From 58c5bac7f6373c2b5ac6683bffc3432e89a4acc3 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 30 May 2025 18:32:47 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-87r3-r32q-8qpf.json | 13 ++++- .../GHSA-jx3f-hj4m-h7p9.json | 13 ++++- .../GHSA-x8r9-m3mh-g58r.json | 13 ++++- .../GHSA-9mj5-r67q-gqfq.json | 6 ++- .../GHSA-fq7v-xj92-r9mr.json | 6 ++- .../GHSA-2c4q-25x9-p644.json | 13 ++++- .../GHSA-34xh-3qm2-46mg.json | 13 ++++- .../GHSA-4mmf-jfc6-j4wj.json | 13 ++++- .../GHSA-5fvw-cpvx-xfq3.json | 1 + .../GHSA-645f-643g-f2h4.json | 10 +++- .../GHSA-76h3-5354-76w2.json | 6 ++- .../GHSA-7g52-j5fp-g582.json | 6 ++- .../GHSA-7qgr-9v2j-3xr8.json | 4 +- .../GHSA-7x9q-8q38-89cr.json | 3 +- .../GHSA-82m6-xpgw-xcxg.json | 6 ++- .../GHSA-8474-8f3q-2jhh.json | 13 ++++- .../GHSA-8jc2-pvhh-pcg8.json | 13 ++++- .../GHSA-8wpj-w799-92rg.json | 10 +++- .../GHSA-96c8-xgpw-cf29.json | 6 ++- .../GHSA-9gg4-742m-cc8x.json | 6 ++- .../GHSA-9hp9-487w-ffqm.json | 13 ++++- .../GHSA-9wpj-x75c-4r84.json | 6 ++- .../GHSA-c54r-ffv6-72gm.json | 13 +++-- .../GHSA-c9p5-2jv2-63vv.json | 13 ++++- .../GHSA-ccr5-qp85-4v82.json | 6 ++- .../GHSA-fpmq-9j97-cq2c.json | 13 ++++- .../GHSA-frmc-7grc-fhjw.json | 6 ++- .../GHSA-gmf9-gfhv-6xhp.json | 13 ++++- .../GHSA-gw6r-2xfv-2c8w.json | 13 ++++- .../GHSA-h4w8-wwg9-q6pr.json | 17 ++++-- .../GHSA-hfx5-55x6-5xfr.json | 13 ++++- .../GHSA-hgc9-x857-7qx4.json | 6 ++- .../GHSA-j99f-3mvg-4m4r.json | 4 +- .../GHSA-jv95-xvv4-phc9.json | 6 ++- .../GHSA-mvm2-v629-ff77.json | 6 ++- .../GHSA-p23p-m9mc-pg6q.json | 6 ++- .../GHSA-p5f8-j7c4-pr59.json | 6 ++- .../GHSA-p74w-76h9-xxqv.json | 6 ++- .../GHSA-p78q-972x-mrg3.json | 6 ++- .../GHSA-phmh-5xpr-c83f.json | 6 ++- .../GHSA-pr66-gfw7-8w5p.json | 17 ++++-- .../GHSA-q4rq-wjvw-rh5x.json | 13 ++++- .../GHSA-qc22-6662-58rj.json | 17 +++++- .../GHSA-rjw6-fhxf-vxvf.json | 13 ++++- .../GHSA-v3x2-gf8f-p55r.json | 17 ++++-- .../GHSA-vgc4-27p4-9gfq.json | 13 ++++- .../GHSA-vw8v-x3mw-g32q.json | 6 ++- .../GHSA-wh2f-7mq6-xvc5.json | 13 ++++- .../GHSA-wrf8-p6r2-xw72.json | 6 ++- .../GHSA-xjh5-4qmv-vw5r.json | 17 +++++- .../GHSA-xjrh-8gjh-h7rm.json | 6 ++- .../GHSA-xqh9-89v8-g968.json | 13 ++++- .../GHSA-58c3-q676-fmqx.json | 6 ++- .../GHSA-v68v-g8q2-4vqq.json | 6 ++- .../GHSA-8g9x-2rqx-hwvf.json | 4 +- .../GHSA-vh37-fmrj-jmpx.json | 10 +++- .../GHSA-67q7-2m82-v47j.json | 6 ++- .../GHSA-47xh-88vf-mqw7.json | 6 ++- .../GHSA-489f-78mr-mq29.json | 6 ++- .../GHSA-5c9w-vq5m-266h.json | 6 ++- .../GHSA-cm4x-r333-vvv9.json | 6 ++- .../GHSA-fwgh-82pj-8vp9.json | 6 ++- .../GHSA-g5qg-593p-j5gq.json | 6 ++- .../GHSA-gg38-fph6-54g7.json | 6 ++- .../GHSA-jc4j-5j4g-r9cv.json | 6 ++- .../GHSA-m5jj-959w-4x33.json | 6 ++- .../GHSA-vfm9-f37f-c9j3.json | 6 ++- .../GHSA-34vj-fgrq-mq4v.json | 6 ++- .../GHSA-3f3j-x9h2-qcf8.json | 6 ++- .../GHSA-92r6-gw4h-q44j.json | 6 ++- .../GHSA-4vgw-728w-p4h7.json | 6 ++- .../GHSA-4x6f-629h-vv8j.json | 6 ++- .../GHSA-5c5q-xj8p-hrg3.json | 6 ++- .../GHSA-22wj-5rv2-cqf6.json | 6 ++- .../GHSA-9f3h-5jcm-xmgf.json | 6 ++- .../GHSA-g5g4-5h6q-mrwm.json | 6 ++- .../GHSA-r976-44r3-hm6v.json | 6 ++- .../GHSA-4hhm-hpr8-q62r.json | 6 ++- .../GHSA-q9fm-wwch-86pf.json | 6 ++- .../GHSA-f49c-c736-9g2j.json | 6 ++- .../GHSA-vr69-cpcv-wf75.json | 6 ++- .../GHSA-8r5c-mgwc-qg49.json | 6 ++- .../GHSA-5j36-2f99-3384.json | 6 ++- .../GHSA-8cpv-pp42-ppmr.json | 6 ++- .../GHSA-f78h-hr6r-68jw.json | 6 ++- .../GHSA-m7gg-q7qj-3r2r.json | 6 ++- .../GHSA-xq72-5mqw-j6rc.json | 6 ++- .../GHSA-67wm-85xj-pgvv.json | 4 +- .../GHSA-p7q5-2qf4-97cw.json | 4 +- .../GHSA-qj2m-h9cr-4gv7.json | 6 ++- .../GHSA-chqx-rw2r-xgw8.json | 6 ++- .../GHSA-xq5f-88w9-ffw2.json | 4 +- .../GHSA-58xh-xqmq-2mmr.json | 4 +- .../GHSA-96vr-9q65-96gj.json | 4 +- .../GHSA-cx67-m2rh-98xh.json | 4 +- .../GHSA-wrpc-6v65-cc7f.json | 4 +- .../GHSA-rfh5-gx7w-h7v7.json | 6 ++- .../GHSA-2vx2-pv2m-vwrq.json | 4 +- .../GHSA-4c8w-67qj-c8vp.json | 44 ++++++++++++++++ .../GHSA-63xm-x5g2-5gr3.json | 1 + .../GHSA-6pg5-rmm9-6cq9.json | 52 +++++++++++++++++++ .../GHSA-89c4-h5cm-8ppg.json | 36 +++++++++++++ .../GHSA-89vx-m8mc-p558.json | 36 +++++++++++++ .../GHSA-8vfw-v3xx-j7xw.json | 36 +++++++++++++ .../GHSA-9m9c-m3m8-59vc.json | 36 +++++++++++++ .../GHSA-fg72-v8xw-hm7h.json | 15 ++++-- .../GHSA-ghmf-r624-m2jq.json | 36 +++++++++++++ .../GHSA-hc7m-j4w7-pv6w.json | 15 ++++-- .../GHSA-p4hr-xgjf-v467.json | 52 +++++++++++++++++++ .../GHSA-ppq4-7pwf-rg3r.json | 36 +++++++++++++ .../GHSA-pw53-33fx-vf55.json | 36 +++++++++++++ .../GHSA-rcv8-vxjp-vqcw.json | 11 ++-- .../GHSA-x6fc-488r-qh93.json | 15 ++++-- .../GHSA-x8ch-h5vv-q6cm.json | 11 ++-- .../GHSA-xwh8-466p-8642.json | 52 +++++++++++++++++++ 115 files changed, 1140 insertions(+), 145 deletions(-) create mode 100644 advisories/unreviewed/2025/05/GHSA-4c8w-67qj-c8vp/GHSA-4c8w-67qj-c8vp.json create mode 100644 advisories/unreviewed/2025/05/GHSA-6pg5-rmm9-6cq9/GHSA-6pg5-rmm9-6cq9.json create mode 100644 advisories/unreviewed/2025/05/GHSA-89c4-h5cm-8ppg/GHSA-89c4-h5cm-8ppg.json create mode 100644 advisories/unreviewed/2025/05/GHSA-89vx-m8mc-p558/GHSA-89vx-m8mc-p558.json create mode 100644 advisories/unreviewed/2025/05/GHSA-8vfw-v3xx-j7xw/GHSA-8vfw-v3xx-j7xw.json create mode 100644 advisories/unreviewed/2025/05/GHSA-9m9c-m3m8-59vc/GHSA-9m9c-m3m8-59vc.json create mode 100644 advisories/unreviewed/2025/05/GHSA-ghmf-r624-m2jq/GHSA-ghmf-r624-m2jq.json create mode 100644 advisories/unreviewed/2025/05/GHSA-p4hr-xgjf-v467/GHSA-p4hr-xgjf-v467.json create mode 100644 advisories/unreviewed/2025/05/GHSA-ppq4-7pwf-rg3r/GHSA-ppq4-7pwf-rg3r.json create mode 100644 advisories/unreviewed/2025/05/GHSA-pw53-33fx-vf55/GHSA-pw53-33fx-vf55.json create mode 100644 advisories/unreviewed/2025/05/GHSA-xwh8-466p-8642/GHSA-xwh8-466p-8642.json diff --git a/advisories/unreviewed/2021/12/GHSA-87r3-r32q-8qpf/GHSA-87r3-r32q-8qpf.json b/advisories/unreviewed/2021/12/GHSA-87r3-r32q-8qpf/GHSA-87r3-r32q-8qpf.json index a43c94e0a69..55dac1ba149 100644 --- a/advisories/unreviewed/2021/12/GHSA-87r3-r32q-8qpf/GHSA-87r3-r32q-8qpf.json +++ b/advisories/unreviewed/2021/12/GHSA-87r3-r32q-8qpf/GHSA-87r3-r32q-8qpf.json @@ -1,19 +1,28 @@ { "schema_version": "1.4.0", "id": "GHSA-87r3-r32q-8qpf", - "modified": "2021-12-23T00:01:52Z", + "modified": "2025-05-30T18:30:41Z", "published": "2021-12-18T00:01:02Z", "aliases": [ "CVE-2021-44035" ], "details": "Wolters Kluwer TeamMate AM 12.4 Update 1 mishandles attachment uploads, such that an authenticated user may download and execute malicious files.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-44035" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2021-44035" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2021-44035" diff --git a/advisories/unreviewed/2021/12/GHSA-jx3f-hj4m-h7p9/GHSA-jx3f-hj4m-h7p9.json b/advisories/unreviewed/2021/12/GHSA-jx3f-hj4m-h7p9/GHSA-jx3f-hj4m-h7p9.json index 204fe0c47b9..ae5cbbcbc3a 100644 --- a/advisories/unreviewed/2021/12/GHSA-jx3f-hj4m-h7p9/GHSA-jx3f-hj4m-h7p9.json +++ b/advisories/unreviewed/2021/12/GHSA-jx3f-hj4m-h7p9/GHSA-jx3f-hj4m-h7p9.json @@ -1,19 +1,28 @@ { "schema_version": "1.4.0", "id": "GHSA-jx3f-hj4m-h7p9", - "modified": "2021-12-11T00:01:10Z", + "modified": "2025-05-30T18:30:41Z", "published": "2021-12-09T00:00:39Z", "aliases": [ "CVE-2021-42110" ], "details": "An issue was discovered in Allegro Windows (formerly Popsy Windows) before 3.3.4156.1. A standard user can escalate privileges to SYSTEM if the FTP module is installed, because of DLL hijacking.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-42110" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2021-42110" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2021-42110" diff --git a/advisories/unreviewed/2021/12/GHSA-x8r9-m3mh-g58r/GHSA-x8r9-m3mh-g58r.json b/advisories/unreviewed/2021/12/GHSA-x8r9-m3mh-g58r/GHSA-x8r9-m3mh-g58r.json index 0b8dbca2f4a..17637f98e22 100644 --- a/advisories/unreviewed/2021/12/GHSA-x8r9-m3mh-g58r/GHSA-x8r9-m3mh-g58r.json +++ b/advisories/unreviewed/2021/12/GHSA-x8r9-m3mh-g58r/GHSA-x8r9-m3mh-g58r.json @@ -1,19 +1,28 @@ { "schema_version": "1.4.0", "id": "GHSA-x8r9-m3mh-g58r", - "modified": "2021-12-14T00:01:30Z", + "modified": "2025-05-30T18:30:41Z", "published": "2021-12-09T00:00:33Z", "aliases": [ "CVE-2021-43978" ], "details": "Allegro WIndows 3.3.4152.0, embeds software administrator database credentials into its binary files, which allows users to access and modify data using the same credentials.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-43978" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2021-43978" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2021-43978" diff --git a/advisories/unreviewed/2022/03/GHSA-9mj5-r67q-gqfq/GHSA-9mj5-r67q-gqfq.json b/advisories/unreviewed/2022/03/GHSA-9mj5-r67q-gqfq/GHSA-9mj5-r67q-gqfq.json index 7d7dd2c11ea..916a03ab5e4 100644 --- a/advisories/unreviewed/2022/03/GHSA-9mj5-r67q-gqfq/GHSA-9mj5-r67q-gqfq.json +++ b/advisories/unreviewed/2022/03/GHSA-9mj5-r67q-gqfq/GHSA-9mj5-r67q-gqfq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9mj5-r67q-gqfq", - "modified": "2022-03-17T00:04:14Z", + "modified": "2025-05-30T18:30:42Z", "published": "2022-03-03T00:00:49Z", "aliases": [ "CVE-2022-24447" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-24447" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2022-24447" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/cve-2022-24447" diff --git a/advisories/unreviewed/2022/03/GHSA-fq7v-xj92-r9mr/GHSA-fq7v-xj92-r9mr.json b/advisories/unreviewed/2022/03/GHSA-fq7v-xj92-r9mr/GHSA-fq7v-xj92-r9mr.json index a433e68cd91..934628969a5 100644 --- a/advisories/unreviewed/2022/03/GHSA-fq7v-xj92-r9mr/GHSA-fq7v-xj92-r9mr.json +++ b/advisories/unreviewed/2022/03/GHSA-fq7v-xj92-r9mr/GHSA-fq7v-xj92-r9mr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fq7v-xj92-r9mr", - "modified": "2022-03-17T00:04:32Z", + "modified": "2025-05-30T18:30:42Z", "published": "2022-03-02T00:00:21Z", "aliases": [ "CVE-2022-24446" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-24446" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2022-24446" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory" diff --git a/advisories/unreviewed/2022/05/GHSA-2c4q-25x9-p644/GHSA-2c4q-25x9-p644.json b/advisories/unreviewed/2022/05/GHSA-2c4q-25x9-p644/GHSA-2c4q-25x9-p644.json index 627003be8b2..368f285a7bf 100644 --- a/advisories/unreviewed/2022/05/GHSA-2c4q-25x9-p644/GHSA-2c4q-25x9-p644.json +++ b/advisories/unreviewed/2022/05/GHSA-2c4q-25x9-p644/GHSA-2c4q-25x9-p644.json @@ -1,19 +1,28 @@ { "schema_version": "1.4.0", "id": "GHSA-2c4q-25x9-p644", - "modified": "2022-05-24T19:06:33Z", + "modified": "2025-05-30T18:30:39Z", "published": "2022-05-24T19:06:33Z", "aliases": [ "CVE-2021-31160" ], "details": "Zoho ManageEngine ServiceDesk Plus MSP before 10521 allows an attacker to access internal data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-31160" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2021-31160" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/cve-2021-31160" diff --git a/advisories/unreviewed/2022/05/GHSA-34xh-3qm2-46mg/GHSA-34xh-3qm2-46mg.json b/advisories/unreviewed/2022/05/GHSA-34xh-3qm2-46mg/GHSA-34xh-3qm2-46mg.json index 739a28b6ec4..bf23c4a8a3d 100644 --- a/advisories/unreviewed/2022/05/GHSA-34xh-3qm2-46mg/GHSA-34xh-3qm2-46mg.json +++ b/advisories/unreviewed/2022/05/GHSA-34xh-3qm2-46mg/GHSA-34xh-3qm2-46mg.json @@ -1,19 +1,28 @@ { "schema_version": "1.4.0", "id": "GHSA-34xh-3qm2-46mg", - "modified": "2022-05-24T17:40:33Z", + "modified": "2025-05-30T18:30:38Z", "published": "2022-05-24T17:40:33Z", "aliases": [ "CVE-2020-28401" ], "details": "An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access WIP details about jobs he should not have access to.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-28401" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2020-28401" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2020-28401" diff --git a/advisories/unreviewed/2022/05/GHSA-4mmf-jfc6-j4wj/GHSA-4mmf-jfc6-j4wj.json b/advisories/unreviewed/2022/05/GHSA-4mmf-jfc6-j4wj/GHSA-4mmf-jfc6-j4wj.json index dadee0bcbb2..fe44023e192 100644 --- a/advisories/unreviewed/2022/05/GHSA-4mmf-jfc6-j4wj/GHSA-4mmf-jfc6-j4wj.json +++ b/advisories/unreviewed/2022/05/GHSA-4mmf-jfc6-j4wj/GHSA-4mmf-jfc6-j4wj.json @@ -1,19 +1,28 @@ { "schema_version": "1.4.0", "id": "GHSA-4mmf-jfc6-j4wj", - "modified": "2022-05-24T17:40:33Z", + "modified": "2025-05-30T18:30:39Z", "published": "2022-05-24T17:40:33Z", "aliases": [ "CVE-2020-28403" ], "details": "A Cross-Site Request Forgery (CSRF) vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an attacker to change the privileges of any user of the application. This can be used to grant himself administrative role or remove the administrative account of the application.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-28403" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2020-28403" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2020-28403" diff --git a/advisories/unreviewed/2022/05/GHSA-5fvw-cpvx-xfq3/GHSA-5fvw-cpvx-xfq3.json b/advisories/unreviewed/2022/05/GHSA-5fvw-cpvx-xfq3/GHSA-5fvw-cpvx-xfq3.json index d93113249c7..1527267194f 100644 --- a/advisories/unreviewed/2022/05/GHSA-5fvw-cpvx-xfq3/GHSA-5fvw-cpvx-xfq3.json +++ b/advisories/unreviewed/2022/05/GHSA-5fvw-cpvx-xfq3/GHSA-5fvw-cpvx-xfq3.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/05/GHSA-645f-643g-f2h4/GHSA-645f-643g-f2h4.json b/advisories/unreviewed/2022/05/GHSA-645f-643g-f2h4/GHSA-645f-643g-f2h4.json index 3d91c1ffab8..b3379065f5f 100644 --- a/advisories/unreviewed/2022/05/GHSA-645f-643g-f2h4/GHSA-645f-643g-f2h4.json +++ b/advisories/unreviewed/2022/05/GHSA-645f-643g-f2h4/GHSA-645f-643g-f2h4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-645f-643g-f2h4", - "modified": "2022-05-13T01:08:16Z", + "modified": "2025-05-30T18:30:34Z", "published": "2022-05-13T01:08:16Z", "aliases": [ "CVE-2019-7161" @@ -19,6 +19,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-7161" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2019-7161" + }, + { + "type": "WEB", + "url": "https://www.excellium-services.com/cert-xlm-advisory" + }, { "type": "WEB", "url": "https://www.excellium-services.com/cert-xlm-advisory/cve-2019-7161" diff --git a/advisories/unreviewed/2022/05/GHSA-76h3-5354-76w2/GHSA-76h3-5354-76w2.json b/advisories/unreviewed/2022/05/GHSA-76h3-5354-76w2/GHSA-76h3-5354-76w2.json index ebfb39d6d17..3da3c4ca2c2 100644 --- a/advisories/unreviewed/2022/05/GHSA-76h3-5354-76w2/GHSA-76h3-5354-76w2.json +++ b/advisories/unreviewed/2022/05/GHSA-76h3-5354-76w2/GHSA-76h3-5354-76w2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-76h3-5354-76w2", - "modified": "2022-07-13T00:01:35Z", + "modified": "2025-05-30T18:30:40Z", "published": "2022-05-24T19:13:15Z", "aliases": [ "CVE-2021-38616" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-38616" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2021-38616" + }, { "type": "WEB", "url": "https://eigentech.com" diff --git a/advisories/unreviewed/2022/05/GHSA-7g52-j5fp-g582/GHSA-7g52-j5fp-g582.json b/advisories/unreviewed/2022/05/GHSA-7g52-j5fp-g582/GHSA-7g52-j5fp-g582.json index a8fc805e722..9d4a870c130 100644 --- a/advisories/unreviewed/2022/05/GHSA-7g52-j5fp-g582/GHSA-7g52-j5fp-g582.json +++ b/advisories/unreviewed/2022/05/GHSA-7g52-j5fp-g582/GHSA-7g52-j5fp-g582.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7g52-j5fp-g582", - "modified": "2022-07-13T00:01:35Z", + "modified": "2025-05-30T18:30:40Z", "published": "2022-05-24T19:16:25Z", "aliases": [ "CVE-2021-38618" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-38618" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2021-38618" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/cve-2021-38618" diff --git a/advisories/unreviewed/2022/05/GHSA-7qgr-9v2j-3xr8/GHSA-7qgr-9v2j-3xr8.json b/advisories/unreviewed/2022/05/GHSA-7qgr-9v2j-3xr8/GHSA-7qgr-9v2j-3xr8.json index 7a8528a03d8..27fe09edba7 100644 --- a/advisories/unreviewed/2022/05/GHSA-7qgr-9v2j-3xr8/GHSA-7qgr-9v2j-3xr8.json +++ b/advisories/unreviewed/2022/05/GHSA-7qgr-9v2j-3xr8/GHSA-7qgr-9v2j-3xr8.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-119" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7x9q-8q38-89cr/GHSA-7x9q-8q38-89cr.json b/advisories/unreviewed/2022/05/GHSA-7x9q-8q38-89cr/GHSA-7x9q-8q38-89cr.json index 5a1a6e61cb1..96c76e368cd 100644 --- a/advisories/unreviewed/2022/05/GHSA-7x9q-8q38-89cr/GHSA-7x9q-8q38-89cr.json +++ b/advisories/unreviewed/2022/05/GHSA-7x9q-8q38-89cr/GHSA-7x9q-8q38-89cr.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-693" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-82m6-xpgw-xcxg/GHSA-82m6-xpgw-xcxg.json b/advisories/unreviewed/2022/05/GHSA-82m6-xpgw-xcxg/GHSA-82m6-xpgw-xcxg.json index 3cff281221f..7e2f6246b73 100644 --- a/advisories/unreviewed/2022/05/GHSA-82m6-xpgw-xcxg/GHSA-82m6-xpgw-xcxg.json +++ b/advisories/unreviewed/2022/05/GHSA-82m6-xpgw-xcxg/GHSA-82m6-xpgw-xcxg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-82m6-xpgw-xcxg", - "modified": "2022-05-13T01:48:44Z", + "modified": "2025-05-30T18:30:33Z", "published": "2022-05-13T01:48:44Z", "aliases": [ "CVE-2018-10207" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-10207" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2018-10207" + }, { "type": "WEB", "url": "https://www.excellium-services.com/cert-xlm-advisory/cve-2018-10207" diff --git a/advisories/unreviewed/2022/05/GHSA-8474-8f3q-2jhh/GHSA-8474-8f3q-2jhh.json b/advisories/unreviewed/2022/05/GHSA-8474-8f3q-2jhh/GHSA-8474-8f3q-2jhh.json index 74bed048684..4eadb9efd39 100644 --- a/advisories/unreviewed/2022/05/GHSA-8474-8f3q-2jhh/GHSA-8474-8f3q-2jhh.json +++ b/advisories/unreviewed/2022/05/GHSA-8474-8f3q-2jhh/GHSA-8474-8f3q-2jhh.json @@ -1,19 +1,28 @@ { "schema_version": "1.4.0", "id": "GHSA-8474-8f3q-2jhh", - "modified": "2022-05-24T17:40:34Z", + "modified": "2025-05-30T18:30:39Z", "published": "2022-05-24T17:40:34Z", "aliases": [ "CVE-2020-28406" ], "details": "An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access details about jobs he should not have access to via the Audit Trail Feature.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-28406" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2020-28406" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2020-28406" diff --git a/advisories/unreviewed/2022/05/GHSA-8jc2-pvhh-pcg8/GHSA-8jc2-pvhh-pcg8.json b/advisories/unreviewed/2022/05/GHSA-8jc2-pvhh-pcg8/GHSA-8jc2-pvhh-pcg8.json index 5e3e083fbfc..b1457cfb900 100644 --- a/advisories/unreviewed/2022/05/GHSA-8jc2-pvhh-pcg8/GHSA-8jc2-pvhh-pcg8.json +++ b/advisories/unreviewed/2022/05/GHSA-8jc2-pvhh-pcg8/GHSA-8jc2-pvhh-pcg8.json @@ -1,19 +1,28 @@ { "schema_version": "1.4.0", "id": "GHSA-8jc2-pvhh-pcg8", - "modified": "2022-05-24T17:40:34Z", + "modified": "2025-05-30T18:30:39Z", "published": "2022-05-24T17:40:34Z", "aliases": [ "CVE-2020-28404" ], "details": "An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access the Billing page without the appropriate privileges.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-28404" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2020-28404" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2020-28404" diff --git a/advisories/unreviewed/2022/05/GHSA-8wpj-w799-92rg/GHSA-8wpj-w799-92rg.json b/advisories/unreviewed/2022/05/GHSA-8wpj-w799-92rg/GHSA-8wpj-w799-92rg.json index d54686699cd..801056de043 100644 --- a/advisories/unreviewed/2022/05/GHSA-8wpj-w799-92rg/GHSA-8wpj-w799-92rg.json +++ b/advisories/unreviewed/2022/05/GHSA-8wpj-w799-92rg/GHSA-8wpj-w799-92rg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8wpj-w799-92rg", - "modified": "2024-03-21T03:33:34Z", + "modified": "2025-05-30T18:30:34Z", "published": "2022-05-13T01:19:38Z", "aliases": [ "CVE-2018-18466" @@ -19,6 +19,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-18466" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2018-18466" + }, + { + "type": "WEB", + "url": "https://www.excellium-services.com/cert-xlm-advisory" + }, { "type": "WEB", "url": "https://www.excellium-services.com/cert-xlm-advisory/cve-2018-18466" diff --git a/advisories/unreviewed/2022/05/GHSA-96c8-xgpw-cf29/GHSA-96c8-xgpw-cf29.json b/advisories/unreviewed/2022/05/GHSA-96c8-xgpw-cf29/GHSA-96c8-xgpw-cf29.json index 6ed478d9fe6..8796686f143 100644 --- a/advisories/unreviewed/2022/05/GHSA-96c8-xgpw-cf29/GHSA-96c8-xgpw-cf29.json +++ b/advisories/unreviewed/2022/05/GHSA-96c8-xgpw-cf29/GHSA-96c8-xgpw-cf29.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-96c8-xgpw-cf29", - "modified": "2022-05-13T01:48:44Z", + "modified": "2025-05-30T18:30:33Z", "published": "2022-05-13T01:48:44Z", "aliases": [ "CVE-2018-10211" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-10211" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2018-10211" + }, { "type": "WEB", "url": "https://www.excellium-services.com/cert-xlm-advisory/cve-2018-10211" diff --git a/advisories/unreviewed/2022/05/GHSA-9gg4-742m-cc8x/GHSA-9gg4-742m-cc8x.json b/advisories/unreviewed/2022/05/GHSA-9gg4-742m-cc8x/GHSA-9gg4-742m-cc8x.json index b0b340d5fff..e1a7f6c54fb 100644 --- a/advisories/unreviewed/2022/05/GHSA-9gg4-742m-cc8x/GHSA-9gg4-742m-cc8x.json +++ b/advisories/unreviewed/2022/05/GHSA-9gg4-742m-cc8x/GHSA-9gg4-742m-cc8x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9gg4-742m-cc8x", - "modified": "2022-05-13T01:48:44Z", + "modified": "2025-05-30T18:30:34Z", "published": "2022-05-13T01:48:44Z", "aliases": [ "CVE-2018-10212" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-10212" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2018-10212" + }, { "type": "WEB", "url": "https://www.excellium-services.com/cert-xlm-advisory/cve-2018-10212" diff --git a/advisories/unreviewed/2022/05/GHSA-9hp9-487w-ffqm/GHSA-9hp9-487w-ffqm.json b/advisories/unreviewed/2022/05/GHSA-9hp9-487w-ffqm/GHSA-9hp9-487w-ffqm.json index ac1877b27c7..072cf05b68c 100644 --- a/advisories/unreviewed/2022/05/GHSA-9hp9-487w-ffqm/GHSA-9hp9-487w-ffqm.json +++ b/advisories/unreviewed/2022/05/GHSA-9hp9-487w-ffqm/GHSA-9hp9-487w-ffqm.json @@ -1,19 +1,28 @@ { "schema_version": "1.4.0", "id": "GHSA-9hp9-487w-ffqm", - "modified": "2022-05-24T19:06:32Z", + "modified": "2025-05-30T18:30:40Z", "published": "2022-05-24T19:06:32Z", "aliases": [ "CVE-2021-31531" ], "details": "Zoho ManageEngine ServiceDesk Plus MSP before 10521 is vulnerable to Server-Side Request Forgery (SSRF).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-31531" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2021-31531" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/cve-2021-31531" diff --git a/advisories/unreviewed/2022/05/GHSA-9wpj-x75c-4r84/GHSA-9wpj-x75c-4r84.json b/advisories/unreviewed/2022/05/GHSA-9wpj-x75c-4r84/GHSA-9wpj-x75c-4r84.json index 2142e1bd108..aa58459f69f 100644 --- a/advisories/unreviewed/2022/05/GHSA-9wpj-x75c-4r84/GHSA-9wpj-x75c-4r84.json +++ b/advisories/unreviewed/2022/05/GHSA-9wpj-x75c-4r84/GHSA-9wpj-x75c-4r84.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9wpj-x75c-4r84", - "modified": "2022-05-14T03:21:14Z", + "modified": "2025-05-30T18:30:33Z", "published": "2022-05-14T03:21:14Z", "aliases": [ "CVE-2018-10206" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-10206" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2018-10206" + }, { "type": "WEB", "url": "https://www.excellium-services.com/cert-xlm-advisory/cve-2018-10206" diff --git a/advisories/unreviewed/2022/05/GHSA-c54r-ffv6-72gm/GHSA-c54r-ffv6-72gm.json b/advisories/unreviewed/2022/05/GHSA-c54r-ffv6-72gm/GHSA-c54r-ffv6-72gm.json index fd0a42d66f3..2af49285aca 100644 --- a/advisories/unreviewed/2022/05/GHSA-c54r-ffv6-72gm/GHSA-c54r-ffv6-72gm.json +++ b/advisories/unreviewed/2022/05/GHSA-c54r-ffv6-72gm/GHSA-c54r-ffv6-72gm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c54r-ffv6-72gm", - "modified": "2022-05-24T17:07:50Z", + "modified": "2025-05-30T18:30:36Z", "published": "2022-05-24T17:07:50Z", "aliases": [ "CVE-2020-8422" ], "details": "An authorization issue was discovered in the Credential Manager feature in Zoho ManageEngine Remote Access Plus before 10.0.450. A user with the Guest role can extract the collection of all defined credentials of remote machines: the credential name, credential type, user name, domain/workgroup name, and description (but not the password).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -16,11 +21,11 @@ }, { "type": "WEB", - "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2020-8422" + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2020-8422" }, { "type": "WEB", - "url": "https://excellium-services.com/cert-xlm-advisory/cve-2020-8422" + "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2020-8422" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/05/GHSA-c9p5-2jv2-63vv/GHSA-c9p5-2jv2-63vv.json b/advisories/unreviewed/2022/05/GHSA-c9p5-2jv2-63vv/GHSA-c9p5-2jv2-63vv.json index 6e9b506acc7..6d5144eb4bf 100644 --- a/advisories/unreviewed/2022/05/GHSA-c9p5-2jv2-63vv/GHSA-c9p5-2jv2-63vv.json +++ b/advisories/unreviewed/2022/05/GHSA-c9p5-2jv2-63vv/GHSA-c9p5-2jv2-63vv.json @@ -1,19 +1,28 @@ { "schema_version": "1.4.0", "id": "GHSA-c9p5-2jv2-63vv", - "modified": "2022-05-24T19:11:07Z", + "modified": "2025-05-30T18:30:40Z", "published": "2022-05-24T19:11:07Z", "aliases": [ "CVE-2021-31399" ], "details": "On 2N Access Unit 2.0 2.31.0.40.5 devices, an attacker can pose as the web relay for a man-in-the-middle attack.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-31399" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2021-31399" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/cve-2021-31399" diff --git a/advisories/unreviewed/2022/05/GHSA-ccr5-qp85-4v82/GHSA-ccr5-qp85-4v82.json b/advisories/unreviewed/2022/05/GHSA-ccr5-qp85-4v82/GHSA-ccr5-qp85-4v82.json index 9366ed43624..ae31e7ea401 100644 --- a/advisories/unreviewed/2022/05/GHSA-ccr5-qp85-4v82/GHSA-ccr5-qp85-4v82.json +++ b/advisories/unreviewed/2022/05/GHSA-ccr5-qp85-4v82/GHSA-ccr5-qp85-4v82.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ccr5-qp85-4v82", - "modified": "2022-07-13T00:01:42Z", + "modified": "2025-05-30T18:30:40Z", "published": "2022-05-24T19:20:16Z", "aliases": [ "CVE-2021-42111" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-42111" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2021-42111" + }, { "type": "WEB", "url": "https://excellium-services.com/cve-2021-42111" diff --git a/advisories/unreviewed/2022/05/GHSA-fpmq-9j97-cq2c/GHSA-fpmq-9j97-cq2c.json b/advisories/unreviewed/2022/05/GHSA-fpmq-9j97-cq2c/GHSA-fpmq-9j97-cq2c.json index d786cadb488..de55f6ef8a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-fpmq-9j97-cq2c/GHSA-fpmq-9j97-cq2c.json +++ b/advisories/unreviewed/2022/05/GHSA-fpmq-9j97-cq2c/GHSA-fpmq-9j97-cq2c.json @@ -1,19 +1,28 @@ { "schema_version": "1.4.0", "id": "GHSA-fpmq-9j97-cq2c", - "modified": "2022-05-24T17:40:33Z", + "modified": "2025-05-30T18:30:39Z", "published": "2022-05-24T17:40:33Z", "aliases": [ "CVE-2020-28402" ], "details": "An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access Launcher Configuration Panel.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-28402" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2020-28402" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2020-28402" diff --git a/advisories/unreviewed/2022/05/GHSA-frmc-7grc-fhjw/GHSA-frmc-7grc-fhjw.json b/advisories/unreviewed/2022/05/GHSA-frmc-7grc-fhjw/GHSA-frmc-7grc-fhjw.json index 083cf4e763d..e19bfc420cd 100644 --- a/advisories/unreviewed/2022/05/GHSA-frmc-7grc-fhjw/GHSA-frmc-7grc-fhjw.json +++ b/advisories/unreviewed/2022/05/GHSA-frmc-7grc-fhjw/GHSA-frmc-7grc-fhjw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-frmc-7grc-fhjw", - "modified": "2022-05-14T00:55:18Z", + "modified": "2025-05-30T18:30:34Z", "published": "2022-05-14T00:55:18Z", "aliases": [ "CVE-2019-3905" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-3905" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2019-3905" + }, { "type": "WEB", "url": "https://www.excellium-services.com/cert-xlm-advisory/cve-2019-3905" diff --git a/advisories/unreviewed/2022/05/GHSA-gmf9-gfhv-6xhp/GHSA-gmf9-gfhv-6xhp.json b/advisories/unreviewed/2022/05/GHSA-gmf9-gfhv-6xhp/GHSA-gmf9-gfhv-6xhp.json index a2df6ef1ffb..f3a7949583a 100644 --- a/advisories/unreviewed/2022/05/GHSA-gmf9-gfhv-6xhp/GHSA-gmf9-gfhv-6xhp.json +++ b/advisories/unreviewed/2022/05/GHSA-gmf9-gfhv-6xhp/GHSA-gmf9-gfhv-6xhp.json @@ -1,19 +1,28 @@ { "schema_version": "1.4.0", "id": "GHSA-gmf9-gfhv-6xhp", - "modified": "2022-05-24T19:09:48Z", + "modified": "2025-05-30T18:30:40Z", "published": "2022-05-24T19:09:48Z", "aliases": [ "CVE-2021-32018" ], "details": "An issue was discovered in JUMP AMS 3.6.0.04.009-2487. The JUMP SOAP API was vulnerable to arbitrary file reading due to an improper limitation of file loading on the server filesystem, aka directory traversal.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-32018" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2021-32018" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/cve-2021-32018" diff --git a/advisories/unreviewed/2022/05/GHSA-gw6r-2xfv-2c8w/GHSA-gw6r-2xfv-2c8w.json b/advisories/unreviewed/2022/05/GHSA-gw6r-2xfv-2c8w/GHSA-gw6r-2xfv-2c8w.json index d385f3b52c9..03690455b1a 100644 --- a/advisories/unreviewed/2022/05/GHSA-gw6r-2xfv-2c8w/GHSA-gw6r-2xfv-2c8w.json +++ b/advisories/unreviewed/2022/05/GHSA-gw6r-2xfv-2c8w/GHSA-gw6r-2xfv-2c8w.json @@ -1,19 +1,28 @@ { "schema_version": "1.4.0", "id": "GHSA-gw6r-2xfv-2c8w", - "modified": "2022-05-24T17:42:18Z", + "modified": "2025-05-30T18:30:39Z", "published": "2022-05-24T17:42:18Z", "aliases": [ "CVE-2020-28918" ], "details": "DualShield 5.9.8.0821 allows username enumeration on its login form. A valid username results in prompting for the password, whereas an invalid one will produce an \"unknown username\" error message.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-28918" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2020-28918" + }, { "type": "WEB", "url": "https://deepnetsecurity.com/multi-factor-authentication" diff --git a/advisories/unreviewed/2022/05/GHSA-h4w8-wwg9-q6pr/GHSA-h4w8-wwg9-q6pr.json b/advisories/unreviewed/2022/05/GHSA-h4w8-wwg9-q6pr/GHSA-h4w8-wwg9-q6pr.json index 4e18ae9d8e5..9d5fbbb63a8 100644 --- a/advisories/unreviewed/2022/05/GHSA-h4w8-wwg9-q6pr/GHSA-h4w8-wwg9-q6pr.json +++ b/advisories/unreviewed/2022/05/GHSA-h4w8-wwg9-q6pr/GHSA-h4w8-wwg9-q6pr.json @@ -1,19 +1,28 @@ { "schema_version": "1.4.0", "id": "GHSA-h4w8-wwg9-q6pr", - "modified": "2022-05-24T21:59:49Z", + "modified": "2025-05-30T18:30:35Z", "published": "2022-05-24T21:59:49Z", "aliases": [ "CVE-2019-6512" ], "details": "An issue was discovered in WSO2 API Manager 2.6.0. It is possible to force the application to perform requests to the internal workstation (SSRF port-scanning), other adjacent workstations (SSRF network scanning), or to enumerate files because of the existence of the file:// wrapper.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-6512" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2019-6512" + }, { "type": "WEB", "url": "https://wso2.com/security-patch-releases/api-manager" @@ -24,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-918" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hfx5-55x6-5xfr/GHSA-hfx5-55x6-5xfr.json b/advisories/unreviewed/2022/05/GHSA-hfx5-55x6-5xfr/GHSA-hfx5-55x6-5xfr.json index 49ff07a726b..f083a93d020 100644 --- a/advisories/unreviewed/2022/05/GHSA-hfx5-55x6-5xfr/GHSA-hfx5-55x6-5xfr.json +++ b/advisories/unreviewed/2022/05/GHSA-hfx5-55x6-5xfr/GHSA-hfx5-55x6-5xfr.json @@ -1,19 +1,28 @@ { "schema_version": "1.4.0", "id": "GHSA-hfx5-55x6-5xfr", - "modified": "2022-05-24T19:06:32Z", + "modified": "2025-05-30T18:30:39Z", "published": "2022-05-24T19:06:32Z", "aliases": [ "CVE-2021-31530" ], "details": "Zoho ManageEngine ServiceDesk Plus MSP before 10522 is vulnerable to Information Disclosure.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-31530" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2021-31530" + }, { "type": "WEB", "url": "https://excellium-services.com/cve-2021-31530" diff --git a/advisories/unreviewed/2022/05/GHSA-hgc9-x857-7qx4/GHSA-hgc9-x857-7qx4.json b/advisories/unreviewed/2022/05/GHSA-hgc9-x857-7qx4/GHSA-hgc9-x857-7qx4.json index 4375abce60d..4001a42f9dd 100644 --- a/advisories/unreviewed/2022/05/GHSA-hgc9-x857-7qx4/GHSA-hgc9-x857-7qx4.json +++ b/advisories/unreviewed/2022/05/GHSA-hgc9-x857-7qx4/GHSA-hgc9-x857-7qx4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hgc9-x857-7qx4", - "modified": "2022-07-13T00:01:35Z", + "modified": "2025-05-30T18:30:40Z", "published": "2022-05-24T19:13:14Z", "aliases": [ "CVE-2021-38617" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-38617" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2021-38617" + }, { "type": "WEB", "url": "https://eigentech.com" diff --git a/advisories/unreviewed/2022/05/GHSA-j99f-3mvg-4m4r/GHSA-j99f-3mvg-4m4r.json b/advisories/unreviewed/2022/05/GHSA-j99f-3mvg-4m4r/GHSA-j99f-3mvg-4m4r.json index 3dce7cc8243..789fd481524 100644 --- a/advisories/unreviewed/2022/05/GHSA-j99f-3mvg-4m4r/GHSA-j99f-3mvg-4m4r.json +++ b/advisories/unreviewed/2022/05/GHSA-j99f-3mvg-4m4r/GHSA-j99f-3mvg-4m4r.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-285" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jv95-xvv4-phc9/GHSA-jv95-xvv4-phc9.json b/advisories/unreviewed/2022/05/GHSA-jv95-xvv4-phc9/GHSA-jv95-xvv4-phc9.json index adb0909c72c..0e97b35dcc0 100644 --- a/advisories/unreviewed/2022/05/GHSA-jv95-xvv4-phc9/GHSA-jv95-xvv4-phc9.json +++ b/advisories/unreviewed/2022/05/GHSA-jv95-xvv4-phc9/GHSA-jv95-xvv4-phc9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jv95-xvv4-phc9", - "modified": "2022-05-14T03:21:14Z", + "modified": "2025-05-30T18:30:33Z", "published": "2022-05-14T03:21:14Z", "aliases": [ "CVE-2018-10209" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-10209" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2018-10209" + }, { "type": "WEB", "url": "https://www.excellium-services.com/cert-xlm-advisory/cve-2018-10209" diff --git a/advisories/unreviewed/2022/05/GHSA-mvm2-v629-ff77/GHSA-mvm2-v629-ff77.json b/advisories/unreviewed/2022/05/GHSA-mvm2-v629-ff77/GHSA-mvm2-v629-ff77.json index a52a0686730..24af1f877f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-mvm2-v629-ff77/GHSA-mvm2-v629-ff77.json +++ b/advisories/unreviewed/2022/05/GHSA-mvm2-v629-ff77/GHSA-mvm2-v629-ff77.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mvm2-v629-ff77", - "modified": "2024-03-21T03:33:56Z", + "modified": "2025-05-30T18:30:37Z", "published": "2022-05-24T17:30:28Z", "aliases": [ "CVE-2020-26546" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-26546" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2020-26546" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2020-26546" diff --git a/advisories/unreviewed/2022/05/GHSA-p23p-m9mc-pg6q/GHSA-p23p-m9mc-pg6q.json b/advisories/unreviewed/2022/05/GHSA-p23p-m9mc-pg6q/GHSA-p23p-m9mc-pg6q.json index f9e1943f3e8..31d568d79b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-p23p-m9mc-pg6q/GHSA-p23p-m9mc-pg6q.json +++ b/advisories/unreviewed/2022/05/GHSA-p23p-m9mc-pg6q/GHSA-p23p-m9mc-pg6q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p23p-m9mc-pg6q", - "modified": "2022-07-13T00:01:35Z", + "modified": "2025-05-30T18:30:40Z", "published": "2022-05-24T19:13:14Z", "aliases": [ "CVE-2021-38615" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-38615" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2021-38615" + }, { "type": "WEB", "url": "https://eigentech.com" diff --git a/advisories/unreviewed/2022/05/GHSA-p5f8-j7c4-pr59/GHSA-p5f8-j7c4-pr59.json b/advisories/unreviewed/2022/05/GHSA-p5f8-j7c4-pr59/GHSA-p5f8-j7c4-pr59.json index dccf16f983f..c8101e3be16 100644 --- a/advisories/unreviewed/2022/05/GHSA-p5f8-j7c4-pr59/GHSA-p5f8-j7c4-pr59.json +++ b/advisories/unreviewed/2022/05/GHSA-p5f8-j7c4-pr59/GHSA-p5f8-j7c4-pr59.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p5f8-j7c4-pr59", - "modified": "2022-05-14T03:21:14Z", + "modified": "2025-05-30T18:30:34Z", "published": "2022-05-14T03:21:14Z", "aliases": [ "CVE-2018-10213" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-10213" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2018-10213" + }, { "type": "WEB", "url": "https://www.excellium-services.com/cert-xlm-advisory/cve-2018-10213" diff --git a/advisories/unreviewed/2022/05/GHSA-p74w-76h9-xxqv/GHSA-p74w-76h9-xxqv.json b/advisories/unreviewed/2022/05/GHSA-p74w-76h9-xxqv/GHSA-p74w-76h9-xxqv.json index b428253834d..62c69b86a96 100644 --- a/advisories/unreviewed/2022/05/GHSA-p74w-76h9-xxqv/GHSA-p74w-76h9-xxqv.json +++ b/advisories/unreviewed/2022/05/GHSA-p74w-76h9-xxqv/GHSA-p74w-76h9-xxqv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p74w-76h9-xxqv", - "modified": "2024-04-04T00:44:06Z", + "modified": "2025-05-30T18:30:35Z", "published": "2022-05-24T16:46:17Z", "aliases": [ "CVE-2019-6513" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-6513" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2019-6513" + }, { "type": "WEB", "url": "https://www.excellium-services.com/cert-xlm-advisory" diff --git a/advisories/unreviewed/2022/05/GHSA-p78q-972x-mrg3/GHSA-p78q-972x-mrg3.json b/advisories/unreviewed/2022/05/GHSA-p78q-972x-mrg3/GHSA-p78q-972x-mrg3.json index 9a7092f3840..0f56616fcf2 100644 --- a/advisories/unreviewed/2022/05/GHSA-p78q-972x-mrg3/GHSA-p78q-972x-mrg3.json +++ b/advisories/unreviewed/2022/05/GHSA-p78q-972x-mrg3/GHSA-p78q-972x-mrg3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p78q-972x-mrg3", - "modified": "2022-05-14T03:21:14Z", + "modified": "2025-05-30T18:30:33Z", "published": "2022-05-14T03:21:14Z", "aliases": [ "CVE-2018-10208" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-10208" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2018-10208" + }, { "type": "WEB", "url": "https://www.excellium-services.com/cert-xlm-advisory/cve-2018-10208" diff --git a/advisories/unreviewed/2022/05/GHSA-phmh-5xpr-c83f/GHSA-phmh-5xpr-c83f.json b/advisories/unreviewed/2022/05/GHSA-phmh-5xpr-c83f/GHSA-phmh-5xpr-c83f.json index 2cc4a9d495f..25f7ef33d56 100644 --- a/advisories/unreviewed/2022/05/GHSA-phmh-5xpr-c83f/GHSA-phmh-5xpr-c83f.json +++ b/advisories/unreviewed/2022/05/GHSA-phmh-5xpr-c83f/GHSA-phmh-5xpr-c83f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-phmh-5xpr-c83f", - "modified": "2022-05-14T03:21:09Z", + "modified": "2025-05-30T18:30:33Z", "published": "2022-05-14T03:21:09Z", "aliases": [ "CVE-2018-10210" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-10210" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2018-10210" + }, { "type": "WEB", "url": "https://www.excellium-services.com/cert-xlm-advisory/cve-2018-10210" diff --git a/advisories/unreviewed/2022/05/GHSA-pr66-gfw7-8w5p/GHSA-pr66-gfw7-8w5p.json b/advisories/unreviewed/2022/05/GHSA-pr66-gfw7-8w5p/GHSA-pr66-gfw7-8w5p.json index 563a86649a4..3ee4b0b1dbb 100644 --- a/advisories/unreviewed/2022/05/GHSA-pr66-gfw7-8w5p/GHSA-pr66-gfw7-8w5p.json +++ b/advisories/unreviewed/2022/05/GHSA-pr66-gfw7-8w5p/GHSA-pr66-gfw7-8w5p.json @@ -1,19 +1,28 @@ { "schema_version": "1.4.0", "id": "GHSA-pr66-gfw7-8w5p", - "modified": "2022-05-24T16:45:36Z", + "modified": "2025-05-30T18:30:35Z", "published": "2022-05-24T16:45:36Z", "aliases": [ "CVE-2019-6516" ], "details": "An issue was discovered in WSO2 Dashboard Server 2.0.0. It is possible to force the application to perform requests to the internal workstation (port-scanning) and to perform requests to adjacent workstations (network-scanning), aka SSRF.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-6516" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2019-6516" + }, { "type": "WEB", "url": "https://wso2.com/security-patch-releases/dashboard-server" @@ -24,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-918" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q4rq-wjvw-rh5x/GHSA-q4rq-wjvw-rh5x.json b/advisories/unreviewed/2022/05/GHSA-q4rq-wjvw-rh5x/GHSA-q4rq-wjvw-rh5x.json index cb014ef73c5..63f6bad8dd7 100644 --- a/advisories/unreviewed/2022/05/GHSA-q4rq-wjvw-rh5x/GHSA-q4rq-wjvw-rh5x.json +++ b/advisories/unreviewed/2022/05/GHSA-q4rq-wjvw-rh5x/GHSA-q4rq-wjvw-rh5x.json @@ -1,19 +1,28 @@ { "schema_version": "1.4.0", "id": "GHSA-q4rq-wjvw-rh5x", - "modified": "2022-05-24T17:40:34Z", + "modified": "2025-05-30T18:30:39Z", "published": "2022-05-24T17:40:34Z", "aliases": [ "CVE-2020-28405" ], "details": "An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to change the privileges of any user of the application. This can be used to grant himself the administrative role or remove all administrative accounts of the application.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-28405" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2020-28405" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2020-28405" diff --git a/advisories/unreviewed/2022/05/GHSA-qc22-6662-58rj/GHSA-qc22-6662-58rj.json b/advisories/unreviewed/2022/05/GHSA-qc22-6662-58rj/GHSA-qc22-6662-58rj.json index fbb204e969c..d49650ec2c3 100644 --- a/advisories/unreviewed/2022/05/GHSA-qc22-6662-58rj/GHSA-qc22-6662-58rj.json +++ b/advisories/unreviewed/2022/05/GHSA-qc22-6662-58rj/GHSA-qc22-6662-58rj.json @@ -1,19 +1,32 @@ { "schema_version": "1.4.0", "id": "GHSA-qc22-6662-58rj", - "modified": "2024-06-03T18:53:41Z", + "modified": "2025-05-30T18:30:40Z", "published": "2022-05-24T19:17:39Z", "aliases": [ "CVE-2021-41320" ], "details": "A technical user has hardcoded credentials in Wallstreet Suite TRM 7.4.83 (64-bit edition) with higher privilege than the average authenticated user.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-41320" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2021-41320" + }, + { + "type": "WEB", + "url": "https://client-connect.iongroup.com/library/content/treasury-management/wallstreet-suite/security/suite-7-4-83/user-passwords" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2021-41320" diff --git a/advisories/unreviewed/2022/05/GHSA-rjw6-fhxf-vxvf/GHSA-rjw6-fhxf-vxvf.json b/advisories/unreviewed/2022/05/GHSA-rjw6-fhxf-vxvf/GHSA-rjw6-fhxf-vxvf.json index ec3df5ad5e2..2974c8e6651 100644 --- a/advisories/unreviewed/2022/05/GHSA-rjw6-fhxf-vxvf/GHSA-rjw6-fhxf-vxvf.json +++ b/advisories/unreviewed/2022/05/GHSA-rjw6-fhxf-vxvf/GHSA-rjw6-fhxf-vxvf.json @@ -1,19 +1,28 @@ { "schema_version": "1.4.0", "id": "GHSA-rjw6-fhxf-vxvf", - "modified": "2022-05-24T19:09:50Z", + "modified": "2025-05-30T18:30:40Z", "published": "2022-05-24T19:09:50Z", "aliases": [ "CVE-2021-32017" ], "details": "An issue was discovered in JUMP AMS 3.6.0.04.009-2487. A JUMP SOAP endpoint permitted the listing of the content of the remote file system. This can be used to identify the complete server filesystem structure, i.e., identifying all the directories and files.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-32017" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2021-32017" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/cve-2021-32017" diff --git a/advisories/unreviewed/2022/05/GHSA-v3x2-gf8f-p55r/GHSA-v3x2-gf8f-p55r.json b/advisories/unreviewed/2022/05/GHSA-v3x2-gf8f-p55r/GHSA-v3x2-gf8f-p55r.json index 3d452c2a7c2..cc2cdc88e6f 100644 --- a/advisories/unreviewed/2022/05/GHSA-v3x2-gf8f-p55r/GHSA-v3x2-gf8f-p55r.json +++ b/advisories/unreviewed/2022/05/GHSA-v3x2-gf8f-p55r/GHSA-v3x2-gf8f-p55r.json @@ -1,19 +1,28 @@ { "schema_version": "1.4.0", "id": "GHSA-v3x2-gf8f-p55r", - "modified": "2022-05-24T16:45:36Z", + "modified": "2025-05-30T18:30:35Z", "published": "2022-05-24T16:45:36Z", "aliases": [ "CVE-2019-6514" ], "details": "An issue was discovered in WSO2 Dashboard Server 2.0.0. It is possible to inject a JavaScript payload that will be stored in the database and then displayed and executed on the same page, aka XSS.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-6514" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2019-6514" + }, { "type": "WEB", "url": "https://wso2.com/security-patch-releases/dashboard-server" @@ -24,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vgc4-27p4-9gfq/GHSA-vgc4-27p4-9gfq.json b/advisories/unreviewed/2022/05/GHSA-vgc4-27p4-9gfq/GHSA-vgc4-27p4-9gfq.json index 5429a003314..d9ea1e5a1dd 100644 --- a/advisories/unreviewed/2022/05/GHSA-vgc4-27p4-9gfq/GHSA-vgc4-27p4-9gfq.json +++ b/advisories/unreviewed/2022/05/GHSA-vgc4-27p4-9gfq/GHSA-vgc4-27p4-9gfq.json @@ -1,19 +1,28 @@ { "schema_version": "1.4.0", "id": "GHSA-vgc4-27p4-9gfq", - "modified": "2022-05-24T19:09:48Z", + "modified": "2025-05-30T18:30:40Z", "published": "2022-05-24T19:09:48Z", "aliases": [ "CVE-2021-32016" ], "details": "An issue was discovered in JUMP AMS 3.6.0.04.009-2487. A JUMP SOAP endpoint permitted the writing of arbitrary files to a user-controlled location on the remote filesystem (with user-controlled content) via directory traversal, potentially leading to remote code and command execution.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-32016" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2021-32016" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/cve-2021-32016" diff --git a/advisories/unreviewed/2022/05/GHSA-vw8v-x3mw-g32q/GHSA-vw8v-x3mw-g32q.json b/advisories/unreviewed/2022/05/GHSA-vw8v-x3mw-g32q/GHSA-vw8v-x3mw-g32q.json index 548cb169c0c..d2f8dfec835 100644 --- a/advisories/unreviewed/2022/05/GHSA-vw8v-x3mw-g32q/GHSA-vw8v-x3mw-g32q.json +++ b/advisories/unreviewed/2022/05/GHSA-vw8v-x3mw-g32q/GHSA-vw8v-x3mw-g32q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vw8v-x3mw-g32q", - "modified": "2022-05-17T02:39:38Z", + "modified": "2025-05-30T18:30:33Z", "published": "2022-05-17T02:39:38Z", "aliases": [ "CVE-2015-4596" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2015-4596" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2015-4596" + }, { "type": "WEB", "url": "https://support.lenovo.com/us/en/product_security/len_2015_066" diff --git a/advisories/unreviewed/2022/05/GHSA-wh2f-7mq6-xvc5/GHSA-wh2f-7mq6-xvc5.json b/advisories/unreviewed/2022/05/GHSA-wh2f-7mq6-xvc5/GHSA-wh2f-7mq6-xvc5.json index 4b05dc523ce..bad0cf45ecd 100644 --- a/advisories/unreviewed/2022/05/GHSA-wh2f-7mq6-xvc5/GHSA-wh2f-7mq6-xvc5.json +++ b/advisories/unreviewed/2022/05/GHSA-wh2f-7mq6-xvc5/GHSA-wh2f-7mq6-xvc5.json @@ -1,19 +1,28 @@ { "schema_version": "1.4.0", "id": "GHSA-wh2f-7mq6-xvc5", - "modified": "2022-05-24T21:59:49Z", + "modified": "2025-05-30T18:30:35Z", "published": "2022-05-24T21:59:49Z", "aliases": [ "CVE-2019-6515" ], "details": "An issue was discovered in WSO2 API Manager 2.6.0. Uploaded documents for API documentation are available to an unauthenticated user.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-6515" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2019-6515" + }, { "type": "WEB", "url": "https://wso2.com/security-patch-releases/api-manager" diff --git a/advisories/unreviewed/2022/05/GHSA-wrf8-p6r2-xw72/GHSA-wrf8-p6r2-xw72.json b/advisories/unreviewed/2022/05/GHSA-wrf8-p6r2-xw72/GHSA-wrf8-p6r2-xw72.json index 32fa3da0296..ed0086cda78 100644 --- a/advisories/unreviewed/2022/05/GHSA-wrf8-p6r2-xw72/GHSA-wrf8-p6r2-xw72.json +++ b/advisories/unreviewed/2022/05/GHSA-wrf8-p6r2-xw72/GHSA-wrf8-p6r2-xw72.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wrf8-p6r2-xw72", - "modified": "2024-12-18T15:32:56Z", + "modified": "2025-05-30T18:30:36Z", "published": "2022-05-24T17:29:48Z", "aliases": [ "CVE-2020-15594" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-15594" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2020-15594" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/cve-2020-15594" diff --git a/advisories/unreviewed/2022/05/GHSA-xjh5-4qmv-vw5r/GHSA-xjh5-4qmv-vw5r.json b/advisories/unreviewed/2022/05/GHSA-xjh5-4qmv-vw5r/GHSA-xjh5-4qmv-vw5r.json index 102677eb581..f9296a878d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-xjh5-4qmv-vw5r/GHSA-xjh5-4qmv-vw5r.json +++ b/advisories/unreviewed/2022/05/GHSA-xjh5-4qmv-vw5r/GHSA-xjh5-4qmv-vw5r.json @@ -1,19 +1,32 @@ { "schema_version": "1.4.0", "id": "GHSA-xjh5-4qmv-vw5r", - "modified": "2022-05-24T17:05:27Z", + "modified": "2025-05-30T18:30:35Z", "published": "2022-05-24T17:05:27Z", "aliases": [ "CVE-2019-7162" ], "details": "An issue was discovered in Zoho ManageEngine ADSelfService Plus 5.6 Build 5607. An exposed service allows an unauthenticated person to retrieve internal information from the system and modify the product installation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-7162" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2019-7162" + }, + { + "type": "WEB", + "url": "https://www.excellium-services.com/cert-xlm-advisory" + }, { "type": "WEB", "url": "https://www.excellium-services.com/cert-xlm-advisory/cve-2019-7162" diff --git a/advisories/unreviewed/2022/05/GHSA-xjrh-8gjh-h7rm/GHSA-xjrh-8gjh-h7rm.json b/advisories/unreviewed/2022/05/GHSA-xjrh-8gjh-h7rm/GHSA-xjrh-8gjh-h7rm.json index 91232051a07..0c5ca701dca 100644 --- a/advisories/unreviewed/2022/05/GHSA-xjrh-8gjh-h7rm/GHSA-xjrh-8gjh-h7rm.json +++ b/advisories/unreviewed/2022/05/GHSA-xjrh-8gjh-h7rm/GHSA-xjrh-8gjh-h7rm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xjrh-8gjh-h7rm", - "modified": "2024-12-18T15:32:58Z", + "modified": "2025-05-30T18:30:36Z", "published": "2022-05-24T17:29:48Z", "aliases": [ "CVE-2020-15595" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-15595" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2020-15595" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2020-15595" diff --git a/advisories/unreviewed/2022/05/GHSA-xqh9-89v8-g968/GHSA-xqh9-89v8-g968.json b/advisories/unreviewed/2022/05/GHSA-xqh9-89v8-g968/GHSA-xqh9-89v8-g968.json index da3898acb09..b8080a21fe2 100644 --- a/advisories/unreviewed/2022/05/GHSA-xqh9-89v8-g968/GHSA-xqh9-89v8-g968.json +++ b/advisories/unreviewed/2022/05/GHSA-xqh9-89v8-g968/GHSA-xqh9-89v8-g968.json @@ -1,19 +1,28 @@ { "schema_version": "1.4.0", "id": "GHSA-xqh9-89v8-g968", - "modified": "2022-05-24T17:33:09Z", + "modified": "2025-05-30T18:30:38Z", "published": "2022-05-24T17:33:09Z", "aliases": [ "CVE-2020-26167" ], "details": "In FUEL CMS 11.4.12 and before, the page preview feature allows an anonymous user to take complete ownership of any account including an administrator one.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-26167" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2020-26167" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/cve-2020-26167" diff --git a/advisories/unreviewed/2022/06/GHSA-58c3-q676-fmqx/GHSA-58c3-q676-fmqx.json b/advisories/unreviewed/2022/06/GHSA-58c3-q676-fmqx/GHSA-58c3-q676-fmqx.json index 399e30a2eb9..56d812294f3 100644 --- a/advisories/unreviewed/2022/06/GHSA-58c3-q676-fmqx/GHSA-58c3-q676-fmqx.json +++ b/advisories/unreviewed/2022/06/GHSA-58c3-q676-fmqx/GHSA-58c3-q676-fmqx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-58c3-q676-fmqx", - "modified": "2022-06-10T00:00:53Z", + "modified": "2025-05-30T18:30:43Z", "published": "2022-06-03T00:01:02Z", "aliases": [ "CVE-2022-24967" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://blackrainbow.com/corporate" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2022-24967" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2022-24967" diff --git a/advisories/unreviewed/2022/06/GHSA-v68v-g8q2-4vqq/GHSA-v68v-g8q2-4vqq.json b/advisories/unreviewed/2022/06/GHSA-v68v-g8q2-4vqq/GHSA-v68v-g8q2-4vqq.json index f99a3360b0d..40961731465 100644 --- a/advisories/unreviewed/2022/06/GHSA-v68v-g8q2-4vqq/GHSA-v68v-g8q2-4vqq.json +++ b/advisories/unreviewed/2022/06/GHSA-v68v-g8q2-4vqq/GHSA-v68v-g8q2-4vqq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v68v-g8q2-4vqq", - "modified": "2022-07-07T00:00:23Z", + "modified": "2025-05-30T18:30:43Z", "published": "2022-06-26T00:00:19Z", "aliases": [ "CVE-2022-29931" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-29931" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2022-29931" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2022-29931" diff --git a/advisories/unreviewed/2022/08/GHSA-8g9x-2rqx-hwvf/GHSA-8g9x-2rqx-hwvf.json b/advisories/unreviewed/2022/08/GHSA-8g9x-2rqx-hwvf/GHSA-8g9x-2rqx-hwvf.json index 2fb792bf897..97040a27fd5 100644 --- a/advisories/unreviewed/2022/08/GHSA-8g9x-2rqx-hwvf/GHSA-8g9x-2rqx-hwvf.json +++ b/advisories/unreviewed/2022/08/GHSA-8g9x-2rqx-hwvf/GHSA-8g9x-2rqx-hwvf.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/08/GHSA-vh37-fmrj-jmpx/GHSA-vh37-fmrj-jmpx.json b/advisories/unreviewed/2022/08/GHSA-vh37-fmrj-jmpx/GHSA-vh37-fmrj-jmpx.json index 11d1cb9d10f..1282c4ae970 100644 --- a/advisories/unreviewed/2022/08/GHSA-vh37-fmrj-jmpx/GHSA-vh37-fmrj-jmpx.json +++ b/advisories/unreviewed/2022/08/GHSA-vh37-fmrj-jmpx/GHSA-vh37-fmrj-jmpx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vh37-fmrj-jmpx", - "modified": "2022-08-29T20:06:55Z", + "modified": "2025-05-30T18:30:44Z", "published": "2022-08-25T00:00:25Z", "aliases": [ "CVE-2022-32793" @@ -19,6 +19,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-32793" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7SETAAXEPGNBMYKTUDFEZHS5LGSQ64QL" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YKJGV2EXVMYQW3OAJNI4WUTKKVMD2YYK" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7SETAAXEPGNBMYKTUDFEZHS5LGSQ64QL" diff --git a/advisories/unreviewed/2022/09/GHSA-67q7-2m82-v47j/GHSA-67q7-2m82-v47j.json b/advisories/unreviewed/2022/09/GHSA-67q7-2m82-v47j/GHSA-67q7-2m82-v47j.json index d2996a3e027..475ae2d37bb 100644 --- a/advisories/unreviewed/2022/09/GHSA-67q7-2m82-v47j/GHSA-67q7-2m82-v47j.json +++ b/advisories/unreviewed/2022/09/GHSA-67q7-2m82-v47j/GHSA-67q7-2m82-v47j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-67q7-2m82-v47j", - "modified": "2025-05-21T15:30:25Z", + "modified": "2025-05-30T18:30:44Z", "published": "2022-09-28T00:00:17Z", "aliases": [ "CVE-2022-37028" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37028" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2022-37028" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2022-37028" diff --git a/advisories/unreviewed/2023/01/GHSA-47xh-88vf-mqw7/GHSA-47xh-88vf-mqw7.json b/advisories/unreviewed/2023/01/GHSA-47xh-88vf-mqw7/GHSA-47xh-88vf-mqw7.json index cacfaee8686..be71c82d12f 100644 --- a/advisories/unreviewed/2023/01/GHSA-47xh-88vf-mqw7/GHSA-47xh-88vf-mqw7.json +++ b/advisories/unreviewed/2023/01/GHSA-47xh-88vf-mqw7/GHSA-47xh-88vf-mqw7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-47xh-88vf-mqw7", - "modified": "2025-04-09T18:30:38Z", + "modified": "2025-05-30T18:30:45Z", "published": "2023-01-10T21:30:26Z", "aliases": [ "CVE-2022-45165" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45165" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2022-45165" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2022-45165" diff --git a/advisories/unreviewed/2023/01/GHSA-489f-78mr-mq29/GHSA-489f-78mr-mq29.json b/advisories/unreviewed/2023/01/GHSA-489f-78mr-mq29/GHSA-489f-78mr-mq29.json index c0d80b54dbd..9efe42d7ea0 100644 --- a/advisories/unreviewed/2023/01/GHSA-489f-78mr-mq29/GHSA-489f-78mr-mq29.json +++ b/advisories/unreviewed/2023/01/GHSA-489f-78mr-mq29/GHSA-489f-78mr-mq29.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-489f-78mr-mq29", - "modified": "2023-01-14T06:30:29Z", + "modified": "2025-05-30T18:30:45Z", "published": "2023-01-10T21:30:26Z", "aliases": [ "CVE-2022-38481" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-38481" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2022-38481" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2022-38481" diff --git a/advisories/unreviewed/2023/01/GHSA-5c9w-vq5m-266h/GHSA-5c9w-vq5m-266h.json b/advisories/unreviewed/2023/01/GHSA-5c9w-vq5m-266h/GHSA-5c9w-vq5m-266h.json index 33c029f55d9..194c1ea0ccc 100644 --- a/advisories/unreviewed/2023/01/GHSA-5c9w-vq5m-266h/GHSA-5c9w-vq5m-266h.json +++ b/advisories/unreviewed/2023/01/GHSA-5c9w-vq5m-266h/GHSA-5c9w-vq5m-266h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5c9w-vq5m-266h", - "modified": "2023-01-13T15:30:26Z", + "modified": "2025-05-30T18:30:45Z", "published": "2023-01-10T21:30:27Z", "aliases": [ "CVE-2022-36443" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36443" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2022-36443" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2022-36443" diff --git a/advisories/unreviewed/2023/01/GHSA-cm4x-r333-vvv9/GHSA-cm4x-r333-vvv9.json b/advisories/unreviewed/2023/01/GHSA-cm4x-r333-vvv9/GHSA-cm4x-r333-vvv9.json index bbfa6b2d09e..f66341f0496 100644 --- a/advisories/unreviewed/2023/01/GHSA-cm4x-r333-vvv9/GHSA-cm4x-r333-vvv9.json +++ b/advisories/unreviewed/2023/01/GHSA-cm4x-r333-vvv9/GHSA-cm4x-r333-vvv9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cm4x-r333-vvv9", - "modified": "2023-01-14T06:30:29Z", + "modified": "2025-05-30T18:30:45Z", "published": "2023-01-10T21:30:26Z", "aliases": [ "CVE-2022-38482" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-38482" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2022-38482" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2022-38482" diff --git a/advisories/unreviewed/2023/01/GHSA-fwgh-82pj-8vp9/GHSA-fwgh-82pj-8vp9.json b/advisories/unreviewed/2023/01/GHSA-fwgh-82pj-8vp9/GHSA-fwgh-82pj-8vp9.json index 174455cc3eb..3f4190c58a9 100644 --- a/advisories/unreviewed/2023/01/GHSA-fwgh-82pj-8vp9/GHSA-fwgh-82pj-8vp9.json +++ b/advisories/unreviewed/2023/01/GHSA-fwgh-82pj-8vp9/GHSA-fwgh-82pj-8vp9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fwgh-82pj-8vp9", - "modified": "2024-06-05T06:30:39Z", + "modified": "2025-05-30T18:30:44Z", "published": "2023-01-10T21:30:27Z", "aliases": [ "CVE-2022-30332" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-30332" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2022-30332" + }, { "type": "WEB", "url": "https://cwe.mitre.org/data/definitions/204.html" diff --git a/advisories/unreviewed/2023/01/GHSA-g5qg-593p-j5gq/GHSA-g5qg-593p-j5gq.json b/advisories/unreviewed/2023/01/GHSA-g5qg-593p-j5gq/GHSA-g5qg-593p-j5gq.json index d2aeef22d0a..d62cbeb4e08 100644 --- a/advisories/unreviewed/2023/01/GHSA-g5qg-593p-j5gq/GHSA-g5qg-593p-j5gq.json +++ b/advisories/unreviewed/2023/01/GHSA-g5qg-593p-j5gq/GHSA-g5qg-593p-j5gq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g5qg-593p-j5gq", - "modified": "2025-04-09T18:30:38Z", + "modified": "2025-05-30T18:30:45Z", "published": "2023-01-10T21:30:26Z", "aliases": [ "CVE-2022-45167" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45167" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2022-45167" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2022-45167" diff --git a/advisories/unreviewed/2023/01/GHSA-gg38-fph6-54g7/GHSA-gg38-fph6-54g7.json b/advisories/unreviewed/2023/01/GHSA-gg38-fph6-54g7/GHSA-gg38-fph6-54g7.json index 7dda4840b8b..2f25e3e1051 100644 --- a/advisories/unreviewed/2023/01/GHSA-gg38-fph6-54g7/GHSA-gg38-fph6-54g7.json +++ b/advisories/unreviewed/2023/01/GHSA-gg38-fph6-54g7/GHSA-gg38-fph6-54g7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gg38-fph6-54g7", - "modified": "2023-01-13T15:30:26Z", + "modified": "2025-05-30T18:30:45Z", "published": "2023-01-10T21:30:27Z", "aliases": [ "CVE-2022-36442" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36442" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2022-36442" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2022-36442" diff --git a/advisories/unreviewed/2023/01/GHSA-jc4j-5j4g-r9cv/GHSA-jc4j-5j4g-r9cv.json b/advisories/unreviewed/2023/01/GHSA-jc4j-5j4g-r9cv/GHSA-jc4j-5j4g-r9cv.json index f742fcf0c88..a63ba5ff43a 100644 --- a/advisories/unreviewed/2023/01/GHSA-jc4j-5j4g-r9cv/GHSA-jc4j-5j4g-r9cv.json +++ b/advisories/unreviewed/2023/01/GHSA-jc4j-5j4g-r9cv/GHSA-jc4j-5j4g-r9cv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jc4j-5j4g-r9cv", - "modified": "2025-04-09T18:30:38Z", + "modified": "2025-05-30T18:30:45Z", "published": "2023-01-10T21:30:26Z", "aliases": [ "CVE-2022-45164" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45164" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2022-45164" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2022-45164" diff --git a/advisories/unreviewed/2023/01/GHSA-m5jj-959w-4x33/GHSA-m5jj-959w-4x33.json b/advisories/unreviewed/2023/01/GHSA-m5jj-959w-4x33/GHSA-m5jj-959w-4x33.json index aabc3e8f578..3713b770e63 100644 --- a/advisories/unreviewed/2023/01/GHSA-m5jj-959w-4x33/GHSA-m5jj-959w-4x33.json +++ b/advisories/unreviewed/2023/01/GHSA-m5jj-959w-4x33/GHSA-m5jj-959w-4x33.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m5jj-959w-4x33", - "modified": "2023-01-13T18:30:20Z", + "modified": "2025-05-30T18:30:45Z", "published": "2023-01-10T21:30:27Z", "aliases": [ "CVE-2022-36441" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36441" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2022-36441" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2022-36441" diff --git a/advisories/unreviewed/2023/01/GHSA-vfm9-f37f-c9j3/GHSA-vfm9-f37f-c9j3.json b/advisories/unreviewed/2023/01/GHSA-vfm9-f37f-c9j3/GHSA-vfm9-f37f-c9j3.json index 7b4225bba68..8e3c914f609 100644 --- a/advisories/unreviewed/2023/01/GHSA-vfm9-f37f-c9j3/GHSA-vfm9-f37f-c9j3.json +++ b/advisories/unreviewed/2023/01/GHSA-vfm9-f37f-c9j3/GHSA-vfm9-f37f-c9j3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vfm9-f37f-c9j3", - "modified": "2025-04-09T18:30:38Z", + "modified": "2025-05-30T18:30:45Z", "published": "2023-01-10T21:30:26Z", "aliases": [ "CVE-2022-45166" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45166" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2022-45166" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2022-45166" diff --git a/advisories/unreviewed/2023/02/GHSA-34vj-fgrq-mq4v/GHSA-34vj-fgrq-mq4v.json b/advisories/unreviewed/2023/02/GHSA-34vj-fgrq-mq4v/GHSA-34vj-fgrq-mq4v.json index e353273146c..727d72c2a2b 100644 --- a/advisories/unreviewed/2023/02/GHSA-34vj-fgrq-mq4v/GHSA-34vj-fgrq-mq4v.json +++ b/advisories/unreviewed/2023/02/GHSA-34vj-fgrq-mq4v/GHSA-34vj-fgrq-mq4v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-34vj-fgrq-mq4v", - "modified": "2023-03-07T18:30:39Z", + "modified": "2025-05-30T18:30:46Z", "published": "2023-02-27T15:30:20Z", "aliases": [ "CVE-2022-34908" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-34908" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2022-34908" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2022-34908" diff --git a/advisories/unreviewed/2023/02/GHSA-3f3j-x9h2-qcf8/GHSA-3f3j-x9h2-qcf8.json b/advisories/unreviewed/2023/02/GHSA-3f3j-x9h2-qcf8/GHSA-3f3j-x9h2-qcf8.json index 6dda63226e3..a79188d5192 100644 --- a/advisories/unreviewed/2023/02/GHSA-3f3j-x9h2-qcf8/GHSA-3f3j-x9h2-qcf8.json +++ b/advisories/unreviewed/2023/02/GHSA-3f3j-x9h2-qcf8/GHSA-3f3j-x9h2-qcf8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3f3j-x9h2-qcf8", - "modified": "2023-03-07T18:30:39Z", + "modified": "2025-05-30T18:30:46Z", "published": "2023-02-27T15:30:20Z", "aliases": [ "CVE-2022-34909" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-34909" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2022-34909" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2022-34909" diff --git a/advisories/unreviewed/2023/02/GHSA-92r6-gw4h-q44j/GHSA-92r6-gw4h-q44j.json b/advisories/unreviewed/2023/02/GHSA-92r6-gw4h-q44j/GHSA-92r6-gw4h-q44j.json index bb8c7eec711..6868c00b92e 100644 --- a/advisories/unreviewed/2023/02/GHSA-92r6-gw4h-q44j/GHSA-92r6-gw4h-q44j.json +++ b/advisories/unreviewed/2023/02/GHSA-92r6-gw4h-q44j/GHSA-92r6-gw4h-q44j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-92r6-gw4h-q44j", - "modified": "2023-03-07T18:30:39Z", + "modified": "2025-05-30T18:30:46Z", "published": "2023-02-27T15:30:20Z", "aliases": [ "CVE-2022-34910" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-34910" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2022-34910" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2022-34910" diff --git a/advisories/unreviewed/2023/03/GHSA-4vgw-728w-p4h7/GHSA-4vgw-728w-p4h7.json b/advisories/unreviewed/2023/03/GHSA-4vgw-728w-p4h7/GHSA-4vgw-728w-p4h7.json index d598edf0c58..87138fb31d2 100644 --- a/advisories/unreviewed/2023/03/GHSA-4vgw-728w-p4h7/GHSA-4vgw-728w-p4h7.json +++ b/advisories/unreviewed/2023/03/GHSA-4vgw-728w-p4h7/GHSA-4vgw-728w-p4h7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4vgw-728w-p4h7", - "modified": "2023-03-30T18:30:33Z", + "modified": "2025-05-30T18:30:47Z", "published": "2023-03-25T00:30:27Z", "aliases": [ "CVE-2023-28150" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28150" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2023-28150" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2023-28150" diff --git a/advisories/unreviewed/2023/03/GHSA-4x6f-629h-vv8j/GHSA-4x6f-629h-vv8j.json b/advisories/unreviewed/2023/03/GHSA-4x6f-629h-vv8j/GHSA-4x6f-629h-vv8j.json index bfbb8d9fa31..f1f25b3ae51 100644 --- a/advisories/unreviewed/2023/03/GHSA-4x6f-629h-vv8j/GHSA-4x6f-629h-vv8j.json +++ b/advisories/unreviewed/2023/03/GHSA-4x6f-629h-vv8j/GHSA-4x6f-629h-vv8j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4x6f-629h-vv8j", - "modified": "2023-03-30T18:30:30Z", + "modified": "2025-05-30T18:30:46Z", "published": "2023-03-24T21:30:53Z", "aliases": [ "CVE-2023-28151" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28151" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2023-28151" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2023-28151" diff --git a/advisories/unreviewed/2023/03/GHSA-5c5q-xj8p-hrg3/GHSA-5c5q-xj8p-hrg3.json b/advisories/unreviewed/2023/03/GHSA-5c5q-xj8p-hrg3/GHSA-5c5q-xj8p-hrg3.json index ea3322b119e..5116adeffeb 100644 --- a/advisories/unreviewed/2023/03/GHSA-5c5q-xj8p-hrg3/GHSA-5c5q-xj8p-hrg3.json +++ b/advisories/unreviewed/2023/03/GHSA-5c5q-xj8p-hrg3/GHSA-5c5q-xj8p-hrg3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5c5q-xj8p-hrg3", - "modified": "2023-03-29T15:30:18Z", + "modified": "2025-05-30T18:30:46Z", "published": "2023-03-24T18:30:21Z", "aliases": [ "CVE-2023-28152" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28152" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2023-28152" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2023-28152" diff --git a/advisories/unreviewed/2023/04/GHSA-22wj-5rv2-cqf6/GHSA-22wj-5rv2-cqf6.json b/advisories/unreviewed/2023/04/GHSA-22wj-5rv2-cqf6/GHSA-22wj-5rv2-cqf6.json index 93859297714..77afc2c7543 100644 --- a/advisories/unreviewed/2023/04/GHSA-22wj-5rv2-cqf6/GHSA-22wj-5rv2-cqf6.json +++ b/advisories/unreviewed/2023/04/GHSA-22wj-5rv2-cqf6/GHSA-22wj-5rv2-cqf6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-22wj-5rv2-cqf6", - "modified": "2024-04-04T03:39:41Z", + "modified": "2025-05-30T18:30:47Z", "published": "2023-04-24T18:30:31Z", "aliases": [ "CVE-2023-26097" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26097" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2023-26097" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2023-26097" diff --git a/advisories/unreviewed/2023/04/GHSA-9f3h-5jcm-xmgf/GHSA-9f3h-5jcm-xmgf.json b/advisories/unreviewed/2023/04/GHSA-9f3h-5jcm-xmgf/GHSA-9f3h-5jcm-xmgf.json index f1171669db9..ce4f4a19da7 100644 --- a/advisories/unreviewed/2023/04/GHSA-9f3h-5jcm-xmgf/GHSA-9f3h-5jcm-xmgf.json +++ b/advisories/unreviewed/2023/04/GHSA-9f3h-5jcm-xmgf/GHSA-9f3h-5jcm-xmgf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9f3h-5jcm-xmgf", - "modified": "2024-04-04T03:41:19Z", + "modified": "2025-05-30T18:30:48Z", "published": "2023-04-26T00:30:21Z", "aliases": [ "CVE-2023-31223" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31223" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2023-31223" + }, { "type": "WEB", "url": "https://dradisframework.com/ce/security_reports.html#fixed-4.8.0" diff --git a/advisories/unreviewed/2023/04/GHSA-g5g4-5h6q-mrwm/GHSA-g5g4-5h6q-mrwm.json b/advisories/unreviewed/2023/04/GHSA-g5g4-5h6q-mrwm/GHSA-g5g4-5h6q-mrwm.json index 67f9af08411..03aebc981e8 100644 --- a/advisories/unreviewed/2023/04/GHSA-g5g4-5h6q-mrwm/GHSA-g5g4-5h6q-mrwm.json +++ b/advisories/unreviewed/2023/04/GHSA-g5g4-5h6q-mrwm/GHSA-g5g4-5h6q-mrwm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g5g4-5h6q-mrwm", - "modified": "2024-04-04T03:40:24Z", + "modified": "2025-05-30T18:30:47Z", "published": "2023-04-25T12:30:21Z", "aliases": [ "CVE-2023-26098" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26098" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2023-26098" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2023-26098" diff --git a/advisories/unreviewed/2023/04/GHSA-r976-44r3-hm6v/GHSA-r976-44r3-hm6v.json b/advisories/unreviewed/2023/04/GHSA-r976-44r3-hm6v/GHSA-r976-44r3-hm6v.json index 594cee8d141..1f5a2b77b06 100644 --- a/advisories/unreviewed/2023/04/GHSA-r976-44r3-hm6v/GHSA-r976-44r3-hm6v.json +++ b/advisories/unreviewed/2023/04/GHSA-r976-44r3-hm6v/GHSA-r976-44r3-hm6v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r976-44r3-hm6v", - "modified": "2024-04-04T03:39:46Z", + "modified": "2025-05-30T18:30:47Z", "published": "2023-04-24T18:30:31Z", "aliases": [ "CVE-2023-26099" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26099" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2023-26099" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2023-26099" diff --git a/advisories/unreviewed/2023/07/GHSA-4hhm-hpr8-q62r/GHSA-4hhm-hpr8-q62r.json b/advisories/unreviewed/2023/07/GHSA-4hhm-hpr8-q62r/GHSA-4hhm-hpr8-q62r.json index 9b083eb30c5..72f48b4b635 100644 --- a/advisories/unreviewed/2023/07/GHSA-4hhm-hpr8-q62r/GHSA-4hhm-hpr8-q62r.json +++ b/advisories/unreviewed/2023/07/GHSA-4hhm-hpr8-q62r/GHSA-4hhm-hpr8-q62r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4hhm-hpr8-q62r", - "modified": "2024-04-04T06:26:52Z", + "modified": "2025-05-30T18:30:48Z", "published": "2023-07-31T15:30:25Z", "aliases": [ "CVE-2023-35792" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35792" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2023-35792" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2023-35792" diff --git a/advisories/unreviewed/2023/07/GHSA-q9fm-wwch-86pf/GHSA-q9fm-wwch-86pf.json b/advisories/unreviewed/2023/07/GHSA-q9fm-wwch-86pf/GHSA-q9fm-wwch-86pf.json index 2e351b214c9..71d563952ea 100644 --- a/advisories/unreviewed/2023/07/GHSA-q9fm-wwch-86pf/GHSA-q9fm-wwch-86pf.json +++ b/advisories/unreviewed/2023/07/GHSA-q9fm-wwch-86pf/GHSA-q9fm-wwch-86pf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q9fm-wwch-86pf", - "modified": "2024-04-04T06:26:48Z", + "modified": "2025-05-30T18:30:48Z", "published": "2023-07-31T15:30:25Z", "aliases": [ "CVE-2023-35791" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35791" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2023-35791" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2023-35791" diff --git a/advisories/unreviewed/2023/08/GHSA-f49c-c736-9g2j/GHSA-f49c-c736-9g2j.json b/advisories/unreviewed/2023/08/GHSA-f49c-c736-9g2j/GHSA-f49c-c736-9g2j.json index fdf50cd8017..499f57d20f8 100644 --- a/advisories/unreviewed/2023/08/GHSA-f49c-c736-9g2j/GHSA-f49c-c736-9g2j.json +++ b/advisories/unreviewed/2023/08/GHSA-f49c-c736-9g2j/GHSA-f49c-c736-9g2j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f49c-c736-9g2j", - "modified": "2024-04-04T06:33:48Z", + "modified": "2025-05-30T18:30:49Z", "published": "2023-08-04T15:30:15Z", "aliases": [ "CVE-2023-29505" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29505" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2023-29505" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2023-29505" diff --git a/advisories/unreviewed/2023/09/GHSA-vr69-cpcv-wf75/GHSA-vr69-cpcv-wf75.json b/advisories/unreviewed/2023/09/GHSA-vr69-cpcv-wf75/GHSA-vr69-cpcv-wf75.json index f086bbf23b7..357c1ad7674 100644 --- a/advisories/unreviewed/2023/09/GHSA-vr69-cpcv-wf75/GHSA-vr69-cpcv-wf75.json +++ b/advisories/unreviewed/2023/09/GHSA-vr69-cpcv-wf75/GHSA-vr69-cpcv-wf75.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vr69-cpcv-wf75", - "modified": "2024-04-04T07:35:56Z", + "modified": "2025-05-30T18:30:49Z", "published": "2023-09-11T21:30:16Z", "aliases": [ "CVE-2023-41103" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41103" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2023-41103" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2023-41103" diff --git a/advisories/unreviewed/2024/01/GHSA-8r5c-mgwc-qg49/GHSA-8r5c-mgwc-qg49.json b/advisories/unreviewed/2024/01/GHSA-8r5c-mgwc-qg49/GHSA-8r5c-mgwc-qg49.json index ec91dc223c1..3807195bb3d 100644 --- a/advisories/unreviewed/2024/01/GHSA-8r5c-mgwc-qg49/GHSA-8r5c-mgwc-qg49.json +++ b/advisories/unreviewed/2024/01/GHSA-8r5c-mgwc-qg49/GHSA-8r5c-mgwc-qg49.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8r5c-mgwc-qg49", - "modified": "2025-05-30T15:30:26Z", + "modified": "2025-05-30T18:30:49Z", "published": "2024-01-24T09:30:25Z", "aliases": [ "CVE-2023-51711" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51711" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2023-51711" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/cve-2023-51711" diff --git a/advisories/unreviewed/2024/02/GHSA-5j36-2f99-3384/GHSA-5j36-2f99-3384.json b/advisories/unreviewed/2024/02/GHSA-5j36-2f99-3384/GHSA-5j36-2f99-3384.json index 81a2bc1d2fa..84a398d6947 100644 --- a/advisories/unreviewed/2024/02/GHSA-5j36-2f99-3384/GHSA-5j36-2f99-3384.json +++ b/advisories/unreviewed/2024/02/GHSA-5j36-2f99-3384/GHSA-5j36-2f99-3384.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5j36-2f99-3384", - "modified": "2024-02-13T21:30:28Z", + "modified": "2025-05-30T18:30:50Z", "published": "2024-02-02T09:30:22Z", "aliases": [ "CVE-2023-48645" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48645" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2023-48645" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2023-48645" diff --git a/advisories/unreviewed/2024/02/GHSA-8cpv-pp42-ppmr/GHSA-8cpv-pp42-ppmr.json b/advisories/unreviewed/2024/02/GHSA-8cpv-pp42-ppmr/GHSA-8cpv-pp42-ppmr.json index c262b05da61..39014f4c8f4 100644 --- a/advisories/unreviewed/2024/02/GHSA-8cpv-pp42-ppmr/GHSA-8cpv-pp42-ppmr.json +++ b/advisories/unreviewed/2024/02/GHSA-8cpv-pp42-ppmr/GHSA-8cpv-pp42-ppmr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8cpv-pp42-ppmr", - "modified": "2024-08-14T18:32:36Z", + "modified": "2025-05-30T18:30:51Z", "published": "2024-02-27T03:31:02Z", "aliases": [ "CVE-2024-24720" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24720" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2024-24720" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2024-24720" diff --git a/advisories/unreviewed/2024/02/GHSA-f78h-hr6r-68jw/GHSA-f78h-hr6r-68jw.json b/advisories/unreviewed/2024/02/GHSA-f78h-hr6r-68jw/GHSA-f78h-hr6r-68jw.json index c04cf3afe40..3f7501c3031 100644 --- a/advisories/unreviewed/2024/02/GHSA-f78h-hr6r-68jw/GHSA-f78h-hr6r-68jw.json +++ b/advisories/unreviewed/2024/02/GHSA-f78h-hr6r-68jw/GHSA-f78h-hr6r-68jw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f78h-hr6r-68jw", - "modified": "2024-08-12T21:31:31Z", + "modified": "2025-05-30T18:30:50Z", "published": "2024-02-27T00:32:04Z", "aliases": [ "CVE-2024-24721" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24721" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2024-24721" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2024-24721" diff --git a/advisories/unreviewed/2024/03/GHSA-m7gg-q7qj-3r2r/GHSA-m7gg-q7qj-3r2r.json b/advisories/unreviewed/2024/03/GHSA-m7gg-q7qj-3r2r/GHSA-m7gg-q7qj-3r2r.json index a00e36bc5c4..471c3470b9d 100644 --- a/advisories/unreviewed/2024/03/GHSA-m7gg-q7qj-3r2r/GHSA-m7gg-q7qj-3r2r.json +++ b/advisories/unreviewed/2024/03/GHSA-m7gg-q7qj-3r2r/GHSA-m7gg-q7qj-3r2r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m7gg-q7qj-3r2r", - "modified": "2024-03-11T15:31:24Z", + "modified": "2025-05-30T18:30:51Z", "published": "2024-03-04T18:30:39Z", "aliases": [ "CVE-2024-27199" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27199" }, + { + "type": "WEB", + "url": "https://github.com/Stuub/RCity-CVE-2024-27198/blob/main/RCity.py" + }, { "type": "WEB", "url": "https://www.darkreading.com/cyberattacks-data-breaches/jetbrains-teamcity-mass-exploitation-underway-rogue-accounts-thrive" diff --git a/advisories/unreviewed/2024/03/GHSA-xq72-5mqw-j6rc/GHSA-xq72-5mqw-j6rc.json b/advisories/unreviewed/2024/03/GHSA-xq72-5mqw-j6rc/GHSA-xq72-5mqw-j6rc.json index ae09c666081..a53e13d132b 100644 --- a/advisories/unreviewed/2024/03/GHSA-xq72-5mqw-j6rc/GHSA-xq72-5mqw-j6rc.json +++ b/advisories/unreviewed/2024/03/GHSA-xq72-5mqw-j6rc/GHSA-xq72-5mqw-j6rc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xq72-5mqw-j6rc", - "modified": "2024-08-19T21:35:06Z", + "modified": "2025-05-30T18:30:51Z", "published": "2024-03-06T00:31:26Z", "aliases": [ "CVE-2023-48644" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48644" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2023-48644" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2023-48644" diff --git a/advisories/unreviewed/2024/04/GHSA-67wm-85xj-pgvv/GHSA-67wm-85xj-pgvv.json b/advisories/unreviewed/2024/04/GHSA-67wm-85xj-pgvv/GHSA-67wm-85xj-pgvv.json index 23da7bc3d48..0384373c32c 100644 --- a/advisories/unreviewed/2024/04/GHSA-67wm-85xj-pgvv/GHSA-67wm-85xj-pgvv.json +++ b/advisories/unreviewed/2024/04/GHSA-67wm-85xj-pgvv/GHSA-67wm-85xj-pgvv.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-p7q5-2qf4-97cw/GHSA-p7q5-2qf4-97cw.json b/advisories/unreviewed/2024/04/GHSA-p7q5-2qf4-97cw/GHSA-p7q5-2qf4-97cw.json index 77fdc403702..2ddff5dfb13 100644 --- a/advisories/unreviewed/2024/04/GHSA-p7q5-2qf4-97cw/GHSA-p7q5-2qf4-97cw.json +++ b/advisories/unreviewed/2024/04/GHSA-p7q5-2qf4-97cw/GHSA-p7q5-2qf4-97cw.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-qj2m-h9cr-4gv7/GHSA-qj2m-h9cr-4gv7.json b/advisories/unreviewed/2024/04/GHSA-qj2m-h9cr-4gv7/GHSA-qj2m-h9cr-4gv7.json index 27d872e32d0..2f626c1bc7a 100644 --- a/advisories/unreviewed/2024/04/GHSA-qj2m-h9cr-4gv7/GHSA-qj2m-h9cr-4gv7.json +++ b/advisories/unreviewed/2024/04/GHSA-qj2m-h9cr-4gv7/GHSA-qj2m-h9cr-4gv7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qj2m-h9cr-4gv7", - "modified": "2024-07-08T15:31:54Z", + "modified": "2025-05-30T18:30:51Z", "published": "2024-04-16T18:31:34Z", "aliases": [ "CVE-2023-50872" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50872" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2023-50872" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2023-50872" diff --git a/advisories/unreviewed/2024/05/GHSA-chqx-rw2r-xgw8/GHSA-chqx-rw2r-xgw8.json b/advisories/unreviewed/2024/05/GHSA-chqx-rw2r-xgw8/GHSA-chqx-rw2r-xgw8.json index 6af7824a298..ce599190f1f 100644 --- a/advisories/unreviewed/2024/05/GHSA-chqx-rw2r-xgw8/GHSA-chqx-rw2r-xgw8.json +++ b/advisories/unreviewed/2024/05/GHSA-chqx-rw2r-xgw8/GHSA-chqx-rw2r-xgw8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-chqx-rw2r-xgw8", - "modified": "2024-10-29T21:30:45Z", + "modified": "2025-05-30T18:30:51Z", "published": "2024-05-01T21:30:38Z", "aliases": [ "CVE-2024-25676" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25676" }, + { + "type": "WEB", + "url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2024-25676" + }, { "type": "WEB", "url": "https://excellium-services.com/cert-xlm-advisory/cve-2024-25676" diff --git a/advisories/unreviewed/2024/05/GHSA-xq5f-88w9-ffw2/GHSA-xq5f-88w9-ffw2.json b/advisories/unreviewed/2024/05/GHSA-xq5f-88w9-ffw2/GHSA-xq5f-88w9-ffw2.json index e21a1f82c46..50f0cf26443 100644 --- a/advisories/unreviewed/2024/05/GHSA-xq5f-88w9-ffw2/GHSA-xq5f-88w9-ffw2.json +++ b/advisories/unreviewed/2024/05/GHSA-xq5f-88w9-ffw2/GHSA-xq5f-88w9-ffw2.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-58xh-xqmq-2mmr/GHSA-58xh-xqmq-2mmr.json b/advisories/unreviewed/2024/07/GHSA-58xh-xqmq-2mmr/GHSA-58xh-xqmq-2mmr.json index e73e7a8b1e9..5e5dd936199 100644 --- a/advisories/unreviewed/2024/07/GHSA-58xh-xqmq-2mmr/GHSA-58xh-xqmq-2mmr.json +++ b/advisories/unreviewed/2024/07/GHSA-58xh-xqmq-2mmr/GHSA-58xh-xqmq-2mmr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-96vr-9q65-96gj/GHSA-96vr-9q65-96gj.json b/advisories/unreviewed/2024/07/GHSA-96vr-9q65-96gj/GHSA-96vr-9q65-96gj.json index c2b8e54b7f6..2f983f0184e 100644 --- a/advisories/unreviewed/2024/07/GHSA-96vr-9q65-96gj/GHSA-96vr-9q65-96gj.json +++ b/advisories/unreviewed/2024/07/GHSA-96vr-9q65-96gj/GHSA-96vr-9q65-96gj.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-cx67-m2rh-98xh/GHSA-cx67-m2rh-98xh.json b/advisories/unreviewed/2024/07/GHSA-cx67-m2rh-98xh/GHSA-cx67-m2rh-98xh.json index a416fd2ee79..66e3a3fe571 100644 --- a/advisories/unreviewed/2024/07/GHSA-cx67-m2rh-98xh/GHSA-cx67-m2rh-98xh.json +++ b/advisories/unreviewed/2024/07/GHSA-cx67-m2rh-98xh/GHSA-cx67-m2rh-98xh.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-wrpc-6v65-cc7f/GHSA-wrpc-6v65-cc7f.json b/advisories/unreviewed/2024/07/GHSA-wrpc-6v65-cc7f/GHSA-wrpc-6v65-cc7f.json index b51b508d643..3473ca89b4e 100644 --- a/advisories/unreviewed/2024/07/GHSA-wrpc-6v65-cc7f/GHSA-wrpc-6v65-cc7f.json +++ b/advisories/unreviewed/2024/07/GHSA-wrpc-6v65-cc7f/GHSA-wrpc-6v65-cc7f.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-434" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-rfh5-gx7w-h7v7/GHSA-rfh5-gx7w-h7v7.json b/advisories/unreviewed/2025/04/GHSA-rfh5-gx7w-h7v7/GHSA-rfh5-gx7w-h7v7.json index 81ccf4a1abb..3c7839f1c1f 100644 --- a/advisories/unreviewed/2025/04/GHSA-rfh5-gx7w-h7v7/GHSA-rfh5-gx7w-h7v7.json +++ b/advisories/unreviewed/2025/04/GHSA-rfh5-gx7w-h7v7/GHSA-rfh5-gx7w-h7v7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rfh5-gx7w-h7v7", - "modified": "2025-04-15T06:30:34Z", + "modified": "2025-05-30T18:31:01Z", "published": "2025-04-15T06:30:34Z", "aliases": [ "CVE-2025-3576" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359465" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00047.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/05/GHSA-2vx2-pv2m-vwrq/GHSA-2vx2-pv2m-vwrq.json b/advisories/unreviewed/2025/05/GHSA-2vx2-pv2m-vwrq/GHSA-2vx2-pv2m-vwrq.json index 16fcac12510..c55598f3b62 100644 --- a/advisories/unreviewed/2025/05/GHSA-2vx2-pv2m-vwrq/GHSA-2vx2-pv2m-vwrq.json +++ b/advisories/unreviewed/2025/05/GHSA-2vx2-pv2m-vwrq/GHSA-2vx2-pv2m-vwrq.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-4c8w-67qj-c8vp/GHSA-4c8w-67qj-c8vp.json b/advisories/unreviewed/2025/05/GHSA-4c8w-67qj-c8vp/GHSA-4c8w-67qj-c8vp.json new file mode 100644 index 00000000000..17f964ba59b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4c8w-67qj-c8vp/GHSA-4c8w-67qj-c8vp.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4c8w-67qj-c8vp", + "modified": "2025-05-30T18:31:16Z", + "published": "2025-05-30T18:31:16Z", + "aliases": [ + "CVE-2025-5054" + ], + "details": "Race condition in Canonical apport up to and including 2.32.0 allows a local attacker to leak sensitive information via PID-reuse by leveraging namespaces.\n\n\n\n\nWhen handling a crash, the function `_check_global_pid_and_forward`, which detects if the crashing process resided in a container, was being called before `consistency_checks`, which attempts to detect if the crashing process had been replaced. Because of this, if a process crashed and was quickly replaced with a containerized one, apport could be made to forward the core dump to the container, potentially leaking sensitive information. `consistency_checks` is now being called before `_check_global_pid_and_forward`. Additionally, given that the PID-reuse race condition cannot be reliably detected from userspace alone, crashes are only forwarded to containers if the kernel provided a pidfd, or if the crashing process was unprivileged (i.e., if dump mode == 1).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5054" + }, + { + "type": "WEB", + "url": "https://ubuntu.com/security/CVE-2025-5054" + }, + { + "type": "WEB", + "url": "https://ubuntu.com/security/notices/USN-7545-1" + }, + { + "type": "WEB", + "url": "https://www.qualys.com/2025/05/29/apport-coredump/apport-coredump.txt" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-30T18:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-63xm-x5g2-5gr3/GHSA-63xm-x5g2-5gr3.json b/advisories/unreviewed/2025/05/GHSA-63xm-x5g2-5gr3/GHSA-63xm-x5g2-5gr3.json index fa9a7aff7ad..7d108254449 100644 --- a/advisories/unreviewed/2025/05/GHSA-63xm-x5g2-5gr3/GHSA-63xm-x5g2-5gr3.json +++ b/advisories/unreviewed/2025/05/GHSA-63xm-x5g2-5gr3/GHSA-63xm-x5g2-5gr3.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-35" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/05/GHSA-6pg5-rmm9-6cq9/GHSA-6pg5-rmm9-6cq9.json b/advisories/unreviewed/2025/05/GHSA-6pg5-rmm9-6cq9/GHSA-6pg5-rmm9-6cq9.json new file mode 100644 index 00000000000..0c42f2f0e3d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6pg5-rmm9-6cq9/GHSA-6pg5-rmm9-6cq9.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6pg5-rmm9-6cq9", + "modified": "2025-05-30T18:31:17Z", + "published": "2025-05-30T18:31:17Z", + "aliases": [ + "CVE-2025-5358" + ], + "details": "A vulnerability was found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /bwdates-reports-details.php. The manipulation of the argument fromdate/todate leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5358" + }, + { + "type": "WEB", + "url": "https://github.com/ASantsSec/CVE/issues/1" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310652" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310652" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.586569" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-30T18:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-89c4-h5cm-8ppg/GHSA-89c4-h5cm-8ppg.json b/advisories/unreviewed/2025/05/GHSA-89c4-h5cm-8ppg/GHSA-89c4-h5cm-8ppg.json new file mode 100644 index 00000000000..ec797dd9d46 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-89c4-h5cm-8ppg/GHSA-89c4-h5cm-8ppg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-89c4-h5cm-8ppg", + "modified": "2025-05-30T18:31:15Z", + "published": "2025-05-30T18:31:15Z", + "aliases": [ + "CVE-2024-42190" + ], + "details": "HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42190" + }, + { + "type": "WEB", + "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0120744" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-30T16:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-89vx-m8mc-p558/GHSA-89vx-m8mc-p558.json b/advisories/unreviewed/2025/05/GHSA-89vx-m8mc-p558/GHSA-89vx-m8mc-p558.json new file mode 100644 index 00000000000..e4a26ca3bb6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-89vx-m8mc-p558/GHSA-89vx-m8mc-p558.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-89vx-m8mc-p558", + "modified": "2025-05-30T18:31:14Z", + "published": "2025-05-30T18:31:14Z", + "aliases": [ + "CVE-2024-13917" + ], + "details": "An application \"com.pri.applock\", which is pre-loaded on Kruger&Matz smartphones, allows a user to encrypt any application using user-provided PIN code or by using biometric data.\nExposed ”com.pri.applock.LockUI“ activity allows any other malicious application, with no granted Android system permissions, to inject an arbitrary intent with system-level privileges to a protected application. One must know the protecting PIN number (it might be revealed by exploiting CVE-2024-13916) or ask the user to provide it.\n\nVendor did not provide information about vulnerable versions.\nOnly version (version name: 13, version code: 33) was tested and confirmed to have this vulnerability", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13917" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2025/05/CVE-2024-13915" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-926" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-30T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8vfw-v3xx-j7xw/GHSA-8vfw-v3xx-j7xw.json b/advisories/unreviewed/2025/05/GHSA-8vfw-v3xx-j7xw/GHSA-8vfw-v3xx-j7xw.json new file mode 100644 index 00000000000..277f2ae3c48 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8vfw-v3xx-j7xw/GHSA-8vfw-v3xx-j7xw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8vfw-v3xx-j7xw", + "modified": "2025-05-30T18:31:14Z", + "published": "2025-05-30T18:31:14Z", + "aliases": [ + "CVE-2024-23589" + ], + "details": "Due to outdated Hash algorithm, HCL Glovius Cloud could allow attackers to guess the input data using brute-force or dictionary attacks efficiently using modern hardware such as GPUs or ASICs", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23589" + }, + { + "type": "WEB", + "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0121015" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-328" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-30T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9m9c-m3m8-59vc/GHSA-9m9c-m3m8-59vc.json b/advisories/unreviewed/2025/05/GHSA-9m9c-m3m8-59vc/GHSA-9m9c-m3m8-59vc.json new file mode 100644 index 00000000000..638e9a7ad76 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9m9c-m3m8-59vc/GHSA-9m9c-m3m8-59vc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9m9c-m3m8-59vc", + "modified": "2025-05-30T18:31:13Z", + "published": "2025-05-30T18:31:13Z", + "aliases": [ + "CVE-2024-13915" + ], + "details": "Android based smartphones from vendors such as Ulefone and Krüger&Matz contain \"com.pri.factorytest\" application preloaded onto devices during manufacturing process.\nThe application \"com.pri.factorytest\" (version name: 1.0, version code: 1) exposes a ”com.pri.factorytest.emmc.FactoryResetService“ service allowing any application to perform a factory reset of the device. \nApplication update did not increment the APK version. Instead, it was bundled in OS builds released later than December 2024 (Ulefone) and most probably March 2025 (Krüger&Matz, although the vendor has not confirmed it, so newer releases might be vulnerable as well).", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13915" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2025/05/CVE-2024-13915" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-926" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-30T16:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fg72-v8xw-hm7h/GHSA-fg72-v8xw-hm7h.json b/advisories/unreviewed/2025/05/GHSA-fg72-v8xw-hm7h/GHSA-fg72-v8xw-hm7h.json index d85d277eaa9..abe65d9a88a 100644 --- a/advisories/unreviewed/2025/05/GHSA-fg72-v8xw-hm7h/GHSA-fg72-v8xw-hm7h.json +++ b/advisories/unreviewed/2025/05/GHSA-fg72-v8xw-hm7h/GHSA-fg72-v8xw-hm7h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fg72-v8xw-hm7h", - "modified": "2025-05-28T18:33:28Z", + "modified": "2025-05-30T18:31:01Z", "published": "2025-05-28T18:33:28Z", "aliases": [ "CVE-2025-48746" ], "details": "Netwrix Directory Manager (formerly Imanami GroupID) v.11.0.0.0 and before, as well as after v.11.1.25134.03 lacks Authentication for a Critical Function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-28T17:15:24Z" diff --git a/advisories/unreviewed/2025/05/GHSA-ghmf-r624-m2jq/GHSA-ghmf-r624-m2jq.json b/advisories/unreviewed/2025/05/GHSA-ghmf-r624-m2jq/GHSA-ghmf-r624-m2jq.json new file mode 100644 index 00000000000..21a9ffaa394 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-ghmf-r624-m2jq/GHSA-ghmf-r624-m2jq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ghmf-r624-m2jq", + "modified": "2025-05-30T18:31:15Z", + "published": "2025-05-30T18:31:15Z", + "aliases": [ + "CVE-2023-26226" + ], + "details": "A use after free memory corruption issue exists in Yandex Browser for Desktop prior to version 24.4.0.682", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:L/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26226" + }, + { + "type": "WEB", + "url": "https://yandex.com/bugbounty/i/hall-of-fame-browser" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-30T18:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hc7m-j4w7-pv6w/GHSA-hc7m-j4w7-pv6w.json b/advisories/unreviewed/2025/05/GHSA-hc7m-j4w7-pv6w/GHSA-hc7m-j4w7-pv6w.json index 451e8f18939..0aa99f3b8ae 100644 --- a/advisories/unreviewed/2025/05/GHSA-hc7m-j4w7-pv6w/GHSA-hc7m-j4w7-pv6w.json +++ b/advisories/unreviewed/2025/05/GHSA-hc7m-j4w7-pv6w/GHSA-hc7m-j4w7-pv6w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hc7m-j4w7-pv6w", - "modified": "2025-05-28T18:33:29Z", + "modified": "2025-05-30T18:31:01Z", "published": "2025-05-28T18:33:29Z", "aliases": [ "CVE-2024-57336" ], "details": "Incorrect access control in M2Soft CROWNIX Report & ERS affected v7.x to v7.4.3.599 and v8.x to v8.0.3.79 allows unauthorized attackers to obtain Administrator account access.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-28T18:15:25Z" diff --git a/advisories/unreviewed/2025/05/GHSA-p4hr-xgjf-v467/GHSA-p4hr-xgjf-v467.json b/advisories/unreviewed/2025/05/GHSA-p4hr-xgjf-v467/GHSA-p4hr-xgjf-v467.json new file mode 100644 index 00000000000..e52f5d82513 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p4hr-xgjf-v467/GHSA-p4hr-xgjf-v467.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p4hr-xgjf-v467", + "modified": "2025-05-30T18:31:16Z", + "published": "2025-05-30T18:31:16Z", + "aliases": [ + "CVE-2025-5356" + ], + "details": "A vulnerability was found in FreeFloat FTP Server 1.0. It has been classified as critical. Affected is an unknown function of the component BYE Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5356" + }, + { + "type": "WEB", + "url": "https://fitoxs.com/exploit/exploit-a9c9f7b4f50efc4b4be32e7ec4d3f7dfd7390e9be4ff168d9ab7a0eb911f8f3a.txt" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310650" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310650" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.585639" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-30T17:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-ppq4-7pwf-rg3r/GHSA-ppq4-7pwf-rg3r.json b/advisories/unreviewed/2025/05/GHSA-ppq4-7pwf-rg3r/GHSA-ppq4-7pwf-rg3r.json new file mode 100644 index 00000000000..d2a30f15bbb --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-ppq4-7pwf-rg3r/GHSA-ppq4-7pwf-rg3r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ppq4-7pwf-rg3r", + "modified": "2025-05-30T18:31:15Z", + "published": "2025-05-30T18:31:15Z", + "aliases": [ + "CVE-2024-42191" + ], + "details": "HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a COM hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42191" + }, + { + "type": "WEB", + "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0120745" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-30T16:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-pw53-33fx-vf55/GHSA-pw53-33fx-vf55.json b/advisories/unreviewed/2025/05/GHSA-pw53-33fx-vf55/GHSA-pw53-33fx-vf55.json new file mode 100644 index 00000000000..c28399534c9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pw53-33fx-vf55/GHSA-pw53-33fx-vf55.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pw53-33fx-vf55", + "modified": "2025-05-30T18:31:13Z", + "published": "2025-05-30T18:31:13Z", + "aliases": [ + "CVE-2024-13916" + ], + "details": "An application \"com.pri.applock\", which is pre-loaded on Kruger&Matz smartphones, allows a user to encrypt any application using user-provided PIN code or by using biometric data.\nExposed ”com.android.providers.settings.fingerprint.PriFpShareProvider“ content provider's public method query() allows any other malicious application, without any granted Android system permissions, to exfiltrate the PIN code.\n\nVendor did not provide information about vulnerable versions.\nOnly version (version name: 13, version code: 33) was tested and confirmed to have this vulnerability", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13916" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2025/05/CVE-2024-13915" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-30T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rcv8-vxjp-vqcw/GHSA-rcv8-vxjp-vqcw.json b/advisories/unreviewed/2025/05/GHSA-rcv8-vxjp-vqcw/GHSA-rcv8-vxjp-vqcw.json index dd5821a80f6..a0fcf203cfc 100644 --- a/advisories/unreviewed/2025/05/GHSA-rcv8-vxjp-vqcw/GHSA-rcv8-vxjp-vqcw.json +++ b/advisories/unreviewed/2025/05/GHSA-rcv8-vxjp-vqcw/GHSA-rcv8-vxjp-vqcw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rcv8-vxjp-vqcw", - "modified": "2025-05-21T15:30:33Z", + "modified": "2025-05-30T18:31:01Z", "published": "2025-05-21T15:30:33Z", "aliases": [ "CVE-2025-48416" ], "details": "An OpenSSH daemon listens on TCP port 22. There is a hard-coded entry in the \"/etc/shadow\" file in the firmware image for the \"root\" user. However, in the default SSH configuration the \"PermitRootLogin\" is disabled, preventing the root user from logging in via SSH. This configuration can be bypassed/changed by an attacker through multiple paths though.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-912" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-21T13:16:02Z" diff --git a/advisories/unreviewed/2025/05/GHSA-x6fc-488r-qh93/GHSA-x6fc-488r-qh93.json b/advisories/unreviewed/2025/05/GHSA-x6fc-488r-qh93/GHSA-x6fc-488r-qh93.json index 691d8c9343c..d4bad355546 100644 --- a/advisories/unreviewed/2025/05/GHSA-x6fc-488r-qh93/GHSA-x6fc-488r-qh93.json +++ b/advisories/unreviewed/2025/05/GHSA-x6fc-488r-qh93/GHSA-x6fc-488r-qh93.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x6fc-488r-qh93", - "modified": "2025-05-28T18:33:29Z", + "modified": "2025-05-30T18:31:01Z", "published": "2025-05-28T18:33:29Z", "aliases": [ "CVE-2025-47748" ], "details": "Netwrix Directory Manager v.11.0.0.0 and before & after v.11.1.25134.03 contains a hardcoded password.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-259" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-28T18:15:27Z" diff --git a/advisories/unreviewed/2025/05/GHSA-x8ch-h5vv-q6cm/GHSA-x8ch-h5vv-q6cm.json b/advisories/unreviewed/2025/05/GHSA-x8ch-h5vv-q6cm/GHSA-x8ch-h5vv-q6cm.json index 28e02aa6909..7b87b02cec9 100644 --- a/advisories/unreviewed/2025/05/GHSA-x8ch-h5vv-q6cm/GHSA-x8ch-h5vv-q6cm.json +++ b/advisories/unreviewed/2025/05/GHSA-x8ch-h5vv-q6cm/GHSA-x8ch-h5vv-q6cm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x8ch-h5vv-q6cm", - "modified": "2025-05-28T09:31:26Z", + "modified": "2025-05-30T18:31:01Z", "published": "2025-05-28T09:31:26Z", "aliases": [ "CVE-2025-5025" ], "details": "libcurl supports *pinning* of the server certificate public key for HTTPS transfers. Due to an omission, this check is not performed when connecting with QUIC for HTTP/3, when the TLS backend is wolfSSL. Documentation says the option works with wolfSSL, failing to specify that it does not for QUIC and HTTP/3. Since pinning makes the transfer succeed if the pin is fine, users could unwittingly connect to an impostor server without noticing.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -33,7 +38,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-28T07:15:24Z" diff --git a/advisories/unreviewed/2025/05/GHSA-xwh8-466p-8642/GHSA-xwh8-466p-8642.json b/advisories/unreviewed/2025/05/GHSA-xwh8-466p-8642/GHSA-xwh8-466p-8642.json new file mode 100644 index 00000000000..935b5f8c162 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xwh8-466p-8642/GHSA-xwh8-466p-8642.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xwh8-466p-8642", + "modified": "2025-05-30T18:31:17Z", + "published": "2025-05-30T18:31:17Z", + "aliases": [ + "CVE-2025-5357" + ], + "details": "A vulnerability was found in FreeFloat FTP Server 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component PWD Command Handler. The manipulation leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5357" + }, + { + "type": "WEB", + "url": "https://fitoxs.com/exploit/exploit-c15b3c9a2d7b1618fc5a30df50e5a13d6275f109f1fba20465d4cdd76ee8772b.txt" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310651" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310651" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.585641" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-30T18:15:32Z" + } +} \ No newline at end of file