4xq7-ghg5/GHSA-7fqc-4xq7-ghg5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7fqc-4xq7-ghg5", + "modified": "2025-04-08T18:34:44Z", + "published": "2025-04-08T18:34:44Z", + "aliases": [ + "CVE-2025-21174" + ], + "details": "Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21174" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21174" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7px8-2cr8-7p32/GHSA-7px8-2cr8-7p32.json b/advisories/unreviewed/2025/04/GHSA-7px8-2cr8-7p32/GHSA-7px8-2cr8-7p32.json new file mode 100644 index 00000000000..66a9e84c779 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7px8-2cr8-7p32/GHSA-7px8-2cr8-7p32.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7px8-2cr8-7p32", + "modified": "2025-04-08T18:34:55Z", + "published": "2025-04-08T18:34:55Z", + "aliases": [ + "CVE-2025-27744" + ], + "details": "Improper access control in Microsoft Office allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27744" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27744" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7q5w-7fpv-35wj/GHSA-7q5w-7fpv-35wj.json b/advisories/unreviewed/2025/04/GHSA-7q5w-7fpv-35wj/GHSA-7q5w-7fpv-35wj.json new file mode 100644 index 00000000000..4208014cd37 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7q5w-7fpv-35wj/GHSA-7q5w-7fpv-35wj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7q5w-7fpv-35wj", + "modified": "2025-04-08T18:34:55Z", + "published": "2025-04-08T18:34:55Z", + "aliases": [ + "CVE-2025-27739" + ], + "details": "Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27739" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27739" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-822" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7qv7-c4h7-rw9m/GHSA-7qv7-c4h7-rw9m.json b/advisories/unreviewed/2025/04/GHSA-7qv7-c4h7-rw9m/GHSA-7qv7-c4h7-rw9m.json new file mode 100644 index 00000000000..1cd1f32e190 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7qv7-c4h7-rw9m/GHSA-7qv7-c4h7-rw9m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7qv7-c4h7-rw9m", + "modified": "2025-04-08T18:34:52Z", + "published": "2025-04-08T18:34:52Z", + "aliases": [ + "CVE-2025-27732" + ], + "details": "Sensitive data storage in improperly locked memory in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27732" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27732" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-591" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7r63-qvqc-2fch/GHSA-7r63-qvqc-2fch.json b/advisories/unreviewed/2025/04/GHSA-7r63-qvqc-2fch/GHSA-7r63-qvqc-2fch.json new file mode 100644 index 00000000000..3f7fc846427 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7r63-qvqc-2fch/GHSA-7r63-qvqc-2fch.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7r63-qvqc-2fch", + "modified": "2025-04-08T18:34:43Z", + "published": "2025-04-08T18:34:43Z", + "aliases": [ + "CVE-2025-32279" + ], + "details": "Missing Authorization vulnerability in Shahjada Live Forms. This issue affects Live Forms: from n/a through 4.8.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32279" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/liveforms/vulnerability/wordpress-live-forms-plugin-4-8-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T17:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7wj9-rggf-4prj/GHSA-7wj9-rggf-4prj.json b/advisories/unreviewed/2025/04/GHSA-7wj9-rggf-4prj/GHSA-7wj9-rggf-4prj.json new file mode 100644 index 00000000000..34687af6ef3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7wj9-rggf-4prj/GHSA-7wj9-rggf-4prj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7wj9-rggf-4prj", + "modified": "2025-04-08T18:34:43Z", + "published": "2025-04-08T18:34:43Z", + "aliases": [ + "CVE-2025-32164" + ], + "details": "Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in maennchen1.de m1.DownloadList. This issue affects m1.DownloadList: from n/a through 0.21.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32164" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/m1downloadlist/vulnerability/wordpress-m1-downloadlist-plugin-0-21-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T17:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-82xw-6f7x-r595/GHSA-82xw-6f7x-r595.json b/advisories/unreviewed/2025/04/GHSA-82xw-6f7x-r595/GHSA-82xw-6f7x-r595.json new file mode 100644 index 00000000000..bf8a1dc38e2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-82xw-6f7x-r595/GHSA-82xw-6f7x-r595.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-82xw-6f7x-r595", + "modified": "2025-04-08T18:34:51Z", + "published": "2025-04-08T18:34:51Z", + "aliases": [ + "CVE-2025-27489" + ], + "details": "Improper input validation in Azure Local allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27489" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27489" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8844-88f7-3mwf/GHSA-8844-88f7-3mwf.json b/advisories/unreviewed/2025/04/GHSA-8844-88f7-3mwf/GHSA-8844-88f7-3mwf.json new file mode 100644 index 00000000000..7a3cb7b30bd --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8844-88f7-3mwf/GHSA-8844-88f7-3mwf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8844-88f7-3mwf", + "modified": "2025-04-08T18:34:50Z", + "published": "2025-04-08T18:34:50Z", + "aliases": [ + "CVE-2025-27477" + ], + "details": "Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27477" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27477" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-89pp-mprf-p328/GHSA-89pp-mprf-p328.json b/advisories/unreviewed/2025/04/GHSA-89pp-mprf-p328/GHSA-89pp-mprf-p328.json new file mode 100644 index 00000000000..ee9916d6d5b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-89pp-mprf-p328/GHSA-89pp-mprf-p328.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-89pp-mprf-p328", + "modified": "2025-04-08T18:34:47Z", + "published": "2025-04-08T18:34:47Z", + "aliases": [ + "CVE-2025-26676" + ], + "details": "Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26676" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26676" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8h2h-4x77-6crv/GHSA-8h2h-4x77-6crv.json b/advisories/unreviewed/2025/04/GHSA-8h2h-4x77-6crv/GHSA-8h2h-4x77-6crv.json new file mode 100644 index 00000000000..6598f58af66 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8h2h-4x77-6crv/GHSA-8h2h-4x77-6crv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8h2h-4x77-6crv", + "modified": "2025-04-08T18:34:42Z", + "published": "2025-04-08T18:34:42Z", + "aliases": [ + "CVE-2025-2293" + ], + "details": "A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to write outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data.  If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerability a legitimate user must open a malicious DOE file.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2293" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1726.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8vjw-ghh4-xxg8/GHSA-8vjw-ghh4-xxg8.json b/advisories/unreviewed/2025/04/GHSA-8vjw-ghh4-xxg8/GHSA-8vjw-ghh4-xxg8.json new file mode 100644 index 00000000000..d39e0be2d84 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8vjw-ghh4-xxg8/GHSA-8vjw-ghh4-xxg8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8vjw-ghh4-xxg8", + "modified": "2025-04-08T18:34:41Z", + "published": "2025-04-08T18:34:41Z", + "aliases": [ + "CVE-2025-27078" + ], + "details": "A vulnerability in a system binary of AOS-8 Instant and AOS-10 AP could allow an authenticated remote attacker to inject commands into the underlying operating system while using the CLI. Successful exploitation could lead to complete system compromise.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27078" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04844en_us&docLocale=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8wgx-9672-jj5j/GHSA-8wgx-9672-jj5j.json b/advisories/unreviewed/2025/04/GHSA-8wgx-9672-jj5j/GHSA-8wgx-9672-jj5j.json new file mode 100644 index 00000000000..df6adb3e198 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8wgx-9672-jj5j/GHSA-8wgx-9672-jj5j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8wgx-9672-jj5j", + "modified": "2025-04-08T18:34:46Z", + "published": "2025-04-08T18:34:46Z", + "aliases": [ + "CVE-2025-26664" + ], + "details": "Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26664" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26664" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-923v-g26h-29fj/GHSA-923v-g26h-29fj.json b/advisories/unreviewed/2025/04/GHSA-923v-g26h-29fj/GHSA-923v-g26h-29fj.json new file mode 100644 index 00000000000..45274c9a949 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-923v-g26h-29fj/GHSA-923v-g26h-29fj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-923v-g26h-29fj", + "modified": "2025-04-08T18:34:46Z", + "published": "2025-04-08T18:34:46Z", + "aliases": [ + "CVE-2025-26649" + ], + "details": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Secure Channel allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26649" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26649" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-944c-wq2v-7wrg/GHSA-944c-wq2v-7wrg.json b/advisories/unreviewed/2025/04/GHSA-944c-wq2v-7wrg/GHSA-944c-wq2v-7wrg.json new file mode 100644 index 00000000000..b6f19c2e9c5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-944c-wq2v-7wrg/GHSA-944c-wq2v-7wrg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-944c-wq2v-7wrg", + "modified": "2025-04-08T18:34:43Z", + "published": "2025-04-08T18:34:43Z", + "aliases": [ + "CVE-2025-32211" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Broadstreet Broadstreet allows Stored XSS. This issue affects Broadstreet: from n/a through 1.51.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32211" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/broadstreet/vulnerability/wordpress-broadstreet-plugin-1-51-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T17:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-959p-rfmc-j2w3/GHSA-959p-rfmc-j2w3.json b/advisories/unreviewed/2025/04/GHSA-959p-rfmc-j2w3/GHSA-959p-rfmc-j2w3.json new file mode 100644 index 00000000000..c627ecf8da0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-959p-rfmc-j2w3/GHSA-959p-rfmc-j2w3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-959p-rfmc-j2w3", + "modified": "2025-04-08T18:34:45Z", + "published": "2025-04-08T18:34:45Z", + "aliases": [ + "CVE-2025-26640" + ], + "details": "Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26640" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26640" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-415" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-95rc-q9jr-6jhg/GHSA-95rc-q9jr-6jhg.json b/advisories/unreviewed/2025/04/GHSA-95rc-q9jr-6jhg/GHSA-95rc-q9jr-6jhg.json new file mode 100644 index 00000000000..32c07ea4520 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-95rc-q9jr-6jhg/GHSA-95rc-q9jr-6jhg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-95rc-q9jr-6jhg", + "modified": "2025-04-08T18:34:42Z", + "published": "2025-04-08T18:34:42Z", + "aliases": [ + "CVE-2024-52974" + ], + "details": "An issue has been identified where a specially crafted request sent to an Observability API could cause the kibana server to crash.\n\nA successful attack requires a malicious user to have read permissions for Observability assigned to them.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52974" + }, + { + "type": "WEB", + "url": "https://discuss.elastic.co/t/kibana-7-17-23-and-8-15-1-security-update-esa-2024-36/376923" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T17:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-96vc-522p-f5f2/GHSA-96vc-522p-f5f2.json b/advisories/unreviewed/2025/04/GHSA-96vc-522p-f5f2/GHSA-96vc-522p-f5f2.json new file mode 100644 index 00000000000..cd89838af3b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-96vc-522p-f5f2/GHSA-96vc-522p-f5f2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-96vc-522p-f5f2", + "modified": "2025-04-08T18:34:45Z", + "published": "2025-04-08T18:34:45Z", + "aliases": [ + "CVE-2025-25002" + ], + "details": "Insertion of sensitive information into log file in Azure Local Cluster allows an authorized attacker to disclose information over an adjacent network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25002" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-25002" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9c5m-4mvh-2p3v/GHSA-9c5m-4mvh-2p3v.json b/advisories/unreviewed/2025/04/GHSA-9c5m-4mvh-2p3v/GHSA-9c5m-4mvh-2p3v.json new file mode 100644 index 00000000000..6fb7660f0e3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9c5m-4mvh-2p3v/GHSA-9c5m-4mvh-2p3v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9c5m-4mvh-2p3v", + "modified": "2025-04-08T18:34:48Z", + "published": "2025-04-08T18:34:48Z", + "aliases": [ + "CVE-2025-26681" + ], + "details": "Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26681" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26681" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9hqh-j935-cc49/GHSA-9hqh-j935-cc49.json b/advisories/unreviewed/2025/04/GHSA-9hqh-j935-cc49/GHSA-9hqh-j935-cc49.json new file mode 100644 index 00000000000..50d6ed60a43 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9hqh-j935-cc49/GHSA-9hqh-j935-cc49.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9hqh-j935-cc49", + "modified": "2025-04-08T18:34:41Z", + "published": "2025-04-08T18:34:41Z", + "aliases": [ + "CVE-2025-2285" + ], + "details": "A local code execution vulnerability exists in the Rockwell Automation Arena®  due to an uninitialized pointer. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerability a legitimate user must open a malicious DOE file.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2285" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1726.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-457" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9mm4-w3m4-jvj3/GHSA-9mm4-w3m4-jvj3.json b/advisories/unreviewed/2025/04/GHSA-9mm4-w3m4-jvj3/GHSA-9mm4-w3m4-jvj3.json new file mode 100644 index 00000000000..c7378d7ed50 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9mm4-w3m4-jvj3/GHSA-9mm4-w3m4-jvj3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9mm4-w3m4-jvj3", + "modified": "2025-04-08T18:34:49Z", + "published": "2025-04-08T18:34:49Z", + "aliases": [ + "CVE-2025-27187" + ], + "details": "After Effects versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27187" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/after_effects/apsb25-23.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9qjc-6fwg-p54r/GHSA-9qjc-6fwg-p54r.json b/advisories/unreviewed/2025/04/GHSA-9qjc-6fwg-p54r/GHSA-9qjc-6fwg-p54r.json new file mode 100644 index 00000000000..e0ce6023bf3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9qjc-6fwg-p54r/GHSA-9qjc-6fwg-p54r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qjc-6fwg-p54r", + "modified": "2025-04-08T18:34:52Z", + "published": "2025-04-08T18:34:52Z", + "aliases": [ + "CVE-2025-27729" + ], + "details": "Use after free in Windows Shell allows an unauthorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27729" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27729" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9qpr-rvwc-j2wc/GHSA-9qpr-rvwc-j2wc.json b/advisories/unreviewed/2025/04/GHSA-9qpr-rvwc-j2wc/GHSA-9qpr-rvwc-j2wc.json new file mode 100644 index 00000000000..5050d221e55 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9qpr-rvwc-j2wc/GHSA-9qpr-rvwc-j2wc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qpr-rvwc-j2wc", + "modified": "2025-04-08T18:34:44Z", + "published": "2025-04-08T18:34:44Z", + "aliases": [ + "CVE-2025-21221" + ], + "details": "Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21221" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21221" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c3xg-4h7v-p83w/GHSA-c3xg-4h7v-p83w.json b/advisories/unreviewed/2025/04/GHSA-c3xg-4h7v-p83w/GHSA-c3xg-4h7v-p83w.json new file mode 100644 index 00000000000..d040d9a1468 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c3xg-4h7v-p83w/GHSA-c3xg-4h7v-p83w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c3xg-4h7v-p83w", + "modified": "2025-04-08T18:34:52Z", + "published": "2025-04-08T18:34:52Z", + "aliases": [ + "CVE-2025-27731" + ], + "details": "Improper input validation in OpenSSH for Windows allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27731" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27731" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c4pv-p44r-9xfc/GHSA-c4pv-p44r-9xfc.json b/advisories/unreviewed/2025/04/GHSA-c4pv-p44r-9xfc/GHSA-c4pv-p44r-9xfc.json new file mode 100644 index 00000000000..6baf629f5cb --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c4pv-p44r-9xfc/GHSA-c4pv-p44r-9xfc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c4pv-p44r-9xfc", + "modified": "2025-04-08T18:34:46Z", + "published": "2025-04-08T18:34:46Z", + "aliases": [ + "CVE-2025-26647" + ], + "details": "Improper input validation in Windows Kerberos allows an unauthorized attacker to elevate privileges over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26647" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26647" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c538-wc2q-4rmx/GHSA-c538-wc2q-4rmx.json b/advisories/unreviewed/2025/04/GHSA-c538-wc2q-4rmx/GHSA-c538-wc2q-4rmx.json new file mode 100644 index 00000000000..c056560f6c1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c538-wc2q-4rmx/GHSA-c538-wc2q-4rmx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c538-wc2q-4rmx", + "modified": "2025-04-08T18:34:50Z", + "published": "2025-04-08T18:34:50Z", + "aliases": [ + "CVE-2025-27472" + ], + "details": "Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27472" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27472" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-693" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c57f-m24w-hf5p/GHSA-c57f-m24w-hf5p.json b/advisories/unreviewed/2025/04/GHSA-c57f-m24w-hf5p/GHSA-c57f-m24w-hf5p.json index e3abb76531d..412e9df83fb 100644 --- a/advisories/unreviewed/2025/04/GHSA-c57f-m24w-hf5p/GHSA-c57f-m24w-hf5p.json +++ b/advisories/unreviewed/2025/04/GHSA-c57f-m24w-hf5p/GHSA-c57f-m24w-hf5p.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-c6h2-xp45-96cv/GHSA-c6h2-xp45-96cv.json b/advisories/unreviewed/2025/04/GHSA-c6h2-xp45-96cv/GHSA-c6h2-xp45-96cv.json new file mode 100644 index 00000000000..4ec955e65d0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c6h2-xp45-96cv/GHSA-c6h2-xp45-96cv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c6h2-xp45-96cv", + "modified": "2025-04-08T18:34:46Z", + "published": "2025-04-08T18:34:46Z", + "aliases": [ + "CVE-2025-26667" + ], + "details": "Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26667" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26667" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c8q9-g877-5qr3/GHSA-c8q9-g877-5qr3.json b/advisories/unreviewed/2025/04/GHSA-c8q9-g877-5qr3/GHSA-c8q9-g877-5qr3.json new file mode 100644 index 00000000000..9c3b7faa312 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c8q9-g877-5qr3/GHSA-c8q9-g877-5qr3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c8q9-g877-5qr3", + "modified": "2025-04-08T18:34:51Z", + "published": "2025-04-08T18:34:51Z", + "aliases": [ + "CVE-2025-27491" + ], + "details": "Use after free in Windows Hyper-V allows an authorized attacker to execute code over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27491" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27491" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-ccjx-w7qv-vvc6/GHSA-ccjx-w7qv-vvc6.json b/advisories/unreviewed/2025/04/GHSA-ccjx-w7qv-vvc6/GHSA-ccjx-w7qv-vvc6.json new file mode 100644 index 00000000000..ac30da38b6c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-ccjx-w7qv-vvc6/GHSA-ccjx-w7qv-vvc6.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ccjx-w7qv-vvc6", + "modified": "2025-04-08T18:34:42Z", + "published": "2025-04-08T18:34:42Z", + "aliases": [ + "CVE-2025-3289" + ], + "details": "A local code execution vulnerability exists in the Rockwell Automation Arena® due to a stack-based memory buffer overflow. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerability a legitimate user must open a malicious DOE file.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3289" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1726.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T16:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-ccvc-x2m3-pqg3/GHSA-ccvc-x2m3-pqg3.json b/advisories/unreviewed/2025/04/GHSA-ccvc-x2m3-pqg3/GHSA-ccvc-x2m3-pqg3.json new file mode 100644 index 00000000000..568a1b06afd --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-ccvc-x2m3-pqg3/GHSA-ccvc-x2m3-pqg3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ccvc-x2m3-pqg3", + "modified": "2025-04-08T18:34:42Z", + "published": "2025-04-08T18:34:42Z", + "aliases": [ + "CVE-2025-2829" + ], + "details": "A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to write outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data.  If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerability a legitimate user must open a malicious DOE file.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2829" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1726.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T16:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-ccx5-jh35-2p3c/GHSA-ccx5-jh35-2p3c.json b/advisories/unreviewed/2025/04/GHSA-ccx5-jh35-2p3c/GHSA-ccx5-jh35-2p3c.json new file mode 100644 index 00000000000..2d7993c21a5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-ccx5-jh35-2p3c/GHSA-ccx5-jh35-2p3c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ccx5-jh35-2p3c", + "modified": "2025-04-08T18:34:57Z", + "published": "2025-04-08T18:34:56Z", + "aliases": [ + "CVE-2025-29791" + ], + "details": "Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29791" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29791" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-843" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-ch4m-2996-7xpv/GHSA-ch4m-2996-7xpv.json b/advisories/unreviewed/2025/04/GHSA-ch4m-2996-7xpv/GHSA-ch4m-2996-7xpv.json index 90387ee4df8..53f48ea2d40 100644 --- a/advisories/unreviewed/2025/04/GHSA-ch4m-2996-7xpv/GHSA-ch4m-2996-7xpv.json +++ b/advisories/unreviewed/2025/04/GHSA-ch4m-2996-7xpv/GHSA-ch4m-2996-7xpv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ch4m-2996-7xpv", - "modified": "2025-04-07T21:32:06Z", + "modified": "2025-04-08T18:34:16Z", "published": "2025-04-07T15:31:10Z", "aliases": [ "CVE-2024-57835" diff --git a/advisories/unreviewed/2025/04/GHSA-cj54-rxfj-2qp3/GHSA-cj54-rxfj-2qp3.json b/advisories/unreviewed/2025/04/GHSA-cj54-rxfj-2qp3/GHSA-cj54-rxfj-2qp3.json new file mode 100644 index 00000000000..42168be1382 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cj54-rxfj-2qp3/GHSA-cj54-rxfj-2qp3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cj54-rxfj-2qp3", + "modified": "2025-04-08T18:34:50Z", + "published": "2025-04-08T18:34:50Z", + "aliases": [ + "CVE-2025-27205" + ], + "details": "Adobe Experience Manager Screens versions FP11.3 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. Exploitation of this issue requires user interaction in that a victim must open a malicious link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27205" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/aem-screens/apsb25-32.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cp6c-ff57-294g/GHSA-cp6c-ff57-294g.json b/advisories/unreviewed/2025/04/GHSA-cp6c-ff57-294g/GHSA-cp6c-ff57-294g.json new file mode 100644 index 00000000000..4eefdaafcb8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cp6c-ff57-294g/GHSA-cp6c-ff57-294g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cp6c-ff57-294g", + "modified": "2025-04-08T18:34:45Z", + "published": "2025-04-08T18:34:45Z", + "aliases": [ + "CVE-2025-26635" + ], + "details": "Weak authentication in Windows Hello allows an authorized attacker to bypass a security feature over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26635" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26635" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1390" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cppr-qmr8-4r9j/GHSA-cppr-qmr8-4r9j.json b/advisories/unreviewed/2025/04/GHSA-cppr-qmr8-4r9j/GHSA-cppr-qmr8-4r9j.json new file mode 100644 index 00000000000..9c0647ed3ae --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cppr-qmr8-4r9j/GHSA-cppr-qmr8-4r9j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cppr-qmr8-4r9j", + "modified": "2025-04-08T18:34:43Z", + "published": "2025-04-08T18:34:43Z", + "aliases": [ + "CVE-2025-30670" + ], + "details": "Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30670" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-25015" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T17:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cv6v-q3qg-36vr/GHSA-cv6v-q3qg-36vr.json b/advisories/unreviewed/2025/04/GHSA-cv6v-q3qg-36vr/GHSA-cv6v-q3qg-36vr.json new file mode 100644 index 00000000000..a13a9619643 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cv6v-q3qg-36vr/GHSA-cv6v-q3qg-36vr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cv6v-q3qg-36vr", + "modified": "2025-04-08T18:34:52Z", + "published": "2025-04-08T18:34:52Z", + "aliases": [ + "CVE-2025-27730" + ], + "details": "Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27730" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27730" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-415" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cvhq-cvvf-jw9r/GHSA-cvhq-cvvf-jw9r.json b/advisories/unreviewed/2025/04/GHSA-cvhq-cvvf-jw9r/GHSA-cvhq-cvvf-jw9r.json new file mode 100644 index 00000000000..a5647c245a4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cvhq-cvvf-jw9r/GHSA-cvhq-cvvf-jw9r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cvhq-cvvf-jw9r", + "modified": "2025-04-08T18:34:47Z", + "published": "2025-04-08T18:34:47Z", + "aliases": [ + "CVE-2025-26678" + ], + "details": "Improper access control in Windows Defender Application Control (WDAC) allows an unauthorized attacker to bypass a security feature locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26678" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26678" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cw83-5fh9-w7xx/GHSA-cw83-5fh9-w7xx.json b/advisories/unreviewed/2025/04/GHSA-cw83-5fh9-w7xx/GHSA-cw83-5fh9-w7xx.json new file mode 100644 index 00000000000..d84da3f0a71 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cw83-5fh9-w7xx/GHSA-cw83-5fh9-w7xx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cw83-5fh9-w7xx", + "modified": "2025-04-08T18:34:49Z", + "published": "2025-04-08T18:34:49Z", + "aliases": [ + "CVE-2025-27196" + ], + "details": "Premiere Pro versions 25.1, 24.6.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27196" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/premiere_pro/apsb25-28.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cwwx-grqm-7hjh/GHSA-cwwx-grqm-7hjh.json b/advisories/unreviewed/2025/04/GHSA-cwwx-grqm-7hjh/GHSA-cwwx-grqm-7hjh.json new file mode 100644 index 00000000000..26ce023b78c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cwwx-grqm-7hjh/GHSA-cwwx-grqm-7hjh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cwwx-grqm-7hjh", + "modified": "2025-04-08T18:34:46Z", + "published": "2025-04-08T18:34:46Z", + "aliases": [ + "CVE-2025-26663" + ], + "details": "Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26663" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26663" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f4pv-mh4w-365x/GHSA-f4pv-mh4w-365x.json b/advisories/unreviewed/2025/04/GHSA-f4pv-mh4w-365x/GHSA-f4pv-mh4w-365x.json new file mode 100644 index 00000000000..9fd52c316bc --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f4pv-mh4w-365x/GHSA-f4pv-mh4w-365x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f4pv-mh4w-365x", + "modified": "2025-04-08T18:34:45Z", + "published": "2025-04-08T18:34:45Z", + "aliases": [ + "CVE-2025-24074" + ], + "details": "Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24074" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24074" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f5m3-pwfc-3wq8/GHSA-f5m3-pwfc-3wq8.json b/advisories/unreviewed/2025/04/GHSA-f5m3-pwfc-3wq8/GHSA-f5m3-pwfc-3wq8.json new file mode 100644 index 00000000000..8ee01ae7435 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f5m3-pwfc-3wq8/GHSA-f5m3-pwfc-3wq8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f5m3-pwfc-3wq8", + "modified": "2025-04-08T18:34:52Z", + "published": "2025-04-08T18:34:52Z", + "aliases": [ + "CVE-2025-27735" + ], + "details": "Insufficient verification of data authenticity in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27735" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27735" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-345" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f5p6-vmgq-f9qw/GHSA-f5p6-vmgq-f9qw.json b/advisories/unreviewed/2025/04/GHSA-f5p6-vmgq-f9qw/GHSA-f5p6-vmgq-f9qw.json new file mode 100644 index 00000000000..c2e3c72b684 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f5p6-vmgq-f9qw/GHSA-f5p6-vmgq-f9qw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f5p6-vmgq-f9qw", + "modified": "2025-04-08T18:34:56Z", + "published": "2025-04-08T18:34:56Z", + "aliases": [ + "CVE-2025-29792" + ], + "details": "Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29792" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29792" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f687-cpxh-93rh/GHSA-f687-cpxh-93rh.json b/advisories/unreviewed/2025/04/GHSA-f687-cpxh-93rh/GHSA-f687-cpxh-93rh.json new file mode 100644 index 00000000000..ebb743cc47e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f687-cpxh-93rh/GHSA-f687-cpxh-93rh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f687-cpxh-93rh", + "modified": "2025-04-08T18:34:57Z", + "published": "2025-04-08T18:34:57Z", + "aliases": [ + "CVE-2025-29811" + ], + "details": "Improper input validation in Windows Mobile Broadband allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29811" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29811" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f69r-g2v6-6r6h/GHSA-f69r-g2v6-6r6h.json b/advisories/unreviewed/2025/04/GHSA-f69r-g2v6-6r6h/GHSA-f69r-g2v6-6r6h.json new file mode 100644 index 00000000000..abda48c2178 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f69r-g2v6-6r6h/GHSA-f69r-g2v6-6r6h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f69r-g2v6-6r6h", + "modified": "2025-04-08T18:34:57Z", + "published": "2025-04-08T18:34:57Z", + "aliases": [ + "CVE-2025-29820" + ], + "details": "Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29820" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29820" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f6cf-jwhc-p8rr/GHSA-f6cf-jwhc-p8rr.json b/advisories/unreviewed/2025/04/GHSA-f6cf-jwhc-p8rr/GHSA-f6cf-jwhc-p8rr.json new file mode 100644 index 00000000000..80522a2119b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f6cf-jwhc-p8rr/GHSA-f6cf-jwhc-p8rr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f6cf-jwhc-p8rr", + "modified": "2025-04-08T18:34:45Z", + "published": "2025-04-08T18:34:45Z", + "aliases": [ + "CVE-2025-26628" + ], + "details": "Insufficiently protected credentials in Azure Local Cluster allows an authorized attacker to disclose information locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26628" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26628" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-522" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f777-q5j9-qjx5/GHSA-f777-q5j9-qjx5.json b/advisories/unreviewed/2025/04/GHSA-f777-q5j9-qjx5/GHSA-f777-q5j9-qjx5.json new file mode 100644 index 00000000000..5faf0a9fa6a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f777-q5j9-qjx5/GHSA-f777-q5j9-qjx5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f777-q5j9-qjx5", + "modified": "2025-04-08T18:34:47Z", + "published": "2025-04-08T18:34:47Z", + "aliases": [ + "CVE-2025-26670" + ], + "details": "Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26670" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26670" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f88r-vjvm-q77m/GHSA-f88r-vjvm-q77m.json b/advisories/unreviewed/2025/04/GHSA-f88r-vjvm-q77m/GHSA-f88r-vjvm-q77m.json new file mode 100644 index 00000000000..252d5042645 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f88r-vjvm-q77m/GHSA-f88r-vjvm-q77m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f88r-vjvm-q77m", + "modified": "2025-04-08T18:34:50Z", + "published": "2025-04-08T18:34:50Z", + "aliases": [ + "CVE-2025-27470" + ], + "details": "Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27470" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27470" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-ffww-3j7j-g93q/GHSA-ffww-3j7j-g93q.json b/advisories/unreviewed/2025/04/GHSA-ffww-3j7j-g93q/GHSA-ffww-3j7j-g93q.json new file mode 100644 index 00000000000..c3874eceb13 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-ffww-3j7j-g93q/GHSA-ffww-3j7j-g93q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ffww-3j7j-g93q", + "modified": "2025-04-08T18:34:57Z", + "published": "2025-04-08T18:34:57Z", + "aliases": [ + "CVE-2025-29822" + ], + "details": "Incomplete list of disallowed inputs in Microsoft Office OneNote allows an unauthorized attacker to bypass a security feature locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29822" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29822" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-184" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fg42-rvmc-ccpv/GHSA-fg42-rvmc-ccpv.json b/advisories/unreviewed/2025/04/GHSA-fg42-rvmc-ccpv/GHSA-fg42-rvmc-ccpv.json new file mode 100644 index 00000000000..69512d1006e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fg42-rvmc-ccpv/GHSA-fg42-rvmc-ccpv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fg42-rvmc-ccpv", + "modified": "2025-04-08T18:34:51Z", + "published": "2025-04-08T18:34:51Z", + "aliases": [ + "CVE-2025-27485" + ], + "details": "Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27485" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27485" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fh3v-p8r7-f9p8/GHSA-fh3v-p8r7-f9p8.json b/advisories/unreviewed/2025/04/GHSA-fh3v-p8r7-f9p8/GHSA-fh3v-p8r7-f9p8.json new file mode 100644 index 00000000000..276732687c9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fh3v-p8r7-f9p8/GHSA-fh3v-p8r7-f9p8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fh3v-p8r7-f9p8", + "modified": "2025-04-08T18:34:52Z", + "published": "2025-04-08T18:34:52Z", + "aliases": [ + "CVE-2025-27733" + ], + "details": "Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27733" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27733" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fhf5-q9qm-767w/GHSA-fhf5-q9qm-767w.json b/advisories/unreviewed/2025/04/GHSA-fhf5-q9qm-767w/GHSA-fhf5-q9qm-767w.json new file mode 100644 index 00000000000..a28b684b5b3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fhf5-q9qm-767w/GHSA-fhf5-q9qm-767w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fhf5-q9qm-767w", + "modified": "2025-04-08T18:34:51Z", + "published": "2025-04-08T18:34:51Z", + "aliases": [ + "CVE-2025-27490" + ], + "details": "Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27490" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27490" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fwcf-6vhv-fhqj/GHSA-fwcf-6vhv-fhqj.json b/advisories/unreviewed/2025/04/GHSA-fwcf-6vhv-fhqj/GHSA-fwcf-6vhv-fhqj.json new file mode 100644 index 00000000000..543160ef42e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fwcf-6vhv-fhqj/GHSA-fwcf-6vhv-fhqj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fwcf-6vhv-fhqj", + "modified": "2025-04-08T18:34:49Z", + "published": "2025-04-08T18:34:49Z", + "aliases": [ + "CVE-2025-27186" + ], + "details": "After Effects versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27186" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/after_effects/apsb25-23.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g3jg-gq9w-rmh8/GHSA-g3jg-gq9w-rmh8.json b/advisories/unreviewed/2025/04/GHSA-g3jg-gq9w-rmh8/GHSA-g3jg-gq9w-rmh8.json new file mode 100644 index 00000000000..c042f2abac7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g3jg-gq9w-rmh8/GHSA-g3jg-gq9w-rmh8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g3jg-gq9w-rmh8", + "modified": "2025-04-08T18:34:56Z", + "published": "2025-04-08T18:34:56Z", + "aliases": [ + "CVE-2025-27752" + ], + "details": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27752" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27752" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g453-6hhw-8qx3/GHSA-g453-6hhw-8qx3.json b/advisories/unreviewed/2025/04/GHSA-g453-6hhw-8qx3/GHSA-g453-6hhw-8qx3.json new file mode 100644 index 00000000000..618663871d8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g453-6hhw-8qx3/GHSA-g453-6hhw-8qx3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g453-6hhw-8qx3", + "modified": "2025-04-08T18:34:50Z", + "published": "2025-04-08T18:34:50Z", + "aliases": [ + "CVE-2025-27199" + ], + "details": "Animate versions 24.0.7, 23.0.10 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27199" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/animate/apsb25-31.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g954-x6px-fjvv/GHSA-g954-x6px-fjvv.json b/advisories/unreviewed/2025/04/GHSA-g954-x6px-fjvv/GHSA-g954-x6px-fjvv.json new file mode 100644 index 00000000000..854e63e0e7a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g954-x6px-fjvv/GHSA-g954-x6px-fjvv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g954-x6px-fjvv", + "modified": "2025-04-08T18:34:50Z", + "published": "2025-04-08T18:34:50Z", + "aliases": [ + "CVE-2025-27202" + ], + "details": "Animate versions 24.0.7, 23.0.10 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27202" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/animate/apsb25-31.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gf2r-7cq8-xww9/GHSA-gf2r-7cq8-xww9.json b/advisories/unreviewed/2025/04/GHSA-gf2r-7cq8-xww9/GHSA-gf2r-7cq8-xww9.json new file mode 100644 index 00000000000..ed1c403493a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gf2r-7cq8-xww9/GHSA-gf2r-7cq8-xww9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gf2r-7cq8-xww9", + "modified": "2025-04-08T18:34:49Z", + "published": "2025-04-08T18:34:49Z", + "aliases": [ + "CVE-2025-26682" + ], + "details": "Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26682" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26682" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-ggqx-jcf7-78x8/GHSA-ggqx-jcf7-78x8.json b/advisories/unreviewed/2025/04/GHSA-ggqx-jcf7-78x8/GHSA-ggqx-jcf7-78x8.json new file mode 100644 index 00000000000..6914599a849 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-ggqx-jcf7-78x8/GHSA-ggqx-jcf7-78x8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ggqx-jcf7-78x8", + "modified": "2025-04-08T18:34:49Z", + "published": "2025-04-08T18:34:49Z", + "aliases": [ + "CVE-2025-27195" + ], + "details": "Media Encoder versions 25.1, 24.6.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27195" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/media-encoder/apsb25-24.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-ghfh-p92w-j4mg/GHSA-ghfh-p92w-j4mg.json b/advisories/unreviewed/2025/04/GHSA-ghfh-p92w-j4mg/GHSA-ghfh-p92w-j4mg.json new file mode 100644 index 00000000000..3d8da4cc079 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-ghfh-p92w-j4mg/GHSA-ghfh-p92w-j4mg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ghfh-p92w-j4mg", + "modified": "2025-04-08T18:34:43Z", + "published": "2025-04-08T18:34:42Z", + "aliases": [ + "CVE-2024-52980" + ], + "details": "A flaw was discovered in Elasticsearch, where a large recursion using the innerForbidCircularReferences function of the PatternBank class could cause the Elasticsearch node to crash.\n\nA successful attack requires a malicious user to have read_pipeline Elasticsearch cluster privilege assigned to them.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52980" + }, + { + "type": "WEB", + "url": "https://discuss.elastic.co/t/elasticsearch-8-15-1-security-update-esa-2024-34/376919" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T17:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-ghmp-5866-2jgf/GHSA-ghmp-5866-2jgf.json b/advisories/unreviewed/2025/04/GHSA-ghmp-5866-2jgf/GHSA-ghmp-5866-2jgf.json new file mode 100644 index 00000000000..c336d10d58c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-ghmp-5866-2jgf/GHSA-ghmp-5866-2jgf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ghmp-5866-2jgf", + "modified": "2025-04-08T18:34:53Z", + "published": "2025-04-08T18:34:53Z", + "aliases": [ + "CVE-2025-27737" + ], + "details": "Improper input validation in Windows Security Zone Mapping allows an unauthorized attacker to bypass a security feature locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27737" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27737" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gjc7-752x-rr86/GHSA-gjc7-752x-rr86.json b/advisories/unreviewed/2025/04/GHSA-gjc7-752x-rr86/GHSA-gjc7-752x-rr86.json new file mode 100644 index 00000000000..3fe313f479e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gjc7-752x-rr86/GHSA-gjc7-752x-rr86.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gjc7-752x-rr86", + "modified": "2025-04-08T18:34:55Z", + "published": "2025-04-08T18:34:55Z", + "aliases": [ + "CVE-2025-27742" + ], + "details": "Out-of-bounds read in Windows NTFS allows an unauthorized attacker to disclose information locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27742" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27742" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gr4c-v8p7-98x2/GHSA-gr4c-v8p7-98x2.json b/advisories/unreviewed/2025/04/GHSA-gr4c-v8p7-98x2/GHSA-gr4c-v8p7-98x2.json new file mode 100644 index 00000000000..030923520e6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gr4c-v8p7-98x2/GHSA-gr4c-v8p7-98x2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gr4c-v8p7-98x2", + "modified": "2025-04-08T18:34:47Z", + "published": "2025-04-08T18:34:47Z", + "aliases": [ + "CVE-2025-26671" + ], + "details": "Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26671" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26671" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h78g-f5x3-jrm2/GHSA-h78g-f5x3-jrm2.json b/advisories/unreviewed/2025/04/GHSA-h78g-f5x3-jrm2/GHSA-h78g-f5x3-jrm2.json new file mode 100644 index 00000000000..0122e9b6d14 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-h78g-f5x3-jrm2/GHSA-h78g-f5x3-jrm2.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h78g-f5x3-jrm2", + "modified": "2025-04-08T18:34:43Z", + "published": "2025-04-08T18:34:43Z", + "aliases": [ + "CVE-2025-27082" + ], + "details": "Arbitrary File Write vulnerabilities exist in the web-based management interface of both the AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an Authenticated attacker to upload arbitrary files and execute arbitrary commands on the underlying host operating system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27082" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04845en_us&docLocale=en_US" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T17:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h78m-4g6h-334g/GHSA-h78m-4g6h-334g.json b/advisories/unreviewed/2025/04/GHSA-h78m-4g6h-334g/GHSA-h78m-4g6h-334g.json new file mode 100644 index 00000000000..41eeabdd40f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-h78m-4g6h-334g/GHSA-h78m-4g6h-334g.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h78m-4g6h-334g", + "modified": "2025-04-08T18:34:43Z", + "published": "2025-04-08T18:34:43Z", + "aliases": [ + "CVE-2025-27083" + ], + "details": "Authenticated command injection vulnerabilities exist in the AOS-10 GW and AOS-8 Controller/Mobility Conductor web-based management interface. Successful exploitation of these vulnerabilities allows an Authenticated attacker to execute arbitrary commands as a privileged user on the underlying operating system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27083" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04845en_us&docLocale=en_US" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T17:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h7rc-mcrm-p3mh/GHSA-h7rc-mcrm-p3mh.json b/advisories/unreviewed/2025/04/GHSA-h7rc-mcrm-p3mh/GHSA-h7rc-mcrm-p3mh.json new file mode 100644 index 00000000000..9cc19f3190a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-h7rc-mcrm-p3mh/GHSA-h7rc-mcrm-p3mh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h7rc-mcrm-p3mh", + "modified": "2025-04-08T18:34:56Z", + "published": "2025-04-08T18:34:56Z", + "aliases": [ + "CVE-2025-27746" + ], + "details": "Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27746" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27746" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h8h5-8pv5-88g9/GHSA-h8h5-8pv5-88g9.json b/advisories/unreviewed/2025/04/GHSA-h8h5-8pv5-88g9/GHSA-h8h5-8pv5-88g9.json new file mode 100644 index 00000000000..5e3e605d9c6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-h8h5-8pv5-88g9/GHSA-h8h5-8pv5-88g9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h8h5-8pv5-88g9", + "modified": "2025-04-08T18:34:50Z", + "published": "2025-04-08T18:34:50Z", + "aliases": [ + "CVE-2025-27483" + ], + "details": "Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27483" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27483" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h9r9-jmq5-x5wh/GHSA-h9r9-jmq5-x5wh.json b/advisories/unreviewed/2025/04/GHSA-h9r9-jmq5-x5wh/GHSA-h9r9-jmq5-x5wh.json new file mode 100644 index 00000000000..0584bb7f0db --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-h9r9-jmq5-x5wh/GHSA-h9r9-jmq5-x5wh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9r9-jmq5-x5wh", + "modified": "2025-04-08T18:34:49Z", + "published": "2025-04-08T18:34:49Z", + "aliases": [ + "CVE-2025-26686" + ], + "details": "Sensitive data storage in improperly locked memory in Windows TCP/IP allows an unauthorized attacker to execute code over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26686" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26686" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-591" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hgp6-f396-gg6v/GHSA-hgp6-f396-gg6v.json b/advisories/unreviewed/2025/04/GHSA-hgp6-f396-gg6v/GHSA-hgp6-f396-gg6v.json new file mode 100644 index 00000000000..52a9a77d8a1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hgp6-f396-gg6v/GHSA-hgp6-f396-gg6v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hgp6-f396-gg6v", + "modified": "2025-04-08T18:34:56Z", + "published": "2025-04-08T18:34:56Z", + "aliases": [ + "CVE-2025-29801" + ], + "details": "Incorrect default permissions in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29801" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29801" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hrxg-42v2-hfvm/GHSA-hrxg-42v2-hfvm.json b/advisories/unreviewed/2025/04/GHSA-hrxg-42v2-hfvm/GHSA-hrxg-42v2-hfvm.json new file mode 100644 index 00000000000..ab297a3c69a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hrxg-42v2-hfvm/GHSA-hrxg-42v2-hfvm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hrxg-42v2-hfvm", + "modified": "2025-04-08T18:34:55Z", + "published": "2025-04-08T18:34:55Z", + "aliases": [ + "CVE-2025-27745" + ], + "details": "Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27745" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27745" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hwrv-xj84-453c/GHSA-hwrv-xj84-453c.json b/advisories/unreviewed/2025/04/GHSA-hwrv-xj84-453c/GHSA-hwrv-xj84-453c.json new file mode 100644 index 00000000000..3de0f400325 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hwrv-xj84-453c/GHSA-hwrv-xj84-453c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwrv-xj84-453c", + "modified": "2025-04-08T18:34:50Z", + "published": "2025-04-08T18:34:50Z", + "aliases": [ + "CVE-2025-27201" + ], + "details": "Animate versions 24.0.7, 23.0.10 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27201" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/animate/apsb25-31.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j233-wqrg-q9v9/GHSA-j233-wqrg-q9v9.json b/advisories/unreviewed/2025/04/GHSA-j233-wqrg-q9v9/GHSA-j233-wqrg-q9v9.json new file mode 100644 index 00000000000..4dda9bb0b4f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j233-wqrg-q9v9/GHSA-j233-wqrg-q9v9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j233-wqrg-q9v9", + "modified": "2025-04-08T18:34:56Z", + "published": "2025-04-08T18:34:56Z", + "aliases": [ + "CVE-2025-27751" + ], + "details": "Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27751" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27751" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j5q7-6x8m-99jx/GHSA-j5q7-6x8m-99jx.json b/advisories/unreviewed/2025/04/GHSA-j5q7-6x8m-99jx/GHSA-j5q7-6x8m-99jx.json new file mode 100644 index 00000000000..120e91bef5c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j5q7-6x8m-99jx/GHSA-j5q7-6x8m-99jx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j5q7-6x8m-99jx", + "modified": "2025-04-08T18:34:50Z", + "published": "2025-04-08T18:34:50Z", + "aliases": [ + "CVE-2025-27198" + ], + "details": "Photoshop Desktop versions 25.12.1, 26.4.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27198" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/photoshop/apsb25-30.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j7wg-vqfq-fh3f/GHSA-j7wg-vqfq-fh3f.json b/advisories/unreviewed/2025/04/GHSA-j7wg-vqfq-fh3f/GHSA-j7wg-vqfq-fh3f.json new file mode 100644 index 00000000000..e9c4a04867f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j7wg-vqfq-fh3f/GHSA-j7wg-vqfq-fh3f.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j7wg-vqfq-fh3f", + "modified": "2025-04-08T18:34:43Z", + "published": "2025-04-08T18:34:43Z", + "aliases": [ + "CVE-2025-27085" + ], + "details": "Multiple vulnerabilities exist in the web-based management interface of AOS-10 GW and AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated, remote attacker to download arbitrary files from the filesystem of an affected device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27085" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04845en_us&docLocale=en_US" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T17:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j882-wwwr-7r6q/GHSA-j882-wwwr-7r6q.json b/advisories/unreviewed/2025/04/GHSA-j882-wwwr-7r6q/GHSA-j882-wwwr-7r6q.json index 43a760f61d9..432ab94328c 100644 --- a/advisories/unreviewed/2025/04/GHSA-j882-wwwr-7r6q/GHSA-j882-wwwr-7r6q.json +++ b/advisories/unreviewed/2025/04/GHSA-j882-wwwr-7r6q/GHSA-j882-wwwr-7r6q.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-662", "CWE-821" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/04/GHSA-j923-xmpp-p4g8/GHSA-j923-xmpp-p4g8.json b/advisories/unreviewed/2025/04/GHSA-j923-xmpp-p4g8/GHSA-j923-xmpp-p4g8.json new file mode 100644 index 00000000000..a1d6c94dac3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j923-xmpp-p4g8/GHSA-j923-xmpp-p4g8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j923-xmpp-p4g8", + "modified": "2025-04-08T18:34:56Z", + "published": "2025-04-08T18:34:56Z", + "aliases": [ + "CVE-2025-27750" + ], + "details": "Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27750" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27750" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jc9x-pxc5-cq7f/GHSA-jc9x-pxc5-cq7f.json b/advisories/unreviewed/2025/04/GHSA-jc9x-pxc5-cq7f/GHSA-jc9x-pxc5-cq7f.json new file mode 100644 index 00000000000..a20904681de --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jc9x-pxc5-cq7f/GHSA-jc9x-pxc5-cq7f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jc9x-pxc5-cq7f", + "modified": "2025-04-08T18:34:44Z", + "published": "2025-04-08T18:34:44Z", + "aliases": [ + "CVE-2025-21203" + ], + "details": "Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21203" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21203" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jghh-64fm-ph6v/GHSA-jghh-64fm-ph6v.json b/advisories/unreviewed/2025/04/GHSA-jghh-64fm-ph6v/GHSA-jghh-64fm-ph6v.json index b7ae010dce6..17180a48e8a 100644 --- a/advisories/unreviewed/2025/04/GHSA-jghh-64fm-ph6v/GHSA-jghh-64fm-ph6v.json +++ b/advisories/unreviewed/2025/04/GHSA-jghh-64fm-ph6v/GHSA-jghh-64fm-ph6v.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-jjwr-7vqh-8gf4/GHSA-jjwr-7vqh-8gf4.json b/advisories/unreviewed/2025/04/GHSA-jjwr-7vqh-8gf4/GHSA-jjwr-7vqh-8gf4.json new file mode 100644 index 00000000000..8735fb3952f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jjwr-7vqh-8gf4/GHSA-jjwr-7vqh-8gf4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jjwr-7vqh-8gf4", + "modified": "2025-04-08T18:34:50Z", + "published": "2025-04-08T18:34:50Z", + "aliases": [ + "CVE-2025-27475" + ], + "details": "Sensitive data storage in improperly locked memory in Windows Update Stack allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27475" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27475" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-591" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jpmv-9x86-xvwc/GHSA-jpmv-9x86-xvwc.json b/advisories/unreviewed/2025/04/GHSA-jpmv-9x86-xvwc/GHSA-jpmv-9x86-xvwc.json new file mode 100644 index 00000000000..4f10536b6a6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jpmv-9x86-xvwc/GHSA-jpmv-9x86-xvwc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jpmv-9x86-xvwc", + "modified": "2025-04-08T18:34:56Z", + "published": "2025-04-08T18:34:56Z", + "aliases": [ + "CVE-2025-29800" + ], + "details": "Improper privilege management in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29800" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29800" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jrp5-65w7-pcg2/GHSA-jrp5-65w7-pcg2.json b/advisories/unreviewed/2025/04/GHSA-jrp5-65w7-pcg2/GHSA-jrp5-65w7-pcg2.json new file mode 100644 index 00000000000..8655f755f1c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jrp5-65w7-pcg2/GHSA-jrp5-65w7-pcg2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jrp5-65w7-pcg2", + "modified": "2025-04-08T18:34:50Z", + "published": "2025-04-08T18:34:50Z", + "aliases": [ + "CVE-2025-27469" + ], + "details": "Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27469" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27469" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m46h-3mqp-xh9w/GHSA-m46h-3mqp-xh9w.json b/advisories/unreviewed/2025/04/GHSA-m46h-3mqp-xh9w/GHSA-m46h-3mqp-xh9w.json new file mode 100644 index 00000000000..0608bdd890c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m46h-3mqp-xh9w/GHSA-m46h-3mqp-xh9w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m46h-3mqp-xh9w", + "modified": "2025-04-08T18:34:48Z", + "published": "2025-04-08T18:34:48Z", + "aliases": [ + "CVE-2025-26680" + ], + "details": "Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26680" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26680" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m8g5-jr5h-6c6f/GHSA-m8g5-jr5h-6c6f.json b/advisories/unreviewed/2025/04/GHSA-m8g5-jr5h-6c6f/GHSA-m8g5-jr5h-6c6f.json new file mode 100644 index 00000000000..d192b94d44e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m8g5-jr5h-6c6f/GHSA-m8g5-jr5h-6c6f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m8g5-jr5h-6c6f", + "modified": "2025-04-08T18:34:52Z", + "published": "2025-04-08T18:34:52Z", + "aliases": [ + "CVE-2025-27727" + ], + "details": "Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27727" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27727" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m8qx-v899-58w7/GHSA-m8qx-v899-58w7.json b/advisories/unreviewed/2025/04/GHSA-m8qx-v899-58w7/GHSA-m8qx-v899-58w7.json new file mode 100644 index 00000000000..f3b322babeb --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m8qx-v899-58w7/GHSA-m8qx-v899-58w7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m8qx-v899-58w7", + "modified": "2025-04-08T18:34:51Z", + "published": "2025-04-08T18:34:51Z", + "aliases": [ + "CVE-2025-27492" + ], + "details": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Secure Channel allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27492" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27492" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mrrv-j79h-j3g7/GHSA-mrrv-j79h-j3g7.json b/advisories/unreviewed/2025/04/GHSA-mrrv-j79h-j3g7/GHSA-mrrv-j79h-j3g7.json index 106f6b86aff..2242a7cba31 100644 --- a/advisories/unreviewed/2025/04/GHSA-mrrv-j79h-j3g7/GHSA-mrrv-j79h-j3g7.json +++ b/advisories/unreviewed/2025/04/GHSA-mrrv-j79h-j3g7/GHSA-mrrv-j79h-j3g7.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-mx35-q7v3-5rh9/GHSA-mx35-q7v3-5rh9.json b/advisories/unreviewed/2025/04/GHSA-mx35-q7v3-5rh9/GHSA-mx35-q7v3-5rh9.json new file mode 100644 index 00000000000..110a2162c88 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mx35-q7v3-5rh9/GHSA-mx35-q7v3-5rh9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mx35-q7v3-5rh9", + "modified": "2025-04-08T18:34:45Z", + "published": "2025-04-08T18:34:44Z", + "aliases": [ + "CVE-2025-24073" + ], + "details": "Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24073" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24073" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p24p-f3hr-cw49/GHSA-p24p-f3hr-cw49.json b/advisories/unreviewed/2025/04/GHSA-p24p-f3hr-cw49/GHSA-p24p-f3hr-cw49.json new file mode 100644 index 00000000000..756507a77fa --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p24p-f3hr-cw49/GHSA-p24p-f3hr-cw49.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p24p-f3hr-cw49", + "modified": "2025-04-08T18:34:56Z", + "published": "2025-04-08T18:34:56Z", + "aliases": [ + "CVE-2025-29804" + ], + "details": "Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29804" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29804" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p2fq-4w5w-2ccm/GHSA-p2fq-4w5w-2ccm.json b/advisories/unreviewed/2025/04/GHSA-p2fq-4w5w-2ccm/GHSA-p2fq-4w5w-2ccm.json new file mode 100644 index 00000000000..d4740c04a88 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p2fq-4w5w-2ccm/GHSA-p2fq-4w5w-2ccm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p2fq-4w5w-2ccm", + "modified": "2025-04-08T18:34:42Z", + "published": "2025-04-08T18:34:42Z", + "aliases": [ + "CVE-2025-2288" + ], + "details": "A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to write outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data.  If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerability a legitimate user must open a malicious DOE file.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2288" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1726.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p34p-m244-f7pp/GHSA-p34p-m244-f7pp.json b/advisories/unreviewed/2025/04/GHSA-p34p-m244-f7pp/GHSA-p34p-m244-f7pp.json new file mode 100644 index 00000000000..6d0d11b5db4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p34p-m244-f7pp/GHSA-p34p-m244-f7pp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p34p-m244-f7pp", + "modified": "2025-04-08T18:34:45Z", + "published": "2025-04-08T18:34:45Z", + "aliases": [ + "CVE-2025-26639" + ], + "details": "Integer overflow or wraparound in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26639" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26639" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p5rh-8pxf-mm32/GHSA-p5rh-8pxf-mm32.json b/advisories/unreviewed/2025/04/GHSA-p5rh-8pxf-mm32/GHSA-p5rh-8pxf-mm32.json new file mode 100644 index 00000000000..9b3a200d0f2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p5rh-8pxf-mm32/GHSA-p5rh-8pxf-mm32.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p5rh-8pxf-mm32", + "modified": "2025-04-08T18:34:50Z", + "published": "2025-04-08T18:34:50Z", + "aliases": [ + "CVE-2025-27204" + ], + "details": "After Effects versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27204" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/after_effects/apsb25-23.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p5vq-38hr-952c/GHSA-p5vq-38hr-952c.json b/advisories/unreviewed/2025/04/GHSA-p5vq-38hr-952c/GHSA-p5vq-38hr-952c.json new file mode 100644 index 00000000000..da38a79702a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p5vq-38hr-952c/GHSA-p5vq-38hr-952c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p5vq-38hr-952c", + "modified": "2025-04-08T18:34:56Z", + "published": "2025-04-08T18:34:56Z", + "aliases": [ + "CVE-2025-27747" + ], + "details": "Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27747" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27747" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-822" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p9qw-h5h2-6vw8/GHSA-p9qw-h5h2-6vw8.json b/advisories/unreviewed/2025/04/GHSA-p9qw-h5h2-6vw8/GHSA-p9qw-h5h2-6vw8.json new file mode 100644 index 00000000000..065fb4913a1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p9qw-h5h2-6vw8/GHSA-p9qw-h5h2-6vw8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p9qw-h5h2-6vw8", + "modified": "2025-04-08T18:34:49Z", + "published": "2025-04-08T18:34:49Z", + "aliases": [ + "CVE-2025-26687" + ], + "details": "Use after free in Windows Win32K - GRFX allows an unauthorized attacker to elevate privileges over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26687" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26687" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pcvm-gp76-hqvq/GHSA-pcvm-gp76-hqvq.json b/advisories/unreviewed/2025/04/GHSA-pcvm-gp76-hqvq/GHSA-pcvm-gp76-hqvq.json new file mode 100644 index 00000000000..90d34e9df6b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pcvm-gp76-hqvq/GHSA-pcvm-gp76-hqvq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pcvm-gp76-hqvq", + "modified": "2025-04-08T18:34:42Z", + "published": "2025-04-08T18:34:42Z", + "aliases": [ + "CVE-2025-3285" + ], + "details": "A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data.  If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerability a legitimate user must open a malicious DOE file.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3285" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1726.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pf7h-9fm5-wgv6/GHSA-pf7h-9fm5-wgv6.json b/advisories/unreviewed/2025/04/GHSA-pf7h-9fm5-wgv6/GHSA-pf7h-9fm5-wgv6.json new file mode 100644 index 00000000000..6265c78062e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pf7h-9fm5-wgv6/GHSA-pf7h-9fm5-wgv6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pf7h-9fm5-wgv6", + "modified": "2025-04-08T18:34:42Z", + "published": "2025-04-08T18:34:42Z", + "aliases": [ + "CVE-2025-3288" + ], + "details": "A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data.  If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerability a legitimate user must open a malicious DOE file.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3288" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1726.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T16:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pgr8-v8gq-7h3m/GHSA-pgr8-v8gq-7h3m.json b/advisories/unreviewed/2025/04/GHSA-pgr8-v8gq-7h3m/GHSA-pgr8-v8gq-7h3m.json new file mode 100644 index 00000000000..770277c2da5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pgr8-v8gq-7h3m/GHSA-pgr8-v8gq-7h3m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pgr8-v8gq-7h3m", + "modified": "2025-04-08T18:34:49Z", + "published": "2025-04-08T18:34:49Z", + "aliases": [ + "CVE-2025-27182" + ], + "details": "After Effects versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27182" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/after_effects/apsb25-23.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pjr7-76vx-55xq/GHSA-pjr7-76vx-55xq.json b/advisories/unreviewed/2025/04/GHSA-pjr7-76vx-55xq/GHSA-pjr7-76vx-55xq.json new file mode 100644 index 00000000000..ea730ed131e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pjr7-76vx-55xq/GHSA-pjr7-76vx-55xq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pjr7-76vx-55xq", + "modified": "2025-04-08T18:34:43Z", + "published": "2025-04-08T18:34:43Z", + "aliases": [ + "CVE-2025-27442" + ], + "details": "Cross site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via adjacent network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27442" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-25013" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T17:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pqgf-8vrh-rr46/GHSA-pqgf-8vrh-rr46.json b/advisories/unreviewed/2025/04/GHSA-pqgf-8vrh-rr46/GHSA-pqgf-8vrh-rr46.json new file mode 100644 index 00000000000..df058bf0cdc --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pqgf-8vrh-rr46/GHSA-pqgf-8vrh-rr46.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pqgf-8vrh-rr46", + "modified": "2025-04-08T18:34:47Z", + "published": "2025-04-08T18:34:47Z", + "aliases": [ + "CVE-2025-26673" + ], + "details": "Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26673" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26673" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pxr7-h23v-3wv6/GHSA-pxr7-h23v-3wv6.json b/advisories/unreviewed/2025/04/GHSA-pxr7-h23v-3wv6/GHSA-pxr7-h23v-3wv6.json new file mode 100644 index 00000000000..a4a55164532 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pxr7-h23v-3wv6/GHSA-pxr7-h23v-3wv6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pxr7-h23v-3wv6", + "modified": "2025-04-08T18:34:49Z", + "published": "2025-04-08T18:34:49Z", + "aliases": [ + "CVE-2025-27185" + ], + "details": "After Effects versions 25.1, 24.6.4 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27185" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/after_effects/apsb25-23.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-q7p5-2w2c-9c56/GHSA-q7p5-2w2c-9c56.json b/advisories/unreviewed/2025/04/GHSA-q7p5-2w2c-9c56/GHSA-q7p5-2w2c-9c56.json new file mode 100644 index 00000000000..56f903a999b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-q7p5-2w2c-9c56/GHSA-q7p5-2w2c-9c56.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q7p5-2w2c-9c56", + "modified": "2025-04-08T18:34:43Z", + "published": "2025-04-08T18:34:43Z", + "aliases": [ + "CVE-2025-27084" + ], + "details": "A vulnerability in the Captive Portal of an AOS-10 GW and AOS-8 Controller/Mobility Conductor could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack. Successful exploitation could enable the attacker to execute arbitrary script code in the victim's browser within the context of the affected interface.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27084" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04845en_us&docLocale=en_US" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T17:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-q84m-7mh3-gvhw/GHSA-q84m-7mh3-gvhw.json b/advisories/unreviewed/2025/04/GHSA-q84m-7mh3-gvhw/GHSA-q84m-7mh3-gvhw.json new file mode 100644 index 00000000000..806e0505b27 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-q84m-7mh3-gvhw/GHSA-q84m-7mh3-gvhw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q84m-7mh3-gvhw", + "modified": "2025-04-08T18:34:45Z", + "published": "2025-04-08T18:34:45Z", + "aliases": [ + "CVE-2025-26641" + ], + "details": "Uncontrolled resource consumption in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26641" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26641" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qjm7-f9mj-293h/GHSA-qjm7-f9mj-293h.json b/advisories/unreviewed/2025/04/GHSA-qjm7-f9mj-293h/GHSA-qjm7-f9mj-293h.json new file mode 100644 index 00000000000..5787ca97d3e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qjm7-f9mj-293h/GHSA-qjm7-f9mj-293h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qjm7-f9mj-293h", + "modified": "2025-04-08T18:34:46Z", + "published": "2025-04-08T18:34:46Z", + "aliases": [ + "CVE-2025-26648" + ], + "details": "Sensitive data storage in improperly locked memory in Windows Kernel allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26648" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26648" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qm95-22pj-qx7v/GHSA-qm95-22pj-qx7v.json b/advisories/unreviewed/2025/04/GHSA-qm95-22pj-qx7v/GHSA-qm95-22pj-qx7v.json new file mode 100644 index 00000000000..7a99920e6bd --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qm95-22pj-qx7v/GHSA-qm95-22pj-qx7v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qm95-22pj-qx7v", + "modified": "2025-04-08T18:34:45Z", + "published": "2025-04-08T18:34:45Z", + "aliases": [ + "CVE-2025-26642" + ], + "details": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26642" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26642" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qp8f-6pj7-98h4/GHSA-qp8f-6pj7-98h4.json b/advisories/unreviewed/2025/04/GHSA-qp8f-6pj7-98h4/GHSA-qp8f-6pj7-98h4.json new file mode 100644 index 00000000000..31820473442 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qp8f-6pj7-98h4/GHSA-qp8f-6pj7-98h4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qp8f-6pj7-98h4", + "modified": "2025-04-08T18:34:49Z", + "published": "2025-04-08T18:34:49Z", + "aliases": [ + "CVE-2025-27183" + ], + "details": "After Effects versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27183" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/after_effects/apsb25-23.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-r9m4-84qp-v455/GHSA-r9m4-84qp-v455.json b/advisories/unreviewed/2025/04/GHSA-r9m4-84qp-v455/GHSA-r9m4-84qp-v455.json new file mode 100644 index 00000000000..3dd0f55858f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-r9m4-84qp-v455/GHSA-r9m4-84qp-v455.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r9m4-84qp-v455", + "modified": "2025-04-08T18:34:42Z", + "published": "2025-04-08T18:34:42Z", + "aliases": [ + "CVE-2025-2287" + ], + "details": "A local code execution vulnerability exists in the Rockwell Automation Arena®  due to an uninitialized pointer. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerability a legitimate user must open a malicious DOE file.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2287" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1726.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-457" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rfqv-r3rp-j8mm/GHSA-rfqv-r3rp-j8mm.json b/advisories/unreviewed/2025/04/GHSA-rfqv-r3rp-j8mm/GHSA-rfqv-r3rp-j8mm.json new file mode 100644 index 00000000000..760c63da3f8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rfqv-r3rp-j8mm/GHSA-rfqv-r3rp-j8mm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rfqv-r3rp-j8mm", + "modified": "2025-04-08T18:34:41Z", + "published": "2025-04-08T18:34:41Z", + "aliases": [ + "CVE-2025-27079" + ], + "details": "A vulnerability in the file creation process on the command line interface of AOS-8 Instant and AOS-10 AP could allow an authenticated remote attacker to perform remote code execution (RCE). Successful exploitation could allow an attacker to execute arbitrary operating system commands on the underlying operating system leading to potential system compromise.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27079" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04844en_us&docLocale=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rr38-x2xx-vwr5/GHSA-rr38-x2xx-vwr5.json b/advisories/unreviewed/2025/04/GHSA-rr38-x2xx-vwr5/GHSA-rr38-x2xx-vwr5.json new file mode 100644 index 00000000000..ba5290cd0d1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rr38-x2xx-vwr5/GHSA-rr38-x2xx-vwr5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rr38-x2xx-vwr5", + "modified": "2025-04-08T18:34:43Z", + "published": "2025-04-08T18:34:43Z", + "aliases": [ + "CVE-2025-27443" + ], + "details": "Insecure default variable initialization in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a loss of integrity via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27443" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-25014" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1188" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T17:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-v269-fhhx-vf6j/GHSA-v269-fhhx-vf6j.json b/advisories/unreviewed/2025/04/GHSA-v269-fhhx-vf6j/GHSA-v269-fhhx-vf6j.json new file mode 100644 index 00000000000..8d2fa42353f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v269-fhhx-vf6j/GHSA-v269-fhhx-vf6j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v269-fhhx-vf6j", + "modified": "2025-04-08T18:34:50Z", + "published": "2025-04-08T18:34:50Z", + "aliases": [ + "CVE-2025-27473" + ], + "details": "Uncontrolled resource consumption in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27473" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27473" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-v2ph-qcjx-gh8g/GHSA-v2ph-qcjx-gh8g.json b/advisories/unreviewed/2025/04/GHSA-v2ph-qcjx-gh8g/GHSA-v2ph-qcjx-gh8g.json new file mode 100644 index 00000000000..d10200ea144 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v2ph-qcjx-gh8g/GHSA-v2ph-qcjx-gh8g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v2ph-qcjx-gh8g", + "modified": "2025-04-08T18:34:51Z", + "published": "2025-04-08T18:34:51Z", + "aliases": [ + "CVE-2025-27486" + ], + "details": "Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27486" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27486" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-v3mw-3vwm-c6c7/GHSA-v3mw-3vwm-c6c7.json b/advisories/unreviewed/2025/04/GHSA-v3mw-3vwm-c6c7/GHSA-v3mw-3vwm-c6c7.json new file mode 100644 index 00000000000..aca22f2fd98 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v3mw-3vwm-c6c7/GHSA-v3mw-3vwm-c6c7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v3mw-3vwm-c6c7", + "modified": "2025-04-08T18:34:51Z", + "published": "2025-04-08T18:34:51Z", + "aliases": [ + "CVE-2025-27487" + ], + "details": "Heap-based buffer overflow in Remote Desktop Client allows an authorized attacker to execute code over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27487" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27487" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-v4v5-73p4-rg59/GHSA-v4v5-73p4-rg59.json b/advisories/unreviewed/2025/04/GHSA-v4v5-73p4-rg59/GHSA-v4v5-73p4-rg59.json new file mode 100644 index 00000000000..ac9908e7a47 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v4v5-73p4-rg59/GHSA-v4v5-73p4-rg59.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v4v5-73p4-rg59", + "modified": "2025-04-08T18:34:46Z", + "published": "2025-04-08T18:34:46Z", + "aliases": [ + "CVE-2025-26652" + ], + "details": "Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26652" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26652" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vg4c-j58p-8f66/GHSA-vg4c-j58p-8f66.json b/advisories/unreviewed/2025/04/GHSA-vg4c-j58p-8f66/GHSA-vg4c-j58p-8f66.json new file mode 100644 index 00000000000..84cc0fc1e2d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vg4c-j58p-8f66/GHSA-vg4c-j58p-8f66.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vg4c-j58p-8f66", + "modified": "2025-04-08T18:34:43Z", + "published": "2025-04-08T18:34:43Z", + "aliases": [ + "CVE-2025-30671" + ], + "details": "Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30671" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-25015" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T17:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vg94-crh4-qq4x/GHSA-vg94-crh4-qq4x.json b/advisories/unreviewed/2025/04/GHSA-vg94-crh4-qq4x/GHSA-vg94-crh4-qq4x.json new file mode 100644 index 00000000000..927cd0a0243 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vg94-crh4-qq4x/GHSA-vg94-crh4-qq4x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vg94-crh4-qq4x", + "modified": "2025-04-08T18:34:47Z", + "published": "2025-04-08T18:34:47Z", + "aliases": [ + "CVE-2025-26675" + ], + "details": "Out-of-bounds read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26675" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26675" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vm5w-p85f-gq6r/GHSA-vm5w-p85f-gq6r.json b/advisories/unreviewed/2025/04/GHSA-vm5w-p85f-gq6r/GHSA-vm5w-p85f-gq6r.json new file mode 100644 index 00000000000..528572f55ec --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vm5w-p85f-gq6r/GHSA-vm5w-p85f-gq6r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vm5w-p85f-gq6r", + "modified": "2025-04-08T18:34:47Z", + "published": "2025-04-08T18:34:47Z", + "aliases": [ + "CVE-2025-26672" + ], + "details": "Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26672" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26672" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vq2r-vj3j-964w/GHSA-vq2r-vj3j-964w.json b/advisories/unreviewed/2025/04/GHSA-vq2r-vj3j-964w/GHSA-vq2r-vj3j-964w.json new file mode 100644 index 00000000000..efbc036c8bd --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vq2r-vj3j-964w/GHSA-vq2r-vj3j-964w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vq2r-vj3j-964w", + "modified": "2025-04-08T18:34:57Z", + "published": "2025-04-08T18:34:57Z", + "aliases": [ + "CVE-2025-29805" + ], + "details": "Exposure of sensitive information to an unauthorized actor in Outlook for Android allows an unauthorized attacker to disclose information over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29805" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29805" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vxc2-qxc2-pw67/GHSA-vxc2-qxc2-pw67.json b/advisories/unreviewed/2025/04/GHSA-vxc2-qxc2-pw67/GHSA-vxc2-qxc2-pw67.json new file mode 100644 index 00000000000..216e7a28c4d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vxc2-qxc2-pw67/GHSA-vxc2-qxc2-pw67.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vxc2-qxc2-pw67", + "modified": "2025-04-08T18:34:50Z", + "published": "2025-04-08T18:34:50Z", + "aliases": [ + "CVE-2025-27200" + ], + "details": "Animate versions 24.0.7, 23.0.10 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27200" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/animate/apsb25-31.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-w3h4-x33c-8cc8/GHSA-w3h4-x33c-8cc8.json b/advisories/unreviewed/2025/04/GHSA-w3h4-x33c-8cc8/GHSA-w3h4-x33c-8cc8.json new file mode 100644 index 00000000000..15ebfa2ffae --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-w3h4-x33c-8cc8/GHSA-w3h4-x33c-8cc8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w3h4-x33c-8cc8", + "modified": "2025-04-08T18:34:47Z", + "published": "2025-04-08T18:34:47Z", + "aliases": [ + "CVE-2025-26668" + ], + "details": "Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26668" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26668" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-w4rq-mvcf-xc7h/GHSA-w4rq-mvcf-xc7h.json b/advisories/unreviewed/2025/04/GHSA-w4rq-mvcf-xc7h/GHSA-w4rq-mvcf-xc7h.json new file mode 100644 index 00000000000..99476eb33d8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-w4rq-mvcf-xc7h/GHSA-w4rq-mvcf-xc7h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w4rq-mvcf-xc7h", + "modified": "2025-04-08T18:34:55Z", + "published": "2025-04-08T18:34:55Z", + "aliases": [ + "CVE-2025-27740" + ], + "details": "Weak authentication in Windows Active Directory Certificate Services allows an authorized attacker to elevate privileges over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27740" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27740" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1390" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-w5wx-73w5-58mw/GHSA-w5wx-73w5-58mw.json b/advisories/unreviewed/2025/04/GHSA-w5wx-73w5-58mw/GHSA-w5wx-73w5-58mw.json new file mode 100644 index 00000000000..6bade17cfcc --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-w5wx-73w5-58mw/GHSA-w5wx-73w5-58mw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w5wx-73w5-58mw", + "modified": "2025-04-08T18:34:56Z", + "published": "2025-04-08T18:34:56Z", + "aliases": [ + "CVE-2025-29793" + ], + "details": "Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29793" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29793" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-w84w-59g8-pmg9/GHSA-w84w-59g8-pmg9.json b/advisories/unreviewed/2025/04/GHSA-w84w-59g8-pmg9/GHSA-w84w-59g8-pmg9.json new file mode 100644 index 00000000000..5c726d1edac --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-w84w-59g8-pmg9/GHSA-w84w-59g8-pmg9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w84w-59g8-pmg9", + "modified": "2025-04-08T18:34:42Z", + "published": "2025-04-08T18:34:42Z", + "aliases": [ + "CVE-2024-48887" + ], + "details": "A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin passwords via a specially crafted request", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48887" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-435" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-620" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T17:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-w87f-mr23-wrp9/GHSA-w87f-mr23-wrp9.json b/advisories/unreviewed/2025/04/GHSA-w87f-mr23-wrp9/GHSA-w87f-mr23-wrp9.json new file mode 100644 index 00000000000..25cb23aeb7c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-w87f-mr23-wrp9/GHSA-w87f-mr23-wrp9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w87f-mr23-wrp9", + "modified": "2025-04-08T18:34:47Z", + "published": "2025-04-08T18:34:47Z", + "aliases": [ + "CVE-2025-26669" + ], + "details": "Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26669" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26669" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-w9x5-m47g-3gx6/GHSA-w9x5-m47g-3gx6.json b/advisories/unreviewed/2025/04/GHSA-w9x5-m47g-3gx6/GHSA-w9x5-m47g-3gx6.json new file mode 100644 index 00000000000..333ee003f62 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-w9x5-m47g-3gx6/GHSA-w9x5-m47g-3gx6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w9x5-m47g-3gx6", + "modified": "2025-04-08T18:34:41Z", + "published": "2025-04-08T18:34:41Z", + "aliases": [ + "CVE-2025-1095" + ], + "details": "IBM Personal Communications v14 and v15 include a Windows service that is vulnerable to local privilege escalation (LPE). The vulnerability allows any interactively logged in users on the target computer to run commands with full privileges in the context of NT AUTHORITY\\SYSTEM. This allows for a low privileged attacker to escalate their privileges. This vulnerability is due to an incomplete fix for CVE-2024-25029.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1095" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7230335" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wjr6-rfwf-wx2f/GHSA-wjr6-rfwf-wx2f.json b/advisories/unreviewed/2025/04/GHSA-wjr6-rfwf-wx2f/GHSA-wjr6-rfwf-wx2f.json new file mode 100644 index 00000000000..45cce1f6a1d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wjr6-rfwf-wx2f/GHSA-wjr6-rfwf-wx2f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wjr6-rfwf-wx2f", + "modified": "2025-04-08T18:34:57Z", + "published": "2025-04-08T18:34:56Z", + "aliases": [ + "CVE-2025-29794" + ], + "details": "Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29794" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29794" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wm96-jrv9-gggq/GHSA-wm96-jrv9-gggq.json b/advisories/unreviewed/2025/04/GHSA-wm96-jrv9-gggq/GHSA-wm96-jrv9-gggq.json index da90fb4341b..ae62ee5c157 100644 --- a/advisories/unreviewed/2025/04/GHSA-wm96-jrv9-gggq/GHSA-wm96-jrv9-gggq.json +++ b/advisories/unreviewed/2025/04/GHSA-wm96-jrv9-gggq/GHSA-wm96-jrv9-gggq.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-wq4m-7cp4-8jgg/GHSA-wq4m-7cp4-8jgg.json b/advisories/unreviewed/2025/04/GHSA-wq4m-7cp4-8jgg/GHSA-wq4m-7cp4-8jgg.json new file mode 100644 index 00000000000..65270214897 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wq4m-7cp4-8jgg/GHSA-wq4m-7cp4-8jgg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wq4m-7cp4-8jgg", + "modified": "2025-04-08T18:34:47Z", + "published": "2025-04-08T18:34:47Z", + "aliases": [ + "CVE-2025-26674" + ], + "details": "Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26674" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26674" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wr29-5553-rrh3/GHSA-wr29-5553-rrh3.json b/advisories/unreviewed/2025/04/GHSA-wr29-5553-rrh3/GHSA-wr29-5553-rrh3.json new file mode 100644 index 00000000000..155a62458b8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wr29-5553-rrh3/GHSA-wr29-5553-rrh3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wr29-5553-rrh3", + "modified": "2025-04-08T18:34:50Z", + "published": "2025-04-08T18:34:50Z", + "aliases": [ + "CVE-2025-27482" + ], + "details": "Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27482" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27482" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-591" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wvg7-cvgq-hhh3/GHSA-wvg7-cvgq-hhh3.json b/advisories/unreviewed/2025/04/GHSA-wvg7-cvgq-hhh3/GHSA-wvg7-cvgq-hhh3.json new file mode 100644 index 00000000000..2e2d868a9b5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wvg7-cvgq-hhh3/GHSA-wvg7-cvgq-hhh3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wvg7-cvgq-hhh3", + "modified": "2025-04-08T18:34:56Z", + "published": "2025-04-08T18:34:56Z", + "aliases": [ + "CVE-2025-27748" + ], + "details": "Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27748" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27748" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-x27v-pq4m-wch6/GHSA-x27v-pq4m-wch6.json b/advisories/unreviewed/2025/04/GHSA-x27v-pq4m-wch6/GHSA-x27v-pq4m-wch6.json new file mode 100644 index 00000000000..12b0df1c1a7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-x27v-pq4m-wch6/GHSA-x27v-pq4m-wch6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x27v-pq4m-wch6", + "modified": "2025-04-08T18:34:57Z", + "published": "2025-04-08T18:34:56Z", + "aliases": [ + "CVE-2025-29802" + ], + "details": "Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29802" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29802" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-x599-jjw8-g5vw/GHSA-x599-jjw8-g5vw.json b/advisories/unreviewed/2025/04/GHSA-x599-jjw8-g5vw/GHSA-x599-jjw8-g5vw.json new file mode 100644 index 00000000000..ffad1922647 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-x599-jjw8-g5vw/GHSA-x599-jjw8-g5vw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x599-jjw8-g5vw", + "modified": "2025-04-08T18:34:44Z", + "published": "2025-04-08T18:34:44Z", + "aliases": [ + "CVE-2025-24058" + ], + "details": "Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24058" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24058" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-x65v-wxjf-f672/GHSA-x65v-wxjf-f672.json b/advisories/unreviewed/2025/04/GHSA-x65v-wxjf-f672/GHSA-x65v-wxjf-f672.json new file mode 100644 index 00000000000..efe447bf1de --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-x65v-wxjf-f672/GHSA-x65v-wxjf-f672.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x65v-wxjf-f672", + "modified": "2025-04-08T18:34:43Z", + "published": "2025-04-08T18:34:43Z", + "aliases": [ + "CVE-2025-32117" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Widgetize Pages Light allows Reflected XSS. This issue affects Widgetize Pages Light: from n/a through 3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32117" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/widgetize-pages-light/vulnerability/wordpress-widgetize-pages-light-plugin-3-0-reflected-cross-site-scripting-xss-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T17:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-x7g5-wpm2-r3jm/GHSA-x7g5-wpm2-r3jm.json b/advisories/unreviewed/2025/04/GHSA-x7g5-wpm2-r3jm/GHSA-x7g5-wpm2-r3jm.json new file mode 100644 index 00000000000..2cfcb81a333 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-x7g5-wpm2-r3jm/GHSA-x7g5-wpm2-r3jm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x7g5-wpm2-r3jm", + "modified": "2025-04-08T18:34:53Z", + "published": "2025-04-08T18:34:53Z", + "aliases": [ + "CVE-2025-27738" + ], + "details": "Improper access control in Windows Resilient File System (ReFS) allows an authorized attacker to disclose information over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27738" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27738" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-x998-4j8c-4fq3/GHSA-x998-4j8c-4fq3.json b/advisories/unreviewed/2025/04/GHSA-x998-4j8c-4fq3/GHSA-x998-4j8c-4fq3.json new file mode 100644 index 00000000000..d83627000fe --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-x998-4j8c-4fq3/GHSA-x998-4j8c-4fq3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x998-4j8c-4fq3", + "modified": "2025-04-08T18:34:55Z", + "published": "2025-04-08T18:34:55Z", + "aliases": [ + "CVE-2025-27741" + ], + "details": "Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27741" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27741" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xc3h-9j86-jpjh/GHSA-xc3h-9j86-jpjh.json b/advisories/unreviewed/2025/04/GHSA-xc3h-9j86-jpjh/GHSA-xc3h-9j86-jpjh.json new file mode 100644 index 00000000000..f95443c6596 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xc3h-9j86-jpjh/GHSA-xc3h-9j86-jpjh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xc3h-9j86-jpjh", + "modified": "2025-04-08T18:34:44Z", + "published": "2025-04-08T18:34:44Z", + "aliases": [ + "CVE-2025-24062" + ], + "details": "Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24062" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24062" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xcw6-8574-9qv2/GHSA-xcw6-8574-9qv2.json b/advisories/unreviewed/2025/04/GHSA-xcw6-8574-9qv2/GHSA-xcw6-8574-9qv2.json new file mode 100644 index 00000000000..a1da5190760 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xcw6-8574-9qv2/GHSA-xcw6-8574-9qv2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xcw6-8574-9qv2", + "modified": "2025-04-08T18:34:57Z", + "published": "2025-04-08T18:34:57Z", + "aliases": [ + "CVE-2025-29816" + ], + "details": "Improper input validation in Microsoft Office Word allows an unauthorized attacker to bypass a security feature over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29816" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29816" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-349" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xmq2-8hhc-7629/GHSA-xmq2-8hhc-7629.json b/advisories/unreviewed/2025/04/GHSA-xmq2-8hhc-7629/GHSA-xmq2-8hhc-7629.json index 7a078418a26..41aa89dd388 100644 --- a/advisories/unreviewed/2025/04/GHSA-xmq2-8hhc-7629/GHSA-xmq2-8hhc-7629.json +++ b/advisories/unreviewed/2025/04/GHSA-xmq2-8hhc-7629/GHSA-xmq2-8hhc-7629.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-xp88-vp78-mqm7/GHSA-xp88-vp78-mqm7.json b/advisories/unreviewed/2025/04/GHSA-xp88-vp78-mqm7/GHSA-xp88-vp78-mqm7.json new file mode 100644 index 00000000000..48de2b2758b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xp88-vp78-mqm7/GHSA-xp88-vp78-mqm7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xp88-vp78-mqm7", + "modified": "2025-04-08T18:34:46Z", + "published": "2025-04-08T18:34:46Z", + "aliases": [ + "CVE-2025-26665" + ], + "details": "Sensitive data storage in improperly locked memory in Windows upnphost.dll allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26665" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26665" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-591" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xr7q-639h-425q/GHSA-xr7q-639h-425q.json b/advisories/unreviewed/2025/04/GHSA-xr7q-639h-425q/GHSA-xr7q-639h-425q.json new file mode 100644 index 00000000000..7b42c2c2b0a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xr7q-639h-425q/GHSA-xr7q-639h-425q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xr7q-639h-425q", + "modified": "2025-04-08T18:34:53Z", + "published": "2025-04-08T18:34:53Z", + "aliases": [ + "CVE-2025-27736" + ], + "details": "Exposure of sensitive information to an unauthorized actor in Windows Power Dependency Coordinator allows an authorized attacker to disclose information locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27736" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27736" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xrg8-r4mg-6g2x/GHSA-xrg8-r4mg-6g2x.json b/advisories/unreviewed/2025/04/GHSA-xrg8-r4mg-6g2x/GHSA-xrg8-r4mg-6g2x.json new file mode 100644 index 00000000000..217851403da --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xrg8-r4mg-6g2x/GHSA-xrg8-r4mg-6g2x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xrg8-r4mg-6g2x", + "modified": "2025-04-08T18:34:49Z", + "published": "2025-04-08T18:34:49Z", + "aliases": [ + "CVE-2025-27184" + ], + "details": "After Effects versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27184" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/after_effects/apsb25-23.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xwxw-9gfj-g2c9/GHSA-xwxw-9gfj-g2c9.json b/advisories/unreviewed/2025/04/GHSA-xwxw-9gfj-g2c9/GHSA-xwxw-9gfj-g2c9.json new file mode 100644 index 00000000000..ea4bc17e100 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xwxw-9gfj-g2c9/GHSA-xwxw-9gfj-g2c9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xwxw-9gfj-g2c9", + "modified": "2025-04-08T18:34:44Z", + "published": "2025-04-08T18:34:44Z", + "aliases": [ + "CVE-2025-21191" + ], + "details": "Time-of-check time-of-use (toctou) race condition in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21191" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21191" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T18:15:44Z" + } +} \ No newline at end of file