diff --git a/advisories/unreviewed/2022/12/GHSA-36pv-3r3h-xrc8/GHSA-36pv-3r3h-xrc8.json b/advisories/unreviewed/2022/12/GHSA-36pv-3r3h-xrc8/GHSA-36pv-3r3h-xrc8.json index 19a3ef4d4f8..003c5a9f740 100644 --- a/advisories/unreviewed/2022/12/GHSA-36pv-3r3h-xrc8/GHSA-36pv-3r3h-xrc8.json +++ b/advisories/unreviewed/2022/12/GHSA-36pv-3r3h-xrc8/GHSA-36pv-3r3h-xrc8.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-610" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-4377-hq3v-hgqh/GHSA-4377-hq3v-hgqh.json b/advisories/unreviewed/2022/12/GHSA-4377-hq3v-hgqh/GHSA-4377-hq3v-hgqh.json index a8f423b7138..e41a197532a 100644 --- a/advisories/unreviewed/2022/12/GHSA-4377-hq3v-hgqh/GHSA-4377-hq3v-hgqh.json +++ b/advisories/unreviewed/2022/12/GHSA-4377-hq3v-hgqh/GHSA-4377-hq3v-hgqh.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-610" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-57rw-93xc-4hpv/GHSA-57rw-93xc-4hpv.json b/advisories/unreviewed/2022/12/GHSA-57rw-93xc-4hpv/GHSA-57rw-93xc-4hpv.json index e4cdbdb7e11..184614d40c2 100644 --- a/advisories/unreviewed/2022/12/GHSA-57rw-93xc-4hpv/GHSA-57rw-93xc-4hpv.json +++ b/advisories/unreviewed/2022/12/GHSA-57rw-93xc-4hpv/GHSA-57rw-93xc-4hpv.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-668" + "CWE-668", + "CWE-862" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-5g7j-9r76-23cc/GHSA-5g7j-9r76-23cc.json b/advisories/unreviewed/2022/12/GHSA-5g7j-9r76-23cc/GHSA-5g7j-9r76-23cc.json index a5593a6847c..5f5ee2b9eef 100644 --- a/advisories/unreviewed/2022/12/GHSA-5g7j-9r76-23cc/GHSA-5g7j-9r76-23cc.json +++ b/advisories/unreviewed/2022/12/GHSA-5g7j-9r76-23cc/GHSA-5g7j-9r76-23cc.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-102", "CWE-1021" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/12/GHSA-6973-4pp3-gvj6/GHSA-6973-4pp3-gvj6.json b/advisories/unreviewed/2022/12/GHSA-6973-4pp3-gvj6/GHSA-6973-4pp3-gvj6.json index e527e3e98ed..f81317fb971 100644 --- a/advisories/unreviewed/2022/12/GHSA-6973-4pp3-gvj6/GHSA-6973-4pp3-gvj6.json +++ b/advisories/unreviewed/2022/12/GHSA-6973-4pp3-gvj6/GHSA-6973-4pp3-gvj6.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-190" + "CWE-190", + "CWE-191" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-hjjq-jc6w-mqf5/GHSA-hjjq-jc6w-mqf5.json b/advisories/unreviewed/2022/12/GHSA-hjjq-jc6w-mqf5/GHSA-hjjq-jc6w-mqf5.json index a5555aff50a..ac73aeac484 100644 --- a/advisories/unreviewed/2022/12/GHSA-hjjq-jc6w-mqf5/GHSA-hjjq-jc6w-mqf5.json +++ b/advisories/unreviewed/2022/12/GHSA-hjjq-jc6w-mqf5/GHSA-hjjq-jc6w-mqf5.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-jx7f-5pph-phx8/GHSA-jx7f-5pph-phx8.json b/advisories/unreviewed/2022/12/GHSA-jx7f-5pph-phx8/GHSA-jx7f-5pph-phx8.json index 6c5c43f78ce..f82537fdfda 100644 --- a/advisories/unreviewed/2022/12/GHSA-jx7f-5pph-phx8/GHSA-jx7f-5pph-phx8.json +++ b/advisories/unreviewed/2022/12/GHSA-jx7f-5pph-phx8/GHSA-jx7f-5pph-phx8.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-119" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-vq94-fv28-3h2v/GHSA-vq94-fv28-3h2v.json b/advisories/unreviewed/2022/12/GHSA-vq94-fv28-3h2v/GHSA-vq94-fv28-3h2v.json index 51050cc2aae..d331639e875 100644 --- a/advisories/unreviewed/2022/12/GHSA-vq94-fv28-3h2v/GHSA-vq94-fv28-3h2v.json +++ b/advisories/unreviewed/2022/12/GHSA-vq94-fv28-3h2v/GHSA-vq94-fv28-3h2v.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-451" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-45rx-4g83-g5mj/GHSA-45rx-4g83-g5mj.json b/advisories/unreviewed/2024/03/GHSA-45rx-4g83-g5mj/GHSA-45rx-4g83-g5mj.json index 80289f5c3ce..b0c17e2b6b6 100644 --- a/advisories/unreviewed/2024/03/GHSA-45rx-4g83-g5mj/GHSA-45rx-4g83-g5mj.json +++ b/advisories/unreviewed/2024/03/GHSA-45rx-4g83-g5mj/GHSA-45rx-4g83-g5mj.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-9r5m-gmgr-m7qh/GHSA-9r5m-gmgr-m7qh.json b/advisories/unreviewed/2024/04/GHSA-9r5m-gmgr-m7qh/GHSA-9r5m-gmgr-m7qh.json index 7d98b44294b..7468b2bbdae 100644 --- a/advisories/unreviewed/2024/04/GHSA-9r5m-gmgr-m7qh/GHSA-9r5m-gmgr-m7qh.json +++ b/advisories/unreviewed/2024/04/GHSA-9r5m-gmgr-m7qh/GHSA-9r5m-gmgr-m7qh.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-9r5m-gmgr-m7qh", - "modified": "2024-04-17T12:32:03Z", + "modified": "2025-04-18T18:31:18Z", "published": "2024-04-17T12:32:03Z", "aliases": [ "CVE-2024-32505" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpmet Elements kit Elementor addons allows Stored XSS.This issue affects Elements kit Elementor addons: from n/a through 3.0.6.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpmet Elements kit Elementor addons allows Stored XSS.This issue affects Elements kit Elementor addons: from n/a through 3.0.6.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/05/GHSA-46pr-93vx-57gx/GHSA-46pr-93vx-57gx.json b/advisories/unreviewed/2024/05/GHSA-46pr-93vx-57gx/GHSA-46pr-93vx-57gx.json index a34bcaabd9d..79cffb70152 100644 --- a/advisories/unreviewed/2024/05/GHSA-46pr-93vx-57gx/GHSA-46pr-93vx-57gx.json +++ b/advisories/unreviewed/2024/05/GHSA-46pr-93vx-57gx/GHSA-46pr-93vx-57gx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-46pr-93vx-57gx", - "modified": "2024-05-17T09:31:00Z", + "modified": "2025-04-18T18:31:19Z", "published": "2024-05-17T09:31:00Z", "aliases": [ "CVE-2024-31351" diff --git a/advisories/unreviewed/2024/05/GHSA-6fj9-cq25-9x7h/GHSA-6fj9-cq25-9x7h.json b/advisories/unreviewed/2024/05/GHSA-6fj9-cq25-9x7h/GHSA-6fj9-cq25-9x7h.json index a6dbd457d31..bb2660b8118 100644 --- a/advisories/unreviewed/2024/05/GHSA-6fj9-cq25-9x7h/GHSA-6fj9-cq25-9x7h.json +++ b/advisories/unreviewed/2024/05/GHSA-6fj9-cq25-9x7h/GHSA-6fj9-cq25-9x7h.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-rrv6-pjjr-4r3x/GHSA-rrv6-pjjr-4r3x.json b/advisories/unreviewed/2024/05/GHSA-rrv6-pjjr-4r3x/GHSA-rrv6-pjjr-4r3x.json index f367f4d7325..55b22a520e2 100644 --- a/advisories/unreviewed/2024/05/GHSA-rrv6-pjjr-4r3x/GHSA-rrv6-pjjr-4r3x.json +++ b/advisories/unreviewed/2024/05/GHSA-rrv6-pjjr-4r3x/GHSA-rrv6-pjjr-4r3x.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-22" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-x73j-6c5w-6h22/GHSA-x73j-6c5w-6h22.json b/advisories/unreviewed/2024/12/GHSA-x73j-6c5w-6h22/GHSA-x73j-6c5w-6h22.json index f16d1fd6842..0c6a458bc48 100644 --- a/advisories/unreviewed/2024/12/GHSA-x73j-6c5w-6h22/GHSA-x73j-6c5w-6h22.json +++ b/advisories/unreviewed/2024/12/GHSA-x73j-6c5w-6h22/GHSA-x73j-6c5w-6h22.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x73j-6c5w-6h22", - "modified": "2024-12-06T18:30:45Z", + "modified": "2025-04-18T18:31:20Z", "published": "2024-12-05T18:31:03Z", "aliases": [ "CVE-2024-11158" diff --git a/advisories/unreviewed/2025/04/GHSA-27ww-388c-hfhf/GHSA-27ww-388c-hfhf.json b/advisories/unreviewed/2025/04/GHSA-27ww-388c-hfhf/GHSA-27ww-388c-hfhf.json index f8de3eed727..b3859a0bb17 100644 --- a/advisories/unreviewed/2025/04/GHSA-27ww-388c-hfhf/GHSA-27ww-388c-hfhf.json +++ b/advisories/unreviewed/2025/04/GHSA-27ww-388c-hfhf/GHSA-27ww-388c-hfhf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-27ww-388c-hfhf", - "modified": "2025-04-18T00:30:43Z", + "modified": "2025-04-18T18:31:23Z", "published": "2025-04-18T00:30:43Z", "aliases": [ "CVE-2025-29457" ], "details": "An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Import a Theme function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-17T22:15:15Z" diff --git a/advisories/unreviewed/2025/04/GHSA-3996-4m5r-mmwf/GHSA-3996-4m5r-mmwf.json b/advisories/unreviewed/2025/04/GHSA-3996-4m5r-mmwf/GHSA-3996-4m5r-mmwf.json index 139fcc52709..93d0f387d1c 100644 --- a/advisories/unreviewed/2025/04/GHSA-3996-4m5r-mmwf/GHSA-3996-4m5r-mmwf.json +++ b/advisories/unreviewed/2025/04/GHSA-3996-4m5r-mmwf/GHSA-3996-4m5r-mmwf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3996-4m5r-mmwf", - "modified": "2025-04-18T00:30:43Z", + "modified": "2025-04-18T18:31:23Z", "published": "2025-04-18T00:30:43Z", "aliases": [ "CVE-2025-29458" ], "details": "An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Change Avatar function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-17T22:15:15Z" diff --git a/advisories/unreviewed/2025/04/GHSA-3c8w-xm49-2w5f/GHSA-3c8w-xm49-2w5f.json b/advisories/unreviewed/2025/04/GHSA-3c8w-xm49-2w5f/GHSA-3c8w-xm49-2w5f.json index 38861d1f568..51197323a58 100644 --- a/advisories/unreviewed/2025/04/GHSA-3c8w-xm49-2w5f/GHSA-3c8w-xm49-2w5f.json +++ b/advisories/unreviewed/2025/04/GHSA-3c8w-xm49-2w5f/GHSA-3c8w-xm49-2w5f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3c8w-xm49-2w5f", - "modified": "2025-04-17T21:31:05Z", + "modified": "2025-04-18T18:31:23Z", "published": "2025-04-17T21:31:05Z", "aliases": [ "CVE-2025-29452" ], "details": "An issue in Seo Panel 4.11.0 allows a remote attacker to obtain sensitive information via the Proxy Manager component.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-17T21:15:50Z" diff --git a/advisories/unreviewed/2025/04/GHSA-485p-gmh5-r688/GHSA-485p-gmh5-r688.json b/advisories/unreviewed/2025/04/GHSA-485p-gmh5-r688/GHSA-485p-gmh5-r688.json new file mode 100644 index 00000000000..13768191c3c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-485p-gmh5-r688/GHSA-485p-gmh5-r688.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-485p-gmh5-r688", + "modified": "2025-04-18T18:31:24Z", + "published": "2025-04-18T18:31:24Z", + "aliases": [ + "CVE-2025-28236" + ], + "details": "Nautel VX Series transmitters VX SW v6.4.0 and below was discovered to contain a remote code execution (RCE) vulnerability in the firmware update process. This vulnerability allows attackers to execute arbitrary code via supplying a crafted update package to the /#/software/upgrades endpoint.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28236" + }, + { + "type": "WEB", + "url": "https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-28236" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T18:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-62c2-pjmr-4wx5/GHSA-62c2-pjmr-4wx5.json b/advisories/unreviewed/2025/04/GHSA-62c2-pjmr-4wx5/GHSA-62c2-pjmr-4wx5.json index 3a2ffd1823c..f6affe464d8 100644 --- a/advisories/unreviewed/2025/04/GHSA-62c2-pjmr-4wx5/GHSA-62c2-pjmr-4wx5.json +++ b/advisories/unreviewed/2025/04/GHSA-62c2-pjmr-4wx5/GHSA-62c2-pjmr-4wx5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-62c2-pjmr-4wx5", - "modified": "2025-04-17T21:31:05Z", + "modified": "2025-04-18T18:31:23Z", "published": "2025-04-17T21:31:05Z", "aliases": [ "CVE-2025-29451" ], "details": "An issue in Seo Panel 4.11.0 allows a remote attacker to obtain sensitive information via the Mail Setting component.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-17T21:15:50Z" diff --git a/advisories/unreviewed/2025/04/GHSA-7jpf-hrrg-gcj2/GHSA-7jpf-hrrg-gcj2.json b/advisories/unreviewed/2025/04/GHSA-7jpf-hrrg-gcj2/GHSA-7jpf-hrrg-gcj2.json new file mode 100644 index 00000000000..b41a4aa569c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7jpf-hrrg-gcj2/GHSA-7jpf-hrrg-gcj2.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7jpf-hrrg-gcj2", + "modified": "2025-04-18T18:31:24Z", + "published": "2025-04-18T18:31:24Z", + "aliases": [ + "CVE-2025-28233" + ], + "details": "Incorrect access control in BW Broadcast TX600 (14980), TX300 (32990) (31448), TX150, TX1000, TX30, and TX50 Hardware Version: 2, Software Version: 1.6.0, Control Version: 1.0, AIO Firmware Version: 1.7 allows attackers to access log files and extract session identifiers to execute a session hijacking attack.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28233" + }, + { + "type": "WEB", + "url": "https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-28233" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T18:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9262-x7f9-6hfc/GHSA-9262-x7f9-6hfc.json b/advisories/unreviewed/2025/04/GHSA-9262-x7f9-6hfc/GHSA-9262-x7f9-6hfc.json index 7134ad25a0c..1ddd14211c2 100644 --- a/advisories/unreviewed/2025/04/GHSA-9262-x7f9-6hfc/GHSA-9262-x7f9-6hfc.json +++ b/advisories/unreviewed/2025/04/GHSA-9262-x7f9-6hfc/GHSA-9262-x7f9-6hfc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9262-x7f9-6hfc", - "modified": "2025-04-09T18:30:50Z", + "modified": "2025-04-18T18:31:23Z", "published": "2025-04-09T18:30:50Z", "aliases": [ "CVE-2025-29394" ], "details": "An insecure permissions vulnerability in verydows v2.0 allows a remote attacker to execute arbitrary code by uploading a file type.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-09T16:15:24Z" diff --git a/advisories/unreviewed/2025/04/GHSA-9g64-r942-fvmp/GHSA-9g64-r942-fvmp.json b/advisories/unreviewed/2025/04/GHSA-9g64-r942-fvmp/GHSA-9g64-r942-fvmp.json new file mode 100644 index 00000000000..c690f28194f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9g64-r942-fvmp/GHSA-9g64-r942-fvmp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9g64-r942-fvmp", + "modified": "2025-04-18T18:31:23Z", + "published": "2025-04-18T18:31:23Z", + "aliases": [ + "CVE-2025-29953" + ], + "details": "Deserialization of Untrusted Data vulnerability in Apache ActiveMQ NMS OpenWire Client.\n\nThis issue affects Apache ActiveMQ NMS OpenWire Client before 2.1.1 when performing connections to untrusted servers. Such servers could abuse the unbounded deserialization in the client to provide malicious responses that may eventually cause arbitrary code execution on the client. Version 2.1.0 introduced a allow/denylist feature to restrict deserialization, but this feature could be bypassed.\n\nThe .NET team has deprecated the built-in .NET binary serialization feature starting with .NET 9 and suggests migrating away from binary serialization. The project is considering to follow suit and drop this part of the NMS API altogether.\n\nUsers are recommended to upgrade to version 2.1.1, which fixes the issue. We also recommend to migrate away from relying on .NET binary serialization as a hardening method for the future.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29953" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/vc1sj9y3056d3kkhcvrs9fyw5w8kpmlx" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/04/18/3" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T16:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c6pg-qxgx-74q7/GHSA-c6pg-qxgx-74q7.json b/advisories/unreviewed/2025/04/GHSA-c6pg-qxgx-74q7/GHSA-c6pg-qxgx-74q7.json index f18da9a71c7..89c8e737601 100644 --- a/advisories/unreviewed/2025/04/GHSA-c6pg-qxgx-74q7/GHSA-c6pg-qxgx-74q7.json +++ b/advisories/unreviewed/2025/04/GHSA-c6pg-qxgx-74q7/GHSA-c6pg-qxgx-74q7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c6pg-qxgx-74q7", - "modified": "2025-04-17T18:31:22Z", + "modified": "2025-04-18T18:31:23Z", "published": "2025-04-17T18:31:22Z", "aliases": [ "CVE-2025-29662" ], "details": "A RCE vulnerability in the core application in LandChat 3.25.12.18 allows an unauthenticated attacker to execute system code via remote network access.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-17T17:15:33Z" diff --git a/advisories/unreviewed/2025/04/GHSA-c7rc-cfrf-3v4q/GHSA-c7rc-cfrf-3v4q.json b/advisories/unreviewed/2025/04/GHSA-c7rc-cfrf-3v4q/GHSA-c7rc-cfrf-3v4q.json new file mode 100644 index 00000000000..b05c1645f21 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c7rc-cfrf-3v4q/GHSA-c7rc-cfrf-3v4q.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c7rc-cfrf-3v4q", + "modified": "2025-04-18T18:31:24Z", + "published": "2025-04-18T18:31:24Z", + "aliases": [ + "CVE-2025-28237" + ], + "details": "An issue in WorldCast Systems ECRESO FM/DAB/TV Transmitter v1.10.1 allows authenticated attackers to escalate privileges via a crafted JSON payload.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28237" + }, + { + "type": "WEB", + "url": "https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-28237" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T18:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-chm5-6f56-6fwp/GHSA-chm5-6f56-6fwp.json b/advisories/unreviewed/2025/04/GHSA-chm5-6f56-6fwp/GHSA-chm5-6f56-6fwp.json new file mode 100644 index 00000000000..c7f6ad3d6e6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-chm5-6f56-6fwp/GHSA-chm5-6f56-6fwp.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-chm5-6f56-6fwp", + "modified": "2025-04-18T18:31:24Z", + "published": "2025-04-18T18:31:24Z", + "aliases": [ + "CVE-2025-28231" + ], + "details": "Incorrect access control in Itel Electronics IP Stream v1.7.0.6 allows unauthorized attackers to execute arbitrary commands with Administrator privileges.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28231" + }, + { + "type": "WEB", + "url": "https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-28231" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T18:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fpqq-44hc-vvx2/GHSA-fpqq-44hc-vvx2.json b/advisories/unreviewed/2025/04/GHSA-fpqq-44hc-vvx2/GHSA-fpqq-44hc-vvx2.json new file mode 100644 index 00000000000..358604b8d5b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fpqq-44hc-vvx2/GHSA-fpqq-44hc-vvx2.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fpqq-44hc-vvx2", + "modified": "2025-04-18T18:31:24Z", + "published": "2025-04-18T18:31:24Z", + "aliases": [ + "CVE-2025-28238" + ], + "details": "Improper session management in Elber REBLE310 Firmware v5.5.1.R , Equipment Model: REBLE310/RX10/4ASI allows attackers to execute a session hijacking attack.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28238" + }, + { + "type": "WEB", + "url": "https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-28238" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T18:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fq75-mrrq-hvmj/GHSA-fq75-mrrq-hvmj.json b/advisories/unreviewed/2025/04/GHSA-fq75-mrrq-hvmj/GHSA-fq75-mrrq-hvmj.json index ac1ce53b404..b0bbb1a0868 100644 --- a/advisories/unreviewed/2025/04/GHSA-fq75-mrrq-hvmj/GHSA-fq75-mrrq-hvmj.json +++ b/advisories/unreviewed/2025/04/GHSA-fq75-mrrq-hvmj/GHSA-fq75-mrrq-hvmj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fq75-mrrq-hvmj", - "modified": "2025-04-17T15:32:36Z", + "modified": "2025-04-18T18:31:23Z", "published": "2025-04-17T15:32:36Z", "aliases": [ "CVE-2025-29041" ], "details": "An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and the function 0x41710c", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-17T15:15:54Z" diff --git a/advisories/unreviewed/2025/04/GHSA-gpg3-h2f7-7hcx/GHSA-gpg3-h2f7-7hcx.json b/advisories/unreviewed/2025/04/GHSA-gpg3-h2f7-7hcx/GHSA-gpg3-h2f7-7hcx.json new file mode 100644 index 00000000000..7013bff5bce --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gpg3-h2f7-7hcx/GHSA-gpg3-h2f7-7hcx.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gpg3-h2f7-7hcx", + "modified": "2025-04-18T18:31:24Z", + "published": "2025-04-18T18:31:24Z", + "aliases": [ + "CVE-2025-29512" + ], + "details": "Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code and potentially render the blacklist IP functionality unusable until content is removed via the database.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29512" + }, + { + "type": "WEB", + "url": "https://www.tonysec.com/posts/cve-2025-29512" + }, + { + "type": "WEB", + "url": "http://nodebb.com" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T18:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hfrv-r3rc-g4p6/GHSA-hfrv-r3rc-g4p6.json b/advisories/unreviewed/2025/04/GHSA-hfrv-r3rc-g4p6/GHSA-hfrv-r3rc-g4p6.json new file mode 100644 index 00000000000..4a89646ef14 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hfrv-r3rc-g4p6/GHSA-hfrv-r3rc-g4p6.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hfrv-r3rc-g4p6", + "modified": "2025-04-18T18:31:24Z", + "published": "2025-04-18T18:31:24Z", + "aliases": [ + "CVE-2025-28242" + ], + "details": "Improper session management in the /login_ok.htm endpoint of DAEnetIP4 METO v1.25 allows attackers to execute a session hijacking attack.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28242" + }, + { + "type": "WEB", + "url": "https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-28242" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T18:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m728-3vq8-cxvv/GHSA-m728-3vq8-cxvv.json b/advisories/unreviewed/2025/04/GHSA-m728-3vq8-cxvv/GHSA-m728-3vq8-cxvv.json new file mode 100644 index 00000000000..a61e0d50b0b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m728-3vq8-cxvv/GHSA-m728-3vq8-cxvv.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m728-3vq8-cxvv", + "modified": "2025-04-18T18:31:24Z", + "published": "2025-04-18T18:31:24Z", + "aliases": [ + "CVE-2025-28235" + ], + "details": "An information disclosure vulnerability in the component /socket.io/1/websocket/ of Soundcraft Ui Series Model(s) Ui12 and Ui16 Firmware v1.0.7x and v1.0.5x allows attackers to access Administrator credentials in plaintext.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28235" + }, + { + "type": "WEB", + "url": "https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-28235" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T18:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p6jf-pv8c-623c/GHSA-p6jf-pv8c-623c.json b/advisories/unreviewed/2025/04/GHSA-p6jf-pv8c-623c/GHSA-p6jf-pv8c-623c.json index 6e03e80c149..5d5369a21c7 100644 --- a/advisories/unreviewed/2025/04/GHSA-p6jf-pv8c-623c/GHSA-p6jf-pv8c-623c.json +++ b/advisories/unreviewed/2025/04/GHSA-p6jf-pv8c-623c/GHSA-p6jf-pv8c-623c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p6jf-pv8c-623c", - "modified": "2025-04-14T00:30:35Z", + "modified": "2025-04-18T18:31:23Z", "published": "2025-04-13T15:30:21Z", "aliases": [ "CVE-2024-56406" ], "details": "A heap buffer overflow vulnerability was discovered in Perl. \n\nWhen there are non-ASCII bytes in the left-hand-side of the `tr` operator, `S_do_trans_invmap` can overflow the destination pointer `d`.\n\n   $ perl -e '$_ = \"\\x{FF}\" x 1000000; tr/\\xFF/\\x{100}/;' \n   Segmentation fault (core dumped)\n\nIt is believed that this vulnerability can enable Denial of Service and possibly Code Execution attacks on platforms that lack sufficient defenses.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H" + } + ], "affected": [], "references": [ { @@ -43,7 +48,7 @@ "cwe_ids": [ "CWE-122" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-13T14:15:14Z" diff --git a/advisories/unreviewed/2025/04/GHSA-q7fw-g378-r65g/GHSA-q7fw-g378-r65g.json b/advisories/unreviewed/2025/04/GHSA-q7fw-g378-r65g/GHSA-q7fw-g378-r65g.json new file mode 100644 index 00000000000..db3c74f7bc9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-q7fw-g378-r65g/GHSA-q7fw-g378-r65g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q7fw-g378-r65g", + "modified": "2025-04-18T18:31:24Z", + "published": "2025-04-18T18:31:24Z", + "aliases": [ + "CVE-2025-1697" + ], + "details": "A potential security vulnerability has been identified in the HP Touchpoint Analytics Service for certain HP PC products with versions prior to 4.2.2439. This vulnerability could potentially allow a local attacker to escalate privileges. HP is providing software updates to mitigate this potential vulnerability.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1697" + }, + { + "type": "WEB", + "url": "https://support.hp.com/us-en/document/ish_12269975-12269997-16/hpsbgn04008" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T18:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qgj9-7q8h-gp49/GHSA-qgj9-7q8h-gp49.json b/advisories/unreviewed/2025/04/GHSA-qgj9-7q8h-gp49/GHSA-qgj9-7q8h-gp49.json index 1a1871c5a24..711717bbb05 100644 --- a/advisories/unreviewed/2025/04/GHSA-qgj9-7q8h-gp49/GHSA-qgj9-7q8h-gp49.json +++ b/advisories/unreviewed/2025/04/GHSA-qgj9-7q8h-gp49/GHSA-qgj9-7q8h-gp49.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qgj9-7q8h-gp49", - "modified": "2025-04-17T18:31:15Z", + "modified": "2025-04-18T18:31:23Z", "published": "2025-04-17T18:31:15Z", "aliases": [ "CVE-2025-29043" ], "details": "An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the function 0x417234", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-17T16:15:38Z" diff --git a/advisories/unreviewed/2025/04/GHSA-rw8h-4h76-h2mx/GHSA-rw8h-4h76-h2mx.json b/advisories/unreviewed/2025/04/GHSA-rw8h-4h76-h2mx/GHSA-rw8h-4h76-h2mx.json new file mode 100644 index 00000000000..b3bc775cd42 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rw8h-4h76-h2mx/GHSA-rw8h-4h76-h2mx.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rw8h-4h76-h2mx", + "modified": "2025-04-18T18:31:24Z", + "published": "2025-04-18T18:31:24Z", + "aliases": [ + "CVE-2025-28059" + ], + "details": "An access control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows deleted users to retain access to system resources due to improper session invalidation and stale token handling. When an administrator deletes a user account, the backend fails to terminate active sessions and revoke associated API tokens, enabling unauthorized access to restricted functions.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28059" + }, + { + "type": "WEB", + "url": "https://github.com/aakashtyal/Residual-Data-Access-Post-User-Deletion-in-Nagios-Network-Analyzer-Version-2024R1" + }, + { + "type": "WEB", + "url": "https://www.nagios.com/changelog/#network-analyze" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T17:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-v2rc-5jqj-6rmg/GHSA-v2rc-5jqj-6rmg.json b/advisories/unreviewed/2025/04/GHSA-v2rc-5jqj-6rmg/GHSA-v2rc-5jqj-6rmg.json new file mode 100644 index 00000000000..956421c6ffa --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v2rc-5jqj-6rmg/GHSA-v2rc-5jqj-6rmg.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v2rc-5jqj-6rmg", + "modified": "2025-04-18T18:31:24Z", + "published": "2025-04-18T18:31:24Z", + "aliases": [ + "CVE-2025-29513" + ], + "details": "Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code in the admin API Access token generator.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29513" + }, + { + "type": "WEB", + "url": "https://www.tonysec.com/posts/cve-2025-29513" + }, + { + "type": "WEB", + "url": "http://nodebb.com" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T18:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vq95-6x79-qv8j/GHSA-vq95-6x79-qv8j.json b/advisories/unreviewed/2025/04/GHSA-vq95-6x79-qv8j/GHSA-vq95-6x79-qv8j.json new file mode 100644 index 00000000000..aa9b54bc88a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vq95-6x79-qv8j/GHSA-vq95-6x79-qv8j.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vq95-6x79-qv8j", + "modified": "2025-04-18T18:31:24Z", + "published": "2025-04-18T18:31:24Z", + "aliases": [ + "CVE-2024-41447" + ], + "details": "A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the author parameter under the Create/Modify article function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41447" + }, + { + "type": "WEB", + "url": "https://www.exploit-db.com/exploits/52209" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T17:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-w8ch-v2qx-54xx/GHSA-w8ch-v2qx-54xx.json b/advisories/unreviewed/2025/04/GHSA-w8ch-v2qx-54xx/GHSA-w8ch-v2qx-54xx.json index c35c21717f2..df742884538 100644 --- a/advisories/unreviewed/2025/04/GHSA-w8ch-v2qx-54xx/GHSA-w8ch-v2qx-54xx.json +++ b/advisories/unreviewed/2025/04/GHSA-w8ch-v2qx-54xx/GHSA-w8ch-v2qx-54xx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w8ch-v2qx-54xx", - "modified": "2025-04-17T15:32:36Z", + "modified": "2025-04-18T18:31:23Z", "published": "2025-04-17T15:32:36Z", "aliases": [ "CVE-2025-29040" ], "details": "An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and the function 0x41737c", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-17T15:15:54Z"