diff --git a/advisories/unreviewed/2022/10/GHSA-73hh-p4j2-j7gj/GHSA-73hh-p4j2-j7gj.json b/advisories/unreviewed/2022/10/GHSA-73hh-p4j2-j7gj/GHSA-73hh-p4j2-j7gj.json index 905c5aee129..2ba89e86968 100644 --- a/advisories/unreviewed/2022/10/GHSA-73hh-p4j2-j7gj/GHSA-73hh-p4j2-j7gj.json +++ b/advisories/unreviewed/2022/10/GHSA-73hh-p4j2-j7gj/GHSA-73hh-p4j2-j7gj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-73hh-p4j2-j7gj", - "modified": "2022-10-22T12:00:26Z", + "modified": "2025-05-08T21:32:39Z", "published": "2022-10-19T12:00:21Z", "aliases": [ "CVE-2022-40798" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-8qpr-77x5-fg45/GHSA-8qpr-77x5-fg45.json b/advisories/unreviewed/2022/10/GHSA-8qpr-77x5-fg45/GHSA-8qpr-77x5-fg45.json index 49718008161..ca3cde8ec6f 100644 --- a/advisories/unreviewed/2022/10/GHSA-8qpr-77x5-fg45/GHSA-8qpr-77x5-fg45.json +++ b/advisories/unreviewed/2022/10/GHSA-8qpr-77x5-fg45/GHSA-8qpr-77x5-fg45.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8qpr-77x5-fg45", - "modified": "2022-10-21T12:00:21Z", + "modified": "2025-05-08T21:32:40Z", "published": "2022-10-19T19:00:24Z", "aliases": [ "CVE-2022-43184" @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/10/GHSA-jrf7-j32j-32gj/GHSA-jrf7-j32j-32gj.json b/advisories/unreviewed/2022/10/GHSA-jrf7-j32j-32gj/GHSA-jrf7-j32j-32gj.json index 4aa82aa67cf..9e7e5d8845f 100644 --- a/advisories/unreviewed/2022/10/GHSA-jrf7-j32j-32gj/GHSA-jrf7-j32j-32gj.json +++ b/advisories/unreviewed/2022/10/GHSA-jrf7-j32j-32gj/GHSA-jrf7-j32j-32gj.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-qrw5-w925-f5g8/GHSA-qrw5-w925-f5g8.json b/advisories/unreviewed/2022/10/GHSA-qrw5-w925-f5g8/GHSA-qrw5-w925-f5g8.json index 88f549fee8c..228d74c3a81 100644 --- a/advisories/unreviewed/2022/10/GHSA-qrw5-w925-f5g8/GHSA-qrw5-w925-f5g8.json +++ b/advisories/unreviewed/2022/10/GHSA-qrw5-w925-f5g8/GHSA-qrw5-w925-f5g8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qrw5-w925-f5g8", - "modified": "2022-10-21T19:01:12Z", + "modified": "2025-05-08T21:32:44Z", "published": "2022-10-20T12:00:17Z", "aliases": [ "CVE-2022-41708" diff --git a/advisories/unreviewed/2022/10/GHSA-ww7f-q2j7-w8wr/GHSA-ww7f-q2j7-w8wr.json b/advisories/unreviewed/2022/10/GHSA-ww7f-q2j7-w8wr/GHSA-ww7f-q2j7-w8wr.json index ab22a45183b..a73890a0e34 100644 --- a/advisories/unreviewed/2022/10/GHSA-ww7f-q2j7-w8wr/GHSA-ww7f-q2j7-w8wr.json +++ b/advisories/unreviewed/2022/10/GHSA-ww7f-q2j7-w8wr/GHSA-ww7f-q2j7-w8wr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ww7f-q2j7-w8wr", - "modified": "2022-10-21T12:00:21Z", + "modified": "2025-05-08T21:32:43Z", "published": "2022-10-19T19:00:17Z", "aliases": [ "CVE-2022-41707" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-3x65-x797-c3v9/GHSA-3x65-x797-c3v9.json b/advisories/unreviewed/2024/02/GHSA-3x65-x797-c3v9/GHSA-3x65-x797-c3v9.json index 72c098ced56..2639a3793b9 100644 --- a/advisories/unreviewed/2024/02/GHSA-3x65-x797-c3v9/GHSA-3x65-x797-c3v9.json +++ b/advisories/unreviewed/2024/02/GHSA-3x65-x797-c3v9/GHSA-3x65-x797-c3v9.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-3x65-x797-c3v9", - "modified": "2024-02-15T15:30:26Z", + "modified": "2025-05-08T21:32:47Z", "published": "2024-02-07T18:30:27Z", "aliases": [ "CVE-2024-22012" ], - "details": "In TBD of TBD, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.\n\n", + "details": "In TBD of TBD, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-3898-wjpq-fj5f/GHSA-3898-wjpq-fj5f.json b/advisories/unreviewed/2024/04/GHSA-3898-wjpq-fj5f/GHSA-3898-wjpq-fj5f.json index 1cb8f61aee1..4bfe12c5fab 100644 --- a/advisories/unreviewed/2024/04/GHSA-3898-wjpq-fj5f/GHSA-3898-wjpq-fj5f.json +++ b/advisories/unreviewed/2024/04/GHSA-3898-wjpq-fj5f/GHSA-3898-wjpq-fj5f.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-3gx6-pfq2-pf53/GHSA-3gx6-pfq2-pf53.json b/advisories/unreviewed/2024/04/GHSA-3gx6-pfq2-pf53/GHSA-3gx6-pfq2-pf53.json index 23e072e77d7..6bb7746b55a 100644 --- a/advisories/unreviewed/2024/04/GHSA-3gx6-pfq2-pf53/GHSA-3gx6-pfq2-pf53.json +++ b/advisories/unreviewed/2024/04/GHSA-3gx6-pfq2-pf53/GHSA-3gx6-pfq2-pf53.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-8x3m-wfv9-h46j/GHSA-8x3m-wfv9-h46j.json b/advisories/unreviewed/2024/04/GHSA-8x3m-wfv9-h46j/GHSA-8x3m-wfv9-h46j.json index 73b273a9043..70308c01edb 100644 --- a/advisories/unreviewed/2024/04/GHSA-8x3m-wfv9-h46j/GHSA-8x3m-wfv9-h46j.json +++ b/advisories/unreviewed/2024/04/GHSA-8x3m-wfv9-h46j/GHSA-8x3m-wfv9-h46j.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-c9m8-7p4q-vfm3/GHSA-c9m8-7p4q-vfm3.json b/advisories/unreviewed/2024/04/GHSA-c9m8-7p4q-vfm3/GHSA-c9m8-7p4q-vfm3.json index 1a01b4dfc05..4266faf8ebc 100644 --- a/advisories/unreviewed/2024/04/GHSA-c9m8-7p4q-vfm3/GHSA-c9m8-7p4q-vfm3.json +++ b/advisories/unreviewed/2024/04/GHSA-c9m8-7p4q-vfm3/GHSA-c9m8-7p4q-vfm3.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-fcw6-ccq2-f46p/GHSA-fcw6-ccq2-f46p.json b/advisories/unreviewed/2024/04/GHSA-fcw6-ccq2-f46p/GHSA-fcw6-ccq2-f46p.json index 3197cb60005..3f91b9994f6 100644 --- a/advisories/unreviewed/2024/04/GHSA-fcw6-ccq2-f46p/GHSA-fcw6-ccq2-f46p.json +++ b/advisories/unreviewed/2024/04/GHSA-fcw6-ccq2-f46p/GHSA-fcw6-ccq2-f46p.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-fh99-9gvw-rw3c/GHSA-fh99-9gvw-rw3c.json b/advisories/unreviewed/2024/04/GHSA-fh99-9gvw-rw3c/GHSA-fh99-9gvw-rw3c.json index 7893926799e..f427066ce9d 100644 --- a/advisories/unreviewed/2024/04/GHSA-fh99-9gvw-rw3c/GHSA-fh99-9gvw-rw3c.json +++ b/advisories/unreviewed/2024/04/GHSA-fh99-9gvw-rw3c/GHSA-fh99-9gvw-rw3c.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-g2j7-fw82-h6x5/GHSA-g2j7-fw82-h6x5.json b/advisories/unreviewed/2024/04/GHSA-g2j7-fw82-h6x5/GHSA-g2j7-fw82-h6x5.json index 2cea5b07400..38e42a5b456 100644 --- a/advisories/unreviewed/2024/04/GHSA-g2j7-fw82-h6x5/GHSA-g2j7-fw82-h6x5.json +++ b/advisories/unreviewed/2024/04/GHSA-g2j7-fw82-h6x5/GHSA-g2j7-fw82-h6x5.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-g6jj-43rf-3wc6/GHSA-g6jj-43rf-3wc6.json b/advisories/unreviewed/2024/04/GHSA-g6jj-43rf-3wc6/GHSA-g6jj-43rf-3wc6.json index e20c1604add..ed2b99db7a4 100644 --- a/advisories/unreviewed/2024/04/GHSA-g6jj-43rf-3wc6/GHSA-g6jj-43rf-3wc6.json +++ b/advisories/unreviewed/2024/04/GHSA-g6jj-43rf-3wc6/GHSA-g6jj-43rf-3wc6.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-g6jj-43rf-3wc6", - "modified": "2024-04-10T15:30:38Z", + "modified": "2025-05-08T21:32:47Z", "published": "2024-04-10T15:30:38Z", "aliases": [ "CVE-2023-50347" ], - "details": "HCL DRYiCE MyXalytics is impacted by an insecure SQL interface vulnerability, potentially giving an attacker the ability to execute custom SQL queries. A malicious user can run arbitrary SQL commands including changing system configuration.\n", + "details": "HCL DRYiCE MyXalytics is impacted by an insecure SQL interface vulnerability, potentially giving an attacker the ability to execute custom SQL queries. A malicious user can run arbitrary SQL commands including changing system configuration.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-hv8g-gp7c-5rcj/GHSA-hv8g-gp7c-5rcj.json b/advisories/unreviewed/2024/04/GHSA-hv8g-gp7c-5rcj/GHSA-hv8g-gp7c-5rcj.json index ab424690084..d334cfc5216 100644 --- a/advisories/unreviewed/2024/04/GHSA-hv8g-gp7c-5rcj/GHSA-hv8g-gp7c-5rcj.json +++ b/advisories/unreviewed/2024/04/GHSA-hv8g-gp7c-5rcj/GHSA-hv8g-gp7c-5rcj.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-pp2f-6536-5xg8/GHSA-pp2f-6536-5xg8.json b/advisories/unreviewed/2024/04/GHSA-pp2f-6536-5xg8/GHSA-pp2f-6536-5xg8.json index b935bde67d6..91bcaea0049 100644 --- a/advisories/unreviewed/2024/04/GHSA-pp2f-6536-5xg8/GHSA-pp2f-6536-5xg8.json +++ b/advisories/unreviewed/2024/04/GHSA-pp2f-6536-5xg8/GHSA-pp2f-6536-5xg8.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-918" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-v2xc-vg4h-28jp/GHSA-v2xc-vg4h-28jp.json b/advisories/unreviewed/2024/04/GHSA-v2xc-vg4h-28jp/GHSA-v2xc-vg4h-28jp.json index ba2ab7ef9de..62593e29f88 100644 --- a/advisories/unreviewed/2024/04/GHSA-v2xc-vg4h-28jp/GHSA-v2xc-vg4h-28jp.json +++ b/advisories/unreviewed/2024/04/GHSA-v2xc-vg4h-28jp/GHSA-v2xc-vg4h-28jp.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-v859-v234-c2mg/GHSA-v859-v234-c2mg.json b/advisories/unreviewed/2024/04/GHSA-v859-v234-c2mg/GHSA-v859-v234-c2mg.json index a4d5d637b31..d858b172b88 100644 --- a/advisories/unreviewed/2024/04/GHSA-v859-v234-c2mg/GHSA-v859-v234-c2mg.json +++ b/advisories/unreviewed/2024/04/GHSA-v859-v234-c2mg/GHSA-v859-v234-c2mg.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-vv98-j6p5-8hj3/GHSA-vv98-j6p5-8hj3.json b/advisories/unreviewed/2024/04/GHSA-vv98-j6p5-8hj3/GHSA-vv98-j6p5-8hj3.json index a0febf0e1b9..d85569a9d3c 100644 --- a/advisories/unreviewed/2024/04/GHSA-vv98-j6p5-8hj3/GHSA-vv98-j6p5-8hj3.json +++ b/advisories/unreviewed/2024/04/GHSA-vv98-j6p5-8hj3/GHSA-vv98-j6p5-8hj3.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-x8mf-46wq-x274/GHSA-x8mf-46wq-x274.json b/advisories/unreviewed/2024/04/GHSA-x8mf-46wq-x274/GHSA-x8mf-46wq-x274.json index fd476958052..55a176725f5 100644 --- a/advisories/unreviewed/2024/04/GHSA-x8mf-46wq-x274/GHSA-x8mf-46wq-x274.json +++ b/advisories/unreviewed/2024/04/GHSA-x8mf-46wq-x274/GHSA-x8mf-46wq-x274.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-mgmj-jff7-4w5p/GHSA-mgmj-jff7-4w5p.json b/advisories/unreviewed/2024/05/GHSA-mgmj-jff7-4w5p/GHSA-mgmj-jff7-4w5p.json index 80155c38247..38201e4bdeb 100644 --- a/advisories/unreviewed/2024/05/GHSA-mgmj-jff7-4w5p/GHSA-mgmj-jff7-4w5p.json +++ b/advisories/unreviewed/2024/05/GHSA-mgmj-jff7-4w5p/GHSA-mgmj-jff7-4w5p.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-p6qv-frqj-63r6/GHSA-p6qv-frqj-63r6.json b/advisories/unreviewed/2024/05/GHSA-p6qv-frqj-63r6/GHSA-p6qv-frqj-63r6.json index a0fa1c7001d..0a979f14e02 100644 --- a/advisories/unreviewed/2024/05/GHSA-p6qv-frqj-63r6/GHSA-p6qv-frqj-63r6.json +++ b/advisories/unreviewed/2024/05/GHSA-p6qv-frqj-63r6/GHSA-p6qv-frqj-63r6.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/08/GHSA-5236-gxxf-m73h/GHSA-5236-gxxf-m73h.json b/advisories/unreviewed/2024/08/GHSA-5236-gxxf-m73h/GHSA-5236-gxxf-m73h.json index 52e28b1ff13..415af52a64f 100644 --- a/advisories/unreviewed/2024/08/GHSA-5236-gxxf-m73h/GHSA-5236-gxxf-m73h.json +++ b/advisories/unreviewed/2024/08/GHSA-5236-gxxf-m73h/GHSA-5236-gxxf-m73h.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/08/GHSA-c4v2-g748-rmrp/GHSA-c4v2-g748-rmrp.json b/advisories/unreviewed/2024/08/GHSA-c4v2-g748-rmrp/GHSA-c4v2-g748-rmrp.json index 5c27f55b7eb..6445463bf21 100644 --- a/advisories/unreviewed/2024/08/GHSA-c4v2-g748-rmrp/GHSA-c4v2-g748-rmrp.json +++ b/advisories/unreviewed/2024/08/GHSA-c4v2-g748-rmrp/GHSA-c4v2-g748-rmrp.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/08/GHSA-hfgc-xxrj-48m3/GHSA-hfgc-xxrj-48m3.json b/advisories/unreviewed/2024/08/GHSA-hfgc-xxrj-48m3/GHSA-hfgc-xxrj-48m3.json index 285d3cfc110..416f091843c 100644 --- a/advisories/unreviewed/2024/08/GHSA-hfgc-xxrj-48m3/GHSA-hfgc-xxrj-48m3.json +++ b/advisories/unreviewed/2024/08/GHSA-hfgc-xxrj-48m3/GHSA-hfgc-xxrj-48m3.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-447r-cxfc-3q93/GHSA-447r-cxfc-3q93.json b/advisories/unreviewed/2024/12/GHSA-447r-cxfc-3q93/GHSA-447r-cxfc-3q93.json index 0efec347bf2..b179ae042ce 100644 --- a/advisories/unreviewed/2024/12/GHSA-447r-cxfc-3q93/GHSA-447r-cxfc-3q93.json +++ b/advisories/unreviewed/2024/12/GHSA-447r-cxfc-3q93/GHSA-447r-cxfc-3q93.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-r72x-8472-jjv6/GHSA-r72x-8472-jjv6.json b/advisories/unreviewed/2024/12/GHSA-r72x-8472-jjv6/GHSA-r72x-8472-jjv6.json index d8fc80916b3..0d0986b00e7 100644 --- a/advisories/unreviewed/2024/12/GHSA-r72x-8472-jjv6/GHSA-r72x-8472-jjv6.json +++ b/advisories/unreviewed/2024/12/GHSA-r72x-8472-jjv6/GHSA-r72x-8472-jjv6.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-45gg-w2cf-qwhh/GHSA-45gg-w2cf-qwhh.json b/advisories/unreviewed/2025/01/GHSA-45gg-w2cf-qwhh/GHSA-45gg-w2cf-qwhh.json index 018c232cf11..21e1d54f31e 100644 --- a/advisories/unreviewed/2025/01/GHSA-45gg-w2cf-qwhh/GHSA-45gg-w2cf-qwhh.json +++ b/advisories/unreviewed/2025/01/GHSA-45gg-w2cf-qwhh/GHSA-45gg-w2cf-qwhh.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-6qmq-j47c-v4fj/GHSA-6qmq-j47c-v4fj.json b/advisories/unreviewed/2025/01/GHSA-6qmq-j47c-v4fj/GHSA-6qmq-j47c-v4fj.json index 18f367025be..ebde1279c8e 100644 --- a/advisories/unreviewed/2025/01/GHSA-6qmq-j47c-v4fj/GHSA-6qmq-j47c-v4fj.json +++ b/advisories/unreviewed/2025/01/GHSA-6qmq-j47c-v4fj/GHSA-6qmq-j47c-v4fj.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-cw8x-p7hf-968r/GHSA-cw8x-p7hf-968r.json b/advisories/unreviewed/2025/01/GHSA-cw8x-p7hf-968r/GHSA-cw8x-p7hf-968r.json index de365a85b5b..8255de3ba45 100644 --- a/advisories/unreviewed/2025/01/GHSA-cw8x-p7hf-968r/GHSA-cw8x-p7hf-968r.json +++ b/advisories/unreviewed/2025/01/GHSA-cw8x-p7hf-968r/GHSA-cw8x-p7hf-968r.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-hpcp-qr34-rj6h/GHSA-hpcp-qr34-rj6h.json b/advisories/unreviewed/2025/01/GHSA-hpcp-qr34-rj6h/GHSA-hpcp-qr34-rj6h.json index 35855d511d9..2a863995d23 100644 --- a/advisories/unreviewed/2025/01/GHSA-hpcp-qr34-rj6h/GHSA-hpcp-qr34-rj6h.json +++ b/advisories/unreviewed/2025/01/GHSA-hpcp-qr34-rj6h/GHSA-hpcp-qr34-rj6h.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-20" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-pwfr-93g9-4wj6/GHSA-pwfr-93g9-4wj6.json b/advisories/unreviewed/2025/01/GHSA-pwfr-93g9-4wj6/GHSA-pwfr-93g9-4wj6.json index f1c87ada4a0..4c4659c37b9 100644 --- a/advisories/unreviewed/2025/01/GHSA-pwfr-93g9-4wj6/GHSA-pwfr-93g9-4wj6.json +++ b/advisories/unreviewed/2025/01/GHSA-pwfr-93g9-4wj6/GHSA-pwfr-93g9-4wj6.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-r7m8-pv7c-r2ph/GHSA-r7m8-pv7c-r2ph.json b/advisories/unreviewed/2025/01/GHSA-r7m8-pv7c-r2ph/GHSA-r7m8-pv7c-r2ph.json index c4462eec41a..e45d8c0aa70 100644 --- a/advisories/unreviewed/2025/01/GHSA-r7m8-pv7c-r2ph/GHSA-r7m8-pv7c-r2ph.json +++ b/advisories/unreviewed/2025/01/GHSA-r7m8-pv7c-r2ph/GHSA-r7m8-pv7c-r2ph.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-2cwr-c8cj-f6f4/GHSA-2cwr-c8cj-f6f4.json b/advisories/unreviewed/2025/03/GHSA-2cwr-c8cj-f6f4/GHSA-2cwr-c8cj-f6f4.json index 109eabf45c8..8ca0ff6e40c 100644 --- a/advisories/unreviewed/2025/03/GHSA-2cwr-c8cj-f6f4/GHSA-2cwr-c8cj-f6f4.json +++ b/advisories/unreviewed/2025/03/GHSA-2cwr-c8cj-f6f4/GHSA-2cwr-c8cj-f6f4.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-977w-pp48-pf8q/GHSA-977w-pp48-pf8q.json b/advisories/unreviewed/2025/03/GHSA-977w-pp48-pf8q/GHSA-977w-pp48-pf8q.json index 59341ed30af..5941e87a75c 100644 --- a/advisories/unreviewed/2025/03/GHSA-977w-pp48-pf8q/GHSA-977w-pp48-pf8q.json +++ b/advisories/unreviewed/2025/03/GHSA-977w-pp48-pf8q/GHSA-977w-pp48-pf8q.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-9x7f-6h8g-ffm8/GHSA-9x7f-6h8g-ffm8.json b/advisories/unreviewed/2025/03/GHSA-9x7f-6h8g-ffm8/GHSA-9x7f-6h8g-ffm8.json index 83ccb53d848..ce27053b02d 100644 --- a/advisories/unreviewed/2025/03/GHSA-9x7f-6h8g-ffm8/GHSA-9x7f-6h8g-ffm8.json +++ b/advisories/unreviewed/2025/03/GHSA-9x7f-6h8g-ffm8/GHSA-9x7f-6h8g-ffm8.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-f34f-58mj-qm6g/GHSA-f34f-58mj-qm6g.json b/advisories/unreviewed/2025/03/GHSA-f34f-58mj-qm6g/GHSA-f34f-58mj-qm6g.json index 79c40b84a6e..9e1b5b2e01a 100644 --- a/advisories/unreviewed/2025/03/GHSA-f34f-58mj-qm6g/GHSA-f34f-58mj-qm6g.json +++ b/advisories/unreviewed/2025/03/GHSA-f34f-58mj-qm6g/GHSA-f34f-58mj-qm6g.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-m9p4-xc7j-vhm2/GHSA-m9p4-xc7j-vhm2.json b/advisories/unreviewed/2025/03/GHSA-m9p4-xc7j-vhm2/GHSA-m9p4-xc7j-vhm2.json index 87b6655e142..950d06f4a8d 100644 --- a/advisories/unreviewed/2025/03/GHSA-m9p4-xc7j-vhm2/GHSA-m9p4-xc7j-vhm2.json +++ b/advisories/unreviewed/2025/03/GHSA-m9p4-xc7j-vhm2/GHSA-m9p4-xc7j-vhm2.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-mfx7-6x75-v7hg/GHSA-mfx7-6x75-v7hg.json b/advisories/unreviewed/2025/03/GHSA-mfx7-6x75-v7hg/GHSA-mfx7-6x75-v7hg.json index 44fae9036e2..25fefb75f3d 100644 --- a/advisories/unreviewed/2025/03/GHSA-mfx7-6x75-v7hg/GHSA-mfx7-6x75-v7hg.json +++ b/advisories/unreviewed/2025/03/GHSA-mfx7-6x75-v7hg/GHSA-mfx7-6x75-v7hg.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-w8r4-6553-5894/GHSA-w8r4-6553-5894.json b/advisories/unreviewed/2025/03/GHSA-w8r4-6553-5894/GHSA-w8r4-6553-5894.json index c94f3f534f4..6cc434ef8e8 100644 --- a/advisories/unreviewed/2025/03/GHSA-w8r4-6553-5894/GHSA-w8r4-6553-5894.json +++ b/advisories/unreviewed/2025/03/GHSA-w8r4-6553-5894/GHSA-w8r4-6553-5894.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-xvrr-xhhf-9pj8/GHSA-xvrr-xhhf-9pj8.json b/advisories/unreviewed/2025/03/GHSA-xvrr-xhhf-9pj8/GHSA-xvrr-xhhf-9pj8.json index 43c977a86fe..4ee75970372 100644 --- a/advisories/unreviewed/2025/03/GHSA-xvrr-xhhf-9pj8/GHSA-xvrr-xhhf-9pj8.json +++ b/advisories/unreviewed/2025/03/GHSA-xvrr-xhhf-9pj8/GHSA-xvrr-xhhf-9pj8.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-53jr-r39g-w259/GHSA-53jr-r39g-w259.json b/advisories/unreviewed/2025/04/GHSA-53jr-r39g-w259/GHSA-53jr-r39g-w259.json index ec5b2c57b6d..2b63b5b4ab5 100644 --- a/advisories/unreviewed/2025/04/GHSA-53jr-r39g-w259/GHSA-53jr-r39g-w259.json +++ b/advisories/unreviewed/2025/04/GHSA-53jr-r39g-w259/GHSA-53jr-r39g-w259.json @@ -50,7 +50,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-r5q5-p828-45hr/GHSA-r5q5-p828-45hr.json b/advisories/unreviewed/2025/04/GHSA-r5q5-p828-45hr/GHSA-r5q5-p828-45hr.json index 169d66eb9c5..76988b2c7de 100644 --- a/advisories/unreviewed/2025/04/GHSA-r5q5-p828-45hr/GHSA-r5q5-p828-45hr.json +++ b/advisories/unreviewed/2025/04/GHSA-r5q5-p828-45hr/GHSA-r5q5-p828-45hr.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-xcr2-mqg2-gv48/GHSA-xcr2-mqg2-gv48.json b/advisories/unreviewed/2025/04/GHSA-xcr2-mqg2-gv48/GHSA-xcr2-mqg2-gv48.json index 8ab6dfdcb8f..9cfe4f8b2fc 100644 --- a/advisories/unreviewed/2025/04/GHSA-xcr2-mqg2-gv48/GHSA-xcr2-mqg2-gv48.json +++ b/advisories/unreviewed/2025/04/GHSA-xcr2-mqg2-gv48/GHSA-xcr2-mqg2-gv48.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-4pgh-326f-32p3/GHSA-4pgh-326f-32p3.json b/advisories/unreviewed/2025/05/GHSA-4pgh-326f-32p3/GHSA-4pgh-326f-32p3.json new file mode 100644 index 00000000000..99c79dc3d42 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4pgh-326f-32p3/GHSA-4pgh-326f-32p3.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4pgh-326f-32p3", + "modified": "2025-05-08T21:32:56Z", + "published": "2025-05-08T21:32:56Z", + "aliases": [ + "CVE-2025-28073" + ], + "details": "phpList 3.6.3 is vulnerable to Reflected Cross-Site Scripting (XSS) via the /lists/dl.php endpoint. An attacker can inject arbitrary JavaScript code by manipulating the id parameter, which is improperly sanitized.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28073" + }, + { + "type": "WEB", + "url": "https://github.com/mLniumm/CVE-2025-28073" + }, + { + "type": "WEB", + "url": "https://github.com/phpList/phplist3" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T20:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6rc8-h6xq-v545/GHSA-6rc8-h6xq-v545.json b/advisories/unreviewed/2025/05/GHSA-6rc8-h6xq-v545/GHSA-6rc8-h6xq-v545.json new file mode 100644 index 00000000000..e3c35e6f663 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6rc8-h6xq-v545/GHSA-6rc8-h6xq-v545.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6rc8-h6xq-v545", + "modified": "2025-05-08T21:32:56Z", + "published": "2025-05-08T21:32:56Z", + "aliases": [ + "CVE-2025-45790" + ], + "details": "TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow via the priority parameter in the setMacQos interface of /lib/cste_modules/firewall.so.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45790" + }, + { + "type": "WEB", + "url": "https://github.com/SunnyYANGyaya/cuicuishark-sheep-fishIOT/blob/main/ToTolink/A3100R-4/README.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T20:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-72mf-gxhw-jp8r/GHSA-72mf-gxhw-jp8r.json b/advisories/unreviewed/2025/05/GHSA-72mf-gxhw-jp8r/GHSA-72mf-gxhw-jp8r.json new file mode 100644 index 00000000000..787e8cf1078 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-72mf-gxhw-jp8r/GHSA-72mf-gxhw-jp8r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-72mf-gxhw-jp8r", + "modified": "2025-05-08T21:32:57Z", + "published": "2025-05-08T21:32:57Z", + "aliases": [ + "CVE-2025-4475" + ], + "details": "Issue in my product in blah version x on y allows bad person to break", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4475" + }, + { + "type": "WEB", + "url": "https://xxx" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-319" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T20:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8966-rh6p-j7h4/GHSA-8966-rh6p-j7h4.json b/advisories/unreviewed/2025/05/GHSA-8966-rh6p-j7h4/GHSA-8966-rh6p-j7h4.json new file mode 100644 index 00000000000..94a7381b6a2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8966-rh6p-j7h4/GHSA-8966-rh6p-j7h4.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8966-rh6p-j7h4", + "modified": "2025-05-08T21:32:56Z", + "published": "2025-05-08T21:32:56Z", + "aliases": [ + "CVE-2025-44023" + ], + "details": "An issue in dlink DNS-320 v.1.00 and DNS-320LW v.1.01.0914.20212 allows an attacker to execute arbitrary via the account_mgr.cgi->cgi_chg_admin_pw components.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44023" + }, + { + "type": "WEB", + "url": "https://www.yuque.com/nirvana-chkbf/kb/cakchpet9vxgqm0h?singleDoc" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T20:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8hx2-3q2m-9xxf/GHSA-8hx2-3q2m-9xxf.json b/advisories/unreviewed/2025/05/GHSA-8hx2-3q2m-9xxf/GHSA-8hx2-3q2m-9xxf.json index 5d77cf2f3a0..e3c8d6efb9f 100644 --- a/advisories/unreviewed/2025/05/GHSA-8hx2-3q2m-9xxf/GHSA-8hx2-3q2m-9xxf.json +++ b/advisories/unreviewed/2025/05/GHSA-8hx2-3q2m-9xxf/GHSA-8hx2-3q2m-9xxf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8hx2-3q2m-9xxf", - "modified": "2025-05-08T18:30:43Z", + "modified": "2025-05-08T21:32:55Z", "published": "2025-05-08T18:30:42Z", "aliases": [ "CVE-2025-26845" ], "details": "An Eval Injection issue was discovered in Znuny through 7.1.3. A user with write access to the configuration file can use this to execute a command executed by the user running the backup.pl script.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-95" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-08T17:16:01Z" diff --git a/advisories/unreviewed/2025/05/GHSA-8vj7-x3hq-82c6/GHSA-8vj7-x3hq-82c6.json b/advisories/unreviewed/2025/05/GHSA-8vj7-x3hq-82c6/GHSA-8vj7-x3hq-82c6.json index f040c1ce0e2..b1c78f9e5fa 100644 --- a/advisories/unreviewed/2025/05/GHSA-8vj7-x3hq-82c6/GHSA-8vj7-x3hq-82c6.json +++ b/advisories/unreviewed/2025/05/GHSA-8vj7-x3hq-82c6/GHSA-8vj7-x3hq-82c6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8vj7-x3hq-82c6", - "modified": "2025-05-06T18:30:39Z", + "modified": "2025-05-08T21:32:54Z", "published": "2025-05-06T18:30:39Z", "aliases": [ "CVE-2023-33770" ], "details": "Real Estate Management System v1.0 was discovered to contain a SQL injection vulnerability via the message parameter at /contact.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-06T17:15:53Z" diff --git a/advisories/unreviewed/2025/05/GHSA-9vv2-f3c8-m9x6/GHSA-9vv2-f3c8-m9x6.json b/advisories/unreviewed/2025/05/GHSA-9vv2-f3c8-m9x6/GHSA-9vv2-f3c8-m9x6.json new file mode 100644 index 00000000000..030e0ad1fd8 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9vv2-f3c8-m9x6/GHSA-9vv2-f3c8-m9x6.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9vv2-f3c8-m9x6", + "modified": "2025-05-08T21:32:57Z", + "published": "2025-05-08T21:32:57Z", + "aliases": [ + "CVE-2025-28074" + ], + "details": "phpList prior to 3.6.3 is vulnerable to Cross-Site Scripting (XSS) due to improper input sanitization in lt.php. The vulnerability is exploitable when the application dynamically references internal paths and processes untrusted input without escaping, allowing an attacker to inject malicious JavaScript.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28074" + }, + { + "type": "WEB", + "url": "https://github.com/mLniumm/CVE-2025-28074" + }, + { + "type": "WEB", + "url": "https://github.com/phpList/phplist3/blob/main/public_html/lists/lt.php" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T21:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c2x5-mpj8-v9v9/GHSA-c2x5-mpj8-v9v9.json b/advisories/unreviewed/2025/05/GHSA-c2x5-mpj8-v9v9/GHSA-c2x5-mpj8-v9v9.json index 35fa2115a7c..f9bd7309783 100644 --- a/advisories/unreviewed/2025/05/GHSA-c2x5-mpj8-v9v9/GHSA-c2x5-mpj8-v9v9.json +++ b/advisories/unreviewed/2025/05/GHSA-c2x5-mpj8-v9v9/GHSA-c2x5-mpj8-v9v9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c2x5-mpj8-v9v9", - "modified": "2025-05-08T18:30:42Z", + "modified": "2025-05-08T21:32:55Z", "published": "2025-05-08T18:30:42Z", "aliases": [ "CVE-2025-26842" ], "details": "An issue was discovered in Znuny through 7.1.3. If access to a ticket is not given, the content of S/MIME encrypted e-mail messages is visible to users with access to the CommunicationLog.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-863" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-08T16:15:25Z" diff --git a/advisories/unreviewed/2025/05/GHSA-crjm-f8jp-7pww/GHSA-crjm-f8jp-7pww.json b/advisories/unreviewed/2025/05/GHSA-crjm-f8jp-7pww/GHSA-crjm-f8jp-7pww.json index 30f66e1cbac..a01b2dedd0b 100644 --- a/advisories/unreviewed/2025/05/GHSA-crjm-f8jp-7pww/GHSA-crjm-f8jp-7pww.json +++ b/advisories/unreviewed/2025/05/GHSA-crjm-f8jp-7pww/GHSA-crjm-f8jp-7pww.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-crjm-f8jp-7pww", - "modified": "2025-05-08T18:30:42Z", + "modified": "2025-05-08T21:32:55Z", "published": "2025-05-08T18:30:42Z", "aliases": [ "CVE-2025-26847" ], "details": "An issue was discovered in Znuny before 7.1.5. When generating a support bundle, not all passwords are masked.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-521" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-08T17:16:01Z" diff --git a/advisories/unreviewed/2025/05/GHSA-f369-84xf-vvxq/GHSA-f369-84xf-vvxq.json b/advisories/unreviewed/2025/05/GHSA-f369-84xf-vvxq/GHSA-f369-84xf-vvxq.json new file mode 100644 index 00000000000..06bb199f2e2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-f369-84xf-vvxq/GHSA-f369-84xf-vvxq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f369-84xf-vvxq", + "modified": "2025-05-08T21:32:56Z", + "published": "2025-05-08T21:32:56Z", + "aliases": [ + "CVE-2024-12378" + ], + "details": "On affected platforms running Arista EOS with secure Vxlan configured, restarting the Tunnelsec agent will result in packets being sent over the secure Vxlan tunnels in the clear.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12378" + }, + { + "type": "WEB", + "url": "https://www.arista.com/en/support/advisories-notices/security-advisory/21289-security-advisory-0113" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-319" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T19:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g4cf-3pjw-w4xj/GHSA-g4cf-3pjw-w4xj.json b/advisories/unreviewed/2025/05/GHSA-g4cf-3pjw-w4xj/GHSA-g4cf-3pjw-w4xj.json new file mode 100644 index 00000000000..33409c83843 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g4cf-3pjw-w4xj/GHSA-g4cf-3pjw-w4xj.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g4cf-3pjw-w4xj", + "modified": "2025-05-08T21:32:56Z", + "published": "2025-05-08T21:32:56Z", + "aliases": [ + "CVE-2025-45797" + ], + "details": "TOTOlink A950RG V4.1.2cu.5204_B20210112 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the NoticeUrl parameter in the setNoticeCfg interface of /lib/cste_modules/system.so.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45797" + }, + { + "type": "WEB", + "url": "https://github.com/SunnyYANGyaya/cuicuishark-sheep-fishIOT/blob/main/ToTolink/A950RG/5024-setNoticeCFG-NoticURL-buffer.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T20:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h796-c7fq-p478/GHSA-h796-c7fq-p478.json b/advisories/unreviewed/2025/05/GHSA-h796-c7fq-p478/GHSA-h796-c7fq-p478.json new file mode 100644 index 00000000000..f360524b626 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h796-c7fq-p478/GHSA-h796-c7fq-p478.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h796-c7fq-p478", + "modified": "2025-05-08T21:32:56Z", + "published": "2025-05-08T21:32:56Z", + "aliases": [ + "CVE-2025-27695" + ], + "details": "Dell Wyse Management Suite, versions prior to WMS 5.1 contain an Authentication Bypass by Spoofing vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information Disclosure.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27695" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000296515/dsa-2025-135" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-290" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T19:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-j55q-g28w-q6mv/GHSA-j55q-g28w-q6mv.json b/advisories/unreviewed/2025/05/GHSA-j55q-g28w-q6mv/GHSA-j55q-g28w-q6mv.json new file mode 100644 index 00000000000..6d1e5e5d104 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-j55q-g28w-q6mv/GHSA-j55q-g28w-q6mv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j55q-g28w-q6mv", + "modified": "2025-05-08T21:32:56Z", + "published": "2025-05-08T21:32:56Z", + "aliases": [ + "CVE-2024-8100" + ], + "details": "On affected versions of the Arista CloudVision Portal (CVP on-prem), the time-bound device onboarding token can be used to gain admin privileges on CloudVision.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8100" + }, + { + "type": "WEB", + "url": "https://www.arista.com/en/support/advisories-notices/security-advisory/21316-security-advisory-0116" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T19:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jr2q-36h8-7j24/GHSA-jr2q-36h8-7j24.json b/advisories/unreviewed/2025/05/GHSA-jr2q-36h8-7j24/GHSA-jr2q-36h8-7j24.json index c444e3ee15d..82166bd3aed 100644 --- a/advisories/unreviewed/2025/05/GHSA-jr2q-36h8-7j24/GHSA-jr2q-36h8-7j24.json +++ b/advisories/unreviewed/2025/05/GHSA-jr2q-36h8-7j24/GHSA-jr2q-36h8-7j24.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jr2q-36h8-7j24", - "modified": "2025-05-07T15:31:41Z", + "modified": "2025-05-08T21:32:55Z", "published": "2025-05-07T15:31:41Z", "aliases": [ "CVE-2025-29602" ], "details": "flatpress 1.3.1 is vulnerable to Cross Site Scripting (XSS) in Administration area via Manage categories.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-07T14:15:42Z" diff --git a/advisories/unreviewed/2025/05/GHSA-mf9v-44vc-62r3/GHSA-mf9v-44vc-62r3.json b/advisories/unreviewed/2025/05/GHSA-mf9v-44vc-62r3/GHSA-mf9v-44vc-62r3.json new file mode 100644 index 00000000000..6782178af2c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mf9v-44vc-62r3/GHSA-mf9v-44vc-62r3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mf9v-44vc-62r3", + "modified": "2025-05-08T21:32:56Z", + "published": "2025-05-08T21:32:55Z", + "aliases": [ + "CVE-2024-11186" + ], + "details": "On affected versions of the CloudVision Portal, improper access controls could enable a malicious authenticated user to take broader actions on managed EOS devices than intended. This advisory impacts the Arista CloudVision Portal products when run on-premise. It does not impact CloudVision as-a-Service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11186" + }, + { + "type": "WEB", + "url": "https://www.arista.com/en/support/advisories-notices/security-advisory/21314-security-advisory-0114" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T19:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p797-f93r-qxjf/GHSA-p797-f93r-qxjf.json b/advisories/unreviewed/2025/05/GHSA-p797-f93r-qxjf/GHSA-p797-f93r-qxjf.json new file mode 100644 index 00000000000..2fd98149e9a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p797-f93r-qxjf/GHSA-p797-f93r-qxjf.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p797-f93r-qxjf", + "modified": "2025-05-08T21:32:56Z", + "published": "2025-05-08T21:32:56Z", + "aliases": [ + "CVE-2025-45798" + ], + "details": "A command execution vulnerability exists in the TOTOLINK A950RG V4.1.2cu.5204_B20210112. The vulnerability is located in the setNoticeCfg interface within the /lib/cste_modules/system.so library, specifically in the processing of the IpTo parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45798" + }, + { + "type": "WEB", + "url": "https://github.com/SunnyYANGyaya/cuicuishark-sheep-fishIOT/blob/main/ToTolink/A950RG/5024-setNoticeCFG-IpTo-command.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T20:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qjp8-wwq5-32hp/GHSA-qjp8-wwq5-32hp.json b/advisories/unreviewed/2025/05/GHSA-qjp8-wwq5-32hp/GHSA-qjp8-wwq5-32hp.json index 4cb4faa58ca..249b293fe85 100644 --- a/advisories/unreviewed/2025/05/GHSA-qjp8-wwq5-32hp/GHSA-qjp8-wwq5-32hp.json +++ b/advisories/unreviewed/2025/05/GHSA-qjp8-wwq5-32hp/GHSA-qjp8-wwq5-32hp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qjp8-wwq5-32hp", - "modified": "2025-05-08T18:30:42Z", + "modified": "2025-05-08T21:32:55Z", "published": "2025-05-08T18:30:42Z", "aliases": [ "CVE-2025-26844" ], "details": "An issue was discovered in Znuny through 7.1.3. A cookie is set without the HttpOnly flag.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-1004" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-08T16:15:25Z" diff --git a/advisories/unreviewed/2025/05/GHSA-qwpq-8r8m-w7j2/GHSA-qwpq-8r8m-w7j2.json b/advisories/unreviewed/2025/05/GHSA-qwpq-8r8m-w7j2/GHSA-qwpq-8r8m-w7j2.json index 65adb83a07f..1cd33cf3a4e 100644 --- a/advisories/unreviewed/2025/05/GHSA-qwpq-8r8m-w7j2/GHSA-qwpq-8r8m-w7j2.json +++ b/advisories/unreviewed/2025/05/GHSA-qwpq-8r8m-w7j2/GHSA-qwpq-8r8m-w7j2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qwpq-8r8m-w7j2", - "modified": "2025-05-07T15:31:41Z", + "modified": "2025-05-08T21:32:55Z", "published": "2025-05-07T15:31:41Z", "aliases": [ "CVE-2025-29154" ], "details": "HTML injection vulnerability in lemeconsultoria HCM galera.app v.4.58.0 allows an attacker to execute arbitrary code via the .galera.app/ted/solicitacao_treinamento/, .galera.app/rh/metas/perspectiva_estrategica/edicao/, .galera.app/rh/cadastros/perspectivas/listagem/adc/, .galera.app/escolaridade/listagem/, .galera.app/estados_civis/cadastro/, .galera.app/nivel_hierarquico/listagem/, .galera.app/nivel_decisorio/cadastro/, .galera.app/escolaridade/cadastro/, .galera.app/nivel_decisorio/listagem/, .galera.app/rh/cadastros/perspectivas/listagem/, .galera.app/empresas_grupo/cadastro/, .galera.app/empresas/edicao/, .galera.app/liais/listagem/, .galera.app/noticias/listagem/, .galera.app/gerenciamento-de-ciclo/abertura/cadastrar, .galera.app/colaborador/cadastro/cursos/adc/edicao/, .galera.app/colaborador/cadastro/adc/, .galera.app/cads_aux/escalact/, .galera.app/ncf/tec/cadastro/ct/ .galera.app/rh/metas/painel/, .galera.app/rh/metas/equipe/edicao/, .galera.app/rh/pdi/tipo_recursos/edicao/, .galera.app/rh/pdi/familia_recursos/cadastro/, .galera.app/rh/pdi/fornecedores/edicao/, and .galera.app/rh/pdi/recursos/cadastro/ components.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-07T14:15:42Z" diff --git a/advisories/unreviewed/2025/05/GHSA-r9hp-mj25-9rxr/GHSA-r9hp-mj25-9rxr.json b/advisories/unreviewed/2025/05/GHSA-r9hp-mj25-9rxr/GHSA-r9hp-mj25-9rxr.json new file mode 100644 index 00000000000..01b7a15e79b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-r9hp-mj25-9rxr/GHSA-r9hp-mj25-9rxr.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r9hp-mj25-9rxr", + "modified": "2025-05-08T21:32:56Z", + "published": "2025-05-08T21:32:56Z", + "aliases": [ + "CVE-2025-45789" + ], + "details": "TOTOLINK A3100R V5.9c.1527 is vulnerable to buffer overflow via the urlKeyword parameter in setParentalRules.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45789" + }, + { + "type": "WEB", + "url": "https://github.com/SunnyYANGyaya/cuicuishark-sheep-fishIOT/blob/main/ToTolink/A3100R-3/README.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T20:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rxjj-p248-4ffv/GHSA-rxjj-p248-4ffv.json b/advisories/unreviewed/2025/05/GHSA-rxjj-p248-4ffv/GHSA-rxjj-p248-4ffv.json new file mode 100644 index 00000000000..ab2f99aaeb6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rxjj-p248-4ffv/GHSA-rxjj-p248-4ffv.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rxjj-p248-4ffv", + "modified": "2025-05-08T21:32:57Z", + "published": "2025-05-08T21:32:57Z", + "aliases": [ + "CVE-2023-31585" + ], + "details": "Grocery-CMS-PHP-Restful-API v1.3 is vulnerable to File Upload via /admin/add-category.php.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31585" + }, + { + "type": "WEB", + "url": "https://github.com/ajayrandhawa/Grocery-CMS-PHP-Restful-API/issues/5" + }, + { + "type": "WEB", + "url": "https://gist.github.com/f1rstb100d/487f27964a28b100bd57f38e144f2d35" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T21:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v3m4-v33x-7jhp/GHSA-v3m4-v33x-7jhp.json b/advisories/unreviewed/2025/05/GHSA-v3m4-v33x-7jhp/GHSA-v3m4-v33x-7jhp.json new file mode 100644 index 00000000000..38928b5ca5d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v3m4-v33x-7jhp/GHSA-v3m4-v33x-7jhp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v3m4-v33x-7jhp", + "modified": "2025-05-08T21:32:56Z", + "published": "2025-05-08T21:32:56Z", + "aliases": [ + "CVE-2025-0505" + ], + "details": "On Arista CloudVision systems (virtual or physical on-premise deployments), Zero Touch Provisioning can be used to gain admin privileges on the CloudVision system, with more permissions than necessary, which can be used to query or manipulate system state for devices under management. Note that CloudVision as-a-Service is not affected.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0505" + }, + { + "type": "WEB", + "url": "https://www.arista.com/en/support/advisories-notices/security-advisory/21315-security-advisory-0115" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T19:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vcfr-4r54-mh5g/GHSA-vcfr-4r54-mh5g.json b/advisories/unreviewed/2025/05/GHSA-vcfr-4r54-mh5g/GHSA-vcfr-4r54-mh5g.json index 1bb817db942..d97bf89c540 100644 --- a/advisories/unreviewed/2025/05/GHSA-vcfr-4r54-mh5g/GHSA-vcfr-4r54-mh5g.json +++ b/advisories/unreviewed/2025/05/GHSA-vcfr-4r54-mh5g/GHSA-vcfr-4r54-mh5g.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-vjv2-pp4x-76x9/GHSA-vjv2-pp4x-76x9.json b/advisories/unreviewed/2025/05/GHSA-vjv2-pp4x-76x9/GHSA-vjv2-pp4x-76x9.json new file mode 100644 index 00000000000..3c13c36d658 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vjv2-pp4x-76x9/GHSA-vjv2-pp4x-76x9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vjv2-pp4x-76x9", + "modified": "2025-05-08T21:32:56Z", + "published": "2025-05-08T21:32:56Z", + "aliases": [ + "CVE-2024-9448" + ], + "details": "On affected platforms running Arista EOS with Traffic Policies configured the vulnerability will cause received untagged packets not to hit Traffic Policy rules that they are expected to hit. If the rule was to drop the packet, the packet will not be dropped and instead will be forwarded as if the rule was not in place. This could lead to packets being delivered to unexpected destinations.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9448" + }, + { + "type": "WEB", + "url": "https://www.arista.com/en/support/advisories-notices/security-advisory/21121-security-advisory-0112" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T20:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wmr9-84fj-r9j8/GHSA-wmr9-84fj-r9j8.json b/advisories/unreviewed/2025/05/GHSA-wmr9-84fj-r9j8/GHSA-wmr9-84fj-r9j8.json new file mode 100644 index 00000000000..6853d8b8678 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wmr9-84fj-r9j8/GHSA-wmr9-84fj-r9j8.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wmr9-84fj-r9j8", + "modified": "2025-05-08T21:32:56Z", + "published": "2025-05-08T21:32:56Z", + "aliases": [ + "CVE-2025-45787" + ], + "details": "TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow viathe comment parameter in setIpPortFilterRules.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45787" + }, + { + "type": "WEB", + "url": "https://github.com/SunnyYANGyaya/cuicuishark-sheep-fishIOT/tree/main/ToTolink/A3100R-1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T20:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xgfh-h2p4-f7v7/GHSA-xgfh-h2p4-f7v7.json b/advisories/unreviewed/2025/05/GHSA-xgfh-h2p4-f7v7/GHSA-xgfh-h2p4-f7v7.json new file mode 100644 index 00000000000..d1ab553d000 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xgfh-h2p4-f7v7/GHSA-xgfh-h2p4-f7v7.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xgfh-h2p4-f7v7", + "modified": "2025-05-08T21:32:56Z", + "published": "2025-05-08T21:32:56Z", + "aliases": [ + "CVE-2025-45788" + ], + "details": "TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow via the comment parameter in setMacFilterRules.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45788" + }, + { + "type": "WEB", + "url": "https://github.com/SunnyYANGyaya/cuicuishark-sheep-fishIOT/blob/main/ToTolink/A3100R-2/README.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T20:15:30Z" + } +} \ No newline at end of file