From 5973d9f6cdad2d1e09f7e5394931587bbdaca245 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 24 Apr 2025 15:31:49 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-76p7-773f-r4q5.json | 6 ++- .../GHSA-2346-8v69-w74p.json | 3 +- .../GHSA-2f4p-m737-x9wf.json | 3 +- .../GHSA-2pm2-h49w-3rj5.json | 22 +++++++++- .../GHSA-2wh4-9v67-69x7.json | 2 +- .../GHSA-3g44-8pvw-94rh.json | 3 +- .../GHSA-3p26-6f92-v9vg.json | 1 + .../GHSA-42cv-6jj9-78p6.json | 3 +- .../GHSA-5vx9-xqhh-f79w.json | 2 +- .../GHSA-73ph-jqmg-j67j.json | 3 +- .../GHSA-7588-p92j-p3hh.json | 4 +- .../GHSA-7cp6-q2fv-7m82.json | 2 +- .../GHSA-82vg-p6h3-hr69.json | 4 +- .../GHSA-869f-2f47-3rwh.json | 2 +- .../GHSA-99vr-7hvg-69wf.json | 1 + .../GHSA-g76x-m5qr-8rc7.json | 4 +- .../GHSA-gjqr-jhwx-6m86.json | 4 +- .../GHSA-h8vf-v4qw-mvq4.json | 2 +- .../GHSA-hm6q-fjph-v26v.json | 2 +- .../GHSA-j238-gr37-vx73.json | 3 +- .../GHSA-j2c7-5g87-4vx7.json | 2 +- .../GHSA-jqqc-8vpc-2wjv.json | 6 ++- .../GHSA-q5hc-gpjw-fpvp.json | 1 + .../GHSA-r934-m2c7-26gh.json | 2 +- .../GHSA-rvwm-8qg8-4hp8.json | 2 +- .../GHSA-v7vc-4ppw-r84h.json | 2 +- .../GHSA-v7x7-wh72-mxcc.json | 2 +- .../GHSA-vmww-v9wr-vr83.json | 3 +- .../GHSA-vvq3-c7x5-w3gw.json | 4 +- .../GHSA-vw5p-wqpx-xffp.json | 2 +- .../GHSA-w6h6-prfq-77c8.json | 3 +- .../GHSA-whmx-4qfx-rgh5.json | 4 +- .../GHSA-wxhf-m7w8-4vjp.json | 1 + .../GHSA-x3f7-g9wc-xxpj.json | 1 + .../GHSA-xc7c-j6xx-gfqj.json | 4 +- .../GHSA-6439-9fxj-fc35.json | 2 +- .../GHSA-3cp9-5473-gp87.json | 4 +- .../GHSA-5fxg-7vxp-3w6q.json | 3 +- .../GHSA-crh9-vmx5-ggr8.json | 15 +++++-- .../GHSA-3p2x-hfrr-wj4w.json | 36 +++++++++++++++++ .../GHSA-4735-w7g7-ghx3.json | 11 +++-- .../GHSA-4mxw-7rp7-fhjr.json | 4 +- .../GHSA-53rh-xg3h-r59m.json | 29 ++++++++++++++ .../GHSA-73m2-qfq3-56cx.json | 15 +++++-- .../GHSA-7rg2-x652-w37x.json | 29 ++++++++++++++ .../GHSA-cgw5-xrp3-wfg5.json | 29 ++++++++++++++ .../GHSA-gfc5-vx7h-qx8m.json | 3 +- .../GHSA-p8xc-w865-2hhr.json | 15 +++++-- .../GHSA-pr7v-prvv-52v8.json | 40 +++++++++++++++++++ .../GHSA-pv37-78jj-hvqv.json | 40 +++++++++++++++++++ .../GHSA-q4cq-9g5r-5fvx.json | 36 +++++++++++++++++ .../GHSA-q746-mv6h-3fx6.json | 11 +++-- .../GHSA-qgrf-8g4m-4v9p.json | 3 +- 53 files changed, 386 insertions(+), 54 deletions(-) create mode 100644 advisories/unreviewed/2025/04/GHSA-3p2x-hfrr-wj4w/GHSA-3p2x-hfrr-wj4w.json create mode 100644 advisories/unreviewed/2025/04/GHSA-53rh-xg3h-r59m/GHSA-53rh-xg3h-r59m.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7rg2-x652-w37x/GHSA-7rg2-x652-w37x.json create mode 100644 advisories/unreviewed/2025/04/GHSA-cgw5-xrp3-wfg5/GHSA-cgw5-xrp3-wfg5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-pr7v-prvv-52v8/GHSA-pr7v-prvv-52v8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-pv37-78jj-hvqv/GHSA-pv37-78jj-hvqv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-q4cq-9g5r-5fvx/GHSA-q4cq-9g5r-5fvx.json diff --git a/advisories/github-reviewed/2025/02/GHSA-76p7-773f-r4q5/GHSA-76p7-773f-r4q5.json b/advisories/github-reviewed/2025/02/GHSA-76p7-773f-r4q5/GHSA-76p7-773f-r4q5.json index 05d94ede58d..2e7458d2cd7 100644 --- a/advisories/github-reviewed/2025/02/GHSA-76p7-773f-r4q5/GHSA-76p7-773f-r4q5.json +++ b/advisories/github-reviewed/2025/02/GHSA-76p7-773f-r4q5/GHSA-76p7-773f-r4q5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-76p7-773f-r4q5", - "modified": "2025-02-21T20:19:17Z", + "modified": "2025-04-24T15:30:49Z", "published": "2025-02-10T18:30:47Z", "aliases": [ "CVE-2024-11831" @@ -52,6 +52,10 @@ "type": "WEB", "url": "https://github.com/yahoo/serialize-javascript/commit/f27d65d3de42affe2aac14607066c293891cec4e" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHBA-2025:0304" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:1334" diff --git a/advisories/unreviewed/2022/12/GHSA-2346-8v69-w74p/GHSA-2346-8v69-w74p.json b/advisories/unreviewed/2022/12/GHSA-2346-8v69-w74p/GHSA-2346-8v69-w74p.json index f758e89858c..00805771b3c 100644 --- a/advisories/unreviewed/2022/12/GHSA-2346-8v69-w74p/GHSA-2346-8v69-w74p.json +++ b/advisories/unreviewed/2022/12/GHSA-2346-8v69-w74p/GHSA-2346-8v69-w74p.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-2f4p-m737-x9wf/GHSA-2f4p-m737-x9wf.json b/advisories/unreviewed/2022/12/GHSA-2f4p-m737-x9wf/GHSA-2f4p-m737-x9wf.json index 56cac878276..effa4cb95ef 100644 --- a/advisories/unreviewed/2022/12/GHSA-2f4p-m737-x9wf/GHSA-2f4p-m737-x9wf.json +++ b/advisories/unreviewed/2022/12/GHSA-2f4p-m737-x9wf/GHSA-2f4p-m737-x9wf.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-2pm2-h49w-3rj5/GHSA-2pm2-h49w-3rj5.json b/advisories/unreviewed/2022/12/GHSA-2pm2-h49w-3rj5/GHSA-2pm2-h49w-3rj5.json index f2d7f7644eb..28ceaf4c24a 100644 --- a/advisories/unreviewed/2022/12/GHSA-2pm2-h49w-3rj5/GHSA-2pm2-h49w-3rj5.json +++ b/advisories/unreviewed/2022/12/GHSA-2pm2-h49w-3rj5/GHSA-2pm2-h49w-3rj5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2pm2-h49w-3rj5", - "modified": "2022-12-05T15:30:27Z", + "modified": "2025-04-24T15:30:36Z", "published": "2022-12-01T21:30:19Z", "aliases": [ "CVE-2022-23737" @@ -19,6 +19,26 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-23737" }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server%403.2/admin/release-notes#3.2.20" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server%403.3/admin/release-notes#3.3.15" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server%403.4/admin/release-notes#3.4.10" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server%403.5/admin/release-notes#3.5.7" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server%403.6/admin/release-notes#3.6.3" + }, { "type": "WEB", "url": "https://docs.github.com/en/enterprise-server@3.2/admin/release-notes#3.2.20" diff --git a/advisories/unreviewed/2022/12/GHSA-2wh4-9v67-69x7/GHSA-2wh4-9v67-69x7.json b/advisories/unreviewed/2022/12/GHSA-2wh4-9v67-69x7/GHSA-2wh4-9v67-69x7.json index be7c70def8b..c53892aca4f 100644 --- a/advisories/unreviewed/2022/12/GHSA-2wh4-9v67-69x7/GHSA-2wh4-9v67-69x7.json +++ b/advisories/unreviewed/2022/12/GHSA-2wh4-9v67-69x7/GHSA-2wh4-9v67-69x7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2wh4-9v67-69x7", - "modified": "2022-12-05T21:30:42Z", + "modified": "2025-04-24T15:30:36Z", "published": "2022-12-02T18:30:28Z", "aliases": [ "CVE-2022-45482" diff --git a/advisories/unreviewed/2022/12/GHSA-3g44-8pvw-94rh/GHSA-3g44-8pvw-94rh.json b/advisories/unreviewed/2022/12/GHSA-3g44-8pvw-94rh/GHSA-3g44-8pvw-94rh.json index f9419c06682..8b4673d0bfb 100644 --- a/advisories/unreviewed/2022/12/GHSA-3g44-8pvw-94rh/GHSA-3g44-8pvw-94rh.json +++ b/advisories/unreviewed/2022/12/GHSA-3g44-8pvw-94rh/GHSA-3g44-8pvw-94rh.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-3p26-6f92-v9vg/GHSA-3p26-6f92-v9vg.json b/advisories/unreviewed/2022/12/GHSA-3p26-6f92-v9vg/GHSA-3p26-6f92-v9vg.json index f6fe5529c13..c542bff343f 100644 --- a/advisories/unreviewed/2022/12/GHSA-3p26-6f92-v9vg/GHSA-3p26-6f92-v9vg.json +++ b/advisories/unreviewed/2022/12/GHSA-3p26-6f92-v9vg/GHSA-3p26-6f92-v9vg.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-121", "CWE-787" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/12/GHSA-42cv-6jj9-78p6/GHSA-42cv-6jj9-78p6.json b/advisories/unreviewed/2022/12/GHSA-42cv-6jj9-78p6/GHSA-42cv-6jj9-78p6.json index 022c449f5ed..39de73118c7 100644 --- a/advisories/unreviewed/2022/12/GHSA-42cv-6jj9-78p6/GHSA-42cv-6jj9-78p6.json +++ b/advisories/unreviewed/2022/12/GHSA-42cv-6jj9-78p6/GHSA-42cv-6jj9-78p6.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-125" + "CWE-125", + "CWE-126" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-5vx9-xqhh-f79w/GHSA-5vx9-xqhh-f79w.json b/advisories/unreviewed/2022/12/GHSA-5vx9-xqhh-f79w/GHSA-5vx9-xqhh-f79w.json index b1afafef9a6..3622e6c0170 100644 --- a/advisories/unreviewed/2022/12/GHSA-5vx9-xqhh-f79w/GHSA-5vx9-xqhh-f79w.json +++ b/advisories/unreviewed/2022/12/GHSA-5vx9-xqhh-f79w/GHSA-5vx9-xqhh-f79w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5vx9-xqhh-f79w", - "modified": "2022-12-06T15:30:30Z", + "modified": "2025-04-24T15:30:38Z", "published": "2022-12-05T06:30:21Z", "aliases": [ "CVE-2022-43479" diff --git a/advisories/unreviewed/2022/12/GHSA-73ph-jqmg-j67j/GHSA-73ph-jqmg-j67j.json b/advisories/unreviewed/2022/12/GHSA-73ph-jqmg-j67j/GHSA-73ph-jqmg-j67j.json index 689192c6d8a..3d4acf4f658 100644 --- a/advisories/unreviewed/2022/12/GHSA-73ph-jqmg-j67j/GHSA-73ph-jqmg-j67j.json +++ b/advisories/unreviewed/2022/12/GHSA-73ph-jqmg-j67j/GHSA-73ph-jqmg-j67j.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-7588-p92j-p3hh/GHSA-7588-p92j-p3hh.json b/advisories/unreviewed/2022/12/GHSA-7588-p92j-p3hh/GHSA-7588-p92j-p3hh.json index ae633987472..635c99f6484 100644 --- a/advisories/unreviewed/2022/12/GHSA-7588-p92j-p3hh/GHSA-7588-p92j-p3hh.json +++ b/advisories/unreviewed/2022/12/GHSA-7588-p92j-p3hh/GHSA-7588-p92j-p3hh.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-434" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-7cp6-q2fv-7m82/GHSA-7cp6-q2fv-7m82.json b/advisories/unreviewed/2022/12/GHSA-7cp6-q2fv-7m82/GHSA-7cp6-q2fv-7m82.json index cdbfba5d8ff..beebf3f191f 100644 --- a/advisories/unreviewed/2022/12/GHSA-7cp6-q2fv-7m82/GHSA-7cp6-q2fv-7m82.json +++ b/advisories/unreviewed/2022/12/GHSA-7cp6-q2fv-7m82/GHSA-7cp6-q2fv-7m82.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7cp6-q2fv-7m82", - "modified": "2022-12-08T15:30:25Z", + "modified": "2025-04-24T15:30:40Z", "published": "2022-12-05T18:30:41Z", "aliases": [ "CVE-2022-45477" diff --git a/advisories/unreviewed/2022/12/GHSA-82vg-p6h3-hr69/GHSA-82vg-p6h3-hr69.json b/advisories/unreviewed/2022/12/GHSA-82vg-p6h3-hr69/GHSA-82vg-p6h3-hr69.json index 06030814123..af4ddeb9a74 100644 --- a/advisories/unreviewed/2022/12/GHSA-82vg-p6h3-hr69/GHSA-82vg-p6h3-hr69.json +++ b/advisories/unreviewed/2022/12/GHSA-82vg-p6h3-hr69/GHSA-82vg-p6h3-hr69.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-250" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-869f-2f47-3rwh/GHSA-869f-2f47-3rwh.json b/advisories/unreviewed/2022/12/GHSA-869f-2f47-3rwh/GHSA-869f-2f47-3rwh.json index bd54036b496..5b5d2ff36af 100644 --- a/advisories/unreviewed/2022/12/GHSA-869f-2f47-3rwh/GHSA-869f-2f47-3rwh.json +++ b/advisories/unreviewed/2022/12/GHSA-869f-2f47-3rwh/GHSA-869f-2f47-3rwh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-869f-2f47-3rwh", - "modified": "2022-12-06T21:30:46Z", + "modified": "2025-04-24T15:30:40Z", "published": "2022-12-05T18:30:41Z", "aliases": [ "CVE-2022-3856" diff --git a/advisories/unreviewed/2022/12/GHSA-99vr-7hvg-69wf/GHSA-99vr-7hvg-69wf.json b/advisories/unreviewed/2022/12/GHSA-99vr-7hvg-69wf/GHSA-99vr-7hvg-69wf.json index ca2f556cc90..3b22eca547c 100644 --- a/advisories/unreviewed/2022/12/GHSA-99vr-7hvg-69wf/GHSA-99vr-7hvg-69wf.json +++ b/advisories/unreviewed/2022/12/GHSA-99vr-7hvg-69wf/GHSA-99vr-7hvg-69wf.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-667" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/12/GHSA-g76x-m5qr-8rc7/GHSA-g76x-m5qr-8rc7.json b/advisories/unreviewed/2022/12/GHSA-g76x-m5qr-8rc7/GHSA-g76x-m5qr-8rc7.json index 874ebcd93d8..e655c3e3b59 100644 --- a/advisories/unreviewed/2022/12/GHSA-g76x-m5qr-8rc7/GHSA-g76x-m5qr-8rc7.json +++ b/advisories/unreviewed/2022/12/GHSA-g76x-m5qr-8rc7/GHSA-g76x-m5qr-8rc7.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-gjqr-jhwx-6m86/GHSA-gjqr-jhwx-6m86.json b/advisories/unreviewed/2022/12/GHSA-gjqr-jhwx-6m86/GHSA-gjqr-jhwx-6m86.json index 9d9490717a9..32a9cbc3368 100644 --- a/advisories/unreviewed/2022/12/GHSA-gjqr-jhwx-6m86/GHSA-gjqr-jhwx-6m86.json +++ b/advisories/unreviewed/2022/12/GHSA-gjqr-jhwx-6m86/GHSA-gjqr-jhwx-6m86.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-h8vf-v4qw-mvq4/GHSA-h8vf-v4qw-mvq4.json b/advisories/unreviewed/2022/12/GHSA-h8vf-v4qw-mvq4/GHSA-h8vf-v4qw-mvq4.json index 6e4f64447ba..9e8011445ee 100644 --- a/advisories/unreviewed/2022/12/GHSA-h8vf-v4qw-mvq4/GHSA-h8vf-v4qw-mvq4.json +++ b/advisories/unreviewed/2022/12/GHSA-h8vf-v4qw-mvq4/GHSA-h8vf-v4qw-mvq4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h8vf-v4qw-mvq4", - "modified": "2022-12-06T15:30:30Z", + "modified": "2025-04-24T15:30:38Z", "published": "2022-12-05T06:30:21Z", "aliases": [ "CVE-2022-43504" diff --git a/advisories/unreviewed/2022/12/GHSA-hm6q-fjph-v26v/GHSA-hm6q-fjph-v26v.json b/advisories/unreviewed/2022/12/GHSA-hm6q-fjph-v26v/GHSA-hm6q-fjph-v26v.json index daa614a2bc6..c7f641fe14a 100644 --- a/advisories/unreviewed/2022/12/GHSA-hm6q-fjph-v26v/GHSA-hm6q-fjph-v26v.json +++ b/advisories/unreviewed/2022/12/GHSA-hm6q-fjph-v26v/GHSA-hm6q-fjph-v26v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hm6q-fjph-v26v", - "modified": "2022-12-06T15:30:30Z", + "modified": "2025-04-24T15:30:38Z", "published": "2022-12-05T06:30:21Z", "aliases": [ "CVE-2022-43500" diff --git a/advisories/unreviewed/2022/12/GHSA-j238-gr37-vx73/GHSA-j238-gr37-vx73.json b/advisories/unreviewed/2022/12/GHSA-j238-gr37-vx73/GHSA-j238-gr37-vx73.json index 11888701bd5..c964b5c0c43 100644 --- a/advisories/unreviewed/2022/12/GHSA-j238-gr37-vx73/GHSA-j238-gr37-vx73.json +++ b/advisories/unreviewed/2022/12/GHSA-j238-gr37-vx73/GHSA-j238-gr37-vx73.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-276" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-j2c7-5g87-4vx7/GHSA-j2c7-5g87-4vx7.json b/advisories/unreviewed/2022/12/GHSA-j2c7-5g87-4vx7/GHSA-j2c7-5g87-4vx7.json index b5dd90b9000..75b92fc106a 100644 --- a/advisories/unreviewed/2022/12/GHSA-j2c7-5g87-4vx7/GHSA-j2c7-5g87-4vx7.json +++ b/advisories/unreviewed/2022/12/GHSA-j2c7-5g87-4vx7/GHSA-j2c7-5g87-4vx7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j2c7-5g87-4vx7", - "modified": "2022-12-06T15:30:30Z", + "modified": "2025-04-24T15:30:38Z", "published": "2022-12-05T06:30:21Z", "aliases": [ "CVE-2022-43499" diff --git a/advisories/unreviewed/2022/12/GHSA-jqqc-8vpc-2wjv/GHSA-jqqc-8vpc-2wjv.json b/advisories/unreviewed/2022/12/GHSA-jqqc-8vpc-2wjv/GHSA-jqqc-8vpc-2wjv.json index af4a3914efd..fcb1610f7f7 100644 --- a/advisories/unreviewed/2022/12/GHSA-jqqc-8vpc-2wjv/GHSA-jqqc-8vpc-2wjv.json +++ b/advisories/unreviewed/2022/12/GHSA-jqqc-8vpc-2wjv/GHSA-jqqc-8vpc-2wjv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jqqc-8vpc-2wjv", - "modified": "2022-12-08T18:30:50Z", + "modified": "2025-04-24T15:30:43Z", "published": "2022-12-06T00:30:15Z", "aliases": [ "CVE-2022-40918" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://1af95112-6fd8-4c8f-8bd6-c47f8ef7b77a.filesusr.com/ugd/c1f861_51eb0d33d5764efc93e9d5f19c306950.pdf" }, + { + "type": "WEB", + "url": "https://medium.com/%40meekworth/exploiting-the-lw9621-drone-camera-module-773f00081368" + }, { "type": "WEB", "url": "https://medium.com/@meekworth/exploiting-the-lw9621-drone-camera-module-773f00081368" diff --git a/advisories/unreviewed/2022/12/GHSA-q5hc-gpjw-fpvp/GHSA-q5hc-gpjw-fpvp.json b/advisories/unreviewed/2022/12/GHSA-q5hc-gpjw-fpvp/GHSA-q5hc-gpjw-fpvp.json index 833057eeb05..c35cfc8217e 100644 --- a/advisories/unreviewed/2022/12/GHSA-q5hc-gpjw-fpvp/GHSA-q5hc-gpjw-fpvp.json +++ b/advisories/unreviewed/2022/12/GHSA-q5hc-gpjw-fpvp/GHSA-q5hc-gpjw-fpvp.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-126", "CWE-787" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/12/GHSA-r934-m2c7-26gh/GHSA-r934-m2c7-26gh.json b/advisories/unreviewed/2022/12/GHSA-r934-m2c7-26gh/GHSA-r934-m2c7-26gh.json index 66b6f3a1a18..219e789e3b3 100644 --- a/advisories/unreviewed/2022/12/GHSA-r934-m2c7-26gh/GHSA-r934-m2c7-26gh.json +++ b/advisories/unreviewed/2022/12/GHSA-r934-m2c7-26gh/GHSA-r934-m2c7-26gh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r934-m2c7-26gh", - "modified": "2023-01-20T21:30:31Z", + "modified": "2025-04-24T15:30:42Z", "published": "2022-12-06T00:30:16Z", "aliases": [ "CVE-2022-43548" diff --git a/advisories/unreviewed/2022/12/GHSA-rvwm-8qg8-4hp8/GHSA-rvwm-8qg8-4hp8.json b/advisories/unreviewed/2022/12/GHSA-rvwm-8qg8-4hp8/GHSA-rvwm-8qg8-4hp8.json index ed56d0a1b1b..246e5cbe2e3 100644 --- a/advisories/unreviewed/2022/12/GHSA-rvwm-8qg8-4hp8/GHSA-rvwm-8qg8-4hp8.json +++ b/advisories/unreviewed/2022/12/GHSA-rvwm-8qg8-4hp8/GHSA-rvwm-8qg8-4hp8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rvwm-8qg8-4hp8", - "modified": "2022-12-06T15:30:30Z", + "modified": "2025-04-24T15:30:38Z", "published": "2022-12-05T06:30:21Z", "aliases": [ "CVE-2022-43497" diff --git a/advisories/unreviewed/2022/12/GHSA-v7vc-4ppw-r84h/GHSA-v7vc-4ppw-r84h.json b/advisories/unreviewed/2022/12/GHSA-v7vc-4ppw-r84h/GHSA-v7vc-4ppw-r84h.json index 2e8d222ffbf..2062437ea5f 100644 --- a/advisories/unreviewed/2022/12/GHSA-v7vc-4ppw-r84h/GHSA-v7vc-4ppw-r84h.json +++ b/advisories/unreviewed/2022/12/GHSA-v7vc-4ppw-r84h/GHSA-v7vc-4ppw-r84h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v7vc-4ppw-r84h", - "modified": "2022-12-05T21:30:42Z", + "modified": "2025-04-24T15:30:36Z", "published": "2022-12-02T18:30:28Z", "aliases": [ "CVE-2022-45483" diff --git a/advisories/unreviewed/2022/12/GHSA-v7x7-wh72-mxcc/GHSA-v7x7-wh72-mxcc.json b/advisories/unreviewed/2022/12/GHSA-v7x7-wh72-mxcc/GHSA-v7x7-wh72-mxcc.json index 988fea1a2ec..05a17a5682f 100644 --- a/advisories/unreviewed/2022/12/GHSA-v7x7-wh72-mxcc/GHSA-v7x7-wh72-mxcc.json +++ b/advisories/unreviewed/2022/12/GHSA-v7x7-wh72-mxcc/GHSA-v7x7-wh72-mxcc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v7x7-wh72-mxcc", - "modified": "2022-12-06T15:30:30Z", + "modified": "2025-04-24T15:30:38Z", "published": "2022-12-05T06:30:21Z", "aliases": [ "CVE-2022-43487" diff --git a/advisories/unreviewed/2022/12/GHSA-vmww-v9wr-vr83/GHSA-vmww-v9wr-vr83.json b/advisories/unreviewed/2022/12/GHSA-vmww-v9wr-vr83/GHSA-vmww-v9wr-vr83.json index 6e2a4147d5d..f5788122df7 100644 --- a/advisories/unreviewed/2022/12/GHSA-vmww-v9wr-vr83/GHSA-vmww-v9wr-vr83.json +++ b/advisories/unreviewed/2022/12/GHSA-vmww-v9wr-vr83/GHSA-vmww-v9wr-vr83.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-vvq3-c7x5-w3gw/GHSA-vvq3-c7x5-w3gw.json b/advisories/unreviewed/2022/12/GHSA-vvq3-c7x5-w3gw/GHSA-vvq3-c7x5-w3gw.json index d08ba2fbd89..6e2af9e6da3 100644 --- a/advisories/unreviewed/2022/12/GHSA-vvq3-c7x5-w3gw/GHSA-vvq3-c7x5-w3gw.json +++ b/advisories/unreviewed/2022/12/GHSA-vvq3-c7x5-w3gw/GHSA-vvq3-c7x5-w3gw.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-vw5p-wqpx-xffp/GHSA-vw5p-wqpx-xffp.json b/advisories/unreviewed/2022/12/GHSA-vw5p-wqpx-xffp/GHSA-vw5p-wqpx-xffp.json index 2c70f144eb4..2585ff15123 100644 --- a/advisories/unreviewed/2022/12/GHSA-vw5p-wqpx-xffp/GHSA-vw5p-wqpx-xffp.json +++ b/advisories/unreviewed/2022/12/GHSA-vw5p-wqpx-xffp/GHSA-vw5p-wqpx-xffp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vw5p-wqpx-xffp", - "modified": "2022-12-08T15:30:24Z", + "modified": "2025-04-24T15:30:41Z", "published": "2022-12-05T21:30:41Z", "aliases": [ "CVE-2022-45481" diff --git a/advisories/unreviewed/2022/12/GHSA-w6h6-prfq-77c8/GHSA-w6h6-prfq-77c8.json b/advisories/unreviewed/2022/12/GHSA-w6h6-prfq-77c8/GHSA-w6h6-prfq-77c8.json index 7b32a72b925..ff60b107ff5 100644 --- a/advisories/unreviewed/2022/12/GHSA-w6h6-prfq-77c8/GHSA-w6h6-prfq-77c8.json +++ b/advisories/unreviewed/2022/12/GHSA-w6h6-prfq-77c8/GHSA-w6h6-prfq-77c8.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-276" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-whmx-4qfx-rgh5/GHSA-whmx-4qfx-rgh5.json b/advisories/unreviewed/2022/12/GHSA-whmx-4qfx-rgh5/GHSA-whmx-4qfx-rgh5.json index 1fb5e342c30..8a3ee513ccb 100644 --- a/advisories/unreviewed/2022/12/GHSA-whmx-4qfx-rgh5/GHSA-whmx-4qfx-rgh5.json +++ b/advisories/unreviewed/2022/12/GHSA-whmx-4qfx-rgh5/GHSA-whmx-4qfx-rgh5.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-306" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-wxhf-m7w8-4vjp/GHSA-wxhf-m7w8-4vjp.json b/advisories/unreviewed/2022/12/GHSA-wxhf-m7w8-4vjp/GHSA-wxhf-m7w8-4vjp.json index e3d38278670..27e246ff246 100644 --- a/advisories/unreviewed/2022/12/GHSA-wxhf-m7w8-4vjp/GHSA-wxhf-m7w8-4vjp.json +++ b/advisories/unreviewed/2022/12/GHSA-wxhf-m7w8-4vjp/GHSA-wxhf-m7w8-4vjp.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-131", "CWE-787" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/12/GHSA-x3f7-g9wc-xxpj/GHSA-x3f7-g9wc-xxpj.json b/advisories/unreviewed/2022/12/GHSA-x3f7-g9wc-xxpj/GHSA-x3f7-g9wc-xxpj.json index dab1df9b548..663c818c381 100644 --- a/advisories/unreviewed/2022/12/GHSA-x3f7-g9wc-xxpj/GHSA-x3f7-g9wc-xxpj.json +++ b/advisories/unreviewed/2022/12/GHSA-x3f7-g9wc-xxpj/GHSA-x3f7-g9wc-xxpj.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-121", "CWE-787" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/12/GHSA-xc7c-j6xx-gfqj/GHSA-xc7c-j6xx-gfqj.json b/advisories/unreviewed/2022/12/GHSA-xc7c-j6xx-gfqj/GHSA-xc7c-j6xx-gfqj.json index fb03e9de7d5..3e33c25294f 100644 --- a/advisories/unreviewed/2022/12/GHSA-xc7c-j6xx-gfqj/GHSA-xc7c-j6xx-gfqj.json +++ b/advisories/unreviewed/2022/12/GHSA-xc7c-j6xx-gfqj/GHSA-xc7c-j6xx-gfqj.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/07/GHSA-6439-9fxj-fc35/GHSA-6439-9fxj-fc35.json b/advisories/unreviewed/2023/07/GHSA-6439-9fxj-fc35/GHSA-6439-9fxj-fc35.json index 9e9342218d6..2984eb4c21b 100644 --- a/advisories/unreviewed/2023/07/GHSA-6439-9fxj-fc35/GHSA-6439-9fxj-fc35.json +++ b/advisories/unreviewed/2023/07/GHSA-6439-9fxj-fc35/GHSA-6439-9fxj-fc35.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6439-9fxj-fc35", - "modified": "2024-04-04T05:30:48Z", + "modified": "2025-04-24T15:30:41Z", "published": "2023-07-06T19:24:05Z", "aliases": [ "CVE-2022-44039" diff --git a/advisories/unreviewed/2023/12/GHSA-3cp9-5473-gp87/GHSA-3cp9-5473-gp87.json b/advisories/unreviewed/2023/12/GHSA-3cp9-5473-gp87/GHSA-3cp9-5473-gp87.json index aea07980a28..08d597e8567 100644 --- a/advisories/unreviewed/2023/12/GHSA-3cp9-5473-gp87/GHSA-3cp9-5473-gp87.json +++ b/advisories/unreviewed/2023/12/GHSA-3cp9-5473-gp87/GHSA-3cp9-5473-gp87.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-5fxg-7vxp-3w6q/GHSA-5fxg-7vxp-3w6q.json b/advisories/unreviewed/2024/03/GHSA-5fxg-7vxp-3w6q/GHSA-5fxg-7vxp-3w6q.json index 21b2d7a04f2..5b1102e66d5 100644 --- a/advisories/unreviewed/2024/03/GHSA-5fxg-7vxp-3w6q/GHSA-5fxg-7vxp-3w6q.json +++ b/advisories/unreviewed/2024/03/GHSA-5fxg-7vxp-3w6q/GHSA-5fxg-7vxp-3w6q.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-918" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-crh9-vmx5-ggr8/GHSA-crh9-vmx5-ggr8.json b/advisories/unreviewed/2024/11/GHSA-crh9-vmx5-ggr8/GHSA-crh9-vmx5-ggr8.json index b136afcfeca..42a679f140e 100644 --- a/advisories/unreviewed/2024/11/GHSA-crh9-vmx5-ggr8/GHSA-crh9-vmx5-ggr8.json +++ b/advisories/unreviewed/2024/11/GHSA-crh9-vmx5-ggr8/GHSA-crh9-vmx5-ggr8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-crh9-vmx5-ggr8", - "modified": "2024-11-19T15:31:53Z", + "modified": "2025-04-24T15:30:48Z", "published": "2024-11-19T15:31:53Z", "aliases": [ "CVE-2024-52675" ], "details": "SourceCodester Sentiment Based Movie Rating System 1.0 is vulnerable to SQL Injection in /msrps/movies.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T13:15:04Z" diff --git a/advisories/unreviewed/2025/04/GHSA-3p2x-hfrr-wj4w/GHSA-3p2x-hfrr-wj4w.json b/advisories/unreviewed/2025/04/GHSA-3p2x-hfrr-wj4w/GHSA-3p2x-hfrr-wj4w.json new file mode 100644 index 00000000000..022d7f1d320 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3p2x-hfrr-wj4w/GHSA-3p2x-hfrr-wj4w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3p2x-hfrr-wj4w", + "modified": "2025-04-24T15:30:49Z", + "published": "2025-04-24T15:30:49Z", + "aliases": [ + "CVE-2025-30409" + ], + "details": "Denial of service due to allocation of resources without limits. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39904.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30409" + }, + { + "type": "WEB", + "url": "https://security-advisory.acronis.com/advisories/SEC-8148" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-24T14:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4735-w7g7-ghx3/GHSA-4735-w7g7-ghx3.json b/advisories/unreviewed/2025/04/GHSA-4735-w7g7-ghx3/GHSA-4735-w7g7-ghx3.json index 81d43ebd853..04948be2144 100644 --- a/advisories/unreviewed/2025/04/GHSA-4735-w7g7-ghx3/GHSA-4735-w7g7-ghx3.json +++ b/advisories/unreviewed/2025/04/GHSA-4735-w7g7-ghx3/GHSA-4735-w7g7-ghx3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4735-w7g7-ghx3", - "modified": "2025-04-24T06:30:31Z", + "modified": "2025-04-24T15:30:49Z", "published": "2025-04-24T06:30:31Z", "aliases": [ "CVE-2025-2558" ], "details": "The-wound WordPress theme through 0.0.1 does not validate some parameters before using them to generate paths passed to include function/s, allowing unauthenticated users to perform LFI attacks and download arbitrary file from the server", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-24T06:15:45Z" diff --git a/advisories/unreviewed/2025/04/GHSA-4mxw-7rp7-fhjr/GHSA-4mxw-7rp7-fhjr.json b/advisories/unreviewed/2025/04/GHSA-4mxw-7rp7-fhjr/GHSA-4mxw-7rp7-fhjr.json index 1bedbd1e9ce..3637b643216 100644 --- a/advisories/unreviewed/2025/04/GHSA-4mxw-7rp7-fhjr/GHSA-4mxw-7rp7-fhjr.json +++ b/advisories/unreviewed/2025/04/GHSA-4mxw-7rp7-fhjr/GHSA-4mxw-7rp7-fhjr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-53rh-xg3h-r59m/GHSA-53rh-xg3h-r59m.json b/advisories/unreviewed/2025/04/GHSA-53rh-xg3h-r59m/GHSA-53rh-xg3h-r59m.json new file mode 100644 index 00000000000..d0fc2abbf89 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-53rh-xg3h-r59m/GHSA-53rh-xg3h-r59m.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-53rh-xg3h-r59m", + "modified": "2025-04-24T15:30:49Z", + "published": "2025-04-24T15:30:49Z", + "aliases": [ + "CVE-2025-44135" + ], + "details": "A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0 in /Scheduling/pages/profile_update.php. Manipulating the parameter username will cause SQL injection attacks.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44135" + }, + { + "type": "WEB", + "url": "https://github.com/secloverwang/-Vulnerability-recurrence/issues/4" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-24T15:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-73m2-qfq3-56cx/GHSA-73m2-qfq3-56cx.json b/advisories/unreviewed/2025/04/GHSA-73m2-qfq3-56cx/GHSA-73m2-qfq3-56cx.json index b55785ebb1d..74af6d18b19 100644 --- a/advisories/unreviewed/2025/04/GHSA-73m2-qfq3-56cx/GHSA-73m2-qfq3-56cx.json +++ b/advisories/unreviewed/2025/04/GHSA-73m2-qfq3-56cx/GHSA-73m2-qfq3-56cx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-73m2-qfq3-56cx", - "modified": "2025-04-24T12:31:28Z", + "modified": "2025-04-24T15:30:49Z", "published": "2025-04-24T12:31:28Z", "aliases": [ "CVE-2025-27820" ], "details": "A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-295" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-24T12:15:16Z" diff --git a/advisories/unreviewed/2025/04/GHSA-7rg2-x652-w37x/GHSA-7rg2-x652-w37x.json b/advisories/unreviewed/2025/04/GHSA-7rg2-x652-w37x/GHSA-7rg2-x652-w37x.json new file mode 100644 index 00000000000..6f1641bcf5f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7rg2-x652-w37x/GHSA-7rg2-x652-w37x.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7rg2-x652-w37x", + "modified": "2025-04-24T15:30:49Z", + "published": "2025-04-24T15:30:49Z", + "aliases": [ + "CVE-2025-29568" + ], + "details": "A vulnerability has been discovered in the code-projects Online Class and Exam Scheduling System 1.0. The issue affects some unknown features in the file /Scheduling/pages/class_sched.php. Manipulating the class parameter can lead to cross-site scripting (XSS).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29568" + }, + { + "type": "WEB", + "url": "https://github.com/secloverwang/-Vulnerability-recurrence/issues/1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-24T15:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cgw5-xrp3-wfg5/GHSA-cgw5-xrp3-wfg5.json b/advisories/unreviewed/2025/04/GHSA-cgw5-xrp3-wfg5/GHSA-cgw5-xrp3-wfg5.json new file mode 100644 index 00000000000..029a2ab2833 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cgw5-xrp3-wfg5/GHSA-cgw5-xrp3-wfg5.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cgw5-xrp3-wfg5", + "modified": "2025-04-24T15:30:49Z", + "published": "2025-04-24T15:30:49Z", + "aliases": [ + "CVE-2025-44134" + ], + "details": "A vulnerability was found in Code-Projects Online Class and Exam Scheduling System 1.0 in the file /Scheduling/pages/class_save.php. Manipulation of parameter class will lead to SQL injection attacks.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44134" + }, + { + "type": "WEB", + "url": "https://github.com/secloverwang/-Vulnerability-recurrence/issues/3" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-24T15:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gfc5-vx7h-qx8m/GHSA-gfc5-vx7h-qx8m.json b/advisories/unreviewed/2025/04/GHSA-gfc5-vx7h-qx8m/GHSA-gfc5-vx7h-qx8m.json index 673aacfd713..fe5a6648c8b 100644 --- a/advisories/unreviewed/2025/04/GHSA-gfc5-vx7h-qx8m/GHSA-gfc5-vx7h-qx8m.json +++ b/advisories/unreviewed/2025/04/GHSA-gfc5-vx7h-qx8m/GHSA-gfc5-vx7h-qx8m.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-p8xc-w865-2hhr/GHSA-p8xc-w865-2hhr.json b/advisories/unreviewed/2025/04/GHSA-p8xc-w865-2hhr/GHSA-p8xc-w865-2hhr.json index 3b75f75b079..e527ca63608 100644 --- a/advisories/unreviewed/2025/04/GHSA-p8xc-w865-2hhr/GHSA-p8xc-w865-2hhr.json +++ b/advisories/unreviewed/2025/04/GHSA-p8xc-w865-2hhr/GHSA-p8xc-w865-2hhr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p8xc-w865-2hhr", - "modified": "2025-04-23T21:30:35Z", + "modified": "2025-04-24T15:30:49Z", "published": "2025-04-23T21:30:35Z", "aliases": [ "CVE-2025-28169" ], "details": "BYD QIN PLUS DM-i Dilink OS v3.0_13.1.7.2204050.1 to v3.0_13.1.7.2312290.1_0 was discovered to cend broadcasts to the manufacturer's cloud server unencrypted, allowing attackers to execute a man-in-the-middle attack.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-295" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-23T20:15:43Z" diff --git a/advisories/unreviewed/2025/04/GHSA-pr7v-prvv-52v8/GHSA-pr7v-prvv-52v8.json b/advisories/unreviewed/2025/04/GHSA-pr7v-prvv-52v8/GHSA-pr7v-prvv-52v8.json new file mode 100644 index 00000000000..97693441b3b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pr7v-prvv-52v8/GHSA-pr7v-prvv-52v8.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pr7v-prvv-52v8", + "modified": "2025-04-24T15:30:49Z", + "published": "2025-04-24T15:30:49Z", + "aliases": [ + "CVE-2025-46421" + ], + "details": "A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the redirection points to. This allows the new host to impersonate the user to the original host that issued the redirect.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46421" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-46421" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2361962" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-24T13:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pv37-78jj-hvqv/GHSA-pv37-78jj-hvqv.json b/advisories/unreviewed/2025/04/GHSA-pv37-78jj-hvqv/GHSA-pv37-78jj-hvqv.json new file mode 100644 index 00000000000..01723047074 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pv37-78jj-hvqv/GHSA-pv37-78jj-hvqv.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pv37-78jj-hvqv", + "modified": "2025-04-24T15:30:49Z", + "published": "2025-04-24T15:30:49Z", + "aliases": [ + "CVE-2025-46420" + ], + "details": "A flaw was found in libsoup. It is vulnerable to memory leaks in the soup_header_parse_quality_list() function when parsing a quality list that contains elements with all zeroes.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46420" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-46420" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2361963" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-24T13:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-q4cq-9g5r-5fvx/GHSA-q4cq-9g5r-5fvx.json b/advisories/unreviewed/2025/04/GHSA-q4cq-9g5r-5fvx/GHSA-q4cq-9g5r-5fvx.json new file mode 100644 index 00000000000..0e4bd1fd41d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-q4cq-9g5r-5fvx/GHSA-q4cq-9g5r-5fvx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q4cq-9g5r-5fvx", + "modified": "2025-04-24T15:30:49Z", + "published": "2025-04-24T15:30:49Z", + "aliases": [ + "CVE-2025-30408" + ], + "details": "Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39904.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30408" + }, + { + "type": "WEB", + "url": "https://security-advisory.acronis.com/advisories/SEC-8035" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-24T14:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-q746-mv6h-3fx6/GHSA-q746-mv6h-3fx6.json b/advisories/unreviewed/2025/04/GHSA-q746-mv6h-3fx6/GHSA-q746-mv6h-3fx6.json index 503ca3b7279..9de10c12166 100644 --- a/advisories/unreviewed/2025/04/GHSA-q746-mv6h-3fx6/GHSA-q746-mv6h-3fx6.json +++ b/advisories/unreviewed/2025/04/GHSA-q746-mv6h-3fx6/GHSA-q746-mv6h-3fx6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q746-mv6h-3fx6", - "modified": "2025-04-24T06:30:31Z", + "modified": "2025-04-24T15:30:49Z", "published": "2025-04-24T06:30:31Z", "aliases": [ "CVE-2025-1453" ], "details": "The Category Posts Widget WordPress plugin before 4.9.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-24T06:15:43Z" diff --git a/advisories/unreviewed/2025/04/GHSA-qgrf-8g4m-4v9p/GHSA-qgrf-8g4m-4v9p.json b/advisories/unreviewed/2025/04/GHSA-qgrf-8g4m-4v9p/GHSA-qgrf-8g4m-4v9p.json index 3eb5f4caf96..af288254d21 100644 --- a/advisories/unreviewed/2025/04/GHSA-qgrf-8g4m-4v9p/GHSA-qgrf-8g4m-4v9p.json +++ b/advisories/unreviewed/2025/04/GHSA-qgrf-8g4m-4v9p/GHSA-qgrf-8g4m-4v9p.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false,