diff --git a/advisories/github-reviewed/2024/10/GHSA-3h3x-2hwv-hr52/GHSA-3h3x-2hwv-hr52.json b/advisories/github-reviewed/2024/10/GHSA-3h3x-2hwv-hr52/GHSA-3h3x-2hwv-hr52.json index 94ba13d0460..a4fd8dc455e 100644 --- a/advisories/github-reviewed/2024/10/GHSA-3h3x-2hwv-hr52/GHSA-3h3x-2hwv-hr52.json +++ b/advisories/github-reviewed/2024/10/GHSA-3h3x-2hwv-hr52/GHSA-3h3x-2hwv-hr52.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3h3x-2hwv-hr52", - "modified": "2025-05-13T21:30:27Z", + "modified": "2025-05-14T18:30:40Z", "published": "2024-10-01T21:31:34Z", "aliases": [ "CVE-2024-9355" @@ -68,6 +68,10 @@ "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-9355" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7624" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:7256" diff --git a/advisories/unreviewed/2022/10/GHSA-2v7r-pp26-r79c/GHSA-2v7r-pp26-r79c.json b/advisories/unreviewed/2022/10/GHSA-2v7r-pp26-r79c/GHSA-2v7r-pp26-r79c.json index 7cdc9d970ad..57c21aa677a 100644 --- a/advisories/unreviewed/2022/10/GHSA-2v7r-pp26-r79c/GHSA-2v7r-pp26-r79c.json +++ b/advisories/unreviewed/2022/10/GHSA-2v7r-pp26-r79c/GHSA-2v7r-pp26-r79c.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-787" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/10/GHSA-3vc7-6p5r-wcm4/GHSA-3vc7-6p5r-wcm4.json b/advisories/unreviewed/2022/10/GHSA-3vc7-6p5r-wcm4/GHSA-3vc7-6p5r-wcm4.json index c79812c1bc4..b1e01df5461 100644 --- a/advisories/unreviewed/2022/10/GHSA-3vc7-6p5r-wcm4/GHSA-3vc7-6p5r-wcm4.json +++ b/advisories/unreviewed/2022/10/GHSA-3vc7-6p5r-wcm4/GHSA-3vc7-6p5r-wcm4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3vc7-6p5r-wcm4", - "modified": "2022-10-15T12:00:54Z", + "modified": "2025-05-14T18:30:34Z", "published": "2022-10-14T19:00:40Z", "aliases": [ "CVE-2022-42066" diff --git a/advisories/unreviewed/2022/10/GHSA-662p-8mx9-xvc4/GHSA-662p-8mx9-xvc4.json b/advisories/unreviewed/2022/10/GHSA-662p-8mx9-xvc4/GHSA-662p-8mx9-xvc4.json index 84865d5b8f8..cc69b976a0f 100644 --- a/advisories/unreviewed/2022/10/GHSA-662p-8mx9-xvc4/GHSA-662p-8mx9-xvc4.json +++ b/advisories/unreviewed/2022/10/GHSA-662p-8mx9-xvc4/GHSA-662p-8mx9-xvc4.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-400", "CWE-787" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/10/GHSA-7443-rx53-4v58/GHSA-7443-rx53-4v58.json b/advisories/unreviewed/2022/10/GHSA-7443-rx53-4v58/GHSA-7443-rx53-4v58.json index b547e0936c4..1bcea3b7970 100644 --- a/advisories/unreviewed/2022/10/GHSA-7443-rx53-4v58/GHSA-7443-rx53-4v58.json +++ b/advisories/unreviewed/2022/10/GHSA-7443-rx53-4v58/GHSA-7443-rx53-4v58.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-400", "CWE-787" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/10/GHSA-8hxv-4x2j-cj7g/GHSA-8hxv-4x2j-cj7g.json b/advisories/unreviewed/2022/10/GHSA-8hxv-4x2j-cj7g/GHSA-8hxv-4x2j-cj7g.json index 93949e0deb9..b9cdd6ceeb9 100644 --- a/advisories/unreviewed/2022/10/GHSA-8hxv-4x2j-cj7g/GHSA-8hxv-4x2j-cj7g.json +++ b/advisories/unreviewed/2022/10/GHSA-8hxv-4x2j-cj7g/GHSA-8hxv-4x2j-cj7g.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-787" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/10/GHSA-fh77-7rc7-3797/GHSA-fh77-7rc7-3797.json b/advisories/unreviewed/2022/10/GHSA-fh77-7rc7-3797/GHSA-fh77-7rc7-3797.json index e2190d91abe..e374683fc71 100644 --- a/advisories/unreviewed/2022/10/GHSA-fh77-7rc7-3797/GHSA-fh77-7rc7-3797.json +++ b/advisories/unreviewed/2022/10/GHSA-fh77-7rc7-3797/GHSA-fh77-7rc7-3797.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-400", "CWE-787" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/10/GHSA-fwrg-4qc6-4q9c/GHSA-fwrg-4qc6-4q9c.json b/advisories/unreviewed/2022/10/GHSA-fwrg-4qc6-4q9c/GHSA-fwrg-4qc6-4q9c.json index 1a607850b0b..9911ed6e88f 100644 --- a/advisories/unreviewed/2022/10/GHSA-fwrg-4qc6-4q9c/GHSA-fwrg-4qc6-4q9c.json +++ b/advisories/unreviewed/2022/10/GHSA-fwrg-4qc6-4q9c/GHSA-fwrg-4qc6-4q9c.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-400", "CWE-787" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/10/GHSA-h8r9-x743-rhhc/GHSA-h8r9-x743-rhhc.json b/advisories/unreviewed/2022/10/GHSA-h8r9-x743-rhhc/GHSA-h8r9-x743-rhhc.json index 419fd697772..f5f36a929ce 100644 --- a/advisories/unreviewed/2022/10/GHSA-h8r9-x743-rhhc/GHSA-h8r9-x743-rhhc.json +++ b/advisories/unreviewed/2022/10/GHSA-h8r9-x743-rhhc/GHSA-h8r9-x743-rhhc.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-352" + "CWE-352", + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/10/GHSA-hc6j-mmwg-vmww/GHSA-hc6j-mmwg-vmww.json b/advisories/unreviewed/2022/10/GHSA-hc6j-mmwg-vmww/GHSA-hc6j-mmwg-vmww.json index c69b01137ea..124f8799f30 100644 --- a/advisories/unreviewed/2022/10/GHSA-hc6j-mmwg-vmww/GHSA-hc6j-mmwg-vmww.json +++ b/advisories/unreviewed/2022/10/GHSA-hc6j-mmwg-vmww/GHSA-hc6j-mmwg-vmww.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-400", "CWE-787" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/10/GHSA-m824-p6mx-3cw8/GHSA-m824-p6mx-3cw8.json b/advisories/unreviewed/2022/10/GHSA-m824-p6mx-3cw8/GHSA-m824-p6mx-3cw8.json index d6716ebebc6..00a627861b2 100644 --- a/advisories/unreviewed/2022/10/GHSA-m824-p6mx-3cw8/GHSA-m824-p6mx-3cw8.json +++ b/advisories/unreviewed/2022/10/GHSA-m824-p6mx-3cw8/GHSA-m824-p6mx-3cw8.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-400", "CWE-787" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/10/GHSA-q44h-82rg-2gpv/GHSA-q44h-82rg-2gpv.json b/advisories/unreviewed/2022/10/GHSA-q44h-82rg-2gpv/GHSA-q44h-82rg-2gpv.json index 8eb09e6efb1..33eecf9fee4 100644 --- a/advisories/unreviewed/2022/10/GHSA-q44h-82rg-2gpv/GHSA-q44h-82rg-2gpv.json +++ b/advisories/unreviewed/2022/10/GHSA-q44h-82rg-2gpv/GHSA-q44h-82rg-2gpv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q44h-82rg-2gpv", - "modified": "2022-10-15T12:00:55Z", + "modified": "2025-05-14T18:30:34Z", "published": "2022-10-14T19:00:39Z", "aliases": [ "CVE-2022-41598" diff --git a/advisories/unreviewed/2022/10/GHSA-qm62-5pc4-c833/GHSA-qm62-5pc4-c833.json b/advisories/unreviewed/2022/10/GHSA-qm62-5pc4-c833/GHSA-qm62-5pc4-c833.json index e91fd2f1d2f..2def3f0d343 100644 --- a/advisories/unreviewed/2022/10/GHSA-qm62-5pc4-c833/GHSA-qm62-5pc4-c833.json +++ b/advisories/unreviewed/2022/10/GHSA-qm62-5pc4-c833/GHSA-qm62-5pc4-c833.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qm62-5pc4-c833", - "modified": "2022-10-18T19:00:32Z", + "modified": "2025-05-14T18:30:34Z", "published": "2022-10-14T19:00:39Z", "aliases": [ "CVE-2022-41589" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-703" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/07/GHSA-ppw7-v579-v4cr/GHSA-ppw7-v579-v4cr.json b/advisories/unreviewed/2023/07/GHSA-ppw7-v579-v4cr/GHSA-ppw7-v579-v4cr.json index c5ef29a6a3b..06b5fd0d8ae 100644 --- a/advisories/unreviewed/2023/07/GHSA-ppw7-v579-v4cr/GHSA-ppw7-v579-v4cr.json +++ b/advisories/unreviewed/2023/07/GHSA-ppw7-v579-v4cr/GHSA-ppw7-v579-v4cr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ppw7-v579-v4cr", - "modified": "2023-07-06T19:24:01Z", + "modified": "2025-05-14T18:30:34Z", "published": "2023-07-06T19:24:01Z", "aliases": [ "CVE-2022-32177" diff --git a/advisories/unreviewed/2024/04/GHSA-27hf-w6wm-652c/GHSA-27hf-w6wm-652c.json b/advisories/unreviewed/2024/04/GHSA-27hf-w6wm-652c/GHSA-27hf-w6wm-652c.json index 3003f78ba1f..8a231051b43 100644 --- a/advisories/unreviewed/2024/04/GHSA-27hf-w6wm-652c/GHSA-27hf-w6wm-652c.json +++ b/advisories/unreviewed/2024/04/GHSA-27hf-w6wm-652c/GHSA-27hf-w6wm-652c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-27hf-w6wm-652c", - "modified": "2024-07-08T15:31:54Z", + "modified": "2025-05-14T18:30:37Z", "published": "2024-04-26T06:30:35Z", "aliases": [ "CVE-2024-3188" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-9vvr-3g53-9w72/GHSA-9vvr-3g53-9w72.json b/advisories/unreviewed/2024/04/GHSA-9vvr-3g53-9w72/GHSA-9vvr-3g53-9w72.json index ba528b1eb6c..1a62a9fd852 100644 --- a/advisories/unreviewed/2024/04/GHSA-9vvr-3g53-9w72/GHSA-9vvr-3g53-9w72.json +++ b/advisories/unreviewed/2024/04/GHSA-9vvr-3g53-9w72/GHSA-9vvr-3g53-9w72.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-3563-pvjf-xg5g/GHSA-3563-pvjf-xg5g.json b/advisories/unreviewed/2024/05/GHSA-3563-pvjf-xg5g/GHSA-3563-pvjf-xg5g.json index de16c42f022..dd225ffe473 100644 --- a/advisories/unreviewed/2024/05/GHSA-3563-pvjf-xg5g/GHSA-3563-pvjf-xg5g.json +++ b/advisories/unreviewed/2024/05/GHSA-3563-pvjf-xg5g/GHSA-3563-pvjf-xg5g.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-928w-mwq7-xvqr/GHSA-928w-mwq7-xvqr.json b/advisories/unreviewed/2024/05/GHSA-928w-mwq7-xvqr/GHSA-928w-mwq7-xvqr.json index f760a1fd3f0..0fe5c34935a 100644 --- a/advisories/unreviewed/2024/05/GHSA-928w-mwq7-xvqr/GHSA-928w-mwq7-xvqr.json +++ b/advisories/unreviewed/2024/05/GHSA-928w-mwq7-xvqr/GHSA-928w-mwq7-xvqr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-c8wr-mrmh-hrhr/GHSA-c8wr-mrmh-hrhr.json b/advisories/unreviewed/2024/05/GHSA-c8wr-mrmh-hrhr/GHSA-c8wr-mrmh-hrhr.json index 1b21ce76bfb..df90e43618e 100644 --- a/advisories/unreviewed/2024/05/GHSA-c8wr-mrmh-hrhr/GHSA-c8wr-mrmh-hrhr.json +++ b/advisories/unreviewed/2024/05/GHSA-c8wr-mrmh-hrhr/GHSA-c8wr-mrmh-hrhr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-hpj4-v4gg-8xfh/GHSA-hpj4-v4gg-8xfh.json b/advisories/unreviewed/2024/05/GHSA-hpj4-v4gg-8xfh/GHSA-hpj4-v4gg-8xfh.json index 84d0b733067..ad9a204ab30 100644 --- a/advisories/unreviewed/2024/05/GHSA-hpj4-v4gg-8xfh/GHSA-hpj4-v4gg-8xfh.json +++ b/advisories/unreviewed/2024/05/GHSA-hpj4-v4gg-8xfh/GHSA-hpj4-v4gg-8xfh.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-q5vv-mwvr-xxrx/GHSA-q5vv-mwvr-xxrx.json b/advisories/unreviewed/2024/05/GHSA-q5vv-mwvr-xxrx/GHSA-q5vv-mwvr-xxrx.json index f3b0a749b54..53997a82167 100644 --- a/advisories/unreviewed/2024/05/GHSA-q5vv-mwvr-xxrx/GHSA-q5vv-mwvr-xxrx.json +++ b/advisories/unreviewed/2024/05/GHSA-q5vv-mwvr-xxrx/GHSA-q5vv-mwvr-xxrx.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-6vqg-wm4f-f8vx/GHSA-6vqg-wm4f-f8vx.json b/advisories/unreviewed/2024/11/GHSA-6vqg-wm4f-f8vx/GHSA-6vqg-wm4f-f8vx.json index 8bc7909c30d..8c24e362b15 100644 --- a/advisories/unreviewed/2024/11/GHSA-6vqg-wm4f-f8vx/GHSA-6vqg-wm4f-f8vx.json +++ b/advisories/unreviewed/2024/11/GHSA-6vqg-wm4f-f8vx/GHSA-6vqg-wm4f-f8vx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6vqg-wm4f-f8vx", - "modified": "2024-12-06T21:30:37Z", + "modified": "2025-05-14T18:30:40Z", "published": "2024-11-26T12:41:37Z", "aliases": [ "CVE-2024-38832" diff --git a/advisories/unreviewed/2024/11/GHSA-m2m4-2g99-6625/GHSA-m2m4-2g99-6625.json b/advisories/unreviewed/2024/11/GHSA-m2m4-2g99-6625/GHSA-m2m4-2g99-6625.json index d17fcac3026..239116baa96 100644 --- a/advisories/unreviewed/2024/11/GHSA-m2m4-2g99-6625/GHSA-m2m4-2g99-6625.json +++ b/advisories/unreviewed/2024/11/GHSA-m2m4-2g99-6625/GHSA-m2m4-2g99-6625.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m2m4-2g99-6625", - "modified": "2024-12-06T21:30:37Z", + "modified": "2025-05-14T18:30:40Z", "published": "2024-11-26T12:41:37Z", "aliases": [ "CVE-2024-38834" diff --git a/advisories/unreviewed/2024/11/GHSA-mff4-qp47-8h8q/GHSA-mff4-qp47-8h8q.json b/advisories/unreviewed/2024/11/GHSA-mff4-qp47-8h8q/GHSA-mff4-qp47-8h8q.json index e519f4d4780..adf677c6dd7 100644 --- a/advisories/unreviewed/2024/11/GHSA-mff4-qp47-8h8q/GHSA-mff4-qp47-8h8q.json +++ b/advisories/unreviewed/2024/11/GHSA-mff4-qp47-8h8q/GHSA-mff4-qp47-8h8q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mff4-qp47-8h8q", - "modified": "2024-12-06T21:30:37Z", + "modified": "2025-05-14T18:30:40Z", "published": "2024-11-26T12:41:37Z", "aliases": [ "CVE-2024-38833" diff --git a/advisories/unreviewed/2024/12/GHSA-j94m-533w-g94g/GHSA-j94m-533w-g94g.json b/advisories/unreviewed/2024/12/GHSA-j94m-533w-g94g/GHSA-j94m-533w-g94g.json index c580da1645b..a33858ac1b2 100644 --- a/advisories/unreviewed/2024/12/GHSA-j94m-533w-g94g/GHSA-j94m-533w-g94g.json +++ b/advisories/unreviewed/2024/12/GHSA-j94m-533w-g94g/GHSA-j94m-533w-g94g.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-5gvr-6wv7-hpcv/GHSA-5gvr-6wv7-hpcv.json b/advisories/unreviewed/2025/01/GHSA-5gvr-6wv7-hpcv/GHSA-5gvr-6wv7-hpcv.json index 24bf7be09af..1e15dede72a 100644 --- a/advisories/unreviewed/2025/01/GHSA-5gvr-6wv7-hpcv/GHSA-5gvr-6wv7-hpcv.json +++ b/advisories/unreviewed/2025/01/GHSA-5gvr-6wv7-hpcv/GHSA-5gvr-6wv7-hpcv.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-72qg-x4rx-vrx3/GHSA-72qg-x4rx-vrx3.json b/advisories/unreviewed/2025/01/GHSA-72qg-x4rx-vrx3/GHSA-72qg-x4rx-vrx3.json index 9bcd27d4f16..f0c680483ea 100644 --- a/advisories/unreviewed/2025/01/GHSA-72qg-x4rx-vrx3/GHSA-72qg-x4rx-vrx3.json +++ b/advisories/unreviewed/2025/01/GHSA-72qg-x4rx-vrx3/GHSA-72qg-x4rx-vrx3.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-9h7m-pf82-g666/GHSA-9h7m-pf82-g666.json b/advisories/unreviewed/2025/01/GHSA-9h7m-pf82-g666/GHSA-9h7m-pf82-g666.json index 04d922945f6..874805984b3 100644 --- a/advisories/unreviewed/2025/01/GHSA-9h7m-pf82-g666/GHSA-9h7m-pf82-g666.json +++ b/advisories/unreviewed/2025/01/GHSA-9h7m-pf82-g666/GHSA-9h7m-pf82-g666.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9h7m-pf82-g666", - "modified": "2025-03-13T15:32:45Z", + "modified": "2025-05-14T18:30:44Z", "published": "2025-01-30T18:32:07Z", "aliases": [ "CVE-2025-22222" diff --git a/advisories/unreviewed/2025/01/GHSA-j5gv-mwmr-ppp5/GHSA-j5gv-mwmr-ppp5.json b/advisories/unreviewed/2025/01/GHSA-j5gv-mwmr-ppp5/GHSA-j5gv-mwmr-ppp5.json index df13b828c8c..0d4a3ef4296 100644 --- a/advisories/unreviewed/2025/01/GHSA-j5gv-mwmr-ppp5/GHSA-j5gv-mwmr-ppp5.json +++ b/advisories/unreviewed/2025/01/GHSA-j5gv-mwmr-ppp5/GHSA-j5gv-mwmr-ppp5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j5gv-mwmr-ppp5", - "modified": "2025-03-13T18:32:17Z", + "modified": "2025-05-14T18:30:44Z", "published": "2025-01-30T18:32:07Z", "aliases": [ "CVE-2025-22219" diff --git a/advisories/unreviewed/2025/01/GHSA-m777-hj92-cw6q/GHSA-m777-hj92-cw6q.json b/advisories/unreviewed/2025/01/GHSA-m777-hj92-cw6q/GHSA-m777-hj92-cw6q.json index 2717909959e..0d4e6e18b87 100644 --- a/advisories/unreviewed/2025/01/GHSA-m777-hj92-cw6q/GHSA-m777-hj92-cw6q.json +++ b/advisories/unreviewed/2025/01/GHSA-m777-hj92-cw6q/GHSA-m777-hj92-cw6q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m777-hj92-cw6q", - "modified": "2025-02-06T15:32:52Z", + "modified": "2025-05-14T18:30:44Z", "published": "2025-01-30T18:32:07Z", "aliases": [ "CVE-2025-22220" diff --git a/advisories/unreviewed/2025/01/GHSA-p52h-3642-m4x3/GHSA-p52h-3642-m4x3.json b/advisories/unreviewed/2025/01/GHSA-p52h-3642-m4x3/GHSA-p52h-3642-m4x3.json index 37bd7fa6a0c..a5ad52fc910 100644 --- a/advisories/unreviewed/2025/01/GHSA-p52h-3642-m4x3/GHSA-p52h-3642-m4x3.json +++ b/advisories/unreviewed/2025/01/GHSA-p52h-3642-m4x3/GHSA-p52h-3642-m4x3.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-qrcx-78jp-35gm/GHSA-qrcx-78jp-35gm.json b/advisories/unreviewed/2025/01/GHSA-qrcx-78jp-35gm/GHSA-qrcx-78jp-35gm.json index 7b090d6f4e0..dd7752e1614 100644 --- a/advisories/unreviewed/2025/01/GHSA-qrcx-78jp-35gm/GHSA-qrcx-78jp-35gm.json +++ b/advisories/unreviewed/2025/01/GHSA-qrcx-78jp-35gm/GHSA-qrcx-78jp-35gm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qrcx-78jp-35gm", - "modified": "2025-03-13T15:32:45Z", + "modified": "2025-05-14T18:30:44Z", "published": "2025-01-30T18:32:07Z", "aliases": [ "CVE-2025-22221" diff --git a/advisories/unreviewed/2025/01/GHSA-x379-p5q2-7954/GHSA-x379-p5q2-7954.json b/advisories/unreviewed/2025/01/GHSA-x379-p5q2-7954/GHSA-x379-p5q2-7954.json index aaeea992145..16d037a75a1 100644 --- a/advisories/unreviewed/2025/01/GHSA-x379-p5q2-7954/GHSA-x379-p5q2-7954.json +++ b/advisories/unreviewed/2025/01/GHSA-x379-p5q2-7954/GHSA-x379-p5q2-7954.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x379-p5q2-7954", - "modified": "2025-03-13T18:32:16Z", + "modified": "2025-05-14T18:30:43Z", "published": "2025-01-30T15:31:39Z", "aliases": [ "CVE-2025-22218" diff --git a/advisories/unreviewed/2025/04/GHSA-h7mx-548v-cr9r/GHSA-h7mx-548v-cr9r.json b/advisories/unreviewed/2025/04/GHSA-h7mx-548v-cr9r/GHSA-h7mx-548v-cr9r.json index 137f258561c..6e0a66e55b4 100644 --- a/advisories/unreviewed/2025/04/GHSA-h7mx-548v-cr9r/GHSA-h7mx-548v-cr9r.json +++ b/advisories/unreviewed/2025/04/GHSA-h7mx-548v-cr9r/GHSA-h7mx-548v-cr9r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h7mx-548v-cr9r", - "modified": "2025-05-13T15:32:11Z", + "modified": "2025-05-14T18:30:45Z", "published": "2025-04-03T15:31:19Z", "aliases": [ "CVE-2025-3155" @@ -51,6 +51,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:7430" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7569" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-3155" diff --git a/advisories/unreviewed/2025/04/GHSA-jm2g-3f56-rvvh/GHSA-jm2g-3f56-rvvh.json b/advisories/unreviewed/2025/04/GHSA-jm2g-3f56-rvvh/GHSA-jm2g-3f56-rvvh.json index 16fdb7d2fef..4f5391af90e 100644 --- a/advisories/unreviewed/2025/04/GHSA-jm2g-3f56-rvvh/GHSA-jm2g-3f56-rvvh.json +++ b/advisories/unreviewed/2025/04/GHSA-jm2g-3f56-rvvh/GHSA-jm2g-3f56-rvvh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jm2g-3f56-rvvh", - "modified": "2025-04-23T12:31:25Z", + "modified": "2025-05-14T18:30:45Z", "published": "2025-04-23T12:31:25Z", "aliases": [ "CVE-2024-10306" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10306" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHBA-2025:5309" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-10306" diff --git a/advisories/unreviewed/2025/05/GHSA-332h-mhjm-x7jm/GHSA-332h-mhjm-x7jm.json b/advisories/unreviewed/2025/05/GHSA-332h-mhjm-x7jm/GHSA-332h-mhjm-x7jm.json new file mode 100644 index 00000000000..46b5551068c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-332h-mhjm-x7jm/GHSA-332h-mhjm-x7jm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-332h-mhjm-x7jm", + "modified": "2025-05-14T18:30:51Z", + "published": "2025-05-14T18:30:51Z", + "aliases": [ + "CVE-2025-4637" + ], + "details": "Divide By Zero vulnerability in davisking dlib allows \n\nremote attackers to cause a denial of service via a crafted file.\n\n.This issue affects dlib: before <19.24.7.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:D/RE:M/U:Amber" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4637" + }, + { + "type": "WEB", + "url": "https://github.com/davisking/dlib/pull/3058" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-369" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T18:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-422f-7vrg-37qx/GHSA-422f-7vrg-37qx.json b/advisories/unreviewed/2025/05/GHSA-422f-7vrg-37qx/GHSA-422f-7vrg-37qx.json index d01ff8c6639..86d29404cf0 100644 --- a/advisories/unreviewed/2025/05/GHSA-422f-7vrg-37qx/GHSA-422f-7vrg-37qx.json +++ b/advisories/unreviewed/2025/05/GHSA-422f-7vrg-37qx/GHSA-422f-7vrg-37qx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-422f-7vrg-37qx", - "modified": "2025-05-13T00:31:13Z", + "modified": "2025-05-14T18:30:45Z", "published": "2025-05-13T00:31:13Z", "aliases": [ "CVE-2025-30448" ], "details": "This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sonoma 14.7.6, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, visionOS 2.5, macOS Ventura 13.7.6, macOS Sequoia 15.4. An attacker may be able to turn on sharing of an iCloud folder without authentication.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-862" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:21Z" diff --git a/advisories/unreviewed/2025/05/GHSA-5r36-pxhw-fw6j/GHSA-5r36-pxhw-fw6j.json b/advisories/unreviewed/2025/05/GHSA-5r36-pxhw-fw6j/GHSA-5r36-pxhw-fw6j.json new file mode 100644 index 00000000000..f2a805dd55e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5r36-pxhw-fw6j/GHSA-5r36-pxhw-fw6j.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5r36-pxhw-fw6j", + "modified": "2025-05-14T18:30:47Z", + "published": "2025-05-14T18:30:47Z", + "aliases": [ + "CVE-2025-26784" + ], + "details": "An issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. The lack of a length check leads to out-of-bounds writes.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26784" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2025-26784" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T17:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-69m9-2g5j-9m4h/GHSA-69m9-2g5j-9m4h.json b/advisories/unreviewed/2025/05/GHSA-69m9-2g5j-9m4h/GHSA-69m9-2g5j-9m4h.json new file mode 100644 index 00000000000..7d9444d43fe --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-69m9-2g5j-9m4h/GHSA-69m9-2g5j-9m4h.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-69m9-2g5j-9m4h", + "modified": "2025-05-14T18:30:47Z", + "published": "2025-05-14T18:30:47Z", + "aliases": [ + "CVE-2025-3877" + ], + "details": "A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's desktop or home directory without prompting, even if auto-saving is disabled. This behavior can be abused to fill the disk with garbage data (e.g. using /dev/urandom on Linux) or to leak Windows credentials via SMB links when the email is viewed in HTML mode. While user interaction is required to download the .pdf file, visual obfuscation can conceal the download trigger. Viewing the email in HTML mode is enough to load external content. This vulnerability affects Thunderbird < 128.10.1 and Thunderbird < 138.0.1.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3877" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1958580" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-34" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-35" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T17:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6whp-h3pf-v3x5/GHSA-6whp-h3pf-v3x5.json b/advisories/unreviewed/2025/05/GHSA-6whp-h3pf-v3x5/GHSA-6whp-h3pf-v3x5.json new file mode 100644 index 00000000000..cfaedfd5fee --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6whp-h3pf-v3x5/GHSA-6whp-h3pf-v3x5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6whp-h3pf-v3x5", + "modified": "2025-05-14T18:30:51Z", + "published": "2025-05-14T18:30:51Z", + "aliases": [ + "CVE-2025-0130" + ], + "details": "A missing exception check in Palo Alto Networks PAN-OSĀ® software with the web proxy feature enabled allows an unauthenticated attacker to send a burst of maliciously crafted packets that causes the firewall to become unresponsive and eventually reboot. Repeated successful attempts to trigger this condition will cause the firewall to enter maintenance mode.\n\nThis issue does not affect Cloud NGFW or Prisma Access.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:L/U:Amber" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0130" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2025-0130" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-754" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T18:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7jmx-9c9v-p8w8/GHSA-7jmx-9c9v-p8w8.json b/advisories/unreviewed/2025/05/GHSA-7jmx-9c9v-p8w8/GHSA-7jmx-9c9v-p8w8.json new file mode 100644 index 00000000000..183a1b61bea --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7jmx-9c9v-p8w8/GHSA-7jmx-9c9v-p8w8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7jmx-9c9v-p8w8", + "modified": "2025-05-14T18:30:51Z", + "published": "2025-05-14T18:30:51Z", + "aliases": [ + "CVE-2025-4639" + ], + "details": "CWE-611 Improper Restriction of XML External Entity Reference in the getDocumentBuilder() method of WebDav servlet in Peergos. This issue affects Peergos through version 1.1.0.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4639" + }, + { + "type": "WEB", + "url": "https://github.com/Peergos/Peergos/pull/1267" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-611" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T18:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-98vp-fcq9-gmj3/GHSA-98vp-fcq9-gmj3.json b/advisories/unreviewed/2025/05/GHSA-98vp-fcq9-gmj3/GHSA-98vp-fcq9-gmj3.json new file mode 100644 index 00000000000..270312d1242 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-98vp-fcq9-gmj3/GHSA-98vp-fcq9-gmj3.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-98vp-fcq9-gmj3", + "modified": "2025-05-14T18:30:48Z", + "published": "2025-05-14T18:30:48Z", + "aliases": [ + "CVE-2025-40595" + ], + "details": "A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. By using an encoded URL, a remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40595" + }, + { + "type": "WEB", + "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0010" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T17:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9m42-x6rr-h5qc/GHSA-9m42-x6rr-h5qc.json b/advisories/unreviewed/2025/05/GHSA-9m42-x6rr-h5qc/GHSA-9m42-x6rr-h5qc.json new file mode 100644 index 00000000000..ee7fe00a239 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9m42-x6rr-h5qc/GHSA-9m42-x6rr-h5qc.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9m42-x6rr-h5qc", + "modified": "2025-05-14T18:30:48Z", + "published": "2025-05-14T18:30:48Z", + "aliases": [ + "CVE-2025-47701" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Drupal Restrict route by IP allows Cross Site Request Forgery.This issue affects Restrict route by IP: from 0.0.0 before 1.3.0.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47701" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-047" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T17:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9v48-2prj-rqc9/GHSA-9v48-2prj-rqc9.json b/advisories/unreviewed/2025/05/GHSA-9v48-2prj-rqc9/GHSA-9v48-2prj-rqc9.json index 26768c7021e..a830d3b3ae5 100644 --- a/advisories/unreviewed/2025/05/GHSA-9v48-2prj-rqc9/GHSA-9v48-2prj-rqc9.json +++ b/advisories/unreviewed/2025/05/GHSA-9v48-2prj-rqc9/GHSA-9v48-2prj-rqc9.json @@ -54,6 +54,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-190", "CWE-284" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/05/GHSA-9vxc-6m6g-68f3/GHSA-9vxc-6m6g-68f3.json b/advisories/unreviewed/2025/05/GHSA-9vxc-6m6g-68f3/GHSA-9vxc-6m6g-68f3.json index 2b2e7e1ec14..6ac26bbbe1a 100644 --- a/advisories/unreviewed/2025/05/GHSA-9vxc-6m6g-68f3/GHSA-9vxc-6m6g-68f3.json +++ b/advisories/unreviewed/2025/05/GHSA-9vxc-6m6g-68f3/GHSA-9vxc-6m6g-68f3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9vxc-6m6g-68f3", - "modified": "2025-05-13T00:31:12Z", + "modified": "2025-05-14T18:30:45Z", "published": "2025-05-13T00:31:12Z", "aliases": [ "CVE-2025-24142" ], "details": "A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. An app may be able to access sensitive user data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:19Z" diff --git a/advisories/unreviewed/2025/05/GHSA-fvmq-5x7q-w2cc/GHSA-fvmq-5x7q-w2cc.json b/advisories/unreviewed/2025/05/GHSA-fvmq-5x7q-w2cc/GHSA-fvmq-5x7q-w2cc.json new file mode 100644 index 00000000000..a61b89d3a5a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fvmq-5x7q-w2cc/GHSA-fvmq-5x7q-w2cc.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fvmq-5x7q-w2cc", + "modified": "2025-05-14T18:30:48Z", + "published": "2025-05-14T18:30:48Z", + "aliases": [ + "CVE-2025-44184" + ], + "details": "SourceCodester Best Employee Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/profile.php via the website_image, fname, lname, contact, username, and address parameters.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44184" + }, + { + "type": "WEB", + "url": "https://github.com/cumakurt/CVE-SourceCodester-Best-Employee-Management-System-1.0/blob/main/CVE-2025-44184-SourceCodester-Best-Employee-Management-System-1.0-Stored%20XSS.md" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com/php/17689/best-employee-management-system-php.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T17:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g9fx-4qg5-6rm4/GHSA-g9fx-4qg5-6rm4.json b/advisories/unreviewed/2025/05/GHSA-g9fx-4qg5-6rm4/GHSA-g9fx-4qg5-6rm4.json new file mode 100644 index 00000000000..56fd131d701 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g9fx-4qg5-6rm4/GHSA-g9fx-4qg5-6rm4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g9fx-4qg5-6rm4", + "modified": "2025-05-14T18:30:51Z", + "published": "2025-05-14T18:30:51Z", + "aliases": [ + "CVE-2025-30665" + ], + "details": "NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30665" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-25018" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T18:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gg5q-2fr6-4w8h/GHSA-gg5q-2fr6-4w8h.json b/advisories/unreviewed/2025/05/GHSA-gg5q-2fr6-4w8h/GHSA-gg5q-2fr6-4w8h.json new file mode 100644 index 00000000000..e4250bedf2b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gg5q-2fr6-4w8h/GHSA-gg5q-2fr6-4w8h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gg5q-2fr6-4w8h", + "modified": "2025-05-14T18:30:51Z", + "published": "2025-05-14T18:30:51Z", + "aliases": [ + "CVE-2025-30666" + ], + "details": "NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30666" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-25018" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T18:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gw9f-frr6-h3c2/GHSA-gw9f-frr6-h3c2.json b/advisories/unreviewed/2025/05/GHSA-gw9f-frr6-h3c2/GHSA-gw9f-frr6-h3c2.json new file mode 100644 index 00000000000..0c4c5632a8d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gw9f-frr6-h3c2/GHSA-gw9f-frr6-h3c2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gw9f-frr6-h3c2", + "modified": "2025-05-14T18:30:51Z", + "published": "2025-05-14T18:30:51Z", + "aliases": [ + "CVE-2025-30667" + ], + "details": "NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30667" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-25019" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T18:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h4mg-vgcw-h6r2/GHSA-h4mg-vgcw-h6r2.json b/advisories/unreviewed/2025/05/GHSA-h4mg-vgcw-h6r2/GHSA-h4mg-vgcw-h6r2.json new file mode 100644 index 00000000000..6423ed8ea21 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h4mg-vgcw-h6r2/GHSA-h4mg-vgcw-h6r2.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h4mg-vgcw-h6r2", + "modified": "2025-05-14T18:30:49Z", + "published": "2025-05-14T18:30:49Z", + "aliases": [ + "CVE-2025-47704" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Klaro Cookie & Consent Management allows Cross-Site Scripting (XSS).This issue affects Klaro Cookie & Consent Management: from 0.0.0 before 3.0.5.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47704" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-050" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T17:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h6cg-6m9j-xj9g/GHSA-h6cg-6m9j-xj9g.json b/advisories/unreviewed/2025/05/GHSA-h6cg-6m9j-xj9g/GHSA-h6cg-6m9j-xj9g.json new file mode 100644 index 00000000000..2d7063bdfa2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h6cg-6m9j-xj9g/GHSA-h6cg-6m9j-xj9g.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h6cg-6m9j-xj9g", + "modified": "2025-05-14T18:30:48Z", + "published": "2025-05-14T18:30:47Z", + "aliases": [ + "CVE-2025-3909" + ], + "details": "Thunderbird's handling of the X-Mozilla-External-Attachment-URL header can be exploited to execute JavaScript in the file:/// context. By crafting a nested email attachment (message/rfc822) and setting its content type to application/pdf, Thunderbird may incorrectly render it as HTML when opened, allowing the embedded JavaScript to run without requiring a file download. This behavior relies on Thunderbird auto-saving the attachment to /tmp and linking to it via the file:/// protocol, potentially enabling JavaScript execution as part of the HTML. This vulnerability affects Thunderbird < 128.10.1 and Thunderbird < 138.0.1.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3909" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1958376" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-34" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-35" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T17:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h6hm-v4gg-9cgp/GHSA-h6hm-v4gg-9cgp.json b/advisories/unreviewed/2025/05/GHSA-h6hm-v4gg-9cgp/GHSA-h6hm-v4gg-9cgp.json index efebbb4ff70..8ddaf43970d 100644 --- a/advisories/unreviewed/2025/05/GHSA-h6hm-v4gg-9cgp/GHSA-h6hm-v4gg-9cgp.json +++ b/advisories/unreviewed/2025/05/GHSA-h6hm-v4gg-9cgp/GHSA-h6hm-v4gg-9cgp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h6hm-v4gg-9cgp", - "modified": "2025-05-13T00:31:12Z", + "modified": "2025-05-14T18:30:45Z", "published": "2025-05-13T00:31:12Z", "aliases": [ "CVE-2025-30436" ], "details": "This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.4 and iPadOS 18.4. An attacker may be able to use Siri to enable Auto-Answer Calls.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:20Z" diff --git a/advisories/unreviewed/2025/05/GHSA-h8vr-q495-8mwj/GHSA-h8vr-q495-8mwj.json b/advisories/unreviewed/2025/05/GHSA-h8vr-q495-8mwj/GHSA-h8vr-q495-8mwj.json new file mode 100644 index 00000000000..a3221d08a38 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h8vr-q495-8mwj/GHSA-h8vr-q495-8mwj.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h8vr-q495-8mwj", + "modified": "2025-05-14T18:30:50Z", + "published": "2025-05-14T18:30:50Z", + "aliases": [ + "CVE-2025-47710" + ], + "details": "Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Authentication Bypass.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47710" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-056" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hc2g-hvv2-qxv7/GHSA-hc2g-hvv2-qxv7.json b/advisories/unreviewed/2025/05/GHSA-hc2g-hvv2-qxv7/GHSA-hc2g-hvv2-qxv7.json new file mode 100644 index 00000000000..24868de1210 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hc2g-hvv2-qxv7/GHSA-hc2g-hvv2-qxv7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hc2g-hvv2-qxv7", + "modified": "2025-05-14T18:30:51Z", + "published": "2025-05-14T18:30:51Z", + "aliases": [ + "CVE-2025-30663" + ], + "details": "Time-of-check time-of-use race condition in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30663" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-25016" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T18:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hg9g-m8wg-jv2x/GHSA-hg9g-m8wg-jv2x.json b/advisories/unreviewed/2025/05/GHSA-hg9g-m8wg-jv2x/GHSA-hg9g-m8wg-jv2x.json new file mode 100644 index 00000000000..28f692f7170 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hg9g-m8wg-jv2x/GHSA-hg9g-m8wg-jv2x.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hg9g-m8wg-jv2x", + "modified": "2025-05-14T18:30:51Z", + "published": "2025-05-14T18:30:51Z", + "aliases": [ + "CVE-2025-4638" + ], + "details": "A vulnerability exists in the inftrees.c component of the zlib library, which is bundled within the PointCloudLibrary (PCL). This issue may allow context-dependent attackers to cause undefined behavior by exploiting improper pointer arithmetic.\n\nSince version 1.14.0, PCL by default uses a zlib installation from the system, unless the user sets WITH_SYSTEM_ZLIB=FALSE. So this potential vulnerability is only relevant if the PCL version is older than 1.14.0 or the user specifically requests to not use the system zlib.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:D/RE:M/U:Amber" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4638" + }, + { + "type": "WEB", + "url": "https://github.com/PointCloudLibrary/pcl/pull/6245" + }, + { + "type": "WEB", + "url": "https://github.com/PointCloudLibrary/pcl/commit/502bd2b013ce635f21632d523aa8cf2e04f7b7ac" + }, + { + "type": "WEB", + "url": "https://github.com/PointCloudLibrary/pcl/blob/master/surface/CMakeLists.txt#L70" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T18:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jfxg-6gv4-f2gh/GHSA-jfxg-6gv4-f2gh.json b/advisories/unreviewed/2025/05/GHSA-jfxg-6gv4-f2gh/GHSA-jfxg-6gv4-f2gh.json new file mode 100644 index 00000000000..40aa377903e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jfxg-6gv4-f2gh/GHSA-jfxg-6gv4-f2gh.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jfxg-6gv4-f2gh", + "modified": "2025-05-14T18:30:48Z", + "published": "2025-05-14T18:30:48Z", + "aliases": [ + "CVE-2025-3932" + ], + "details": "It was possible to craft an email that showed a tracking link as an attachment. If the user attempted to open the attachment, Thunderbird automatically accessed the link. The configuration to block remote content did not prevent that. Thunderbird has been fixed to no longer allow access to web pages listed in the X-Mozilla-External-Attachment-URL header of an email. This vulnerability affects Thunderbird < 128.10.1 and Thunderbird < 138.0.1.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3932" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1960412" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-34" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-35" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T17:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jg4r-7hcf-wqjr/GHSA-jg4r-7hcf-wqjr.json b/advisories/unreviewed/2025/05/GHSA-jg4r-7hcf-wqjr/GHSA-jg4r-7hcf-wqjr.json index 79a4600c3de..946c3c16e0c 100644 --- a/advisories/unreviewed/2025/05/GHSA-jg4r-7hcf-wqjr/GHSA-jg4r-7hcf-wqjr.json +++ b/advisories/unreviewed/2025/05/GHSA-jg4r-7hcf-wqjr/GHSA-jg4r-7hcf-wqjr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jg4r-7hcf-wqjr", - "modified": "2025-05-13T00:31:15Z", + "modified": "2025-05-14T18:30:46Z", "published": "2025-05-13T00:31:15Z", "aliases": [ "CVE-2025-31253" ], "details": "This issue was addressed through improved state management. This issue is fixed in iOS 18.5 and iPadOS 18.5. Muting the microphone during a FaceTime call may not result in audio being silenced.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-672" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:25Z" diff --git a/advisories/unreviewed/2025/05/GHSA-mghr-rhjw-p9jw/GHSA-mghr-rhjw-p9jw.json b/advisories/unreviewed/2025/05/GHSA-mghr-rhjw-p9jw/GHSA-mghr-rhjw-p9jw.json new file mode 100644 index 00000000000..cba8ec203fc --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mghr-rhjw-p9jw/GHSA-mghr-rhjw-p9jw.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mghr-rhjw-p9jw", + "modified": "2025-05-14T18:30:49Z", + "published": "2025-05-14T18:30:49Z", + "aliases": [ + "CVE-2025-47703" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Consent Management allows Cross-Site Scripting (XSS).This issue affects COOKiES Consent Management: from 0.0.0 before 1.2.14.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47703" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-049" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T17:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mqhr-6wmj-4wqg/GHSA-mqhr-6wmj-4wqg.json b/advisories/unreviewed/2025/05/GHSA-mqhr-6wmj-4wqg/GHSA-mqhr-6wmj-4wqg.json new file mode 100644 index 00000000000..e4d6ea618a3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mqhr-6wmj-4wqg/GHSA-mqhr-6wmj-4wqg.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mqhr-6wmj-4wqg", + "modified": "2025-05-14T18:30:50Z", + "published": "2025-05-14T18:30:50Z", + "aliases": [ + "CVE-2025-47709" + ], + "details": "Missing Authorization vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Forceful Browsing.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47709" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-055" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mqmq-2p8r-q32f/GHSA-mqmq-2p8r-q32f.json b/advisories/unreviewed/2025/05/GHSA-mqmq-2p8r-q32f/GHSA-mqmq-2p8r-q32f.json index bf269fd67d1..bf4ac11b27f 100644 --- a/advisories/unreviewed/2025/05/GHSA-mqmq-2p8r-q32f/GHSA-mqmq-2p8r-q32f.json +++ b/advisories/unreviewed/2025/05/GHSA-mqmq-2p8r-q32f/GHSA-mqmq-2p8r-q32f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mqmq-2p8r-q32f", - "modified": "2025-05-13T06:30:23Z", + "modified": "2025-05-14T18:30:45Z", "published": "2025-05-12T12:30:25Z", "aliases": [ "CVE-2025-22247" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22247" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00017.html" + }, { "type": "WEB", "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25683" diff --git a/advisories/unreviewed/2025/05/GHSA-p24g-cj72-gpfv/GHSA-p24g-cj72-gpfv.json b/advisories/unreviewed/2025/05/GHSA-p24g-cj72-gpfv/GHSA-p24g-cj72-gpfv.json new file mode 100644 index 00000000000..fa78a181dd8 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p24g-cj72-gpfv/GHSA-p24g-cj72-gpfv.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p24g-cj72-gpfv", + "modified": "2025-05-14T18:30:50Z", + "published": "2025-05-14T18:30:50Z", + "aliases": [ + "CVE-2025-47707" + ], + "details": "Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Authentication Bypass.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47707" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-053" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T17:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p3vf-h5cf-xmjr/GHSA-p3vf-h5cf-xmjr.json b/advisories/unreviewed/2025/05/GHSA-p3vf-h5cf-xmjr/GHSA-p3vf-h5cf-xmjr.json new file mode 100644 index 00000000000..53871c94d83 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p3vf-h5cf-xmjr/GHSA-p3vf-h5cf-xmjr.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p3vf-h5cf-xmjr", + "modified": "2025-05-14T18:30:50Z", + "published": "2025-05-14T18:30:50Z", + "aliases": [ + "CVE-2025-47708" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Cross Site Request Forgery.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47708" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-054" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-pfh4-m77r-prvx/GHSA-pfh4-m77r-prvx.json b/advisories/unreviewed/2025/05/GHSA-pfh4-m77r-prvx/GHSA-pfh4-m77r-prvx.json new file mode 100644 index 00000000000..5ff3680d0fc --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pfh4-m77r-prvx/GHSA-pfh4-m77r-prvx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pfh4-m77r-prvx", + "modified": "2025-05-14T18:30:51Z", + "published": "2025-05-14T18:30:51Z", + "aliases": [ + "CVE-2025-46786" + ], + "details": "Improper neutralization of special elements in some Zoom Workplace Apps may allow an authenticated user to impact app integrity via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46786" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-25022" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T18:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-pwfh-8xv9-vgc2/GHSA-pwfh-8xv9-vgc2.json b/advisories/unreviewed/2025/05/GHSA-pwfh-8xv9-vgc2/GHSA-pwfh-8xv9-vgc2.json new file mode 100644 index 00000000000..3d77266b29e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pwfh-8xv9-vgc2/GHSA-pwfh-8xv9-vgc2.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pwfh-8xv9-vgc2", + "modified": "2025-05-14T18:30:50Z", + "published": "2025-05-14T18:30:50Z", + "aliases": [ + "CVE-2025-47706" + ], + "details": "Authentication Bypass by Capture-replay vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Remote Services with Stolen Credentials.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47706" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-052" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-294" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T17:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-r2q8-3rg5-p5rg/GHSA-r2q8-3rg5-p5rg.json b/advisories/unreviewed/2025/05/GHSA-r2q8-3rg5-p5rg/GHSA-r2q8-3rg5-p5rg.json new file mode 100644 index 00000000000..0fb8efb0e95 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-r2q8-3rg5-p5rg/GHSA-r2q8-3rg5-p5rg.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r2q8-3rg5-p5rg", + "modified": "2025-05-14T18:30:47Z", + "published": "2025-05-14T18:30:47Z", + "aliases": [ + "CVE-2025-26785" + ], + "details": "An issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. The lack of a length check leads to out-of-bounds writes.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26785" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2025-26785" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T17:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-r3v9-92q2-pvmf/GHSA-r3v9-92q2-pvmf.json b/advisories/unreviewed/2025/05/GHSA-r3v9-92q2-pvmf/GHSA-r3v9-92q2-pvmf.json new file mode 100644 index 00000000000..2f7a00df1af --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-r3v9-92q2-pvmf/GHSA-r3v9-92q2-pvmf.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r3v9-92q2-pvmf", + "modified": "2025-05-14T18:30:48Z", + "published": "2025-05-14T18:30:48Z", + "aliases": [ + "CVE-2025-44186" + ], + "details": "SourceCodester Best Employee Management System 1.0 is vulnerable to Cross Site Request Forgery (CSRF) in /admin/Operation/User.php page.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44186" + }, + { + "type": "WEB", + "url": "https://github.com/cumakurt/CVE-SourceCodester-Best-Employee-Management-System-1.0/blob/main/CVE-2025-44186-SourceCodester-Best-Employee-Management-System-1.0-CSRF-in-User-Update.md" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com/php/17689/best-employee-management-system-php.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T17:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-r8fp-2xg8-32j9/GHSA-r8fp-2xg8-32j9.json b/advisories/unreviewed/2025/05/GHSA-r8fp-2xg8-32j9/GHSA-r8fp-2xg8-32j9.json new file mode 100644 index 00000000000..4f3a70ceaed --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-r8fp-2xg8-32j9/GHSA-r8fp-2xg8-32j9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r8fp-2xg8-32j9", + "modified": "2025-05-14T18:30:51Z", + "published": "2025-05-14T18:30:51Z", + "aliases": [ + "CVE-2025-30664" + ], + "details": "Improper neutralization of special elements in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30664" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-25017" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T18:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rg69-33g2-mp48/GHSA-rg69-33g2-mp48.json b/advisories/unreviewed/2025/05/GHSA-rg69-33g2-mp48/GHSA-rg69-33g2-mp48.json new file mode 100644 index 00000000000..203590f5cc6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rg69-33g2-mp48/GHSA-rg69-33g2-mp48.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rg69-33g2-mp48", + "modified": "2025-05-14T18:30:47Z", + "published": "2025-05-14T18:30:47Z", + "aliases": [ + "CVE-2025-3875" + ], + "details": "Thunderbird parses addresses in a way that can allow sender spoofing in case the server allows an invalid From address to be used. For example, if the From header contains an (invalid) value \"Spoofed Name \", Thunderbird treats spoofed@example.com as the actual address. This vulnerability affects Thunderbird < 128.10.1 and Thunderbird < 138.0.1.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3875" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1950629" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-34" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-35" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T17:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rjrm-h7wx-7c3m/GHSA-rjrm-h7wx-7c3m.json b/advisories/unreviewed/2025/05/GHSA-rjrm-h7wx-7c3m/GHSA-rjrm-h7wx-7c3m.json new file mode 100644 index 00000000000..5163a49ff4a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rjrm-h7wx-7c3m/GHSA-rjrm-h7wx-7c3m.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rjrm-h7wx-7c3m", + "modified": "2025-05-14T18:30:48Z", + "published": "2025-05-14T18:30:48Z", + "aliases": [ + "CVE-2025-47702" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal oEmbed Providers allows Cross-Site Scripting (XSS).This issue affects oEmbed Providers: from 0.0.0 before 2.2.2.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47702" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-048" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T17:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v265-mq78-w999/GHSA-v265-mq78-w999.json b/advisories/unreviewed/2025/05/GHSA-v265-mq78-w999/GHSA-v265-mq78-w999.json new file mode 100644 index 00000000000..c1a6a9916d0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v265-mq78-w999/GHSA-v265-mq78-w999.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v265-mq78-w999", + "modified": "2025-05-14T18:30:49Z", + "published": "2025-05-14T18:30:49Z", + "aliases": [ + "CVE-2025-47705" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal IFrame Remove Filter allows Cross-Site Scripting (XSS).This issue affects IFrame Remove Filter: from 0.0.0 before 2.0.5.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47705" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-051" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T17:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v68q-76v8-92qh/GHSA-v68q-76v8-92qh.json b/advisories/unreviewed/2025/05/GHSA-v68q-76v8-92qh/GHSA-v68q-76v8-92qh.json new file mode 100644 index 00000000000..e699dbb3be8 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v68q-76v8-92qh/GHSA-v68q-76v8-92qh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v68q-76v8-92qh", + "modified": "2025-05-14T18:30:51Z", + "published": "2025-05-14T18:30:51Z", + "aliases": [ + "CVE-2025-46785" + ], + "details": "Buffer over-read in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46785" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-25021" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T18:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vxhm-55mv-5fhx/GHSA-vxhm-55mv-5fhx.json b/advisories/unreviewed/2025/05/GHSA-vxhm-55mv-5fhx/GHSA-vxhm-55mv-5fhx.json new file mode 100644 index 00000000000..56c8f06fab6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vxhm-55mv-5fhx/GHSA-vxhm-55mv-5fhx.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vxhm-55mv-5fhx", + "modified": "2025-05-14T18:30:51Z", + "published": "2025-05-14T18:30:51Z", + "aliases": [ + "CVE-2025-4664" + ], + "details": "Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4664" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2025/05/stable-channel-update-for-desktop_14.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/415810136" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T18:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w53q-p36j-4538/GHSA-w53q-p36j-4538.json b/advisories/unreviewed/2025/05/GHSA-w53q-p36j-4538/GHSA-w53q-p36j-4538.json new file mode 100644 index 00000000000..5f20d7e2222 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w53q-p36j-4538/GHSA-w53q-p36j-4538.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w53q-p36j-4538", + "modified": "2025-05-14T18:30:51Z", + "published": "2025-05-14T18:30:51Z", + "aliases": [ + "CVE-2025-30668" + ], + "details": "Integer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct a denial of service via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30668" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-25020" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T18:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w97v-vj4h-46rv/GHSA-w97v-vj4h-46rv.json b/advisories/unreviewed/2025/05/GHSA-w97v-vj4h-46rv/GHSA-w97v-vj4h-46rv.json index a0091752786..1062aa17b3f 100644 --- a/advisories/unreviewed/2025/05/GHSA-w97v-vj4h-46rv/GHSA-w97v-vj4h-46rv.json +++ b/advisories/unreviewed/2025/05/GHSA-w97v-vj4h-46rv/GHSA-w97v-vj4h-46rv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w97v-vj4h-46rv", - "modified": "2025-05-13T00:31:13Z", + "modified": "2025-05-14T18:30:45Z", "published": "2025-05-13T00:31:13Z", "aliases": [ "CVE-2025-31207" ], "details": "A logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5. An app may be able to enumerate a user's installed apps.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:21Z"