diff --git a/advisories/unreviewed/2023/12/GHSA-8qp6-rm76-vj9q/GHSA-8qp6-rm76-vj9q.json b/advisories/unreviewed/2023/12/GHSA-8qp6-rm76-vj9q/GHSA-8qp6-rm76-vj9q.json index 499ce258529..8f21c55a43c 100644 --- a/advisories/unreviewed/2023/12/GHSA-8qp6-rm76-vj9q/GHSA-8qp6-rm76-vj9q.json +++ b/advisories/unreviewed/2023/12/GHSA-8qp6-rm76-vj9q/GHSA-8qp6-rm76-vj9q.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-8qp6-rm76-vj9q", - "modified": "2023-12-28T12:30:19Z", + "modified": "2025-06-02T21:30:23Z", "published": "2023-12-28T12:30:19Z", "aliases": [ "CVE-2023-50854" ], - "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Squirrly Squirrly SEO - Advanced Pack.This issue affects Squirrly SEO - Advanced Pack: from n/a through 2.3.8.\n\n", + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Squirrly Squirrly SEO - Advanced Pack.This issue affects Squirrly SEO - Advanced Pack: from n/a through 2.3.8.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/01/GHSA-25g8-7mhh-fm84/GHSA-25g8-7mhh-fm84.json b/advisories/unreviewed/2024/01/GHSA-25g8-7mhh-fm84/GHSA-25g8-7mhh-fm84.json index ed44fac9934..110d5b80e9c 100644 --- a/advisories/unreviewed/2024/01/GHSA-25g8-7mhh-fm84/GHSA-25g8-7mhh-fm84.json +++ b/advisories/unreviewed/2024/01/GHSA-25g8-7mhh-fm84/GHSA-25g8-7mhh-fm84.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-25g8-7mhh-fm84", - "modified": "2024-02-05T18:31:36Z", + "modified": "2025-06-02T21:30:24Z", "published": "2024-01-29T15:30:30Z", "aliases": [ "CVE-2023-7200" diff --git a/advisories/unreviewed/2024/01/GHSA-2jx2-r7f9-93pw/GHSA-2jx2-r7f9-93pw.json b/advisories/unreviewed/2024/01/GHSA-2jx2-r7f9-93pw/GHSA-2jx2-r7f9-93pw.json index acc94a26a71..4f3c5bc331a 100644 --- a/advisories/unreviewed/2024/01/GHSA-2jx2-r7f9-93pw/GHSA-2jx2-r7f9-93pw.json +++ b/advisories/unreviewed/2024/01/GHSA-2jx2-r7f9-93pw/GHSA-2jx2-r7f9-93pw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2jx2-r7f9-93pw", - "modified": "2024-02-02T18:30:29Z", + "modified": "2025-06-02T21:30:23Z", "published": "2024-01-29T00:30:17Z", "aliases": [ "CVE-2024-23782" diff --git a/advisories/unreviewed/2024/01/GHSA-9xv5-7pc9-8rr3/GHSA-9xv5-7pc9-8rr3.json b/advisories/unreviewed/2024/01/GHSA-9xv5-7pc9-8rr3/GHSA-9xv5-7pc9-8rr3.json index ac7369005eb..3f188159762 100644 --- a/advisories/unreviewed/2024/01/GHSA-9xv5-7pc9-8rr3/GHSA-9xv5-7pc9-8rr3.json +++ b/advisories/unreviewed/2024/01/GHSA-9xv5-7pc9-8rr3/GHSA-9xv5-7pc9-8rr3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9xv5-7pc9-8rr3", - "modified": "2024-02-03T03:30:27Z", + "modified": "2025-06-02T21:30:24Z", "published": "2024-01-29T15:30:29Z", "aliases": [ "CVE-2023-6279" diff --git a/advisories/unreviewed/2025/04/GHSA-8f6m-fvf9-6397/GHSA-8f6m-fvf9-6397.json b/advisories/unreviewed/2025/04/GHSA-8f6m-fvf9-6397/GHSA-8f6m-fvf9-6397.json index 4671fc37960..cbb86ebc01c 100644 --- a/advisories/unreviewed/2025/04/GHSA-8f6m-fvf9-6397/GHSA-8f6m-fvf9-6397.json +++ b/advisories/unreviewed/2025/04/GHSA-8f6m-fvf9-6397/GHSA-8f6m-fvf9-6397.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8f6m-fvf9-6397", - "modified": "2025-04-16T21:30:57Z", + "modified": "2025-06-02T21:30:24Z", "published": "2025-04-16T21:30:56Z", "aliases": [ "CVE-2025-31200" @@ -19,6 +19,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31200" }, + { + "type": "WEB", + "url": "https://blog.noahhw.dev/posts/cve-2025-31200" + }, + { + "type": "WEB", + "url": "https://news.ycombinator.com/item?id=44161894" + }, { "type": "WEB", "url": "https://support.apple.com/en-us/122282" diff --git a/advisories/unreviewed/2025/05/GHSA-jpf5-526x-c5hw/GHSA-jpf5-526x-c5hw.json b/advisories/unreviewed/2025/05/GHSA-jpf5-526x-c5hw/GHSA-jpf5-526x-c5hw.json index c18f1fa05cc..b4e2c0fc76d 100644 --- a/advisories/unreviewed/2025/05/GHSA-jpf5-526x-c5hw/GHSA-jpf5-526x-c5hw.json +++ b/advisories/unreviewed/2025/05/GHSA-jpf5-526x-c5hw/GHSA-jpf5-526x-c5hw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jpf5-526x-c5hw", - "modified": "2025-06-02T12:30:33Z", + "modified": "2025-06-02T21:30:24Z", "published": "2025-05-30T15:30:30Z", "aliases": [ "CVE-2025-40909" @@ -58,6 +58,14 @@ { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2025/06/02/2" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/06/02/5" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/06/02/6" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/06/GHSA-3h3m-9w6m-92hw/GHSA-3h3m-9w6m-92hw.json b/advisories/unreviewed/2025/06/GHSA-3h3m-9w6m-92hw/GHSA-3h3m-9w6m-92hw.json index f173ff873e4..7f4da58d5e4 100644 --- a/advisories/unreviewed/2025/06/GHSA-3h3m-9w6m-92hw/GHSA-3h3m-9w6m-92hw.json +++ b/advisories/unreviewed/2025/06/GHSA-3h3m-9w6m-92hw/GHSA-3h3m-9w6m-92hw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3h3m-9w6m-92hw", - "modified": "2025-06-02T18:30:51Z", + "modified": "2025-06-02T21:30:24Z", "published": "2025-06-02T18:30:51Z", "aliases": [ "CVE-2024-40113" ], "details": "Sitecom WLX-2006 Wall Mount Range Extender N300 v.1.5 and before is vulnerable to Use of Default Credentials.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-1392" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-02T16:15:27Z" diff --git a/advisories/unreviewed/2025/06/GHSA-55pf-868x-9jw7/GHSA-55pf-868x-9jw7.json b/advisories/unreviewed/2025/06/GHSA-55pf-868x-9jw7/GHSA-55pf-868x-9jw7.json new file mode 100644 index 00000000000..ee22964e7d4 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-55pf-868x-9jw7/GHSA-55pf-868x-9jw7.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-55pf-868x-9jw7", + "modified": "2025-06-02T21:30:25Z", + "published": "2025-06-02T21:30:25Z", + "aliases": [ + "CVE-2025-23099" + ], + "details": "An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The lack of a length check leads to out-of-bounds writes.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23099" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2025-23099" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-02T19:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-5877-58jr-h687/GHSA-5877-58jr-h687.json b/advisories/unreviewed/2025/06/GHSA-5877-58jr-h687/GHSA-5877-58jr-h687.json new file mode 100644 index 00000000000..7fe691ea5b1 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-5877-58jr-h687/GHSA-5877-58jr-h687.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5877-58jr-h687", + "modified": "2025-06-02T21:30:25Z", + "published": "2025-06-02T21:30:25Z", + "aliases": [ + "CVE-2025-49069" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Cimatti Consulting Contact Forms by Cimatti allows Cross Site Request Forgery.This issue affects Contact Forms by Cimatti: from n/a through 1.9.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49069" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/contact-forms/vulnerability/wordpress-contact-forms-by-cimatti-plugin-1-9-8-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-02T19:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-778m-4r28-2hp8/GHSA-778m-4r28-2hp8.json b/advisories/unreviewed/2025/06/GHSA-778m-4r28-2hp8/GHSA-778m-4r28-2hp8.json index 0157622e2bd..098e57296a7 100644 --- a/advisories/unreviewed/2025/06/GHSA-778m-4r28-2hp8/GHSA-778m-4r28-2hp8.json +++ b/advisories/unreviewed/2025/06/GHSA-778m-4r28-2hp8/GHSA-778m-4r28-2hp8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-778m-4r28-2hp8", - "modified": "2025-06-02T15:31:25Z", + "modified": "2025-06-02T21:30:24Z", "published": "2025-06-02T15:31:25Z", "aliases": [ "CVE-2025-44172" ], "details": "Tenda AC6 V15.03.05.16 was discovered to contain a stack overflow via the time parameter in the setSmartPowerManagement function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-02T15:15:34Z" diff --git a/advisories/unreviewed/2025/06/GHSA-7wp3-36m3-58j5/GHSA-7wp3-36m3-58j5.json b/advisories/unreviewed/2025/06/GHSA-7wp3-36m3-58j5/GHSA-7wp3-36m3-58j5.json index e744af42fe2..af8898ac589 100644 --- a/advisories/unreviewed/2025/06/GHSA-7wp3-36m3-58j5/GHSA-7wp3-36m3-58j5.json +++ b/advisories/unreviewed/2025/06/GHSA-7wp3-36m3-58j5/GHSA-7wp3-36m3-58j5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7wp3-36m3-58j5", - "modified": "2025-06-02T18:30:52Z", + "modified": "2025-06-02T21:30:24Z", "published": "2025-06-02T18:30:52Z", "aliases": [ "CVE-2025-44115" ], "details": "A vulnerability has been found in Cotonti Siena v0.9.25. Affected by this vulnerability is the file /admin.php?m=config&n=edit&o=core&p=title. The manipulation of the value of title leads to cross-site scripting.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-02T16:15:29Z" diff --git a/advisories/unreviewed/2025/06/GHSA-hh39-985p-g37g/GHSA-hh39-985p-g37g.json b/advisories/unreviewed/2025/06/GHSA-hh39-985p-g37g/GHSA-hh39-985p-g37g.json index e6425321ec7..90a2141fab4 100644 --- a/advisories/unreviewed/2025/06/GHSA-hh39-985p-g37g/GHSA-hh39-985p-g37g.json +++ b/advisories/unreviewed/2025/06/GHSA-hh39-985p-g37g/GHSA-hh39-985p-g37g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hh39-985p-g37g", - "modified": "2025-06-02T18:30:51Z", + "modified": "2025-06-02T21:30:24Z", "published": "2025-06-02T18:30:51Z", "aliases": [ "CVE-2024-40114" ], "details": "A Cross Site Scripting (XSS) vulnerability in Sitecom WLX-2006 Wall Mount Range Extender N300 v1.5 and before allows an attacker to manipulate the language cookie to inject malicious JavaScript code.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-02T16:15:27Z" diff --git a/advisories/unreviewed/2025/06/GHSA-j3qf-mq3f-rgcf/GHSA-j3qf-mq3f-rgcf.json b/advisories/unreviewed/2025/06/GHSA-j3qf-mq3f-rgcf/GHSA-j3qf-mq3f-rgcf.json index 2c499cfcac5..a2c7f87f4b9 100644 --- a/advisories/unreviewed/2025/06/GHSA-j3qf-mq3f-rgcf/GHSA-j3qf-mq3f-rgcf.json +++ b/advisories/unreviewed/2025/06/GHSA-j3qf-mq3f-rgcf/GHSA-j3qf-mq3f-rgcf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j3qf-mq3f-rgcf", - "modified": "2025-06-02T18:30:51Z", + "modified": "2025-06-02T21:30:24Z", "published": "2025-06-02T18:30:51Z", "aliases": [ "CVE-2024-40112" ], "details": "A Local File Inclusion (LFI) vulnerability exists in Sitecom WLX-2006 Wall Mount Range Extender N300 v1.5 and before, which allows an attacker to manipulate the \"language\" cookie to include arbitrary files from the server. This vulnerability can be exploited to disclose sensitive information.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-98" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-02T16:15:26Z" diff --git a/advisories/unreviewed/2025/06/GHSA-j6ph-fhmg-qfhg/GHSA-j6ph-fhmg-qfhg.json b/advisories/unreviewed/2025/06/GHSA-j6ph-fhmg-qfhg/GHSA-j6ph-fhmg-qfhg.json new file mode 100644 index 00000000000..0395eef0b0b --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-j6ph-fhmg-qfhg/GHSA-j6ph-fhmg-qfhg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6ph-fhmg-qfhg", + "modified": "2025-06-02T21:30:25Z", + "published": "2025-06-02T21:30:25Z", + "aliases": [ + "CVE-2025-47585" + ], + "details": "Missing Authorization vulnerability in Mage people team Booking and Rental Manager allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Booking and Rental Manager: from n/a through 2.3.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47585" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/booking-and-rental-manager-for-woocommerce/vulnerability/wordpress-booking-and-rental-manager-2-3-8-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-02T20:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-jqw7-hgh5-2ppr/GHSA-jqw7-hgh5-2ppr.json b/advisories/unreviewed/2025/06/GHSA-jqw7-hgh5-2ppr/GHSA-jqw7-hgh5-2ppr.json index ca82acc90d6..333c630395b 100644 --- a/advisories/unreviewed/2025/06/GHSA-jqw7-hgh5-2ppr/GHSA-jqw7-hgh5-2ppr.json +++ b/advisories/unreviewed/2025/06/GHSA-jqw7-hgh5-2ppr/GHSA-jqw7-hgh5-2ppr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jqw7-hgh5-2ppr", - "modified": "2025-06-02T18:30:52Z", + "modified": "2025-06-02T21:30:24Z", "published": "2025-06-02T18:30:52Z", "aliases": [ "CVE-2025-23104" ], "details": "An issue was discovered in Samsung Mobile Processor Exynos 2200, 1480, and 2400. A Use-After-Free in the mobile processor leads to privilege escalation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-02T18:15:23Z" diff --git a/advisories/unreviewed/2025/06/GHSA-jv3c-qh2g-5f2r/GHSA-jv3c-qh2g-5f2r.json b/advisories/unreviewed/2025/06/GHSA-jv3c-qh2g-5f2r/GHSA-jv3c-qh2g-5f2r.json new file mode 100644 index 00000000000..22fea3f513a --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-jv3c-qh2g-5f2r/GHSA-jv3c-qh2g-5f2r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jv3c-qh2g-5f2r", + "modified": "2025-06-02T21:30:25Z", + "published": "2025-06-02T21:30:25Z", + "aliases": [ + "CVE-2025-1051" + ], + "details": "Sonos Era 300 Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Sonos Era 300 speakers. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the processing of ALAC data. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the anacapa user. Was ZDI-CAN-25865.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1051" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-311" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-02T19:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-jwc3-6wrj-fj5w/GHSA-jwc3-6wrj-fj5w.json b/advisories/unreviewed/2025/06/GHSA-jwc3-6wrj-fj5w/GHSA-jwc3-6wrj-fj5w.json index 87e58f1ec1d..ea44c15cf19 100644 --- a/advisories/unreviewed/2025/06/GHSA-jwc3-6wrj-fj5w/GHSA-jwc3-6wrj-fj5w.json +++ b/advisories/unreviewed/2025/06/GHSA-jwc3-6wrj-fj5w/GHSA-jwc3-6wrj-fj5w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jwc3-6wrj-fj5w", - "modified": "2025-06-02T18:30:53Z", + "modified": "2025-06-02T21:30:24Z", "published": "2025-06-02T18:30:52Z", "aliases": [ "CVE-2025-27956" ], "details": "Directory Traversal vulnerability in WebLaudos 24.2 (04) allows a remote attacker to obtain sensitive information via the id parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-02T18:15:24Z" diff --git a/advisories/unreviewed/2025/06/GHSA-mc52-7658-v986/GHSA-mc52-7658-v986.json b/advisories/unreviewed/2025/06/GHSA-mc52-7658-v986/GHSA-mc52-7658-v986.json index 964e634d72a..f34e7f4f558 100644 --- a/advisories/unreviewed/2025/06/GHSA-mc52-7658-v986/GHSA-mc52-7658-v986.json +++ b/advisories/unreviewed/2025/06/GHSA-mc52-7658-v986/GHSA-mc52-7658-v986.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mc52-7658-v986", - "modified": "2025-06-02T18:30:53Z", + "modified": "2025-06-02T21:30:24Z", "published": "2025-06-02T18:30:53Z", "aliases": [ "CVE-2025-45387" ], "details": "osTicket prior to v1.17.6 and v1.18.2 are vulnerable to Broken Access Control Vulnerability in /scp/ajax.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-02T18:15:24Z" diff --git a/advisories/unreviewed/2025/06/GHSA-rcj3-h239-hjc8/GHSA-rcj3-h239-hjc8.json b/advisories/unreviewed/2025/06/GHSA-rcj3-h239-hjc8/GHSA-rcj3-h239-hjc8.json new file mode 100644 index 00000000000..16e205bbbf9 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-rcj3-h239-hjc8/GHSA-rcj3-h239-hjc8.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rcj3-h239-hjc8", + "modified": "2025-06-02T21:30:25Z", + "published": "2025-06-02T21:30:25Z", + "aliases": [ + "CVE-2025-23105" + ], + "details": "An issue was discovered in Samsung Mobile Processor Exynos 2200, 1480, and 2400. A Use-After-Free in the mobile processor leads to privilege escalation.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23105" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2025-23105" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-02T19:15:26Z" + } +} \ No newline at end of file