diff --git a/advisories/unreviewed/2022/10/GHSA-2q6q-v4gf-4wh6/GHSA-2q6q-v4gf-4wh6.json b/advisories/unreviewed/2022/10/GHSA-2q6q-v4gf-4wh6/GHSA-2q6q-v4gf-4wh6.json index 7c617a5fd55..200a8d3ded1 100644 --- a/advisories/unreviewed/2022/10/GHSA-2q6q-v4gf-4wh6/GHSA-2q6q-v4gf-4wh6.json +++ b/advisories/unreviewed/2022/10/GHSA-2q6q-v4gf-4wh6/GHSA-2q6q-v4gf-4wh6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2q6q-v4gf-4wh6", - "modified": "2022-10-13T19:00:21Z", + "modified": "2025-05-15T18:31:24Z", "published": "2022-10-12T12:00:18Z", "aliases": [ "CVE-2022-42711" diff --git a/advisories/unreviewed/2022/10/GHSA-4ppq-669j-6f73/GHSA-4ppq-669j-6f73.json b/advisories/unreviewed/2022/10/GHSA-4ppq-669j-6f73/GHSA-4ppq-669j-6f73.json index c680ebe2b94..9c2f3b1a9a4 100644 --- a/advisories/unreviewed/2022/10/GHSA-4ppq-669j-6f73/GHSA-4ppq-669j-6f73.json +++ b/advisories/unreviewed/2022/10/GHSA-4ppq-669j-6f73/GHSA-4ppq-669j-6f73.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4ppq-669j-6f73", - "modified": "2022-10-18T19:00:30Z", + "modified": "2025-05-15T18:31:33Z", "published": "2022-10-14T19:00:38Z", "aliases": [ "CVE-2021-46840" diff --git a/advisories/unreviewed/2022/10/GHSA-4r3g-w96h-5qxg/GHSA-4r3g-w96h-5qxg.json b/advisories/unreviewed/2022/10/GHSA-4r3g-w96h-5qxg/GHSA-4r3g-w96h-5qxg.json index 2f4bed82f77..096d3f82202 100644 --- a/advisories/unreviewed/2022/10/GHSA-4r3g-w96h-5qxg/GHSA-4r3g-w96h-5qxg.json +++ b/advisories/unreviewed/2022/10/GHSA-4r3g-w96h-5qxg/GHSA-4r3g-w96h-5qxg.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-306", "CWE-862" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/10/GHSA-5cvm-9gmj-pww2/GHSA-5cvm-9gmj-pww2.json b/advisories/unreviewed/2022/10/GHSA-5cvm-9gmj-pww2/GHSA-5cvm-9gmj-pww2.json index 8395bf941a0..a16e6cc178d 100644 --- a/advisories/unreviewed/2022/10/GHSA-5cvm-9gmj-pww2/GHSA-5cvm-9gmj-pww2.json +++ b/advisories/unreviewed/2022/10/GHSA-5cvm-9gmj-pww2/GHSA-5cvm-9gmj-pww2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5cvm-9gmj-pww2", - "modified": "2022-10-14T19:00:32Z", + "modified": "2025-05-15T18:31:25Z", "published": "2022-10-12T19:00:40Z", "aliases": [ "CVE-2022-42715" diff --git a/advisories/unreviewed/2022/10/GHSA-7j36-8hpq-mwr9/GHSA-7j36-8hpq-mwr9.json b/advisories/unreviewed/2022/10/GHSA-7j36-8hpq-mwr9/GHSA-7j36-8hpq-mwr9.json index 6a3cdf85da8..b928537ddbd 100644 --- a/advisories/unreviewed/2022/10/GHSA-7j36-8hpq-mwr9/GHSA-7j36-8hpq-mwr9.json +++ b/advisories/unreviewed/2022/10/GHSA-7j36-8hpq-mwr9/GHSA-7j36-8hpq-mwr9.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-693" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-7x4q-86g3-3vwp/GHSA-7x4q-86g3-3vwp.json b/advisories/unreviewed/2022/10/GHSA-7x4q-86g3-3vwp/GHSA-7x4q-86g3-3vwp.json index 52db3b23eff..1694508f02c 100644 --- a/advisories/unreviewed/2022/10/GHSA-7x4q-86g3-3vwp/GHSA-7x4q-86g3-3vwp.json +++ b/advisories/unreviewed/2022/10/GHSA-7x4q-86g3-3vwp/GHSA-7x4q-86g3-3vwp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7x4q-86g3-3vwp", - "modified": "2022-10-18T19:00:35Z", + "modified": "2025-05-15T18:31:29Z", "published": "2022-10-14T12:00:25Z", "aliases": [ "CVE-2022-42161" diff --git a/advisories/unreviewed/2022/10/GHSA-f37p-jfgg-9646/GHSA-f37p-jfgg-9646.json b/advisories/unreviewed/2022/10/GHSA-f37p-jfgg-9646/GHSA-f37p-jfgg-9646.json index 709a61beb77..913aa2efb90 100644 --- a/advisories/unreviewed/2022/10/GHSA-f37p-jfgg-9646/GHSA-f37p-jfgg-9646.json +++ b/advisories/unreviewed/2022/10/GHSA-f37p-jfgg-9646/GHSA-f37p-jfgg-9646.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-gmj3-7vpf-cgw6/GHSA-gmj3-7vpf-cgw6.json b/advisories/unreviewed/2022/10/GHSA-gmj3-7vpf-cgw6/GHSA-gmj3-7vpf-cgw6.json index 385175fef1a..c0fd2cc82f2 100644 --- a/advisories/unreviewed/2022/10/GHSA-gmj3-7vpf-cgw6/GHSA-gmj3-7vpf-cgw6.json +++ b/advisories/unreviewed/2022/10/GHSA-gmj3-7vpf-cgw6/GHSA-gmj3-7vpf-cgw6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gmj3-7vpf-cgw6", - "modified": "2022-10-18T19:00:34Z", + "modified": "2025-05-15T18:31:33Z", "published": "2022-10-14T19:00:37Z", "aliases": [ "CVE-2021-46839" diff --git a/advisories/unreviewed/2022/10/GHSA-jv64-2wh8-m723/GHSA-jv64-2wh8-m723.json b/advisories/unreviewed/2022/10/GHSA-jv64-2wh8-m723/GHSA-jv64-2wh8-m723.json index 260b089db84..676fbe28b83 100644 --- a/advisories/unreviewed/2022/10/GHSA-jv64-2wh8-m723/GHSA-jv64-2wh8-m723.json +++ b/advisories/unreviewed/2022/10/GHSA-jv64-2wh8-m723/GHSA-jv64-2wh8-m723.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jv64-2wh8-m723", - "modified": "2022-10-14T12:00:24Z", + "modified": "2025-05-15T18:31:26Z", "published": "2022-10-13T12:00:26Z", "aliases": [ "CVE-2022-42899" diff --git a/advisories/unreviewed/2022/10/GHSA-r93j-cm86-gfc2/GHSA-r93j-cm86-gfc2.json b/advisories/unreviewed/2022/10/GHSA-r93j-cm86-gfc2/GHSA-r93j-cm86-gfc2.json index b5197c58b1a..d60a11bbaa8 100644 --- a/advisories/unreviewed/2022/10/GHSA-r93j-cm86-gfc2/GHSA-r93j-cm86-gfc2.json +++ b/advisories/unreviewed/2022/10/GHSA-r93j-cm86-gfc2/GHSA-r93j-cm86-gfc2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r93j-cm86-gfc2", - "modified": "2022-10-14T12:00:24Z", + "modified": "2025-05-15T18:31:26Z", "published": "2022-10-13T12:00:26Z", "aliases": [ "CVE-2022-42900" diff --git a/advisories/unreviewed/2022/10/GHSA-w686-vvxm-p6q4/GHSA-w686-vvxm-p6q4.json b/advisories/unreviewed/2022/10/GHSA-w686-vvxm-p6q4/GHSA-w686-vvxm-p6q4.json index a24f32e1c04..91cb9a0ab6e 100644 --- a/advisories/unreviewed/2022/10/GHSA-w686-vvxm-p6q4/GHSA-w686-vvxm-p6q4.json +++ b/advisories/unreviewed/2022/10/GHSA-w686-vvxm-p6q4/GHSA-w686-vvxm-p6q4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w686-vvxm-p6q4", - "modified": "2022-10-14T12:00:24Z", + "modified": "2025-05-15T18:31:26Z", "published": "2022-10-13T12:00:26Z", "aliases": [ "CVE-2022-42901" diff --git a/advisories/unreviewed/2022/10/GHSA-xpmg-m9rm-chxc/GHSA-xpmg-m9rm-chxc.json b/advisories/unreviewed/2022/10/GHSA-xpmg-m9rm-chxc/GHSA-xpmg-m9rm-chxc.json index acb32488bac..29824e18423 100644 --- a/advisories/unreviewed/2022/10/GHSA-xpmg-m9rm-chxc/GHSA-xpmg-m9rm-chxc.json +++ b/advisories/unreviewed/2022/10/GHSA-xpmg-m9rm-chxc/GHSA-xpmg-m9rm-chxc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xpmg-m9rm-chxc", - "modified": "2022-10-19T12:00:20Z", + "modified": "2025-05-15T18:31:35Z", "published": "2022-10-17T19:00:28Z", "aliases": [ "CVE-2022-42221" diff --git a/advisories/unreviewed/2024/01/GHSA-5rwv-g8gv-qc9g/GHSA-5rwv-g8gv-qc9g.json b/advisories/unreviewed/2024/01/GHSA-5rwv-g8gv-qc9g/GHSA-5rwv-g8gv-qc9g.json index 20b8ffd8ec0..84345f3c432 100644 --- a/advisories/unreviewed/2024/01/GHSA-5rwv-g8gv-qc9g/GHSA-5rwv-g8gv-qc9g.json +++ b/advisories/unreviewed/2024/01/GHSA-5rwv-g8gv-qc9g/GHSA-5rwv-g8gv-qc9g.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/01/GHSA-9vm4-r3mm-m2cq/GHSA-9vm4-r3mm-m2cq.json b/advisories/unreviewed/2024/01/GHSA-9vm4-r3mm-m2cq/GHSA-9vm4-r3mm-m2cq.json index db072375699..35d4f825962 100644 --- a/advisories/unreviewed/2024/01/GHSA-9vm4-r3mm-m2cq/GHSA-9vm4-r3mm-m2cq.json +++ b/advisories/unreviewed/2024/01/GHSA-9vm4-r3mm-m2cq/GHSA-9vm4-r3mm-m2cq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9vm4-r3mm-m2cq", - "modified": "2024-01-17T00:30:21Z", + "modified": "2025-05-15T18:31:37Z", "published": "2024-01-17T00:30:21Z", "aliases": [ "CVE-2024-20977" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/01/GHSA-hjh6-9v4w-w32w/GHSA-hjh6-9v4w-w32w.json b/advisories/unreviewed/2024/01/GHSA-hjh6-9v4w-w32w/GHSA-hjh6-9v4w-w32w.json index b6c008abd39..426fd94f120 100644 --- a/advisories/unreviewed/2024/01/GHSA-hjh6-9v4w-w32w/GHSA-hjh6-9v4w-w32w.json +++ b/advisories/unreviewed/2024/01/GHSA-hjh6-9v4w-w32w/GHSA-hjh6-9v4w-w32w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hjh6-9v4w-w32w", - "modified": "2024-01-17T00:30:20Z", + "modified": "2025-05-15T18:31:37Z", "published": "2024-01-17T00:30:20Z", "aliases": [ "CVE-2024-20926" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-cr7c-5w66-wh22/GHSA-cr7c-5w66-wh22.json b/advisories/unreviewed/2024/07/GHSA-cr7c-5w66-wh22/GHSA-cr7c-5w66-wh22.json index 46f2e87d870..2b507334f0f 100644 --- a/advisories/unreviewed/2024/07/GHSA-cr7c-5w66-wh22/GHSA-cr7c-5w66-wh22.json +++ b/advisories/unreviewed/2024/07/GHSA-cr7c-5w66-wh22/GHSA-cr7c-5w66-wh22.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-g2vh-gv38-gppg/GHSA-g2vh-gv38-gppg.json b/advisories/unreviewed/2024/07/GHSA-g2vh-gv38-gppg/GHSA-g2vh-gv38-gppg.json index ffffbc36026..81828976afe 100644 --- a/advisories/unreviewed/2024/07/GHSA-g2vh-gv38-gppg/GHSA-g2vh-gv38-gppg.json +++ b/advisories/unreviewed/2024/07/GHSA-g2vh-gv38-gppg/GHSA-g2vh-gv38-gppg.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-qh4x-j5x9-4f8m/GHSA-qh4x-j5x9-4f8m.json b/advisories/unreviewed/2024/07/GHSA-qh4x-j5x9-4f8m/GHSA-qh4x-j5x9-4f8m.json index 29ddaea7953..c37fc9c814d 100644 --- a/advisories/unreviewed/2024/07/GHSA-qh4x-j5x9-4f8m/GHSA-qh4x-j5x9-4f8m.json +++ b/advisories/unreviewed/2024/07/GHSA-qh4x-j5x9-4f8m/GHSA-qh4x-j5x9-4f8m.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-26fv-px38-wm73/GHSA-26fv-px38-wm73.json b/advisories/unreviewed/2024/11/GHSA-26fv-px38-wm73/GHSA-26fv-px38-wm73.json index a793dcece5c..94b55070ce9 100644 --- a/advisories/unreviewed/2024/11/GHSA-26fv-px38-wm73/GHSA-26fv-px38-wm73.json +++ b/advisories/unreviewed/2024/11/GHSA-26fv-px38-wm73/GHSA-26fv-px38-wm73.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-2mvw-cmvf-9wp4/GHSA-2mvw-cmvf-9wp4.json b/advisories/unreviewed/2024/11/GHSA-2mvw-cmvf-9wp4/GHSA-2mvw-cmvf-9wp4.json index 01726ee3ce7..4c5f6532733 100644 --- a/advisories/unreviewed/2024/11/GHSA-2mvw-cmvf-9wp4/GHSA-2mvw-cmvf-9wp4.json +++ b/advisories/unreviewed/2024/11/GHSA-2mvw-cmvf-9wp4/GHSA-2mvw-cmvf-9wp4.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-3m72-96fp-2vmr/GHSA-3m72-96fp-2vmr.json b/advisories/unreviewed/2024/11/GHSA-3m72-96fp-2vmr/GHSA-3m72-96fp-2vmr.json index bf6fcc50fe4..2f92236eaec 100644 --- a/advisories/unreviewed/2024/11/GHSA-3m72-96fp-2vmr/GHSA-3m72-96fp-2vmr.json +++ b/advisories/unreviewed/2024/11/GHSA-3m72-96fp-2vmr/GHSA-3m72-96fp-2vmr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3m72-96fp-2vmr", - "modified": "2024-11-09T09:30:29Z", + "modified": "2025-05-15T18:31:39Z", "published": "2024-11-09T09:30:29Z", "aliases": [ "CVE-2024-9874" diff --git a/advisories/unreviewed/2024/11/GHSA-434f-v35r-xr4j/GHSA-434f-v35r-xr4j.json b/advisories/unreviewed/2024/11/GHSA-434f-v35r-xr4j/GHSA-434f-v35r-xr4j.json index a5ca92bb840..fc91668eff5 100644 --- a/advisories/unreviewed/2024/11/GHSA-434f-v35r-xr4j/GHSA-434f-v35r-xr4j.json +++ b/advisories/unreviewed/2024/11/GHSA-434f-v35r-xr4j/GHSA-434f-v35r-xr4j.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-439g-ccc3-vp4h/GHSA-439g-ccc3-vp4h.json b/advisories/unreviewed/2024/11/GHSA-439g-ccc3-vp4h/GHSA-439g-ccc3-vp4h.json index 156ad5fde10..175e9f06b95 100644 --- a/advisories/unreviewed/2024/11/GHSA-439g-ccc3-vp4h/GHSA-439g-ccc3-vp4h.json +++ b/advisories/unreviewed/2024/11/GHSA-439g-ccc3-vp4h/GHSA-439g-ccc3-vp4h.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-4jvj-8r9f-f6pm/GHSA-4jvj-8r9f-f6pm.json b/advisories/unreviewed/2024/11/GHSA-4jvj-8r9f-f6pm/GHSA-4jvj-8r9f-f6pm.json index d30b1b056aa..c50000e13ac 100644 --- a/advisories/unreviewed/2024/11/GHSA-4jvj-8r9f-f6pm/GHSA-4jvj-8r9f-f6pm.json +++ b/advisories/unreviewed/2024/11/GHSA-4jvj-8r9f-f6pm/GHSA-4jvj-8r9f-f6pm.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-97cw-cf8m-4xxc/GHSA-97cw-cf8m-4xxc.json b/advisories/unreviewed/2024/11/GHSA-97cw-cf8m-4xxc/GHSA-97cw-cf8m-4xxc.json index fd3a2e1766e..99638842588 100644 --- a/advisories/unreviewed/2024/11/GHSA-97cw-cf8m-4xxc/GHSA-97cw-cf8m-4xxc.json +++ b/advisories/unreviewed/2024/11/GHSA-97cw-cf8m-4xxc/GHSA-97cw-cf8m-4xxc.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-c5rh-2mpx-r3x4/GHSA-c5rh-2mpx-r3x4.json b/advisories/unreviewed/2024/11/GHSA-c5rh-2mpx-r3x4/GHSA-c5rh-2mpx-r3x4.json index d362bb8a1cb..bcf034e4441 100644 --- a/advisories/unreviewed/2024/11/GHSA-c5rh-2mpx-r3x4/GHSA-c5rh-2mpx-r3x4.json +++ b/advisories/unreviewed/2024/11/GHSA-c5rh-2mpx-r3x4/GHSA-c5rh-2mpx-r3x4.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-hw6j-ph25-g43c/GHSA-hw6j-ph25-g43c.json b/advisories/unreviewed/2024/11/GHSA-hw6j-ph25-g43c/GHSA-hw6j-ph25-g43c.json index 6d58cd2ca28..54c472efbe8 100644 --- a/advisories/unreviewed/2024/11/GHSA-hw6j-ph25-g43c/GHSA-hw6j-ph25-g43c.json +++ b/advisories/unreviewed/2024/11/GHSA-hw6j-ph25-g43c/GHSA-hw6j-ph25-g43c.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-pvmv-37h8-9j25/GHSA-pvmv-37h8-9j25.json b/advisories/unreviewed/2024/11/GHSA-pvmv-37h8-9j25/GHSA-pvmv-37h8-9j25.json index da0601d37fd..63cf0cea4ce 100644 --- a/advisories/unreviewed/2024/11/GHSA-pvmv-37h8-9j25/GHSA-pvmv-37h8-9j25.json +++ b/advisories/unreviewed/2024/11/GHSA-pvmv-37h8-9j25/GHSA-pvmv-37h8-9j25.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-r5h8-fch6-xr5v/GHSA-r5h8-fch6-xr5v.json b/advisories/unreviewed/2024/11/GHSA-r5h8-fch6-xr5v/GHSA-r5h8-fch6-xr5v.json index 5d830ec1725..f1858a5a22d 100644 --- a/advisories/unreviewed/2024/11/GHSA-r5h8-fch6-xr5v/GHSA-r5h8-fch6-xr5v.json +++ b/advisories/unreviewed/2024/11/GHSA-r5h8-fch6-xr5v/GHSA-r5h8-fch6-xr5v.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-v5rm-528g-7mvp/GHSA-v5rm-528g-7mvp.json b/advisories/unreviewed/2024/11/GHSA-v5rm-528g-7mvp/GHSA-v5rm-528g-7mvp.json index 7383b050a8c..63bb9ecf11d 100644 --- a/advisories/unreviewed/2024/11/GHSA-v5rm-528g-7mvp/GHSA-v5rm-528g-7mvp.json +++ b/advisories/unreviewed/2024/11/GHSA-v5rm-528g-7mvp/GHSA-v5rm-528g-7mvp.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-v664-p69f-2qfg/GHSA-v664-p69f-2qfg.json b/advisories/unreviewed/2024/11/GHSA-v664-p69f-2qfg/GHSA-v664-p69f-2qfg.json index 2ef9751bdb4..2c53c9958bc 100644 --- a/advisories/unreviewed/2024/11/GHSA-v664-p69f-2qfg/GHSA-v664-p69f-2qfg.json +++ b/advisories/unreviewed/2024/11/GHSA-v664-p69f-2qfg/GHSA-v664-p69f-2qfg.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-h5h2-cvc7-hm6x/GHSA-h5h2-cvc7-hm6x.json b/advisories/unreviewed/2025/04/GHSA-h5h2-cvc7-hm6x/GHSA-h5h2-cvc7-hm6x.json index 254ee64836d..bf1692733e1 100644 --- a/advisories/unreviewed/2025/04/GHSA-h5h2-cvc7-hm6x/GHSA-h5h2-cvc7-hm6x.json +++ b/advisories/unreviewed/2025/04/GHSA-h5h2-cvc7-hm6x/GHSA-h5h2-cvc7-hm6x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h5h2-cvc7-hm6x", - "modified": "2025-04-30T18:31:54Z", + "modified": "2025-05-15T18:31:42Z", "published": "2025-04-23T21:30:36Z", "aliases": [ "CVE-2025-46399" @@ -19,6 +19,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46399" }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-46399" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2362053" + }, { "type": "WEB", "url": "https://sourceforge.net/p/mcj/tickets/190" diff --git a/advisories/unreviewed/2025/05/GHSA-28x8-4wmv-cxfw/GHSA-28x8-4wmv-cxfw.json b/advisories/unreviewed/2025/05/GHSA-28x8-4wmv-cxfw/GHSA-28x8-4wmv-cxfw.json new file mode 100644 index 00000000000..df88368159e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-28x8-4wmv-cxfw/GHSA-28x8-4wmv-cxfw.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-28x8-4wmv-cxfw", + "modified": "2025-05-15T18:31:48Z", + "published": "2025-05-15T18:31:48Z", + "aliases": [ + "CVE-2025-4711" + ], + "details": "A vulnerability, which was classified as critical, was found in Campcodes Sales and Inventory System 1.0. This affects an unknown part of the file /pages/stockin_add.php. The manipulation of the argument prod_name leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4711" + }, + { + "type": "WEB", + "url": "https://github.com/lanxia0/CVE/issues/5" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309009" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309009" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.568291" + }, + { + "type": "WEB", + "url": "https://www.campcodes.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T18:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4762-7j7m-8cjh/GHSA-4762-7j7m-8cjh.json b/advisories/unreviewed/2025/05/GHSA-4762-7j7m-8cjh/GHSA-4762-7j7m-8cjh.json new file mode 100644 index 00000000000..fce9a854c7c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4762-7j7m-8cjh/GHSA-4762-7j7m-8cjh.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4762-7j7m-8cjh", + "modified": "2025-05-15T18:31:45Z", + "published": "2025-05-15T18:31:45Z", + "aliases": [ + "CVE-2024-52880" + ], + "details": "An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 05.54.50, kernel 5.6 before version 05.61.50, and kernel 5.7 before version 05.70.50. In VariableRuntimeDxe driver, SecureBootHandler uses DataSize and VariableNameSize when determining if the data or name are in the buffer, but these are supplied by the caller and therefore cannot be trusted.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52880" + }, + { + "type": "WEB", + "url": "https://www.insyde.com/security-pledge" + }, + { + "type": "WEB", + "url": "https://www.insyde.com/security-pledge/sa-2024016" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T16:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4f7m-v6hv-9hcr/GHSA-4f7m-v6hv-9hcr.json b/advisories/unreviewed/2025/05/GHSA-4f7m-v6hv-9hcr/GHSA-4f7m-v6hv-9hcr.json new file mode 100644 index 00000000000..b063dd3e536 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4f7m-v6hv-9hcr/GHSA-4f7m-v6hv-9hcr.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4f7m-v6hv-9hcr", + "modified": "2025-05-15T18:31:45Z", + "published": "2025-05-15T18:31:45Z", + "aliases": [ + "CVE-2024-52879" + ], + "details": "An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 05.54.50, kernel 5.6 before version 05.61.50, and kernel 5.7 before version 05.70.50. In VariableRuntimeDxe driver, SmmUpdateVariablePropertySmi () is a SMM callback function and it uses StrCmp () to compare variable names. This action may cause a buffer over-read.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52879" + }, + { + "type": "WEB", + "url": "https://www.insyde.com/security-pledge" + }, + { + "type": "WEB", + "url": "https://www.insyde.com/security-pledge/sa-2024016" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T16:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5h64-37wc-rj27/GHSA-5h64-37wc-rj27.json b/advisories/unreviewed/2025/05/GHSA-5h64-37wc-rj27/GHSA-5h64-37wc-rj27.json new file mode 100644 index 00000000000..ac53f9b41b3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5h64-37wc-rj27/GHSA-5h64-37wc-rj27.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5h64-37wc-rj27", + "modified": "2025-05-15T18:31:46Z", + "published": "2025-05-15T18:31:46Z", + "aliases": [ + "CVE-2025-48050" + ], + "details": "In DOMPurify through 3.2.5 before 6bc6d60, scripts/server.js does not ensure that a pathname is located under the current working directory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48050" + }, + { + "type": "WEB", + "url": "https://github.com/cure53/DOMPurify/pull/1101" + }, + { + "type": "WEB", + "url": "https://github.com/cure53/DOMPurify/commit/6bc6d60e49256f27a4022181b7d8a5b0721fd534" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-24" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T16:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5ppx-9rrh-j4wr/GHSA-5ppx-9rrh-j4wr.json b/advisories/unreviewed/2025/05/GHSA-5ppx-9rrh-j4wr/GHSA-5ppx-9rrh-j4wr.json new file mode 100644 index 00000000000..e24e1db4a4f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5ppx-9rrh-j4wr/GHSA-5ppx-9rrh-j4wr.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5ppx-9rrh-j4wr", + "modified": "2025-05-15T18:31:47Z", + "published": "2025-05-15T18:31:47Z", + "aliases": [ + "CVE-2025-30421" + ], + "details": "There is a memory corruption vulnerability due to a stack-based buffer overflow in DrObjectStorage::XML_Serialize() when using the SymbolEditor in NI Circuit Design Suite.  This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted .sym file. This vulnerability affects NI Circuit Design Suite 14.3.0 and prior versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30421" + }, + { + "type": "WEB", + "url": "https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/memory-corruption-vulnerabilities-in-ni-circuit-design-suite.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T17:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8pjq-8vp2-wh6r/GHSA-8pjq-8vp2-wh6r.json b/advisories/unreviewed/2025/05/GHSA-8pjq-8vp2-wh6r/GHSA-8pjq-8vp2-wh6r.json new file mode 100644 index 00000000000..2bc79922d3c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8pjq-8vp2-wh6r/GHSA-8pjq-8vp2-wh6r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8pjq-8vp2-wh6r", + "modified": "2025-05-15T18:31:41Z", + "published": "2025-05-15T18:31:41Z", + "aliases": [ + "CVE-2024-8157" + ], + "details": "The Alphabetical List WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8157" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/9bc18c41-fc4c-48c9-bcec-323c502ae620" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-21T11:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8w85-45qx-p356/GHSA-8w85-45qx-p356.json b/advisories/unreviewed/2025/05/GHSA-8w85-45qx-p356/GHSA-8w85-45qx-p356.json new file mode 100644 index 00000000000..696fb52cd37 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8w85-45qx-p356/GHSA-8w85-45qx-p356.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8w85-45qx-p356", + "modified": "2025-05-15T18:31:41Z", + "published": "2025-05-15T18:31:41Z", + "aliases": [ + "CVE-2024-9600" + ], + "details": "The Ditty WordPress plugin before 3.1.47 does not sanitise and escape some of its settings, which could allow high privilege users such as author to perform Stored Cross-Site Scripting attacks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9600" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/d1c78389-29eb-4dce-848c-e0eab85ff5cd" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-21T11:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-955v-h2r9-q4cw/GHSA-955v-h2r9-q4cw.json b/advisories/unreviewed/2025/05/GHSA-955v-h2r9-q4cw/GHSA-955v-h2r9-q4cw.json new file mode 100644 index 00000000000..203a89ec605 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-955v-h2r9-q4cw/GHSA-955v-h2r9-q4cw.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-955v-h2r9-q4cw", + "modified": "2025-05-15T18:31:47Z", + "published": "2025-05-15T18:31:47Z", + "aliases": [ + "CVE-2025-4703" + ], + "details": "A vulnerability has been found in PHPGurukul Vehicle Parking Management System 1.13 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/admin-profile.php. The manipulation of the argument contactnumber leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4703" + }, + { + "type": "WEB", + "url": "https://github.com/baixiaobai001/myCVE/issues/2" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309001" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309001" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.567820" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T16:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-95xc-5cxv-mp93/GHSA-95xc-5cxv-mp93.json b/advisories/unreviewed/2025/05/GHSA-95xc-5cxv-mp93/GHSA-95xc-5cxv-mp93.json new file mode 100644 index 00000000000..cdd5f1a00fa --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-95xc-5cxv-mp93/GHSA-95xc-5cxv-mp93.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-95xc-5cxv-mp93", + "modified": "2025-05-15T18:31:47Z", + "published": "2025-05-15T18:31:47Z", + "aliases": [ + "CVE-2025-4705" + ], + "details": "A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13. It has been classified as critical. This affects an unknown part of the file /admin/view-incomingvehicle-detail.php. The manipulation of the argument viewid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4705" + }, + { + "type": "WEB", + "url": "https://github.com/baixiaobai001/myCVE/issues/4" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309003" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309003" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.567827" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T16:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-99pf-wjvr-5q4j/GHSA-99pf-wjvr-5q4j.json b/advisories/unreviewed/2025/05/GHSA-99pf-wjvr-5q4j/GHSA-99pf-wjvr-5q4j.json index 989cd41278b..00694f0279f 100644 --- a/advisories/unreviewed/2025/05/GHSA-99pf-wjvr-5q4j/GHSA-99pf-wjvr-5q4j.json +++ b/advisories/unreviewed/2025/05/GHSA-99pf-wjvr-5q4j/GHSA-99pf-wjvr-5q4j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-99pf-wjvr-5q4j", - "modified": "2025-05-15T00:30:26Z", + "modified": "2025-05-15T18:31:43Z", "published": "2025-05-15T00:30:26Z", "aliases": [ "CVE-2025-29686" ], "details": "A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the title parameter at /inform/InformManageController.java.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-14T22:15:17Z" diff --git a/advisories/unreviewed/2025/05/GHSA-9x5p-gmqf-87ww/GHSA-9x5p-gmqf-87ww.json b/advisories/unreviewed/2025/05/GHSA-9x5p-gmqf-87ww/GHSA-9x5p-gmqf-87ww.json new file mode 100644 index 00000000000..babd84a22d8 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9x5p-gmqf-87ww/GHSA-9x5p-gmqf-87ww.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9x5p-gmqf-87ww", + "modified": "2025-05-15T18:31:47Z", + "published": "2025-05-15T18:31:47Z", + "aliases": [ + "CVE-2025-4708" + ], + "details": "A vulnerability classified as critical has been found in Campcodes Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/sales_add.php. The manipulation of the argument discount leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4708" + }, + { + "type": "WEB", + "url": "https://github.com/lanxia0/CVE/issues/2" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309006" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309006" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.568288" + }, + { + "type": "WEB", + "url": "https://www.campcodes.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T17:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-chv9-fg26-xg8h/GHSA-chv9-fg26-xg8h.json b/advisories/unreviewed/2025/05/GHSA-chv9-fg26-xg8h/GHSA-chv9-fg26-xg8h.json new file mode 100644 index 00000000000..309e8c91700 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-chv9-fg26-xg8h/GHSA-chv9-fg26-xg8h.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-chv9-fg26-xg8h", + "modified": "2025-05-15T18:31:47Z", + "published": "2025-05-15T18:31:47Z", + "aliases": [ + "CVE-2025-48051" + ], + "details": "powertip.ts in Lila (for Lichess) before ab0beaf allows XSS in some applications because of an innerHTML usage pattern in which text is extracted from a DOM node and interpreted as HTML.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "WEB", + "url": "https://github.com/lichess-org/lila/security/advisories/GHSA-9xhx-p3c5-p4v6" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48051" + }, + { + "type": "WEB", + "url": "https://github.com/lichess-org/lila/commit/ab0beaf0ad671761705d9274663c5dc450608527" + }, + { + "type": "WEB", + "url": "https://github.com/lichess-org/lila/blob/7b82f35d15f9113ac8a0a9271d34bef4f6119e9f/ui/site/src/powertip.ts#L60" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T16:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-f27r-j5cw-63q3/GHSA-f27r-j5cw-63q3.json b/advisories/unreviewed/2025/05/GHSA-f27r-j5cw-63q3/GHSA-f27r-j5cw-63q3.json new file mode 100644 index 00000000000..ad2ddbbd20d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-f27r-j5cw-63q3/GHSA-f27r-j5cw-63q3.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f27r-j5cw-63q3", + "modified": "2025-05-15T18:31:47Z", + "published": "2025-05-15T18:31:47Z", + "aliases": [ + "CVE-2025-30417" + ], + "details": "There is a memory corruption vulnerability due to an out of bounds write in Library!DecodeBase64() when using the SymbolEditor in NI Circuit Design Suite.  This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted .sym file. This vulnerability affects NI Circuit Design Suite 14.3.0 and prior versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30417" + }, + { + "type": "WEB", + "url": "https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/memory-corruption-vulnerabilities-in-ni-circuit-design-suite.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T17:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fpff-wj6m-grvr/GHSA-fpff-wj6m-grvr.json b/advisories/unreviewed/2025/05/GHSA-fpff-wj6m-grvr/GHSA-fpff-wj6m-grvr.json new file mode 100644 index 00000000000..320d0e407dd --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fpff-wj6m-grvr/GHSA-fpff-wj6m-grvr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fpff-wj6m-grvr", + "modified": "2025-05-15T18:31:46Z", + "published": "2025-05-15T18:31:46Z", + "aliases": [ + "CVE-2025-2570" + ], + "details": "Mattermost versions 10.5.x <= 10.5.3, 9.11.x <= 9.11.11 fail to check `RestrictSystemAdmin` setting if user doesn't have access to `ExperimentalSettings` which allows a System Manager to access `ExperimentSettings` when `RestrictSystemAdmin` is true via System Console.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2570" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T16:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fwg2-cw8q-4fc7/GHSA-fwg2-cw8q-4fc7.json b/advisories/unreviewed/2025/05/GHSA-fwg2-cw8q-4fc7/GHSA-fwg2-cw8q-4fc7.json new file mode 100644 index 00000000000..a42c3c6b5cd --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fwg2-cw8q-4fc7/GHSA-fwg2-cw8q-4fc7.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fwg2-cw8q-4fc7", + "modified": "2025-05-15T18:31:48Z", + "published": "2025-05-15T18:31:48Z", + "aliases": [ + "CVE-2025-4709" + ], + "details": "A vulnerability classified as critical was found in Campcodes Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/transaction_del.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4709" + }, + { + "type": "WEB", + "url": "https://github.com/lanxia0/CVE/issues/3" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309007" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309007" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.568289" + }, + { + "type": "WEB", + "url": "https://www.campcodes.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T18:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g45r-4866-8vwq/GHSA-g45r-4866-8vwq.json b/advisories/unreviewed/2025/05/GHSA-g45r-4866-8vwq/GHSA-g45r-4866-8vwq.json new file mode 100644 index 00000000000..a1706650f95 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g45r-4866-8vwq/GHSA-g45r-4866-8vwq.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g45r-4866-8vwq", + "modified": "2025-05-15T18:31:47Z", + "published": "2025-05-15T18:31:47Z", + "aliases": [ + "CVE-2025-44110" + ], + "details": "FluxBB 1.5.11 is vulnerable to Cross Site Scripting (XSS) in via the Forum Description Field in admin_forums.php.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44110" + }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/189672" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T18:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gcxc-jhjw-r2q3/GHSA-gcxc-jhjw-r2q3.json b/advisories/unreviewed/2025/05/GHSA-gcxc-jhjw-r2q3/GHSA-gcxc-jhjw-r2q3.json index 310f3eaa27d..63f06b03119 100644 --- a/advisories/unreviewed/2025/05/GHSA-gcxc-jhjw-r2q3/GHSA-gcxc-jhjw-r2q3.json +++ b/advisories/unreviewed/2025/05/GHSA-gcxc-jhjw-r2q3/GHSA-gcxc-jhjw-r2q3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gcxc-jhjw-r2q3", - "modified": "2025-05-15T09:31:20Z", + "modified": "2025-05-15T18:31:43Z", "published": "2025-05-15T09:31:20Z", "aliases": [ "CVE-2025-4737" ], "details": "Insufficient encryption vulnerability in the mobile application (com.transsion.aivoiceassistant) may lead to the risk of sensitive information leakage.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-312" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T08:15:17Z" diff --git a/advisories/unreviewed/2025/05/GHSA-gh72-rxwr-vvrq/GHSA-gh72-rxwr-vvrq.json b/advisories/unreviewed/2025/05/GHSA-gh72-rxwr-vvrq/GHSA-gh72-rxwr-vvrq.json index de8849bf0d7..6fe999abd4f 100644 --- a/advisories/unreviewed/2025/05/GHSA-gh72-rxwr-vvrq/GHSA-gh72-rxwr-vvrq.json +++ b/advisories/unreviewed/2025/05/GHSA-gh72-rxwr-vvrq/GHSA-gh72-rxwr-vvrq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gh72-rxwr-vvrq", - "modified": "2025-05-15T15:31:26Z", + "modified": "2025-05-15T18:31:43Z", "published": "2025-05-15T15:31:26Z", "aliases": [ "CVE-2025-44180" ], "details": "Phpgurukul Vehicle Record Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /edit-brand.php?bid={brandId}.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T14:15:29Z" diff --git a/advisories/unreviewed/2025/05/GHSA-gj42-cfph-mjj4/GHSA-gj42-cfph-mjj4.json b/advisories/unreviewed/2025/05/GHSA-gj42-cfph-mjj4/GHSA-gj42-cfph-mjj4.json new file mode 100644 index 00000000000..cdd8f67744f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gj42-cfph-mjj4/GHSA-gj42-cfph-mjj4.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gj42-cfph-mjj4", + "modified": "2025-05-15T18:31:44Z", + "published": "2025-05-15T18:31:44Z", + "aliases": [ + "CVE-2024-52877" + ], + "details": "An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 05.54.50, kernel 5.6 before version 05.61.50, and kernel 5.7 before version 05.70.50. In VariableRuntimeDxe driver, callback function SmmCreateVariableLockList () calls CreateVariableLockListInSmm (). In CreateVariableLockListInSmm (), it uses StrSize () to get variable name size and it could lead to a buffer over-read.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52877" + }, + { + "type": "WEB", + "url": "https://www.insyde.com/security-pledge" + }, + { + "type": "WEB", + "url": "https://www.insyde.com/security-pledge/sa-2024016" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T16:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gj5g-vm2w-qcmj/GHSA-gj5g-vm2w-qcmj.json b/advisories/unreviewed/2025/05/GHSA-gj5g-vm2w-qcmj/GHSA-gj5g-vm2w-qcmj.json new file mode 100644 index 00000000000..582131fc12f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gj5g-vm2w-qcmj/GHSA-gj5g-vm2w-qcmj.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gj5g-vm2w-qcmj", + "modified": "2025-05-15T18:31:47Z", + "published": "2025-05-15T18:31:47Z", + "aliases": [ + "CVE-2025-30420" + ], + "details": "There is a memory corruption vulnerability due to an out of bounds read in Bitmap::InternalDraw() when using the SymbolEditor in NI Circuit Design Suite.  This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted .sym file. This vulnerability affects NI Circuit Design Suite 14.3.0 and prior versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30420" + }, + { + "type": "WEB", + "url": "https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/memory-corruption-vulnerabilities-in-ni-circuit-design-suite.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T17:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h356-3mfw-x368/GHSA-h356-3mfw-x368.json b/advisories/unreviewed/2025/05/GHSA-h356-3mfw-x368/GHSA-h356-3mfw-x368.json new file mode 100644 index 00000000000..ef627f8f077 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h356-3mfw-x368/GHSA-h356-3mfw-x368.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h356-3mfw-x368", + "modified": "2025-05-15T18:31:46Z", + "published": "2025-05-15T18:31:46Z", + "aliases": [ + "CVE-2025-2527" + ], + "details": "Mattermost versions 10.5.x <= 10.5.2, 9.11.x <= 9.11.11 failed to properly verify a user's permissions when accessing groups, which allows an attacker to view group information via an API request.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2527" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T16:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h3wp-4mqq-v8c4/GHSA-h3wp-4mqq-v8c4.json b/advisories/unreviewed/2025/05/GHSA-h3wp-4mqq-v8c4/GHSA-h3wp-4mqq-v8c4.json new file mode 100644 index 00000000000..528e6703852 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h3wp-4mqq-v8c4/GHSA-h3wp-4mqq-v8c4.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h3wp-4mqq-v8c4", + "modified": "2025-05-15T18:31:47Z", + "published": "2025-05-15T18:31:47Z", + "aliases": [ + "CVE-2025-30418" + ], + "details": "There is a memory corruption vulnerability due to an out of bounds write in CheckPins() when using the SymbolEditor in NI Circuit Design Suite.  This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted .sym file. This vulnerability affects NI Circuit Design Suite 14.3.0 and prior versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30418" + }, + { + "type": "WEB", + "url": "https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/memory-corruption-vulnerabilities-in-ni-circuit-design-suite.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T17:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hcj4-wc76-h25v/GHSA-hcj4-wc76-h25v.json b/advisories/unreviewed/2025/05/GHSA-hcj4-wc76-h25v/GHSA-hcj4-wc76-h25v.json new file mode 100644 index 00000000000..3595f142e33 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hcj4-wc76-h25v/GHSA-hcj4-wc76-h25v.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hcj4-wc76-h25v", + "modified": "2025-05-15T18:31:47Z", + "published": "2025-05-15T18:31:47Z", + "aliases": [ + "CVE-2025-30419" + ], + "details": "There is a memory corruption vulnerability due to an out of bounds read in GetSymbolBorderRectSize() when using the SymbolEditor in NI Circuit Design Suite.  This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted .sym file. This vulnerability affects NI Circuit Design Suite 14.3.0 and prior versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30419" + }, + { + "type": "WEB", + "url": "https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/memory-corruption-vulnerabilities-in-ni-circuit-design-suite.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T17:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-j442-3j4w-vh9f/GHSA-j442-3j4w-vh9f.json b/advisories/unreviewed/2025/05/GHSA-j442-3j4w-vh9f/GHSA-j442-3j4w-vh9f.json new file mode 100644 index 00000000000..cc5aeed3fa9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-j442-3j4w-vh9f/GHSA-j442-3j4w-vh9f.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j442-3j4w-vh9f", + "modified": "2025-05-15T18:31:47Z", + "published": "2025-05-15T18:31:47Z", + "aliases": [ + "CVE-2025-4707" + ], + "details": "A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /pages/transaction_add.php. The manipulation of the argument prod_name leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4707" + }, + { + "type": "WEB", + "url": "https://github.com/lanxia0/CVE/issues/1" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309005" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309005" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.568287" + }, + { + "type": "WEB", + "url": "https://www.campcodes.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T17:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jqjm-72wg-wcxg/GHSA-jqjm-72wg-wcxg.json b/advisories/unreviewed/2025/05/GHSA-jqjm-72wg-wcxg/GHSA-jqjm-72wg-wcxg.json new file mode 100644 index 00000000000..08ff0d01ba0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jqjm-72wg-wcxg/GHSA-jqjm-72wg-wcxg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jqjm-72wg-wcxg", + "modified": "2025-05-15T18:31:46Z", + "published": "2025-05-15T18:31:46Z", + "aliases": [ + "CVE-2025-3440" + ], + "details": "IBM Security Guardium 11.5 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3440" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7233600" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T16:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-m4qv-7jq9-f554/GHSA-m4qv-7jq9-f554.json b/advisories/unreviewed/2025/05/GHSA-m4qv-7jq9-f554/GHSA-m4qv-7jq9-f554.json index 7a7fd5e9a64..46ca8ed0a91 100644 --- a/advisories/unreviewed/2025/05/GHSA-m4qv-7jq9-f554/GHSA-m4qv-7jq9-f554.json +++ b/advisories/unreviewed/2025/05/GHSA-m4qv-7jq9-f554/GHSA-m4qv-7jq9-f554.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m4qv-7jq9-f554", - "modified": "2025-05-15T06:31:13Z", + "modified": "2025-05-15T18:31:43Z", "published": "2025-05-15T06:31:13Z", "aliases": [ "CVE-2025-3742" ], "details": "The Responsive Lightbox & Gallery WordPress plugin before 2.5.1 does not validate and escape some of its attributes before outputting them back in a page/post, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T06:15:37Z" diff --git a/advisories/unreviewed/2025/05/GHSA-mjmf-7vj6-xw78/GHSA-mjmf-7vj6-xw78.json b/advisories/unreviewed/2025/05/GHSA-mjmf-7vj6-xw78/GHSA-mjmf-7vj6-xw78.json new file mode 100644 index 00000000000..ac9dcd6104b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mjmf-7vj6-xw78/GHSA-mjmf-7vj6-xw78.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mjmf-7vj6-xw78", + "modified": "2025-05-15T18:31:47Z", + "published": "2025-05-15T18:31:47Z", + "aliases": [ + "CVE-2025-4704" + ], + "details": "A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/edit-category.php. The manipulation of the argument editid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4704" + }, + { + "type": "WEB", + "url": "https://github.com/baixiaobai001/myCVE/issues/3" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309002" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309002" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.567821" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T16:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p274-32q4-g22c/GHSA-p274-32q4-g22c.json b/advisories/unreviewed/2025/05/GHSA-p274-32q4-g22c/GHSA-p274-32q4-g22c.json new file mode 100644 index 00000000000..9b5f5d7f3e9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p274-32q4-g22c/GHSA-p274-32q4-g22c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p274-32q4-g22c", + "modified": "2025-05-15T18:31:47Z", + "published": "2025-05-15T18:31:47Z", + "aliases": [ + "CVE-2025-47580" + ], + "details": "Missing Authorization vulnerability in Rustaurius Front End Users allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Front End Users: from n/a through 3.2.32.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47580" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/front-end-only-users/vulnerability/wordpress-front-end-users-plugin-3-2-32-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T17:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p5gc-747c-w32p/GHSA-p5gc-747c-w32p.json b/advisories/unreviewed/2025/05/GHSA-p5gc-747c-w32p/GHSA-p5gc-747c-w32p.json new file mode 100644 index 00000000000..b4078f05019 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p5gc-747c-w32p/GHSA-p5gc-747c-w32p.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p5gc-747c-w32p", + "modified": "2025-05-15T18:31:47Z", + "published": "2025-05-15T18:31:47Z", + "aliases": [ + "CVE-2025-4706" + ], + "details": "A vulnerability was found in projectworlds Online Examination System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /Procedure3b_yearwiseVisit.php. The manipulation of the argument Visit_year leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4706" + }, + { + "type": "WEB", + "url": "https://github.com/Welhelm666/666/issues/2" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309004" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309004" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.567923" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T17:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q58r-hwc8-rm9j/GHSA-q58r-hwc8-rm9j.json b/advisories/unreviewed/2025/05/GHSA-q58r-hwc8-rm9j/GHSA-q58r-hwc8-rm9j.json new file mode 100644 index 00000000000..308f0e8664f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q58r-hwc8-rm9j/GHSA-q58r-hwc8-rm9j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q58r-hwc8-rm9j", + "modified": "2025-05-15T18:31:47Z", + "published": "2025-05-15T18:31:47Z", + "aliases": [ + "CVE-2025-1647" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Bootstrap allows Cross-Site Scripting (XSS).This issue affects Bootstrap: from 3.4.1 before 4.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1647" + }, + { + "type": "WEB", + "url": "https://www.herodevs.com/vulnerability-directory/cve-2025-1647" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T17:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qc53-6pcv-3q2p/GHSA-qc53-6pcv-3q2p.json b/advisories/unreviewed/2025/05/GHSA-qc53-6pcv-3q2p/GHSA-qc53-6pcv-3q2p.json new file mode 100644 index 00000000000..86fe2f96128 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qc53-6pcv-3q2p/GHSA-qc53-6pcv-3q2p.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qc53-6pcv-3q2p", + "modified": "2025-05-15T18:31:44Z", + "published": "2025-05-15T18:31:44Z", + "aliases": [ + "CVE-2024-52878" + ], + "details": "An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 05.54.50, kernel 5.6 before version 05.61.50, and kernel 5.7 before version 05.70.50. In VariableRuntimeDxe driver, VariableServicesSetVariable () can be called by gRT_>SetVariable () or the SmmSetSensitiveVariable () or SmmInternalSetVariable () from SMM. In VariableServicesSetVariable (), it uses StrSize () to get variable name size, uses StrLen () to get variable name length and uses StrCmp () to compare strings. These actions may cause a buffer over-read.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52878" + }, + { + "type": "WEB", + "url": "https://www.insyde.com/security-pledge" + }, + { + "type": "WEB", + "url": "https://www.insyde.com/security-pledge/sa-2024016" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T16:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vh6r-wx95-v75w/GHSA-vh6r-wx95-v75w.json b/advisories/unreviewed/2025/05/GHSA-vh6r-wx95-v75w/GHSA-vh6r-wx95-v75w.json new file mode 100644 index 00000000000..abed30ecbea --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vh6r-wx95-v75w/GHSA-vh6r-wx95-v75w.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vh6r-wx95-v75w", + "modified": "2025-05-15T18:31:48Z", + "published": "2025-05-15T18:31:48Z", + "aliases": [ + "CVE-2025-4710" + ], + "details": "A vulnerability, which was classified as critical, has been found in Campcodes Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file /pages/transaction.php. The manipulation of the argument cid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4710" + }, + { + "type": "WEB", + "url": "https://github.com/lanxia0/CVE/issues/4" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309008" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309008" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.568290" + }, + { + "type": "WEB", + "url": "https://www.campcodes.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T18:15:38Z" + } +} \ No newline at end of file