diff --git a/advisories/unreviewed/2023/08/GHSA-7xfv-pf6f-p6v2/GHSA-7xfv-pf6f-p6v2.json b/advisories/unreviewed/2023/08/GHSA-7xfv-pf6f-p6v2/GHSA-7xfv-pf6f-p6v2.json index 39f05eb694d..cf59bceeb6c 100644 --- a/advisories/unreviewed/2023/08/GHSA-7xfv-pf6f-p6v2/GHSA-7xfv-pf6f-p6v2.json +++ b/advisories/unreviewed/2023/08/GHSA-7xfv-pf6f-p6v2/GHSA-7xfv-pf6f-p6v2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7xfv-pf6f-p6v2", - "modified": "2025-05-05T15:30:44Z", + "modified": "2025-05-19T21:30:27Z", "published": "2023-08-04T00:30:16Z", "aliases": [ "CVE-2023-38952" @@ -23,6 +23,14 @@ "type": "WEB", "url": "https://claroty.com/team82/disclosure-dashboard/cve-2023-38952" }, + { + "type": "WEB", + "url": "https://github.com/omair2084/biotime-rce-8.5.5/blob/main/biotime_enum.py" + }, + { + "type": "WEB", + "url": "https://krashconsulting.com/fury-of-fingers-biotime-rce" + }, { "type": "WEB", "url": "https://sploitus.com/exploit?id=PACKETSTORM:177859" diff --git a/advisories/unreviewed/2023/12/GHSA-g8gc-c7p5-2xq8/GHSA-g8gc-c7p5-2xq8.json b/advisories/unreviewed/2023/12/GHSA-g8gc-c7p5-2xq8/GHSA-g8gc-c7p5-2xq8.json index 41e29d3b647..516653d47e2 100644 --- a/advisories/unreviewed/2023/12/GHSA-g8gc-c7p5-2xq8/GHSA-g8gc-c7p5-2xq8.json +++ b/advisories/unreviewed/2023/12/GHSA-g8gc-c7p5-2xq8/GHSA-g8gc-c7p5-2xq8.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-g8gc-c7p5-2xq8", - "modified": "2023-12-20T18:30:32Z", + "modified": "2025-05-19T21:30:27Z", "published": "2023-12-20T18:30:32Z", "aliases": [ "CVE-2023-5007" ], - "details": "Student Information System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'id' parameter of the marks.php resource does not validate the characters received and they are sent unfiltered to the database.\n\n", + "details": "Student Information System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'id' parameter of the marks.php resource does not validate the characters received and they are sent unfiltered to the database.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/12/GHSA-rwhw-p34v-qx7h/GHSA-rwhw-p34v-qx7h.json b/advisories/unreviewed/2023/12/GHSA-rwhw-p34v-qx7h/GHSA-rwhw-p34v-qx7h.json index d4294ead037..949fb69359f 100644 --- a/advisories/unreviewed/2023/12/GHSA-rwhw-p34v-qx7h/GHSA-rwhw-p34v-qx7h.json +++ b/advisories/unreviewed/2023/12/GHSA-rwhw-p34v-qx7h/GHSA-rwhw-p34v-qx7h.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-rwhw-p34v-qx7h", - "modified": "2023-12-20T18:30:32Z", + "modified": "2025-05-19T21:30:28Z", "published": "2023-12-20T18:30:32Z", "aliases": [ "CVE-2023-5011" ], - "details": "Student Information System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'coursename' parameter of the marks.php resource does not validate the characters received and they are sent unfiltered to the database.\n\n", + "details": "Student Information System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'coursename' parameter of the marks.php resource does not validate the characters received and they are sent unfiltered to the database.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/12/GHSA-xf73-8777-6w59/GHSA-xf73-8777-6w59.json b/advisories/unreviewed/2023/12/GHSA-xf73-8777-6w59/GHSA-xf73-8777-6w59.json index be0fdb55382..c16928fc56a 100644 --- a/advisories/unreviewed/2023/12/GHSA-xf73-8777-6w59/GHSA-xf73-8777-6w59.json +++ b/advisories/unreviewed/2023/12/GHSA-xf73-8777-6w59/GHSA-xf73-8777-6w59.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-xf73-8777-6w59", - "modified": "2023-12-20T18:30:32Z", + "modified": "2025-05-19T21:30:27Z", "published": "2023-12-20T18:30:32Z", "aliases": [ "CVE-2023-5010" ], - "details": "Student Information System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'coursecode' parameter of the marks.php resource does not validate the characters received and they are sent unfiltered to the database.\n\n", + "details": "Student Information System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'coursecode' parameter of the marks.php resource does not validate the characters received and they are sent unfiltered to the database.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/06/GHSA-2347-3mgh-xw2g/GHSA-2347-3mgh-xw2g.json b/advisories/unreviewed/2024/06/GHSA-2347-3mgh-xw2g/GHSA-2347-3mgh-xw2g.json index dcebc017088..e5ba758612f 100644 --- a/advisories/unreviewed/2024/06/GHSA-2347-3mgh-xw2g/GHSA-2347-3mgh-xw2g.json +++ b/advisories/unreviewed/2024/06/GHSA-2347-3mgh-xw2g/GHSA-2347-3mgh-xw2g.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-252v-9w3r-w4vm/GHSA-252v-9w3r-w4vm.json b/advisories/unreviewed/2024/06/GHSA-252v-9w3r-w4vm/GHSA-252v-9w3r-w4vm.json index 33c6da260ab..b78e4d82e10 100644 --- a/advisories/unreviewed/2024/06/GHSA-252v-9w3r-w4vm/GHSA-252v-9w3r-w4vm.json +++ b/advisories/unreviewed/2024/06/GHSA-252v-9w3r-w4vm/GHSA-252v-9w3r-w4vm.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-3vf3-j8cr-x4g6/GHSA-3vf3-j8cr-x4g6.json b/advisories/unreviewed/2024/06/GHSA-3vf3-j8cr-x4g6/GHSA-3vf3-j8cr-x4g6.json index d602d9d40d1..d4022e867ae 100644 --- a/advisories/unreviewed/2024/06/GHSA-3vf3-j8cr-x4g6/GHSA-3vf3-j8cr-x4g6.json +++ b/advisories/unreviewed/2024/06/GHSA-3vf3-j8cr-x4g6/GHSA-3vf3-j8cr-x4g6.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-8925-jp4p-j7g9/GHSA-8925-jp4p-j7g9.json b/advisories/unreviewed/2024/06/GHSA-8925-jp4p-j7g9/GHSA-8925-jp4p-j7g9.json index f5cb4ccb465..7680e50d16c 100644 --- a/advisories/unreviewed/2024/06/GHSA-8925-jp4p-j7g9/GHSA-8925-jp4p-j7g9.json +++ b/advisories/unreviewed/2024/06/GHSA-8925-jp4p-j7g9/GHSA-8925-jp4p-j7g9.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-hfgv-wmc3-7jwm/GHSA-hfgv-wmc3-7jwm.json b/advisories/unreviewed/2024/06/GHSA-hfgv-wmc3-7jwm/GHSA-hfgv-wmc3-7jwm.json index d44931c5368..c50a47cab22 100644 --- a/advisories/unreviewed/2024/06/GHSA-hfgv-wmc3-7jwm/GHSA-hfgv-wmc3-7jwm.json +++ b/advisories/unreviewed/2024/06/GHSA-hfgv-wmc3-7jwm/GHSA-hfgv-wmc3-7jwm.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-m6hr-8q9f-92q4/GHSA-m6hr-8q9f-92q4.json b/advisories/unreviewed/2024/06/GHSA-m6hr-8q9f-92q4/GHSA-m6hr-8q9f-92q4.json index 3d1c619b9cc..fd1cd9b0fbe 100644 --- a/advisories/unreviewed/2024/06/GHSA-m6hr-8q9f-92q4/GHSA-m6hr-8q9f-92q4.json +++ b/advisories/unreviewed/2024/06/GHSA-m6hr-8q9f-92q4/GHSA-m6hr-8q9f-92q4.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-rxxp-gpv7-w3c9/GHSA-rxxp-gpv7-w3c9.json b/advisories/unreviewed/2024/06/GHSA-rxxp-gpv7-w3c9/GHSA-rxxp-gpv7-w3c9.json index cd5d9fec999..408e7f24a91 100644 --- a/advisories/unreviewed/2024/06/GHSA-rxxp-gpv7-w3c9/GHSA-rxxp-gpv7-w3c9.json +++ b/advisories/unreviewed/2024/06/GHSA-rxxp-gpv7-w3c9/GHSA-rxxp-gpv7-w3c9.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-vjx7-hf5r-chv4/GHSA-vjx7-hf5r-chv4.json b/advisories/unreviewed/2024/06/GHSA-vjx7-hf5r-chv4/GHSA-vjx7-hf5r-chv4.json index 3c2826a85e5..cc42391536f 100644 --- a/advisories/unreviewed/2024/06/GHSA-vjx7-hf5r-chv4/GHSA-vjx7-hf5r-chv4.json +++ b/advisories/unreviewed/2024/06/GHSA-vjx7-hf5r-chv4/GHSA-vjx7-hf5r-chv4.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-601" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-c7r5-8gm8-mxqv/GHSA-c7r5-8gm8-mxqv.json b/advisories/unreviewed/2024/07/GHSA-c7r5-8gm8-mxqv/GHSA-c7r5-8gm8-mxqv.json index 276684307a7..2a349dfe07a 100644 --- a/advisories/unreviewed/2024/07/GHSA-c7r5-8gm8-mxqv/GHSA-c7r5-8gm8-mxqv.json +++ b/advisories/unreviewed/2024/07/GHSA-c7r5-8gm8-mxqv/GHSA-c7r5-8gm8-mxqv.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-jw4h-9877-397h/GHSA-jw4h-9877-397h.json b/advisories/unreviewed/2024/07/GHSA-jw4h-9877-397h/GHSA-jw4h-9877-397h.json index d80f6f5d87d..db887a61ff6 100644 --- a/advisories/unreviewed/2024/07/GHSA-jw4h-9877-397h/GHSA-jw4h-9877-397h.json +++ b/advisories/unreviewed/2024/07/GHSA-jw4h-9877-397h/GHSA-jw4h-9877-397h.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-p7f8-9f83-g966/GHSA-p7f8-9f83-g966.json b/advisories/unreviewed/2024/07/GHSA-p7f8-9f83-g966/GHSA-p7f8-9f83-g966.json index 198c30f636b..b7f28236755 100644 --- a/advisories/unreviewed/2024/07/GHSA-p7f8-9f83-g966/GHSA-p7f8-9f83-g966.json +++ b/advisories/unreviewed/2024/07/GHSA-p7f8-9f83-g966/GHSA-p7f8-9f83-g966.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-rfwq-7qrf-xm4m/GHSA-rfwq-7qrf-xm4m.json b/advisories/unreviewed/2024/07/GHSA-rfwq-7qrf-xm4m/GHSA-rfwq-7qrf-xm4m.json index dc76e64f333..b662f428aae 100644 --- a/advisories/unreviewed/2024/07/GHSA-rfwq-7qrf-xm4m/GHSA-rfwq-7qrf-xm4m.json +++ b/advisories/unreviewed/2024/07/GHSA-rfwq-7qrf-xm4m/GHSA-rfwq-7qrf-xm4m.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-258r-rc8h-56rv/GHSA-258r-rc8h-56rv.json b/advisories/unreviewed/2025/05/GHSA-258r-rc8h-56rv/GHSA-258r-rc8h-56rv.json new file mode 100644 index 00000000000..8ea2c01e32f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-258r-rc8h-56rv/GHSA-258r-rc8h-56rv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-258r-rc8h-56rv", + "modified": "2025-05-19T21:30:34Z", + "published": "2025-05-19T21:30:34Z", + "aliases": [ + "CVE-2025-39365" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rocket Apps wProject allows Reflected XSS.This issue affects wProject: from n/a before 5.8.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39365" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/wproject/vulnerability/wordpress-wproject-theme-5-8-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T20:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-28xq-f23c-p68m/GHSA-28xq-f23c-p68m.json b/advisories/unreviewed/2025/05/GHSA-28xq-f23c-p68m/GHSA-28xq-f23c-p68m.json new file mode 100644 index 00000000000..d902c4a14f2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-28xq-f23c-p68m/GHSA-28xq-f23c-p68m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-28xq-f23c-p68m", + "modified": "2025-05-19T21:30:33Z", + "published": "2025-05-19T21:30:33Z", + "aliases": [ + "CVE-2025-43838" + ], + "details": "Missing Authorization vulnerability in ChoPlugins Custom PC Builder Lite for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Custom PC Builder Lite for WooCommerce: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43838" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/custom-pc-builder-lite-for-woocommerce/vulnerability/wordpress-custom-pc-builder-lite-for-woocommerce-1-0-1-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T19:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2gj6-8x44-7f5c/GHSA-2gj6-8x44-7f5c.json b/advisories/unreviewed/2025/05/GHSA-2gj6-8x44-7f5c/GHSA-2gj6-8x44-7f5c.json new file mode 100644 index 00000000000..73f3c249a39 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2gj6-8x44-7f5c/GHSA-2gj6-8x44-7f5c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2gj6-8x44-7f5c", + "modified": "2025-05-19T21:30:32Z", + "published": "2025-05-19T21:30:32Z", + "aliases": [ + "CVE-2025-39446" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pluggabl LLC Booster Plus for WooCommerce allows Reflected XSS.This issue affects Booster Plus for WooCommerce: from n/a through 7.2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39446" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/booster-plus-for-woocommerce/vulnerability/wordpress-booster-plus-for-woocommerce-plugin-7-2-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T19:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-33v4-3fqc-hxh5/GHSA-33v4-3fqc-hxh5.json b/advisories/unreviewed/2025/05/GHSA-33v4-3fqc-hxh5/GHSA-33v4-3fqc-hxh5.json new file mode 100644 index 00000000000..f372bb79b89 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-33v4-3fqc-hxh5/GHSA-33v4-3fqc-hxh5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-33v4-3fqc-hxh5", + "modified": "2025-05-19T21:30:34Z", + "published": "2025-05-19T21:30:34Z", + "aliases": [ + "CVE-2025-32925" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in FantasticPlugins SUMO Reward Points allows PHP Local File Inclusion.This issue affects SUMO Reward Points: from n/a through 30.7.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32925" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/rewardsystem/vulnerability/wordpress-sumo-reward-points-plugin-30-7-0-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T20:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-357g-hmp7-jxcf/GHSA-357g-hmp7-jxcf.json b/advisories/unreviewed/2025/05/GHSA-357g-hmp7-jxcf/GHSA-357g-hmp7-jxcf.json index bdcc9757716..ddd5509bb60 100644 --- a/advisories/unreviewed/2025/05/GHSA-357g-hmp7-jxcf/GHSA-357g-hmp7-jxcf.json +++ b/advisories/unreviewed/2025/05/GHSA-357g-hmp7-jxcf/GHSA-357g-hmp7-jxcf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-357g-hmp7-jxcf", - "modified": "2025-05-15T15:31:27Z", + "modified": "2025-05-19T21:30:30Z", "published": "2025-05-15T15:31:27Z", "aliases": [ "CVE-2025-44185" ], "details": "SourceCodester Best Employee Management System V1.0 is vulnerable to Cross Site Request Forgery (CSRF) in /admin/change_pass.php via the password parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T15:16:10Z" diff --git a/advisories/unreviewed/2025/05/GHSA-4f7m-v6hv-9hcr/GHSA-4f7m-v6hv-9hcr.json b/advisories/unreviewed/2025/05/GHSA-4f7m-v6hv-9hcr/GHSA-4f7m-v6hv-9hcr.json index b063dd3e536..e4b039e4679 100644 --- a/advisories/unreviewed/2025/05/GHSA-4f7m-v6hv-9hcr/GHSA-4f7m-v6hv-9hcr.json +++ b/advisories/unreviewed/2025/05/GHSA-4f7m-v6hv-9hcr/GHSA-4f7m-v6hv-9hcr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4f7m-v6hv-9hcr", - "modified": "2025-05-15T18:31:45Z", + "modified": "2025-05-19T21:30:31Z", "published": "2025-05-15T18:31:45Z", "aliases": [ "CVE-2024-52879" ], "details": "An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 05.54.50, kernel 5.6 before version 05.61.50, and kernel 5.7 before version 05.70.50. In VariableRuntimeDxe driver, SmmUpdateVariablePropertySmi () is a SMM callback function and it uses StrCmp () to compare variable names. This action may cause a buffer over-read.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-126" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T16:15:33Z" diff --git a/advisories/unreviewed/2025/05/GHSA-4qcc-c9vm-4w36/GHSA-4qcc-c9vm-4w36.json b/advisories/unreviewed/2025/05/GHSA-4qcc-c9vm-4w36/GHSA-4qcc-c9vm-4w36.json new file mode 100644 index 00000000000..48c85538107 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4qcc-c9vm-4w36/GHSA-4qcc-c9vm-4w36.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4qcc-c9vm-4w36", + "modified": "2025-05-19T21:30:34Z", + "published": "2025-05-19T21:30:34Z", + "aliases": [ + "CVE-2025-39372" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in elbisnero WordPress Events Calendar Registration & Tickets allows Reflected XSS.This issue affects WordPress Events Calendar Registration & Tickets: from n/a through 2.6.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39372" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpeventplus/vulnerability/wordpress-wordpress-events-calendar-registration-tickets-plugin-2-6-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T20:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5742-qxvw-5848/GHSA-5742-qxvw-5848.json b/advisories/unreviewed/2025/05/GHSA-5742-qxvw-5848/GHSA-5742-qxvw-5848.json new file mode 100644 index 00000000000..660f92f7e47 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5742-qxvw-5848/GHSA-5742-qxvw-5848.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5742-qxvw-5848", + "modified": "2025-05-19T21:30:33Z", + "published": "2025-05-19T21:30:33Z", + "aliases": [ + "CVE-2025-39459" + ], + "details": "Incorrect Privilege Assignment vulnerability in Contempo Themes Real Estate 7 allows Privilege Escalation.This issue affects Real Estate 7: from n/a through 3.5.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39459" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/realestate-7/vulnerability/wordpress-real-estate-7-theme-3-5-2-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T19:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-66q6-24vw-2g98/GHSA-66q6-24vw-2g98.json b/advisories/unreviewed/2025/05/GHSA-66q6-24vw-2g98/GHSA-66q6-24vw-2g98.json index 5f5f808e647..8179aa57f73 100644 --- a/advisories/unreviewed/2025/05/GHSA-66q6-24vw-2g98/GHSA-66q6-24vw-2g98.json +++ b/advisories/unreviewed/2025/05/GHSA-66q6-24vw-2g98/GHSA-66q6-24vw-2g98.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-22" + "CWE-22", + "CWE-24" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-66wx-257c-489x/GHSA-66wx-257c-489x.json b/advisories/unreviewed/2025/05/GHSA-66wx-257c-489x/GHSA-66wx-257c-489x.json new file mode 100644 index 00000000000..280e3b18cb5 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-66wx-257c-489x/GHSA-66wx-257c-489x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-66wx-257c-489x", + "modified": "2025-05-19T21:30:35Z", + "published": "2025-05-19T21:30:35Z", + "aliases": [ + "CVE-2025-48340" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Danny Vink User Profile Meta Manager allows Privilege Escalation.This issue affects User Profile Meta Manager: from n/a through 1.02.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48340" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/user-profile-meta/vulnerability/wordpress-user-profile-meta-manager-plugin-1-02-csrf-to-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T21:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6r4g-8vrx-4gmq/GHSA-6r4g-8vrx-4gmq.json b/advisories/unreviewed/2025/05/GHSA-6r4g-8vrx-4gmq/GHSA-6r4g-8vrx-4gmq.json new file mode 100644 index 00000000000..9b89be22cda --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6r4g-8vrx-4gmq/GHSA-6r4g-8vrx-4gmq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6r4g-8vrx-4gmq", + "modified": "2025-05-19T21:30:34Z", + "published": "2025-05-19T21:30:34Z", + "aliases": [ + "CVE-2025-39350" + ], + "details": "Missing Authorization vulnerability in Rocket Apps wProject.This issue affects wProject: from n/a before 5.8.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39350" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/wproject/vulnerability/wordpress-wproject-theme-5-8-0-unauthenticated-post-comment-attachment-modification-deletion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T20:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-75pg-hm2h-v575/GHSA-75pg-hm2h-v575.json b/advisories/unreviewed/2025/05/GHSA-75pg-hm2h-v575/GHSA-75pg-hm2h-v575.json new file mode 100644 index 00000000000..d21e55ac9d1 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-75pg-hm2h-v575/GHSA-75pg-hm2h-v575.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75pg-hm2h-v575", + "modified": "2025-05-19T21:30:34Z", + "published": "2025-05-19T21:30:34Z", + "aliases": [ + "CVE-2025-39352" + ], + "details": "Missing Authorization vulnerability in ThemeGoods Grand Restaurant WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Grand Restaurant WordPress: from n/a through 7.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39352" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/grandrestaurant/vulnerability/wordpress-grand-restaurant-wordpress-theme-7-0-arbitrary-options-deletion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T20:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-775f-97x4-x974/GHSA-775f-97x4-x974.json b/advisories/unreviewed/2025/05/GHSA-775f-97x4-x974/GHSA-775f-97x4-x974.json index 0a35740b2ac..d2c4bedb6cc 100644 --- a/advisories/unreviewed/2025/05/GHSA-775f-97x4-x974/GHSA-775f-97x4-x974.json +++ b/advisories/unreviewed/2025/05/GHSA-775f-97x4-x974/GHSA-775f-97x4-x974.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-775f-97x4-x974", - "modified": "2025-05-15T15:31:27Z", + "modified": "2025-05-19T21:30:30Z", "published": "2025-05-15T15:31:27Z", "aliases": [ "CVE-2025-46053" ], "details": "A SQL Injection vulnerability in WebERP v4.15.2 allows attackers to execute arbitrary SQL commands and extract sensitive data by injecting a crafted payload into the ReportID and ReplaceReportID parameters within a POST request to /reportwriter/admin/ReportCreator.php", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T15:16:10Z" diff --git a/advisories/unreviewed/2025/05/GHSA-77cx-wrr4-hvr9/GHSA-77cx-wrr4-hvr9.json b/advisories/unreviewed/2025/05/GHSA-77cx-wrr4-hvr9/GHSA-77cx-wrr4-hvr9.json new file mode 100644 index 00000000000..ab476c2b6c3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-77cx-wrr4-hvr9/GHSA-77cx-wrr4-hvr9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-77cx-wrr4-hvr9", + "modified": "2025-05-19T21:30:34Z", + "published": "2025-05-19T21:30:34Z", + "aliases": [ + "CVE-2025-39386" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla Hospital Management System allows SQL Injection.This issue affects Hospital Management System: from n/a through 47.0(20-11-2023).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39386" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/hospital-management/vulnerability/wordpress-hospital-management-system-plugin-47-0-20-11-2023-sql-injection-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T20:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7c8r-v4x3-jvvm/GHSA-7c8r-v4x3-jvvm.json b/advisories/unreviewed/2025/05/GHSA-7c8r-v4x3-jvvm/GHSA-7c8r-v4x3-jvvm.json new file mode 100644 index 00000000000..3286f5d01f5 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7c8r-v4x3-jvvm/GHSA-7c8r-v4x3-jvvm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7c8r-v4x3-jvvm", + "modified": "2025-05-19T21:30:34Z", + "published": "2025-05-19T21:30:34Z", + "aliases": [ + "CVE-2025-32926" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThemeGoods Grand Restaurant WordPress allows Path Traversal.This issue affects Grand Restaurant WordPress: from n/a through 7.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32926" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/grandrestaurant/vulnerability/wordpress-grand-restaurant-wordpress-theme-7-0-path-traversal-to-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T20:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7hp3-hv9v-w85q/GHSA-7hp3-hv9v-w85q.json b/advisories/unreviewed/2025/05/GHSA-7hp3-hv9v-w85q/GHSA-7hp3-hv9v-w85q.json new file mode 100644 index 00000000000..07df359a29c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7hp3-hv9v-w85q/GHSA-7hp3-hv9v-w85q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7hp3-hv9v-w85q", + "modified": "2025-05-19T21:30:35Z", + "published": "2025-05-19T21:30:35Z", + "aliases": [ + "CVE-2025-3223" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in GE Vernova WorkstationST on Windows (EGD Configuration Server modules) allows Path Traversal.This issue affects WorkstationST: WorkstationST V07.10.10C and earlier.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3223" + }, + { + "type": "WEB", + "url": "https://www.gevernova.com/content/dam/cyber_security/global/en_US/pdfs/2024-09-24_EGD_Config_Server_File_Overwrite.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T21:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-848q-rw57-4rf8/GHSA-848q-rw57-4rf8.json b/advisories/unreviewed/2025/05/GHSA-848q-rw57-4rf8/GHSA-848q-rw57-4rf8.json new file mode 100644 index 00000000000..5d3e944ab6a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-848q-rw57-4rf8/GHSA-848q-rw57-4rf8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-848q-rw57-4rf8", + "modified": "2025-05-19T21:30:34Z", + "published": "2025-05-19T21:30:34Z", + "aliases": [ + "CVE-2025-32928" + ], + "details": "Deserialization of Untrusted Data vulnerability in ThemeGoods Altair allows Object Injection.This issue affects Altair: from n/a through 5.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32928" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/altair/vulnerability/wordpress-altair-theme-5-2-2-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T20:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8797-93f2-f3hv/GHSA-8797-93f2-f3hv.json b/advisories/unreviewed/2025/05/GHSA-8797-93f2-f3hv/GHSA-8797-93f2-f3hv.json new file mode 100644 index 00000000000..a35c2dba8da --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8797-93f2-f3hv/GHSA-8797-93f2-f3hv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8797-93f2-f3hv", + "modified": "2025-05-19T21:30:33Z", + "published": "2025-05-19T21:30:33Z", + "aliases": [ + "CVE-2025-43839" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shanebp BP Messages Tool allows Reflected XSS.This issue affects BP Messages Tool: from n/a through 2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43839" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bp-messages-tool/vulnerability/wordpress-bp-messages-tool-plugin-2-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T19:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8g92-fqgw-q495/GHSA-8g92-fqgw-q495.json b/advisories/unreviewed/2025/05/GHSA-8g92-fqgw-q495/GHSA-8g92-fqgw-q495.json index 5e4f3c4d418..8ed37754c9c 100644 --- a/advisories/unreviewed/2025/05/GHSA-8g92-fqgw-q495/GHSA-8g92-fqgw-q495.json +++ b/advisories/unreviewed/2025/05/GHSA-8g92-fqgw-q495/GHSA-8g92-fqgw-q495.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8g92-fqgw-q495", - "modified": "2025-05-19T15:30:59Z", + "modified": "2025-05-19T21:30:31Z", "published": "2025-05-19T15:30:59Z", "aliases": [ "CVE-2025-44108" ], "details": "A stored Cross-Site Scripting (XSS) vulnerability exists in the administration panel of Flatpress CMS before 1.4 via the gallery captions component. An attacker with admin privileges can inject a malicious JavaScript payload into the system, which is then stored persistently.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-19T14:15:24Z" diff --git a/advisories/unreviewed/2025/05/GHSA-9458-hcvv-2c36/GHSA-9458-hcvv-2c36.json b/advisories/unreviewed/2025/05/GHSA-9458-hcvv-2c36/GHSA-9458-hcvv-2c36.json new file mode 100644 index 00000000000..8d98c3f0292 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9458-hcvv-2c36/GHSA-9458-hcvv-2c36.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9458-hcvv-2c36", + "modified": "2025-05-19T21:30:34Z", + "published": "2025-05-19T21:30:34Z", + "aliases": [ + "CVE-2025-39392" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mojoomla WPAMS allows Reflected XSS.This issue affects WPAMS: from n/a through 44.0 (17-08-2023).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39392" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/apartment-management/vulnerability/wordpress-wpams-plugin-44-0-17-08-2023-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T20:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9j2q-rv22-36xm/GHSA-9j2q-rv22-36xm.json b/advisories/unreviewed/2025/05/GHSA-9j2q-rv22-36xm/GHSA-9j2q-rv22-36xm.json index d4434f3b066..537b0657b2c 100644 --- a/advisories/unreviewed/2025/05/GHSA-9j2q-rv22-36xm/GHSA-9j2q-rv22-36xm.json +++ b/advisories/unreviewed/2025/05/GHSA-9j2q-rv22-36xm/GHSA-9j2q-rv22-36xm.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-9v5x-rh5f-9mfh/GHSA-9v5x-rh5f-9mfh.json b/advisories/unreviewed/2025/05/GHSA-9v5x-rh5f-9mfh/GHSA-9v5x-rh5f-9mfh.json new file mode 100644 index 00000000000..d7e67fe7124 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9v5x-rh5f-9mfh/GHSA-9v5x-rh5f-9mfh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9v5x-rh5f-9mfh", + "modified": "2025-05-19T21:30:32Z", + "published": "2025-05-19T21:30:32Z", + "aliases": [ + "CVE-2025-39410" + ], + "details": "Deserialization of Untrusted Data vulnerability in themegusta Smart Sections Theme Builder - WPBakery Page Builder Addon.This issue affects Smart Sections Theme Builder - WPBakery Page Builder Addon: from n/a through 1.7.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39410" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/visucom-smart-sections/vulnerability/wordpress-smart-sections-theme-builder-wpbakery-page-builder-addon-plugin-1-7-8-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T19:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-crp9-8xr4-fg7p/GHSA-crp9-8xr4-fg7p.json b/advisories/unreviewed/2025/05/GHSA-crp9-8xr4-fg7p/GHSA-crp9-8xr4-fg7p.json new file mode 100644 index 00000000000..27c1c314099 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-crp9-8xr4-fg7p/GHSA-crp9-8xr4-fg7p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crp9-8xr4-fg7p", + "modified": "2025-05-19T21:30:34Z", + "published": "2025-05-19T21:30:34Z", + "aliases": [ + "CVE-2025-39366" + ], + "details": "Incorrect Privilege Assignment vulnerability in Rocket Apps wProject.This issue affects wProject: from n/a before 5.8.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39366" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/wproject/vulnerability/wordpress-wproject-theme-5-8-0-subscriber-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T20:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fhgm-mxgh-gfpj/GHSA-fhgm-mxgh-gfpj.json b/advisories/unreviewed/2025/05/GHSA-fhgm-mxgh-gfpj/GHSA-fhgm-mxgh-gfpj.json index dff32291c60..03d71214201 100644 --- a/advisories/unreviewed/2025/05/GHSA-fhgm-mxgh-gfpj/GHSA-fhgm-mxgh-gfpj.json +++ b/advisories/unreviewed/2025/05/GHSA-fhgm-mxgh-gfpj/GHSA-fhgm-mxgh-gfpj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fhgm-mxgh-gfpj", - "modified": "2025-05-18T21:30:20Z", + "modified": "2025-05-19T21:30:31Z", "published": "2025-05-18T00:30:27Z", "aliases": [ "CVE-2025-4918" ], "details": "An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object. This vulnerability affects Firefox ESR < 115.23.1.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-17T22:15:19Z" diff --git a/advisories/unreviewed/2025/05/GHSA-fq8m-56f9-pv5r/GHSA-fq8m-56f9-pv5r.json b/advisories/unreviewed/2025/05/GHSA-fq8m-56f9-pv5r/GHSA-fq8m-56f9-pv5r.json new file mode 100644 index 00000000000..63905c1145d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fq8m-56f9-pv5r/GHSA-fq8m-56f9-pv5r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fq8m-56f9-pv5r", + "modified": "2025-05-19T21:30:32Z", + "published": "2025-05-19T21:30:32Z", + "aliases": [ + "CVE-2025-39409" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pressaholic WordPress Video Robot - The Ultimate Video Importer.This issue affects WordPress Video Robot - The Ultimate Video Importer: from n/a through 1.20.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39409" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-video-robot/vulnerability/wordpress-wordpress-video-robot-the-ultimate-video-importer-plugin-1-20-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T19:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fx4h-5r26-fxgm/GHSA-fx4h-5r26-fxgm.json b/advisories/unreviewed/2025/05/GHSA-fx4h-5r26-fxgm/GHSA-fx4h-5r26-fxgm.json new file mode 100644 index 00000000000..57b80ae1815 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fx4h-5r26-fxgm/GHSA-fx4h-5r26-fxgm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fx4h-5r26-fxgm", + "modified": "2025-05-19T21:30:33Z", + "published": "2025-05-19T21:30:33Z", + "aliases": [ + "CVE-2025-47577" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in TemplateInvaders TI WooCommerce Wishlist allows Upload a Web Shell to a Web Server.This issue affects TI WooCommerce Wishlist: from n/a through 2.9.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47577" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ti-woocommerce-wishlist/vulnerability/wordpress-ti-woocommerce-wishlist-2-9-2-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T19:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gj42-cfph-mjj4/GHSA-gj42-cfph-mjj4.json b/advisories/unreviewed/2025/05/GHSA-gj42-cfph-mjj4/GHSA-gj42-cfph-mjj4.json index cdd8f67744f..69c9a6c3fbb 100644 --- a/advisories/unreviewed/2025/05/GHSA-gj42-cfph-mjj4/GHSA-gj42-cfph-mjj4.json +++ b/advisories/unreviewed/2025/05/GHSA-gj42-cfph-mjj4/GHSA-gj42-cfph-mjj4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gj42-cfph-mjj4", - "modified": "2025-05-15T18:31:44Z", + "modified": "2025-05-19T21:30:30Z", "published": "2025-05-15T18:31:44Z", "aliases": [ "CVE-2024-52877" ], "details": "An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 05.54.50, kernel 5.6 before version 05.61.50, and kernel 5.7 before version 05.70.50. In VariableRuntimeDxe driver, callback function SmmCreateVariableLockList () calls CreateVariableLockListInSmm (). In CreateVariableLockListInSmm (), it uses StrSize () to get variable name size and it could lead to a buffer over-read.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-126" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T16:15:32Z" diff --git a/advisories/unreviewed/2025/05/GHSA-gjpm-x9rf-g2j2/GHSA-gjpm-x9rf-g2j2.json b/advisories/unreviewed/2025/05/GHSA-gjpm-x9rf-g2j2/GHSA-gjpm-x9rf-g2j2.json new file mode 100644 index 00000000000..a0f3a47f929 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gjpm-x9rf-g2j2/GHSA-gjpm-x9rf-g2j2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gjpm-x9rf-g2j2", + "modified": "2025-05-19T21:30:34Z", + "published": "2025-05-19T21:30:34Z", + "aliases": [ + "CVE-2025-39356" + ], + "details": "Deserialization of Untrusted Data vulnerability in Chimpstudio Foodbakery Sticky Cart allows Object Injection.This issue affects Foodbakery Sticky Cart: from n/a through 3.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39356" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/foodbakery-sticky-cart/vulnerability/wordpress-foodbakery-sticky-cart-plugin-3-2-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T20:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gv25-7gvw-4p47/GHSA-gv25-7gvw-4p47.json b/advisories/unreviewed/2025/05/GHSA-gv25-7gvw-4p47/GHSA-gv25-7gvw-4p47.json new file mode 100644 index 00000000000..2e5e5472938 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gv25-7gvw-4p47/GHSA-gv25-7gvw-4p47.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gv25-7gvw-4p47", + "modified": "2025-05-19T21:30:32Z", + "published": "2025-05-19T21:30:32Z", + "aliases": [ + "CVE-2025-39411" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Indie_Plugins WhatsApp Click to Chat Plugin for WordPress.This issue affects WhatsApp Click to Chat Plugin for WordPress: from n/a through 2.2.12.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39411" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpt-whatsapp/vulnerability/wordpress-whatsapp-click-to-chat-plugin-for-wordpress-plugin-2-2-12-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T19:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gx2x-4jjf-6wf2/GHSA-gx2x-4jjf-6wf2.json b/advisories/unreviewed/2025/05/GHSA-gx2x-4jjf-6wf2/GHSA-gx2x-4jjf-6wf2.json new file mode 100644 index 00000000000..2f80cb561f4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gx2x-4jjf-6wf2/GHSA-gx2x-4jjf-6wf2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gx2x-4jjf-6wf2", + "modified": "2025-05-19T21:30:34Z", + "published": "2025-05-19T21:30:34Z", + "aliases": [ + "CVE-2025-39349" + ], + "details": "Deserialization of Untrusted Data vulnerability in Potenzaglobalsolutions CiyaShop allows Object Injection.This issue affects CiyaShop: from n/a through 4.18.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39349" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/ciyashop/vulnerability/wordpress-ciyashop-theme-4-18-0-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T20:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h5cq-h88x-4gq5/GHSA-h5cq-h88x-4gq5.json b/advisories/unreviewed/2025/05/GHSA-h5cq-h88x-4gq5/GHSA-h5cq-h88x-4gq5.json new file mode 100644 index 00000000000..49aa8a41388 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h5cq-h88x-4gq5/GHSA-h5cq-h88x-4gq5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h5cq-h88x-4gq5", + "modified": "2025-05-19T21:30:33Z", + "published": "2025-05-19T21:30:33Z", + "aliases": [ + "CVE-2025-43837" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in binti76 Total Donations allows Reflected XSS.This issue affects Total Donations: from n/a through 3.0.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43837" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/total-donations/vulnerability/wordpress-total-donations-3-0-8-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T19:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h67r-f4jm-f2hc/GHSA-h67r-f4jm-f2hc.json b/advisories/unreviewed/2025/05/GHSA-h67r-f4jm-f2hc/GHSA-h67r-f4jm-f2hc.json new file mode 100644 index 00000000000..231403b4476 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h67r-f4jm-f2hc/GHSA-h67r-f4jm-f2hc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h67r-f4jm-f2hc", + "modified": "2025-05-19T21:30:33Z", + "published": "2025-05-19T21:30:33Z", + "aliases": [ + "CVE-2025-39458" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Foton allows PHP Local File Inclusion.This issue affects Foton: from n/a through 2.5.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39458" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/foton/vulnerability/wordpress-foton-theme-2-5-2-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T19:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-j23f-5pvr-62h7/GHSA-j23f-5pvr-62h7.json b/advisories/unreviewed/2025/05/GHSA-j23f-5pvr-62h7/GHSA-j23f-5pvr-62h7.json new file mode 100644 index 00000000000..bdb93138b4b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-j23f-5pvr-62h7/GHSA-j23f-5pvr-62h7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j23f-5pvr-62h7", + "modified": "2025-05-19T21:30:34Z", + "published": "2025-05-19T21:30:34Z", + "aliases": [ + "CVE-2025-39380" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla Hospital Management System allows Upload a Web Shell to a Web Server.This issue affects Hospital Management System: from n/a through 47.0(20-11-2023).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39380" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/hospital-management/vulnerability/wordpress-hospital-management-system-plugin-47-0-20-11-2023-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T20:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-j6mm-98gm-g9jj/GHSA-j6mm-98gm-g9jj.json b/advisories/unreviewed/2025/05/GHSA-j6mm-98gm-g9jj/GHSA-j6mm-98gm-g9jj.json new file mode 100644 index 00000000000..0928e975ada --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-j6mm-98gm-g9jj/GHSA-j6mm-98gm-g9jj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6mm-98gm-g9jj", + "modified": "2025-05-19T21:30:34Z", + "published": "2025-05-19T21:30:34Z", + "aliases": [ + "CVE-2025-39348" + ], + "details": "Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Restaurant WordPress allows Object Injection.This issue affects Grand Restaurant WordPress: from n/a through 7.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39348" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/grandrestaurant/vulnerability/wordpress-grand-restaurant-wordpress-theme-7-0-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T20:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-m7rf-rfhp-h3m3/GHSA-m7rf-rfhp-h3m3.json b/advisories/unreviewed/2025/05/GHSA-m7rf-rfhp-h3m3/GHSA-m7rf-rfhp-h3m3.json new file mode 100644 index 00000000000..1165f2b0bd4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-m7rf-rfhp-h3m3/GHSA-m7rf-rfhp-h3m3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m7rf-rfhp-h3m3", + "modified": "2025-05-19T21:30:34Z", + "published": "2025-05-19T21:30:34Z", + "aliases": [ + "CVE-2025-46441" + ], + "details": "Path Traversal: '.../...//' vulnerability in ctltwp Section Widget allows Path Traversal.This issue affects Section Widget: from n/a through 3.3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46441" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/section-widget/vulnerability/wordpress-section-widget-plugin-3-2-5-path-traversal-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-35" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T20:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p5p2-m2mh-3r9v/GHSA-p5p2-m2mh-3r9v.json b/advisories/unreviewed/2025/05/GHSA-p5p2-m2mh-3r9v/GHSA-p5p2-m2mh-3r9v.json new file mode 100644 index 00000000000..8f99934d39e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p5p2-m2mh-3r9v/GHSA-p5p2-m2mh-3r9v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p5p2-m2mh-3r9v", + "modified": "2025-05-19T21:30:34Z", + "published": "2025-05-19T21:30:34Z", + "aliases": [ + "CVE-2025-39354" + ], + "details": "Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Conference allows Object Injection.This issue affects Grand Conference: from n/a through 5.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39354" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/grandconference/vulnerability/wordpress-grand-conference-theme-5-2-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T20:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-pqfx-2rpj-fmv3/GHSA-pqfx-2rpj-fmv3.json b/advisories/unreviewed/2025/05/GHSA-pqfx-2rpj-fmv3/GHSA-pqfx-2rpj-fmv3.json new file mode 100644 index 00000000000..840a71aca0e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pqfx-2rpj-fmv3/GHSA-pqfx-2rpj-fmv3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pqfx-2rpj-fmv3", + "modified": "2025-05-19T21:30:34Z", + "published": "2025-05-19T21:30:34Z", + "aliases": [ + "CVE-2025-39357" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla Hospital Management System allows SQL Injection.This issue affects Hospital Management System: from n/a through 47.0(20-11-2023).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39357" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/hospital-management/vulnerability/wordpress-hospital-management-system-plugin-47-0-20-11-2023-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T20:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qc53-6pcv-3q2p/GHSA-qc53-6pcv-3q2p.json b/advisories/unreviewed/2025/05/GHSA-qc53-6pcv-3q2p/GHSA-qc53-6pcv-3q2p.json index 86fe2f96128..adcbf4d8961 100644 --- a/advisories/unreviewed/2025/05/GHSA-qc53-6pcv-3q2p/GHSA-qc53-6pcv-3q2p.json +++ b/advisories/unreviewed/2025/05/GHSA-qc53-6pcv-3q2p/GHSA-qc53-6pcv-3q2p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qc53-6pcv-3q2p", - "modified": "2025-05-15T18:31:44Z", + "modified": "2025-05-19T21:30:31Z", "published": "2025-05-15T18:31:44Z", "aliases": [ "CVE-2024-52878" ], "details": "An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 05.54.50, kernel 5.6 before version 05.61.50, and kernel 5.7 before version 05.70.50. In VariableRuntimeDxe driver, VariableServicesSetVariable () can be called by gRT_>SetVariable () or the SmmSetSensitiveVariable () or SmmInternalSetVariable () from SMM. In VariableServicesSetVariable (), it uses StrSize () to get variable name size, uses StrLen () to get variable name length and uses StrCmp () to compare strings. These actions may cause a buffer over-read.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-126" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T16:15:32Z" diff --git a/advisories/unreviewed/2025/05/GHSA-qwp7-w63j-vxcr/GHSA-qwp7-w63j-vxcr.json b/advisories/unreviewed/2025/05/GHSA-qwp7-w63j-vxcr/GHSA-qwp7-w63j-vxcr.json new file mode 100644 index 00000000000..373a0824e20 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qwp7-w63j-vxcr/GHSA-qwp7-w63j-vxcr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qwp7-w63j-vxcr", + "modified": "2025-05-19T21:30:33Z", + "published": "2025-05-19T21:30:33Z", + "aliases": [ + "CVE-2025-47581" + ], + "details": "Deserialization of Untrusted Data vulnerability in Elbisnero WordPress Events Calendar Registration & Tickets allows Object Injection.This issue affects WordPress Events Calendar Registration & Tickets: from n/a through 2.6.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47581" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpeventplus/vulnerability/wordpress-wordpress-events-calendar-registration-tickets-plugin-2-6-0-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T19:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-r6hq-8qvx-xrxp/GHSA-r6hq-8qvx-xrxp.json b/advisories/unreviewed/2025/05/GHSA-r6hq-8qvx-xrxp/GHSA-r6hq-8qvx-xrxp.json new file mode 100644 index 00000000000..3bd95027f7d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-r6hq-8qvx-xrxp/GHSA-r6hq-8qvx-xrxp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r6hq-8qvx-xrxp", + "modified": "2025-05-19T21:30:31Z", + "published": "2025-05-19T21:30:31Z", + "aliases": [ + "CVE-2025-39405" + ], + "details": "Incorrect Privilege Assignment vulnerability in mojoomla WPAMS allows Privilege Escalation.This issue affects WPAMS: from n/a through 44.0 (17-08-2023).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39405" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/apartment-management/vulnerability/wordpress-wpams-plugin-44-0-17-08-2023-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T19:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-r7vh-rp85-3p35/GHSA-r7vh-rp85-3p35.json b/advisories/unreviewed/2025/05/GHSA-r7vh-rp85-3p35/GHSA-r7vh-rp85-3p35.json new file mode 100644 index 00000000000..101c2dda529 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-r7vh-rp85-3p35/GHSA-r7vh-rp85-3p35.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r7vh-rp85-3p35", + "modified": "2025-05-19T21:30:33Z", + "published": "2025-05-19T21:30:33Z", + "aliases": [ + "CVE-2025-43836" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in confuzzledduck Syndicate Out allows Reflected XSS.This issue affects Syndicate Out: from n/a through 0.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43836" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/syndicate-out/vulnerability/wordpress-syndicate-out-0-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T19:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rhc9-85rp-3j38/GHSA-rhc9-85rp-3j38.json b/advisories/unreviewed/2025/05/GHSA-rhc9-85rp-3j38/GHSA-rhc9-85rp-3j38.json new file mode 100644 index 00000000000..509ce1c89e9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rhc9-85rp-3j38/GHSA-rhc9-85rp-3j38.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rhc9-85rp-3j38", + "modified": "2025-05-19T21:30:34Z", + "published": "2025-05-19T21:30:34Z", + "aliases": [ + "CVE-2025-39355" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in roninwp FAT Services Booking allows SQL Injection.This issue affects FAT Services Booking: from n/a through 5.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39355" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/fat-services-booking/vulnerability/wordpress-fat-services-booking-plugin-5-6-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T20:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rhhq-38wr-94j3/GHSA-rhhq-38wr-94j3.json b/advisories/unreviewed/2025/05/GHSA-rhhq-38wr-94j3/GHSA-rhhq-38wr-94j3.json new file mode 100644 index 00000000000..9c6ce372888 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rhhq-38wr-94j3/GHSA-rhhq-38wr-94j3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rhhq-38wr-94j3", + "modified": "2025-05-19T21:30:34Z", + "published": "2025-05-19T21:30:34Z", + "aliases": [ + "CVE-2025-39389" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Solid Plugins AnalyticsWP allows SQL Injection.This issue affects AnalyticsWP: from n/a through 2.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39389" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/analyticswp/vulnerability/wordpress-analyticswp-2-1-2-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T20:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rmc6-76f7-wwpm/GHSA-rmc6-76f7-wwpm.json b/advisories/unreviewed/2025/05/GHSA-rmc6-76f7-wwpm/GHSA-rmc6-76f7-wwpm.json new file mode 100644 index 00000000000..c9832552e5d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rmc6-76f7-wwpm/GHSA-rmc6-76f7-wwpm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rmc6-76f7-wwpm", + "modified": "2025-05-19T21:30:32Z", + "published": "2025-05-19T21:30:32Z", + "aliases": [ + "CVE-2025-39447" + ], + "details": "Missing Authorization vulnerability in Crocoblock JetElements For Elementor allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JetElements For Elementor: from n/a through 2.7.4.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39447" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/jet-elements/vulnerability/wordpress-jetelements-for-elementor-2-7-4-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T19:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rr7m-4h79-q5qx/GHSA-rr7m-4h79-q5qx.json b/advisories/unreviewed/2025/05/GHSA-rr7m-4h79-q5qx/GHSA-rr7m-4h79-q5qx.json new file mode 100644 index 00000000000..9b1d6d88a66 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rr7m-4h79-q5qx/GHSA-rr7m-4h79-q5qx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rr7m-4h79-q5qx", + "modified": "2025-05-19T21:30:34Z", + "published": "2025-05-19T21:30:33Z", + "aliases": [ + "CVE-2025-32927" + ], + "details": "Deserialization of Untrusted Data vulnerability in Chimpstudio FoodBakery allows Object Injection.This issue affects FoodBakery: from n/a through 3.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32927" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-foodbakery/vulnerability/wordpress-foodbakery-plugin-3-3-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T20:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v7hf-vpqg-3mwp/GHSA-v7hf-vpqg-3mwp.json b/advisories/unreviewed/2025/05/GHSA-v7hf-vpqg-3mwp/GHSA-v7hf-vpqg-3mwp.json new file mode 100644 index 00000000000..700bbf70b7b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v7hf-vpqg-3mwp/GHSA-v7hf-vpqg-3mwp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v7hf-vpqg-3mwp", + "modified": "2025-05-19T21:30:33Z", + "published": "2025-05-19T21:30:33Z", + "aliases": [ + "CVE-2025-32924" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in roninwp Revy allows SQL Injection.This issue affects Revy: from n/a through 2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32924" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/revy/vulnerability/wordpress-revy-plugin-2-1-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T20:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vjc8-jp3q-38qw/GHSA-vjc8-jp3q-38qw.json b/advisories/unreviewed/2025/05/GHSA-vjc8-jp3q-38qw/GHSA-vjc8-jp3q-38qw.json new file mode 100644 index 00000000000..feaa78500e9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vjc8-jp3q-38qw/GHSA-vjc8-jp3q-38qw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vjc8-jp3q-38qw", + "modified": "2025-05-19T21:30:31Z", + "published": "2025-05-19T21:30:31Z", + "aliases": [ + "CVE-2025-39403" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla WPAMS allows SQL Injection.This issue affects WPAMS: from n/a through 44.0 (17-08-2023).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39403" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/apartment-management/vulnerability/wordpress-wpams-plugin-44-0-17-08-2023-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T19:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vmf3-pfxm-vf92/GHSA-vmf3-pfxm-vf92.json b/advisories/unreviewed/2025/05/GHSA-vmf3-pfxm-vf92/GHSA-vmf3-pfxm-vf92.json new file mode 100644 index 00000000000..5cfea5a817f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vmf3-pfxm-vf92/GHSA-vmf3-pfxm-vf92.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vmf3-pfxm-vf92", + "modified": "2025-05-19T21:30:34Z", + "published": "2025-05-19T21:30:34Z", + "aliases": [ + "CVE-2025-39401" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla WPAMS allows Upload a Web Shell to a Web Server.This issue affects WPAMS: from n/a through 44.0 (17-08-2023).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39401" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/apartment-management/vulnerability/wordpress-wpams-plugin-44-0-17-08-2023-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T20:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vrmh-6895-jfpm/GHSA-vrmh-6895-jfpm.json b/advisories/unreviewed/2025/05/GHSA-vrmh-6895-jfpm/GHSA-vrmh-6895-jfpm.json new file mode 100644 index 00000000000..131e6bffd82 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vrmh-6895-jfpm/GHSA-vrmh-6895-jfpm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vrmh-6895-jfpm", + "modified": "2025-05-19T21:30:32Z", + "published": "2025-05-19T21:30:32Z", + "aliases": [ + "CVE-2025-39445" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in highwarden Super Store Finder allows SQL Injection.This issue affects Super Store Finder: from n/a through 7.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39445" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/superstorefinder-wp/vulnerability/wordpress-super-store-finder-7-2-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T19:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vvpw-jpw8-hr7r/GHSA-vvpw-jpw8-hr7r.json b/advisories/unreviewed/2025/05/GHSA-vvpw-jpw8-hr7r/GHSA-vvpw-jpw8-hr7r.json new file mode 100644 index 00000000000..1c8bce8063f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vvpw-jpw8-hr7r/GHSA-vvpw-jpw8-hr7r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vvpw-jpw8-hr7r", + "modified": "2025-05-19T21:30:34Z", + "published": "2025-05-19T21:30:34Z", + "aliases": [ + "CVE-2025-39393" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mojoomla Hospital Management System allows Reflected XSS.This issue affects Hospital Management System: from n/a through 47.0 (20-11-2023).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39393" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/hospital-management/vulnerability/wordpress-hospital-management-system-plugin-47-0-20-11-2023-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T20:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w6qw-pq8j-j38w/GHSA-w6qw-pq8j-j38w.json b/advisories/unreviewed/2025/05/GHSA-w6qw-pq8j-j38w/GHSA-w6qw-pq8j-j38w.json new file mode 100644 index 00000000000..608b2923ba1 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w6qw-pq8j-j38w/GHSA-w6qw-pq8j-j38w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w6qw-pq8j-j38w", + "modified": "2025-05-19T21:30:34Z", + "published": "2025-05-19T21:30:34Z", + "aliases": [ + "CVE-2025-39402" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla WPAMS allows Upload a Web Shell to a Web Server.This issue affects WPAMS: from n/a through 44.0 (17-08-2023).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39402" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/apartment-management/vulnerability/wordpress-wpams-plugin-44-0-17-08-2023-arbitrary-file-upload-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T20:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w9wx-6pwp-f355/GHSA-w9wx-6pwp-f355.json b/advisories/unreviewed/2025/05/GHSA-w9wx-6pwp-f355/GHSA-w9wx-6pwp-f355.json new file mode 100644 index 00000000000..19e3a7ae7d8 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w9wx-6pwp-f355/GHSA-w9wx-6pwp-f355.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w9wx-6pwp-f355", + "modified": "2025-05-19T21:30:32Z", + "published": "2025-05-19T21:30:32Z", + "aliases": [ + "CVE-2025-39407" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Caseproof, LLC Memberpress allows Reflected XSS.This issue affects Memberpress: from n/a through 1.11.37.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39407" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/memberpress/vulnerability/wordpress-memberpress-plugin-1-11-37-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T19:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wf5p-w85h-5j8f/GHSA-wf5p-w85h-5j8f.json b/advisories/unreviewed/2025/05/GHSA-wf5p-w85h-5j8f/GHSA-wf5p-w85h-5j8f.json new file mode 100644 index 00000000000..cc68aa6a64e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wf5p-w85h-5j8f/GHSA-wf5p-w85h-5j8f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wf5p-w85h-5j8f", + "modified": "2025-05-19T21:30:33Z", + "published": "2025-05-19T21:30:33Z", + "aliases": [ + "CVE-2025-43832" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in andreyk Remote Images Grabber allows Reflected XSS.This issue affects Remote Images Grabber: from n/a through 0.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43832" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/remote-images-grabber/vulnerability/wordpress-remote-images-grabber-plugin-0-6-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T19:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wq25-m95j-8rw5/GHSA-wq25-m95j-8rw5.json b/advisories/unreviewed/2025/05/GHSA-wq25-m95j-8rw5/GHSA-wq25-m95j-8rw5.json index 434da592b88..1ed679980cf 100644 --- a/advisories/unreviewed/2025/05/GHSA-wq25-m95j-8rw5/GHSA-wq25-m95j-8rw5.json +++ b/advisories/unreviewed/2025/05/GHSA-wq25-m95j-8rw5/GHSA-wq25-m95j-8rw5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wq25-m95j-8rw5", - "modified": "2025-05-17T03:30:32Z", + "modified": "2025-05-19T21:30:31Z", "published": "2025-05-17T03:30:32Z", "aliases": [ "CVE-2025-1706" ], "details": "Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kernel exceptions.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-17T01:15:18Z" diff --git a/advisories/unreviewed/2025/05/GHSA-wxm4-3j5f-3j3v/GHSA-wxm4-3j5f-3j3v.json b/advisories/unreviewed/2025/05/GHSA-wxm4-3j5f-3j3v/GHSA-wxm4-3j5f-3j3v.json index f098c81954b..20a7dfef7c3 100644 --- a/advisories/unreviewed/2025/05/GHSA-wxm4-3j5f-3j3v/GHSA-wxm4-3j5f-3j3v.json +++ b/advisories/unreviewed/2025/05/GHSA-wxm4-3j5f-3j3v/GHSA-wxm4-3j5f-3j3v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wxm4-3j5f-3j3v", - "modified": "2025-05-17T03:30:32Z", + "modified": "2025-05-19T21:30:31Z", "published": "2025-05-17T03:30:32Z", "aliases": [ "CVE-2024-47893" ], "details": "Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to read and/or write data outside the Guest's virtualised GPU memory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-823" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-17T01:15:17Z" diff --git a/advisories/unreviewed/2025/05/GHSA-x3h8-5m65-8vcm/GHSA-x3h8-5m65-8vcm.json b/advisories/unreviewed/2025/05/GHSA-x3h8-5m65-8vcm/GHSA-x3h8-5m65-8vcm.json new file mode 100644 index 00000000000..96a8803e99f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-x3h8-5m65-8vcm/GHSA-x3h8-5m65-8vcm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x3h8-5m65-8vcm", + "modified": "2025-05-19T21:30:32Z", + "published": "2025-05-19T21:30:32Z", + "aliases": [ + "CVE-2025-39406" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in mojoomla WPAMS allows PHP Local File Inclusion.This issue affects WPAMS: from n/a through 44.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39406" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/apartment-management/vulnerability/wordpress-wpams-plugin-44-0-local-file-inclusion-to-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T19:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-x6rw-fcc2-6wgg/GHSA-x6rw-fcc2-6wgg.json b/advisories/unreviewed/2025/05/GHSA-x6rw-fcc2-6wgg/GHSA-x6rw-fcc2-6wgg.json new file mode 100644 index 00000000000..a79af960c23 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-x6rw-fcc2-6wgg/GHSA-x6rw-fcc2-6wgg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x6rw-fcc2-6wgg", + "modified": "2025-05-19T21:30:33Z", + "published": "2025-05-19T21:30:33Z", + "aliases": [ + "CVE-2025-39449" + ], + "details": "Missing Authorization vulnerability in Crocoblock JetWooBuilder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JetWooBuilder: from n/a through 2.1.18.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39449" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/jet-woo-builder/vulnerability/wordpress-jetwoobuilder-2-1-18-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T19:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-x74x-7784-j459/GHSA-x74x-7784-j459.json b/advisories/unreviewed/2025/05/GHSA-x74x-7784-j459/GHSA-x74x-7784-j459.json new file mode 100644 index 00000000000..6b9f35fa195 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-x74x-7784-j459/GHSA-x74x-7784-j459.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x74x-7784-j459", + "modified": "2025-05-19T21:30:34Z", + "published": "2025-05-19T21:30:34Z", + "aliases": [ + "CVE-2025-39395" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla WPAMS allows SQL Injection.This issue affects WPAMS: from n/a through 44.0 (17-08-2023).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39395" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/apartment-management/vulnerability/wordpress-wpams-plugin-44-0-17-08-2023-sql-injection-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T20:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xq2w-qxwp-qw9f/GHSA-xq2w-qxwp-qw9f.json b/advisories/unreviewed/2025/05/GHSA-xq2w-qxwp-qw9f/GHSA-xq2w-qxwp-qw9f.json new file mode 100644 index 00000000000..8d09425d056 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xq2w-qxwp-qw9f/GHSA-xq2w-qxwp-qw9f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xq2w-qxwp-qw9f", + "modified": "2025-05-19T21:30:33Z", + "published": "2025-05-19T21:30:33Z", + "aliases": [ + "CVE-2025-39451" + ], + "details": "Missing Authorization vulnerability in Crocoblock JetBlocks For Elementor allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JetBlocks For Elementor: from n/a through 1.3.16.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39451" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/jet-blocks/vulnerability/wordpress-jetblocks-for-elementor-1-3-16-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T19:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xxjw-vw5q-j33v/GHSA-xxjw-vw5q-j33v.json b/advisories/unreviewed/2025/05/GHSA-xxjw-vw5q-j33v/GHSA-xxjw-vw5q-j33v.json new file mode 100644 index 00000000000..a14d6b32b6d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xxjw-vw5q-j33v/GHSA-xxjw-vw5q-j33v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xxjw-vw5q-j33v", + "modified": "2025-05-19T21:30:33Z", + "published": "2025-05-19T21:30:33Z", + "aliases": [ + "CVE-2025-31027" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jocoxdesign Tiger tiger allows Reflected XSS.This issue affects Tiger: from n/a through 2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31027" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/tiger/vulnerability/wordpress-tiger-theme-2-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T20:15:21Z" + } +} \ No newline at end of file