From 888f13e9c79fd465f90a7a915f585d67162c6a7e Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 11 Jun 2025 15:31:59 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-p5c8-x5qh-v2mv.json | 9 ++- .../GHSA-2986-9f3x-j93c.json | 2 +- .../GHSA-h9h6-5vxm-9xx3.json | 2 +- .../GHSA-p99v-qjfm-8vvq.json | 2 +- .../GHSA-ph4x-8w6x-4q6x.json | 2 +- .../GHSA-jj7c-wrfh-7qqh.json | 10 +++- .../GHSA-5ch8-q94v-8r99.json | 4 +- .../GHSA-gw62-7pm8-x49v.json | 4 +- .../GHSA-qgvm-vj48-358p.json | 4 +- .../GHSA-qr28-f5f9-2wjf.json | 4 +- .../GHSA-v7fp-w3f5-7445.json | 4 +- .../GHSA-22v5-q59j-h85m.json | 11 +++- .../GHSA-2972-gp35-c62r.json | 15 +++-- .../GHSA-2vc6-9c9h-vvhf.json | 36 ++++++++++++ .../GHSA-2wpw-3v5g-3wff.json | 11 +++- .../GHSA-3fxc-2crv-fg9x.json | 19 +++++-- .../GHSA-48wx-8736-jgx2.json | 31 ++++++++++ .../GHSA-57x8-g7cj-crwq.json | 15 +++-- .../GHSA-6236-fhhc-64mr.json | 11 +++- .../GHSA-64mp-f6ff-c8jm.json | 15 +++-- .../GHSA-6fpm-c38x-hr9h.json | 15 +++-- .../GHSA-6mvj-rxp7-39x3.json | 15 +++-- .../GHSA-7g9m-wm2f-95fg.json | 15 +++-- .../GHSA-93gr-9vgp-hf59.json | 11 +++- .../GHSA-9xq9-jfj9-8mqm.json | 15 +++-- .../GHSA-c424-hgg9-9c4w.json | 31 ++++++++++ .../GHSA-gqmw-jrgv-446q.json | 11 +++- .../GHSA-gxgp-r84x-ph9x.json | 15 +++-- .../GHSA-h2w9-p5qf-qmrh.json | 36 ++++++++++++ .../GHSA-h4m7-pg92-x2q8.json | 15 +++-- .../GHSA-h889-475r-wfmm.json | 6 +- .../GHSA-hxvr-gg2w-j48x.json | 6 +- .../GHSA-p5g7-573c-m74m.json | 15 +++-- .../GHSA-p9cf-2mrg-w42q.json | 56 +++++++++++++++++++ .../GHSA-pwj7-5c7c-mwjc.json | 31 ++++++++++ .../GHSA-q7fj-77gc-45xq.json | 15 +++-- .../GHSA-q9h3-r6wr-p3j3.json | 31 ++++++++++ .../GHSA-qmmh-h9p5-p2f7.json | 11 +++- .../GHSA-r5jq-h47c-74h3.json | 11 +++- .../GHSA-r6xj-43cf-9f88.json | 31 ++++++++++ .../GHSA-rx97-6c62-55mf.json | 36 ++++++++++++ .../GHSA-w5px-5878-m9x4.json | 31 ++++++++++ .../GHSA-ww23-g4h9-82c4.json | 11 +++- .../GHSA-ww28-4m4v-cq4j.json | 6 +- .../GHSA-x573-8wx6-vhf4.json | 11 +++- .../GHSA-x854-vvhc-p3c8.json | 36 ++++++++++++ .../GHSA-x8wm-pq66-9pp3.json | 36 ++++++++++++ .../GHSA-xqpf-p6qg-xgxp.json | 36 ++++++++++++ .../GHSA-xwv7-xr8f-pf75.json | 6 +- 49 files changed, 721 insertions(+), 91 deletions(-) create mode 100644 advisories/unreviewed/2025/06/GHSA-2vc6-9c9h-vvhf/GHSA-2vc6-9c9h-vvhf.json create mode 100644 advisories/unreviewed/2025/06/GHSA-48wx-8736-jgx2/GHSA-48wx-8736-jgx2.json create mode 100644 advisories/unreviewed/2025/06/GHSA-c424-hgg9-9c4w/GHSA-c424-hgg9-9c4w.json create mode 100644 advisories/unreviewed/2025/06/GHSA-h2w9-p5qf-qmrh/GHSA-h2w9-p5qf-qmrh.json create mode 100644 advisories/unreviewed/2025/06/GHSA-p9cf-2mrg-w42q/GHSA-p9cf-2mrg-w42q.json create mode 100644 advisories/unreviewed/2025/06/GHSA-pwj7-5c7c-mwjc/GHSA-pwj7-5c7c-mwjc.json create mode 100644 advisories/unreviewed/2025/06/GHSA-q9h3-r6wr-p3j3/GHSA-q9h3-r6wr-p3j3.json create mode 100644 advisories/unreviewed/2025/06/GHSA-r6xj-43cf-9f88/GHSA-r6xj-43cf-9f88.json create mode 100644 advisories/unreviewed/2025/06/GHSA-rx97-6c62-55mf/GHSA-rx97-6c62-55mf.json create mode 100644 advisories/unreviewed/2025/06/GHSA-w5px-5878-m9x4/GHSA-w5px-5878-m9x4.json create mode 100644 advisories/unreviewed/2025/06/GHSA-x854-vvhc-p3c8/GHSA-x854-vvhc-p3c8.json create mode 100644 advisories/unreviewed/2025/06/GHSA-x8wm-pq66-9pp3/GHSA-x8wm-pq66-9pp3.json create mode 100644 advisories/unreviewed/2025/06/GHSA-xqpf-p6qg-xgxp/GHSA-xqpf-p6qg-xgxp.json diff --git a/advisories/unreviewed/2021/12/GHSA-p5c8-x5qh-v2mv/GHSA-p5c8-x5qh-v2mv.json b/advisories/unreviewed/2021/12/GHSA-p5c8-x5qh-v2mv/GHSA-p5c8-x5qh-v2mv.json index 9d6960e1222..025228dffd3 100644 --- a/advisories/unreviewed/2021/12/GHSA-p5c8-x5qh-v2mv/GHSA-p5c8-x5qh-v2mv.json +++ b/advisories/unreviewed/2021/12/GHSA-p5c8-x5qh-v2mv/GHSA-p5c8-x5qh-v2mv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p5c8-x5qh-v2mv", - "modified": "2021-12-24T00:01:14Z", + "modified": "2025-06-11T15:30:23Z", "published": "2021-12-16T00:01:41Z", "aliases": [ "CVE-2021-43905" ], "details": "Microsoft Office app Remote Code Execution Vulnerability", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2023/11/GHSA-2986-9f3x-j93c/GHSA-2986-9f3x-j93c.json b/advisories/unreviewed/2023/11/GHSA-2986-9f3x-j93c/GHSA-2986-9f3x-j93c.json index b06a5373a08..c2c96978d6b 100644 --- a/advisories/unreviewed/2023/11/GHSA-2986-9f3x-j93c/GHSA-2986-9f3x-j93c.json +++ b/advisories/unreviewed/2023/11/GHSA-2986-9f3x-j93c/GHSA-2986-9f3x-j93c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2986-9f3x-j93c", - "modified": "2023-11-16T18:30:28Z", + "modified": "2025-06-11T15:30:23Z", "published": "2023-11-09T06:30:28Z", "aliases": [ "CVE-2023-47488" diff --git a/advisories/unreviewed/2023/11/GHSA-h9h6-5vxm-9xx3/GHSA-h9h6-5vxm-9xx3.json b/advisories/unreviewed/2023/11/GHSA-h9h6-5vxm-9xx3/GHSA-h9h6-5vxm-9xx3.json index 5df4c633696..47cc5def896 100644 --- a/advisories/unreviewed/2023/11/GHSA-h9h6-5vxm-9xx3/GHSA-h9h6-5vxm-9xx3.json +++ b/advisories/unreviewed/2023/11/GHSA-h9h6-5vxm-9xx3/GHSA-h9h6-5vxm-9xx3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h9h6-5vxm-9xx3", - "modified": "2023-12-05T21:31:00Z", + "modified": "2025-06-11T15:30:24Z", "published": "2023-11-16T09:30:24Z", "aliases": [ "CVE-2023-47674" diff --git a/advisories/unreviewed/2023/11/GHSA-p99v-qjfm-8vvq/GHSA-p99v-qjfm-8vvq.json b/advisories/unreviewed/2023/11/GHSA-p99v-qjfm-8vvq/GHSA-p99v-qjfm-8vvq.json index f8746509292..457344938f6 100644 --- a/advisories/unreviewed/2023/11/GHSA-p99v-qjfm-8vvq/GHSA-p99v-qjfm-8vvq.json +++ b/advisories/unreviewed/2023/11/GHSA-p99v-qjfm-8vvq/GHSA-p99v-qjfm-8vvq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p99v-qjfm-8vvq", - "modified": "2023-11-28T21:30:24Z", + "modified": "2025-06-11T15:30:24Z", "published": "2023-11-11T03:30:16Z", "aliases": [ "CVE-2023-46849" diff --git a/advisories/unreviewed/2023/11/GHSA-ph4x-8w6x-4q6x/GHSA-ph4x-8w6x-4q6x.json b/advisories/unreviewed/2023/11/GHSA-ph4x-8w6x-4q6x/GHSA-ph4x-8w6x-4q6x.json index f3b183e3dfd..4bea321f3e2 100644 --- a/advisories/unreviewed/2023/11/GHSA-ph4x-8w6x-4q6x/GHSA-ph4x-8w6x-4q6x.json +++ b/advisories/unreviewed/2023/11/GHSA-ph4x-8w6x-4q6x/GHSA-ph4x-8w6x-4q6x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ph4x-8w6x-4q6x", - "modified": "2023-11-21T03:30:25Z", + "modified": "2025-06-11T15:30:24Z", "published": "2023-11-16T00:30:55Z", "aliases": [ "CVE-2023-48197" diff --git a/advisories/unreviewed/2024/04/GHSA-jj7c-wrfh-7qqh/GHSA-jj7c-wrfh-7qqh.json b/advisories/unreviewed/2024/04/GHSA-jj7c-wrfh-7qqh/GHSA-jj7c-wrfh-7qqh.json index 9b48ae49758..e90cb786d42 100644 --- a/advisories/unreviewed/2024/04/GHSA-jj7c-wrfh-7qqh/GHSA-jj7c-wrfh-7qqh.json +++ b/advisories/unreviewed/2024/04/GHSA-jj7c-wrfh-7qqh/GHSA-jj7c-wrfh-7qqh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jj7c-wrfh-7qqh", - "modified": "2024-04-18T00:30:32Z", + "modified": "2025-06-11T15:30:24Z", "published": "2024-04-18T00:30:32Z", "aliases": [ "CVE-2024-3932" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], @@ -19,6 +23,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3932" }, + { + "type": "WEB", + "url": "https://totara.community/mod/forum/discuss.php?d=27644" + }, { "type": "WEB", "url": "https://vuldb.com/?ctiid.261369" diff --git a/advisories/unreviewed/2024/11/GHSA-5ch8-q94v-8r99/GHSA-5ch8-q94v-8r99.json b/advisories/unreviewed/2024/11/GHSA-5ch8-q94v-8r99/GHSA-5ch8-q94v-8r99.json index 68403147ff8..af27f9afb80 100644 --- a/advisories/unreviewed/2024/11/GHSA-5ch8-q94v-8r99/GHSA-5ch8-q94v-8r99.json +++ b/advisories/unreviewed/2024/11/GHSA-5ch8-q94v-8r99/GHSA-5ch8-q94v-8r99.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-290" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-gw62-7pm8-x49v/GHSA-gw62-7pm8-x49v.json b/advisories/unreviewed/2025/05/GHSA-gw62-7pm8-x49v/GHSA-gw62-7pm8-x49v.json index 67758c0a32e..1e65d85ac6d 100644 --- a/advisories/unreviewed/2025/05/GHSA-gw62-7pm8-x49v/GHSA-gw62-7pm8-x49v.json +++ b/advisories/unreviewed/2025/05/GHSA-gw62-7pm8-x49v/GHSA-gw62-7pm8-x49v.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-qgvm-vj48-358p/GHSA-qgvm-vj48-358p.json b/advisories/unreviewed/2025/05/GHSA-qgvm-vj48-358p/GHSA-qgvm-vj48-358p.json index a40442ea82c..2a924f88f11 100644 --- a/advisories/unreviewed/2025/05/GHSA-qgvm-vj48-358p/GHSA-qgvm-vj48-358p.json +++ b/advisories/unreviewed/2025/05/GHSA-qgvm-vj48-358p/GHSA-qgvm-vj48-358p.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-601" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-qr28-f5f9-2wjf/GHSA-qr28-f5f9-2wjf.json b/advisories/unreviewed/2025/05/GHSA-qr28-f5f9-2wjf/GHSA-qr28-f5f9-2wjf.json index 7f4f3599472..90f97e1d966 100644 --- a/advisories/unreviewed/2025/05/GHSA-qr28-f5f9-2wjf/GHSA-qr28-f5f9-2wjf.json +++ b/advisories/unreviewed/2025/05/GHSA-qr28-f5f9-2wjf/GHSA-qr28-f5f9-2wjf.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-v7fp-w3f5-7445/GHSA-v7fp-w3f5-7445.json b/advisories/unreviewed/2025/05/GHSA-v7fp-w3f5-7445/GHSA-v7fp-w3f5-7445.json index 6e0aa4a64c9..16c90d1b119 100644 --- a/advisories/unreviewed/2025/05/GHSA-v7fp-w3f5-7445/GHSA-v7fp-w3f5-7445.json +++ b/advisories/unreviewed/2025/05/GHSA-v7fp-w3f5-7445/GHSA-v7fp-w3f5-7445.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/06/GHSA-22v5-q59j-h85m/GHSA-22v5-q59j-h85m.json b/advisories/unreviewed/2025/06/GHSA-22v5-q59j-h85m/GHSA-22v5-q59j-h85m.json index d9d1e33d49f..bf684fbc462 100644 --- a/advisories/unreviewed/2025/06/GHSA-22v5-q59j-h85m/GHSA-22v5-q59j-h85m.json +++ b/advisories/unreviewed/2025/06/GHSA-22v5-q59j-h85m/GHSA-22v5-q59j-h85m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-22v5-q59j-h85m", - "modified": "2025-06-11T03:31:07Z", + "modified": "2025-06-11T15:30:28Z", "published": "2025-06-11T03:31:07Z", "aliases": [ "CVE-2025-5959" ], "details": "Type Confusion in V8 in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-843" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-11T01:15:21Z" diff --git a/advisories/unreviewed/2025/06/GHSA-2972-gp35-c62r/GHSA-2972-gp35-c62r.json b/advisories/unreviewed/2025/06/GHSA-2972-gp35-c62r/GHSA-2972-gp35-c62r.json index 8cc1dad2188..865bcfe6219 100644 --- a/advisories/unreviewed/2025/06/GHSA-2972-gp35-c62r/GHSA-2972-gp35-c62r.json +++ b/advisories/unreviewed/2025/06/GHSA-2972-gp35-c62r/GHSA-2972-gp35-c62r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2972-gp35-c62r", - "modified": "2025-06-10T18:32:31Z", + "modified": "2025-06-11T15:30:27Z", "published": "2025-06-10T18:32:31Z", "aliases": [ "CVE-2024-37395" ], "details": "A stored cross-site scripting (XSS) vulnerability in the Public Survey function of REDCap 13.1.9 allows authenticated users to execute arbitrary web script or HTML by injecting a crafted payload into the 'Survey Title' and 'Survey Instructions' fields. This vulnerability could be exploited by attackers to execute malicious scripts when the survey is accessed through its public link. It is advised to update to version 14.2.1 or later to fix this issue.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-10T18:15:29Z" diff --git a/advisories/unreviewed/2025/06/GHSA-2vc6-9c9h-vvhf/GHSA-2vc6-9c9h-vvhf.json b/advisories/unreviewed/2025/06/GHSA-2vc6-9c9h-vvhf/GHSA-2vc6-9c9h-vvhf.json new file mode 100644 index 00000000000..679638d7a6d --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-2vc6-9c9h-vvhf/GHSA-2vc6-9c9h-vvhf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2vc6-9c9h-vvhf", + "modified": "2025-06-11T15:30:29Z", + "published": "2025-06-11T15:30:29Z", + "aliases": [ + "CVE-2025-3473" + ], + "details": "IBM Security Guardium 12.1 could allow a local privileged user to escalate their privileges to root due to insecure inherited permissions created by the program.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3473" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7236356" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-277" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T15:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-2wpw-3v5g-3wff/GHSA-2wpw-3v5g-3wff.json b/advisories/unreviewed/2025/06/GHSA-2wpw-3v5g-3wff/GHSA-2wpw-3v5g-3wff.json index b6ea7b33d1e..178df8e6170 100644 --- a/advisories/unreviewed/2025/06/GHSA-2wpw-3v5g-3wff/GHSA-2wpw-3v5g-3wff.json +++ b/advisories/unreviewed/2025/06/GHSA-2wpw-3v5g-3wff/GHSA-2wpw-3v5g-3wff.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2wpw-3v5g-3wff", - "modified": "2025-06-11T00:30:48Z", + "modified": "2025-06-11T15:30:28Z", "published": "2025-06-11T00:30:48Z", "aliases": [ "CVE-2025-47849" ], "details": "A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT domain can get the API key and secret key of user-accounts of Admin role type in the same domain. This operation is not appropriately restricted and allows the attacker to assume control over higher-privileged user-accounts. A malicious Domain Admin attacker can impersonate an Admin user-account and gain access to sensitive APIs and resources that could result in the compromise of resource integrity and confidentiality, data loss, denial of service, and availability of infrastructure managed by CloudStack.\n\nUsers are recommended to upgrade to Apache CloudStack 4.19.3.0 or 4.20.1.0, which fixes the issue with the following:\n\n\n * Strict validation on Role Type hierarchy: the caller's role must be equal to or higher than the target user's role. \n * API privilege comparison: the caller must possess all privileges of the user they are operating on. \n * Two new domain-level settings (restricted to the default admin): \n - role.types.allowed.for.operations.on.accounts.of.same.role.type: Defines which role types are allowed to act on users of the same role type. Default: \"Admin, DomainAdmin, ResourceAdmin\". \n - allow.operations.on.users.in.same.account: Allows/disallows user operations within the same account. Default: true.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -31,7 +36,7 @@ "cwe_ids": [ "CWE-269" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-10T23:15:58Z" diff --git a/advisories/unreviewed/2025/06/GHSA-3fxc-2crv-fg9x/GHSA-3fxc-2crv-fg9x.json b/advisories/unreviewed/2025/06/GHSA-3fxc-2crv-fg9x/GHSA-3fxc-2crv-fg9x.json index 01fa1188ca9..de92a1ce1ad 100644 --- a/advisories/unreviewed/2025/06/GHSA-3fxc-2crv-fg9x/GHSA-3fxc-2crv-fg9x.json +++ b/advisories/unreviewed/2025/06/GHSA-3fxc-2crv-fg9x/GHSA-3fxc-2crv-fg9x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3fxc-2crv-fg9x", - "modified": "2025-06-10T21:31:22Z", + "modified": "2025-06-11T15:30:27Z", "published": "2025-06-10T18:32:32Z", "aliases": [ "CVE-2025-2884" ], "details": "TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with the signature key's algorithm. See Errata 1.83 of TCG standard TPM2.0", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -22,6 +27,10 @@ "type": "WEB", "url": "https://trustedcomputinggroup.org/wp-content/uploads/TPM2.0-Library-Spec-v1.83-Errata_v1_pub.pdf" }, + { + "type": "WEB", + "url": "https://trustedcomputinggroup.org/wp-content/uploads/VRT0009-Advisory-FINAL.pdf" + }, { "type": "WEB", "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01209.html" @@ -32,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-10T18:15:30Z" diff --git a/advisories/unreviewed/2025/06/GHSA-48wx-8736-jgx2/GHSA-48wx-8736-jgx2.json b/advisories/unreviewed/2025/06/GHSA-48wx-8736-jgx2/GHSA-48wx-8736-jgx2.json new file mode 100644 index 00000000000..b6837d54136 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-48wx-8736-jgx2/GHSA-48wx-8736-jgx2.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-48wx-8736-jgx2", + "modified": "2025-06-11T15:30:29Z", + "published": "2025-06-11T15:30:29Z", + "aliases": [ + "CVE-2025-48446" + ], + "details": "Incorrect Authorization vulnerability in Drupal Commerce Alphabank Redirect allows Functionality Misuse.This issue affects Commerce Alphabank Redirect: from 0.0.0 before 1.0.3.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48446" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-067" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T15:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-57x8-g7cj-crwq/GHSA-57x8-g7cj-crwq.json b/advisories/unreviewed/2025/06/GHSA-57x8-g7cj-crwq/GHSA-57x8-g7cj-crwq.json index 9dbd97f0d53..f2f02c99778 100644 --- a/advisories/unreviewed/2025/06/GHSA-57x8-g7cj-crwq/GHSA-57x8-g7cj-crwq.json +++ b/advisories/unreviewed/2025/06/GHSA-57x8-g7cj-crwq/GHSA-57x8-g7cj-crwq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-57x8-g7cj-crwq", - "modified": "2025-06-10T21:31:23Z", + "modified": "2025-06-11T15:30:27Z", "published": "2025-06-10T21:31:23Z", "aliases": [ "CVE-2024-41504" ], "details": "Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS). In the \"Oportunidades\" (opportunities) section of the application when creating or editing an \"Atividade\" (activity), the form field \"Descrico\" allows injection of JavaScript.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-10T20:15:21Z" diff --git a/advisories/unreviewed/2025/06/GHSA-6236-fhhc-64mr/GHSA-6236-fhhc-64mr.json b/advisories/unreviewed/2025/06/GHSA-6236-fhhc-64mr/GHSA-6236-fhhc-64mr.json index 5725752a613..b147ac5095e 100644 --- a/advisories/unreviewed/2025/06/GHSA-6236-fhhc-64mr/GHSA-6236-fhhc-64mr.json +++ b/advisories/unreviewed/2025/06/GHSA-6236-fhhc-64mr/GHSA-6236-fhhc-64mr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6236-fhhc-64mr", - "modified": "2025-06-10T12:30:18Z", + "modified": "2025-06-11T15:30:26Z", "published": "2025-06-10T12:30:18Z", "aliases": [ "CVE-2025-43697" ], "details": "Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (DataMapper) allows exposure of encrypted data.\nThis impacts OmniStudio: before Spring 2025", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-281" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-10T12:15:24Z" diff --git a/advisories/unreviewed/2025/06/GHSA-64mp-f6ff-c8jm/GHSA-64mp-f6ff-c8jm.json b/advisories/unreviewed/2025/06/GHSA-64mp-f6ff-c8jm/GHSA-64mp-f6ff-c8jm.json index 1df672eec02..c525934abf2 100644 --- a/advisories/unreviewed/2025/06/GHSA-64mp-f6ff-c8jm/GHSA-64mp-f6ff-c8jm.json +++ b/advisories/unreviewed/2025/06/GHSA-64mp-f6ff-c8jm/GHSA-64mp-f6ff-c8jm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-64mp-f6ff-c8jm", - "modified": "2025-06-11T12:30:36Z", + "modified": "2025-06-11T15:30:28Z", "published": "2025-06-11T12:30:36Z", "aliases": [ "CVE-2025-49710" ], "details": "An integer overflow was present in `OrderedHashTable` used by the JavaScript engine This vulnerability affects Firefox < 139.0.4.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-190" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-11T12:15:27Z" diff --git a/advisories/unreviewed/2025/06/GHSA-6fpm-c38x-hr9h/GHSA-6fpm-c38x-hr9h.json b/advisories/unreviewed/2025/06/GHSA-6fpm-c38x-hr9h/GHSA-6fpm-c38x-hr9h.json index b3ce4d6ebf2..559e4614515 100644 --- a/advisories/unreviewed/2025/06/GHSA-6fpm-c38x-hr9h/GHSA-6fpm-c38x-hr9h.json +++ b/advisories/unreviewed/2025/06/GHSA-6fpm-c38x-hr9h/GHSA-6fpm-c38x-hr9h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6fpm-c38x-hr9h", - "modified": "2025-06-10T21:31:23Z", + "modified": "2025-06-11T15:30:27Z", "published": "2025-06-10T21:31:23Z", "aliases": [ "CVE-2024-41503" ], "details": "Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS) in the field \"Ttulo\" (title) inside the filter Save option in the \"Busca\" (search) function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-10T20:15:21Z" diff --git a/advisories/unreviewed/2025/06/GHSA-6mvj-rxp7-39x3/GHSA-6mvj-rxp7-39x3.json b/advisories/unreviewed/2025/06/GHSA-6mvj-rxp7-39x3/GHSA-6mvj-rxp7-39x3.json index 273b54c74d3..cc855a18c05 100644 --- a/advisories/unreviewed/2025/06/GHSA-6mvj-rxp7-39x3/GHSA-6mvj-rxp7-39x3.json +++ b/advisories/unreviewed/2025/06/GHSA-6mvj-rxp7-39x3/GHSA-6mvj-rxp7-39x3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6mvj-rxp7-39x3", - "modified": "2025-06-10T21:31:23Z", + "modified": "2025-06-11T15:30:27Z", "published": "2025-06-10T21:31:23Z", "aliases": [ "CVE-2024-41505" ], "details": "Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS) in the \"Pessoas\" (persons) section via the field \"Profisso\" (professor).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-10T20:15:21Z" diff --git a/advisories/unreviewed/2025/06/GHSA-7g9m-wm2f-95fg/GHSA-7g9m-wm2f-95fg.json b/advisories/unreviewed/2025/06/GHSA-7g9m-wm2f-95fg/GHSA-7g9m-wm2f-95fg.json index a568acc36f1..45cafa6ff16 100644 --- a/advisories/unreviewed/2025/06/GHSA-7g9m-wm2f-95fg/GHSA-7g9m-wm2f-95fg.json +++ b/advisories/unreviewed/2025/06/GHSA-7g9m-wm2f-95fg/GHSA-7g9m-wm2f-95fg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7g9m-wm2f-95fg", - "modified": "2025-06-10T18:32:31Z", + "modified": "2025-06-11T15:30:26Z", "published": "2025-06-10T18:32:31Z", "aliases": [ "CVE-2024-37394" ], "details": "A stored cross-site scripting (XSS) vulnerability in the Project Dashboards of REDCap 13.1.9 allows authenticated users to execute arbitrary web script or HTML by injecting a crafted payload into the 'Dashboard title' and 'Dashboard content' text boxes. This can lead to the execution of malicious scripts when the dashboard is viewed. Users are recommended to update to version 14.2.1 or later to mitigate this vulnerability.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-10T18:15:29Z" diff --git a/advisories/unreviewed/2025/06/GHSA-93gr-9vgp-hf59/GHSA-93gr-9vgp-hf59.json b/advisories/unreviewed/2025/06/GHSA-93gr-9vgp-hf59/GHSA-93gr-9vgp-hf59.json index 3e52d4afa89..4c781b7a5b0 100644 --- a/advisories/unreviewed/2025/06/GHSA-93gr-9vgp-hf59/GHSA-93gr-9vgp-hf59.json +++ b/advisories/unreviewed/2025/06/GHSA-93gr-9vgp-hf59/GHSA-93gr-9vgp-hf59.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-93gr-9vgp-hf59", - "modified": "2025-06-10T06:31:38Z", + "modified": "2025-06-11T15:30:26Z", "published": "2025-06-10T06:31:38Z", "aliases": [ "CVE-2025-4954" ], "details": "The Axle Demo Importer WordPress plugin through 1.0.3 does not validate files to be uploaded, which could allow authenticated users (author and above) to upload arbitrary files such as PHP on the server", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-10T06:15:22Z" diff --git a/advisories/unreviewed/2025/06/GHSA-9xq9-jfj9-8mqm/GHSA-9xq9-jfj9-8mqm.json b/advisories/unreviewed/2025/06/GHSA-9xq9-jfj9-8mqm/GHSA-9xq9-jfj9-8mqm.json index dcb33db2e1a..84dca79fdbc 100644 --- a/advisories/unreviewed/2025/06/GHSA-9xq9-jfj9-8mqm/GHSA-9xq9-jfj9-8mqm.json +++ b/advisories/unreviewed/2025/06/GHSA-9xq9-jfj9-8mqm/GHSA-9xq9-jfj9-8mqm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9xq9-jfj9-8mqm", - "modified": "2025-06-10T18:32:31Z", + "modified": "2025-06-11T15:30:27Z", "published": "2025-06-10T18:32:31Z", "aliases": [ "CVE-2024-37396" ], "details": "A stored cross-site scripting (XSS) vulnerability in the Calendar function of REDCap 13.1.9 allows authenticated users to execute arbitrary web script or HTML by injecting a crafted payload into the 'Notes' field of a calendar event. This could lead to the execution of malicious scripts when the event is viewed. Updating to version 14.2.1 or later is recommended to remediate this vulnerability.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-10T18:15:29Z" diff --git a/advisories/unreviewed/2025/06/GHSA-c424-hgg9-9c4w/GHSA-c424-hgg9-9c4w.json b/advisories/unreviewed/2025/06/GHSA-c424-hgg9-9c4w/GHSA-c424-hgg9-9c4w.json new file mode 100644 index 00000000000..a52dbde3b14 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-c424-hgg9-9c4w/GHSA-c424-hgg9-9c4w.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c424-hgg9-9c4w", + "modified": "2025-06-11T15:30:30Z", + "published": "2025-06-11T15:30:29Z", + "aliases": [ + "CVE-2025-48444" + ], + "details": "Missing Authorization vulnerability in Drupal Quick Node Block allows Forceful Browsing.This issue affects Quick Node Block: from 0.0.0 before 2.0.0.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48444" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-064" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T15:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-gqmw-jrgv-446q/GHSA-gqmw-jrgv-446q.json b/advisories/unreviewed/2025/06/GHSA-gqmw-jrgv-446q/GHSA-gqmw-jrgv-446q.json index bcdc649b38e..eb08ca36129 100644 --- a/advisories/unreviewed/2025/06/GHSA-gqmw-jrgv-446q/GHSA-gqmw-jrgv-446q.json +++ b/advisories/unreviewed/2025/06/GHSA-gqmw-jrgv-446q/GHSA-gqmw-jrgv-446q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gqmw-jrgv-446q", - "modified": "2025-06-10T12:30:19Z", + "modified": "2025-06-11T15:30:26Z", "published": "2025-06-10T12:30:19Z", "aliases": [ "CVE-2025-43698" ], "details": "Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows bypass of field level security controls for Salesforce objects. \nThis impacts OmniStudio: before Spring 2025", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-281" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-10T12:15:24Z" diff --git a/advisories/unreviewed/2025/06/GHSA-gxgp-r84x-ph9x/GHSA-gxgp-r84x-ph9x.json b/advisories/unreviewed/2025/06/GHSA-gxgp-r84x-ph9x/GHSA-gxgp-r84x-ph9x.json index c9bd2e87c0a..f7d2595fd16 100644 --- a/advisories/unreviewed/2025/06/GHSA-gxgp-r84x-ph9x/GHSA-gxgp-r84x-ph9x.json +++ b/advisories/unreviewed/2025/06/GHSA-gxgp-r84x-ph9x/GHSA-gxgp-r84x-ph9x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gxgp-r84x-ph9x", - "modified": "2025-06-10T21:31:23Z", + "modified": "2025-06-11T15:30:27Z", "published": "2025-06-10T21:31:23Z", "aliases": [ "CVE-2024-41502" ], "details": "Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS) via the form field \"Observaces\" (observances) in the \"Pessoas\" (persons) section when creating or editing either a legal or a natural person.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-10T20:15:21Z" diff --git a/advisories/unreviewed/2025/06/GHSA-h2w9-p5qf-qmrh/GHSA-h2w9-p5qf-qmrh.json b/advisories/unreviewed/2025/06/GHSA-h2w9-p5qf-qmrh/GHSA-h2w9-p5qf-qmrh.json new file mode 100644 index 00000000000..91a70bd0703 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-h2w9-p5qf-qmrh/GHSA-h2w9-p5qf-qmrh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h2w9-p5qf-qmrh", + "modified": "2025-06-11T15:30:29Z", + "published": "2025-06-11T15:30:29Z", + "aliases": [ + "CVE-2025-32711" + ], + "details": "Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32711" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-32711" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T14:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-h4m7-pg92-x2q8/GHSA-h4m7-pg92-x2q8.json b/advisories/unreviewed/2025/06/GHSA-h4m7-pg92-x2q8/GHSA-h4m7-pg92-x2q8.json index c96e49ce44b..000153ca219 100644 --- a/advisories/unreviewed/2025/06/GHSA-h4m7-pg92-x2q8/GHSA-h4m7-pg92-x2q8.json +++ b/advisories/unreviewed/2025/06/GHSA-h4m7-pg92-x2q8/GHSA-h4m7-pg92-x2q8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h4m7-pg92-x2q8", - "modified": "2025-06-11T12:30:36Z", + "modified": "2025-06-11T15:30:28Z", "published": "2025-06-11T12:30:36Z", "aliases": [ "CVE-2025-5687" ], "details": "A vulnerability in Mozilla VPN on macOS allows privilege escalation from a normal user to root.\n*This bug only affects Mozilla VPN on macOS. Other operating systems are unaffected.* This vulnerability affects Mozilla VPN 2.28.0 < (macOS).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-11T12:15:29Z" diff --git a/advisories/unreviewed/2025/06/GHSA-h889-475r-wfmm/GHSA-h889-475r-wfmm.json b/advisories/unreviewed/2025/06/GHSA-h889-475r-wfmm/GHSA-h889-475r-wfmm.json index 5720ba09780..e256d92b8b9 100644 --- a/advisories/unreviewed/2025/06/GHSA-h889-475r-wfmm/GHSA-h889-475r-wfmm.json +++ b/advisories/unreviewed/2025/06/GHSA-h889-475r-wfmm/GHSA-h889-475r-wfmm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h889-475r-wfmm", - "modified": "2025-06-09T18:32:17Z", + "modified": "2025-06-11T15:30:26Z", "published": "2025-06-09T18:32:17Z", "aliases": [ "CVE-2025-49651" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://hiddenlayer.com/sai_security_advisor/2025-05-backendai-49653" + }, + { + "type": "WEB", + "url": "https://hiddenlayer.com/sai_security_advisor/2025-06-backendai" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/06/GHSA-hxvr-gg2w-j48x/GHSA-hxvr-gg2w-j48x.json b/advisories/unreviewed/2025/06/GHSA-hxvr-gg2w-j48x/GHSA-hxvr-gg2w-j48x.json index 8764fc741b7..edf7bb05056 100644 --- a/advisories/unreviewed/2025/06/GHSA-hxvr-gg2w-j48x/GHSA-hxvr-gg2w-j48x.json +++ b/advisories/unreviewed/2025/06/GHSA-hxvr-gg2w-j48x/GHSA-hxvr-gg2w-j48x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hxvr-gg2w-j48x", - "modified": "2025-06-09T18:32:17Z", + "modified": "2025-06-11T15:30:26Z", "published": "2025-06-09T18:32:17Z", "aliases": [ "CVE-2025-49653" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://hiddenlayer.com/sai_security_advisor/2025-05-backendai-49653" + }, + { + "type": "WEB", + "url": "https://hiddenlayer.com/sai_security_advisor/2025-06-backendai" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/06/GHSA-p5g7-573c-m74m/GHSA-p5g7-573c-m74m.json b/advisories/unreviewed/2025/06/GHSA-p5g7-573c-m74m/GHSA-p5g7-573c-m74m.json index 4769926fe19..31efd7baf6b 100644 --- a/advisories/unreviewed/2025/06/GHSA-p5g7-573c-m74m/GHSA-p5g7-573c-m74m.json +++ b/advisories/unreviewed/2025/06/GHSA-p5g7-573c-m74m/GHSA-p5g7-573c-m74m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p5g7-573c-m74m", - "modified": "2025-06-11T12:30:36Z", + "modified": "2025-06-11T15:30:28Z", "published": "2025-06-11T12:30:36Z", "aliases": [ "CVE-2025-49709" ], "details": "Certain canvas operations could have lead to memory corruption. This vulnerability affects Firefox < 139.0.4.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-11T12:15:26Z" diff --git a/advisories/unreviewed/2025/06/GHSA-p9cf-2mrg-w42q/GHSA-p9cf-2mrg-w42q.json b/advisories/unreviewed/2025/06/GHSA-p9cf-2mrg-w42q/GHSA-p9cf-2mrg-w42q.json new file mode 100644 index 00000000000..8ed68530a94 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-p9cf-2mrg-w42q/GHSA-p9cf-2mrg-w42q.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p9cf-2mrg-w42q", + "modified": "2025-06-11T15:30:29Z", + "published": "2025-06-11T15:30:29Z", + "aliases": [ + "CVE-2025-5144" + ], + "details": "The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-date-*’ parameters in all versions up to, and including, 6.13.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5144" + }, + { + "type": "WEB", + "url": "https://bootstrap-datepicker.readthedocs.io/en/latest/index.html#data-api" + }, + { + "type": "WEB", + "url": "https://github.com/uxsolutions/bootstrap-datepicker/blob/master/js/bootstrap-datepicker.js#L131" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/the-events-calendar/tags/6.12.0.1/vendor/bootstrap-datepicker/js/bootstrap-datepicker.min.js" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/the-events-calendar/tags/6.13.0/vendor/bootstrap-datepicker/js/bootstrap-datepicker.min.js" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3307301" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/56822fe5-352c-4269-9fab-d8c796362b74?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T13:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-pwj7-5c7c-mwjc/GHSA-pwj7-5c7c-mwjc.json b/advisories/unreviewed/2025/06/GHSA-pwj7-5c7c-mwjc/GHSA-pwj7-5c7c-mwjc.json new file mode 100644 index 00000000000..35fe67e9236 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-pwj7-5c7c-mwjc/GHSA-pwj7-5c7c-mwjc.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pwj7-5c7c-mwjc", + "modified": "2025-06-11T15:30:30Z", + "published": "2025-06-11T15:30:30Z", + "aliases": [ + "CVE-2025-48448" + ], + "details": "Allocation of Resources Without Limits or Throttling vulnerability in Drupal Admin Audit Trail allows Excessive Allocation.This issue affects Admin Audit Trail: from 0.0.0 before 1.0.5.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48448" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-068" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T15:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-q7fj-77gc-45xq/GHSA-q7fj-77gc-45xq.json b/advisories/unreviewed/2025/06/GHSA-q7fj-77gc-45xq/GHSA-q7fj-77gc-45xq.json index 80abd54ecdb..173500e410e 100644 --- a/advisories/unreviewed/2025/06/GHSA-q7fj-77gc-45xq/GHSA-q7fj-77gc-45xq.json +++ b/advisories/unreviewed/2025/06/GHSA-q7fj-77gc-45xq/GHSA-q7fj-77gc-45xq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q7fj-77gc-45xq", - "modified": "2025-06-11T12:30:36Z", + "modified": "2025-06-11T15:30:28Z", "published": "2025-06-11T12:30:36Z", "aliases": [ "CVE-2025-5986" ], "details": "A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's desktop or home directory without prompting, even if auto-saving is disabled. This behavior can be abused to fill the disk with garbage data (e.g. using /dev/urandom on Linux) or to leak Windows credentials via SMB links when the email is viewed in HTML mode. While user interaction is required to download the .pdf file, visual obfuscation can conceal the download trigger. Viewing the email in HTML mode is enough to load external content. This vulnerability affects Thunderbird < 128.11.1 and Thunderbird < 139.0.2.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-451" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-11T12:15:29Z" diff --git a/advisories/unreviewed/2025/06/GHSA-q9h3-r6wr-p3j3/GHSA-q9h3-r6wr-p3j3.json b/advisories/unreviewed/2025/06/GHSA-q9h3-r6wr-p3j3/GHSA-q9h3-r6wr-p3j3.json new file mode 100644 index 00000000000..013a84f6471 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-q9h3-r6wr-p3j3/GHSA-q9h3-r6wr-p3j3.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q9h3-r6wr-p3j3", + "modified": "2025-06-11T15:30:29Z", + "published": "2025-06-11T15:30:29Z", + "aliases": [ + "CVE-2025-48445" + ], + "details": "Incorrect Authorization vulnerability in Drupal Commerce Eurobank (Redirect) allows Functionality Misuse.This issue affects Commerce Eurobank (Redirect): from 0.0.0 before 2.1.1.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48445" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-066" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T15:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-qmmh-h9p5-p2f7/GHSA-qmmh-h9p5-p2f7.json b/advisories/unreviewed/2025/06/GHSA-qmmh-h9p5-p2f7/GHSA-qmmh-h9p5-p2f7.json index 6a38ff574c6..eb535e4202f 100644 --- a/advisories/unreviewed/2025/06/GHSA-qmmh-h9p5-p2f7/GHSA-qmmh-h9p5-p2f7.json +++ b/advisories/unreviewed/2025/06/GHSA-qmmh-h9p5-p2f7/GHSA-qmmh-h9p5-p2f7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qmmh-h9p5-p2f7", - "modified": "2025-06-11T00:30:48Z", + "modified": "2025-06-11T15:30:28Z", "published": "2025-06-11T00:30:48Z", "aliases": [ "CVE-2025-47713" ], "details": "A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT domain can reset the password of user-accounts of Admin role type. This operation is not appropriately restricted and allows the attacker to assume control over higher-privileged user-accounts. A malicious Domain Admin attacker can impersonate an Admin user-account and gain access to sensitive APIs and resources that could result in the compromise of resource integrity and confidentiality, data loss, denial of service, and availability of infrastructure managed by CloudStack.\n\n\n\nUsers are recommended to upgrade to Apache CloudStack 4.19.3.0 or 4.20.1.0, which fixes the issue with the following:\n * Strict validation on Role Type hierarchy: the caller's user-account role must be equal to or higher than the target user-account's role.\n * API privilege comparison: the caller must possess all privileges of the user they are operating on. \n * Two new domain-level settings (restricted to the default Admin): \n - role.types.allowed.for.operations.on.accounts.of.same.role.type: Defines which role types are allowed to act on users of the same role type. Default: \"Admin, DomainAdmin, ResourceAdmin\". \n   - allow.operations.on.users.in.same.account: Allows/disallows user operations within the same account. Default: true.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -31,7 +36,7 @@ "cwe_ids": [ "CWE-269" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-10T23:15:58Z" diff --git a/advisories/unreviewed/2025/06/GHSA-r5jq-h47c-74h3/GHSA-r5jq-h47c-74h3.json b/advisories/unreviewed/2025/06/GHSA-r5jq-h47c-74h3/GHSA-r5jq-h47c-74h3.json index d53ff18ab1d..11e6d6e0300 100644 --- a/advisories/unreviewed/2025/06/GHSA-r5jq-h47c-74h3/GHSA-r5jq-h47c-74h3.json +++ b/advisories/unreviewed/2025/06/GHSA-r5jq-h47c-74h3/GHSA-r5jq-h47c-74h3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r5jq-h47c-74h3", - "modified": "2025-06-11T00:30:36Z", + "modified": "2025-06-11T15:30:27Z", "published": "2025-06-11T00:30:36Z", "aliases": [ "CVE-2025-26521" ], "details": "When an Apache CloudStack user-account creates a CKS-based Kubernetes cluster in a project, the API key and the secret key of the 'kubeadmin' user of the caller account are used to create the secret config in the CKS-based Kubernetes cluster. A member of the project who can access the CKS-based Kubernetes cluster, can also access the API key and secret key of the 'kubeadmin' user of the CKS cluster's creator's account. An attacker who's a member of the project can exploit this to impersonate and perform privileged actions that can result in complete compromise of the confidentiality, integrity, and availability of resources owned by the creator's account.\n\nCKS users are recommended to upgrade to version 4.19.3.0 or 4.20.1.0, which fixes this issue.Updating Existing Kubernetes Clusters in ProjectsA service account should be created for each project to provide limited access specifically for Kubernetes cluster providers and autoscaling. Follow the steps below to create a new service account, update the secret inside the cluster, and regenerate existing API and service keys:1. Create a New Service AccountCreate a new account using the role \"Project Kubernetes Service Role\" with the following details:\n\nAccount Name\nkubeadmin-\nFirst Name\nKubernetes\nLast Name\nService User\nAccount Type\n0 (Normal User)\nRole ID\n\n\n\n\n2. Add the Service Account to the ProjectAdd this account to the project where the Kubernetes cluster(s) are hosted.\n3. Generate API and Secret KeysGenerate API Key and Secret Key for the default user of this account.\n4. Update the CloudStack Secret in the Kubernetes ClusterCreate a temporary file `/tmp/cloud-config` with the following data:\n   api-url =     # For example: /client/api\n  api-key = \n  secret-key = \n  project-id = \n\n\n\n\nDelete the existing secret using kubectl and Kubernetes cluster config:\n   ./kubectl --kubeconfig kube.conf -n kube-system delete secret cloudstack-secret\n\n\n\n\nCreate a new secret using kubectl and Kubernetes cluster config:\n    ./kubectl --kubeconfig kube.conf -n kube-system create secret generic cloudstack-secret --from-file=/tmp/cloud-config\n\n\n\n\nRemove the temporary file:\n    rm /tmp/cloud-config5. Regenerate API and Secret KeysRegenerate the API and secret keys for the original user account that was used to create the Kubernetes cluster.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -31,7 +36,7 @@ "cwe_ids": [ "CWE-200" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-10T23:15:23Z" diff --git a/advisories/unreviewed/2025/06/GHSA-r6xj-43cf-9f88/GHSA-r6xj-43cf-9f88.json b/advisories/unreviewed/2025/06/GHSA-r6xj-43cf-9f88/GHSA-r6xj-43cf-9f88.json new file mode 100644 index 00000000000..17c966fe119 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-r6xj-43cf-9f88/GHSA-r6xj-43cf-9f88.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r6xj-43cf-9f88", + "modified": "2025-06-11T15:30:29Z", + "published": "2025-06-11T15:30:29Z", + "aliases": [ + "CVE-2025-48013" + ], + "details": "Missing Authorization vulnerability in Drupal Quick Node Block allows Forceful Browsing.This issue affects Quick Node Block: from 0.0.0 before 2.0.0.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48013" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-065" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T15:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-rx97-6c62-55mf/GHSA-rx97-6c62-55mf.json b/advisories/unreviewed/2025/06/GHSA-rx97-6c62-55mf/GHSA-rx97-6c62-55mf.json new file mode 100644 index 00000000000..db683ab4823 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-rx97-6c62-55mf/GHSA-rx97-6c62-55mf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rx97-6c62-55mf", + "modified": "2025-06-11T15:30:29Z", + "published": "2025-06-11T15:30:29Z", + "aliases": [ + "CVE-2025-4922" + ], + "details": "Nomad Community and Nomad Enterprise (“Nomad”) prefix-based ACL policy lookup can lead to incorrect rule application and shadowing. This vulnerability, identified as CVE-2025-4922, is fixed in Nomad Community Edition 1.10.2 and Nomad Enterprise 1.10.2, 1.9.10, and 1.8.14.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4922" + }, + { + "type": "WEB", + "url": "https://discuss.hashicorp.com/t/hcsec-2025-12-nomad-vulnerable-to-incorrect-acl-policy-lookup-attached-to-a-job/75396" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T14:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-w5px-5878-m9x4/GHSA-w5px-5878-m9x4.json b/advisories/unreviewed/2025/06/GHSA-w5px-5878-m9x4/GHSA-w5px-5878-m9x4.json new file mode 100644 index 00000000000..5e9303325b9 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-w5px-5878-m9x4/GHSA-w5px-5878-m9x4.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w5px-5878-m9x4", + "modified": "2025-06-11T15:30:30Z", + "published": "2025-06-11T15:30:30Z", + "aliases": [ + "CVE-2025-48447" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Lightgallery allows Cross-Site Scripting (XSS).This issue affects Lightgallery: from 0.0.0 before 1.6.0.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48447" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-069" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T15:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-ww23-g4h9-82c4/GHSA-ww23-g4h9-82c4.json b/advisories/unreviewed/2025/06/GHSA-ww23-g4h9-82c4/GHSA-ww23-g4h9-82c4.json index 7175300808d..af1cd72ea1b 100644 --- a/advisories/unreviewed/2025/06/GHSA-ww23-g4h9-82c4/GHSA-ww23-g4h9-82c4.json +++ b/advisories/unreviewed/2025/06/GHSA-ww23-g4h9-82c4/GHSA-ww23-g4h9-82c4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-ww23-g4h9-82c4", - "modified": "2025-06-11T09:30:33Z", + "modified": "2025-06-11T15:30:28Z", "published": "2025-06-11T09:30:33Z", "aliases": [ "CVE-2025-26412" ], "details": "The SIMCom SIM7600G modem supports an undocumented AT command, which allows an attacker to execute system commands with root permission on the modem. An attacker needs either physical access or remote shell access to a device that interacts directly with the modem via AT commands.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-912" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-11T09:15:22Z" diff --git a/advisories/unreviewed/2025/06/GHSA-ww28-4m4v-cq4j/GHSA-ww28-4m4v-cq4j.json b/advisories/unreviewed/2025/06/GHSA-ww28-4m4v-cq4j/GHSA-ww28-4m4v-cq4j.json index fee89a64f41..bf5182cc96b 100644 --- a/advisories/unreviewed/2025/06/GHSA-ww28-4m4v-cq4j/GHSA-ww28-4m4v-cq4j.json +++ b/advisories/unreviewed/2025/06/GHSA-ww28-4m4v-cq4j/GHSA-ww28-4m4v-cq4j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ww28-4m4v-cq4j", - "modified": "2025-06-09T18:32:17Z", + "modified": "2025-06-11T15:30:26Z", "published": "2025-06-09T18:32:17Z", "aliases": [ "CVE-2025-49652" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://hiddenlayer.com/sai_security_advisor/2025-05-backendai-49653" + }, + { + "type": "WEB", + "url": "https://hiddenlayer.com/sai_security_advisor/2025-06-backendai" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/06/GHSA-x573-8wx6-vhf4/GHSA-x573-8wx6-vhf4.json b/advisories/unreviewed/2025/06/GHSA-x573-8wx6-vhf4/GHSA-x573-8wx6-vhf4.json index 7cd0dcea7a6..5fcf94542f7 100644 --- a/advisories/unreviewed/2025/06/GHSA-x573-8wx6-vhf4/GHSA-x573-8wx6-vhf4.json +++ b/advisories/unreviewed/2025/06/GHSA-x573-8wx6-vhf4/GHSA-x573-8wx6-vhf4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x573-8wx6-vhf4", - "modified": "2025-06-11T03:31:07Z", + "modified": "2025-06-11T15:30:28Z", "published": "2025-06-11T03:31:07Z", "aliases": [ "CVE-2025-5958" ], "details": "Use after free in Media in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-11T01:15:20Z" diff --git a/advisories/unreviewed/2025/06/GHSA-x854-vvhc-p3c8/GHSA-x854-vvhc-p3c8.json b/advisories/unreviewed/2025/06/GHSA-x854-vvhc-p3c8/GHSA-x854-vvhc-p3c8.json new file mode 100644 index 00000000000..074016ddc5c --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-x854-vvhc-p3c8/GHSA-x854-vvhc-p3c8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x854-vvhc-p3c8", + "modified": "2025-06-11T15:30:29Z", + "published": "2025-06-11T15:30:29Z", + "aliases": [ + "CVE-2025-0163" + ], + "details": "IBM Security Verify Access Appliance and Docker 10.0 through 10.0.8 could allow a remote attacker to enumerate usernames due to an observable response discrepancy of disabled accounts.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0163" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7236314" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-204" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T15:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-x8wm-pq66-9pp3/GHSA-x8wm-pq66-9pp3.json b/advisories/unreviewed/2025/06/GHSA-x8wm-pq66-9pp3/GHSA-x8wm-pq66-9pp3.json new file mode 100644 index 00000000000..6d08706f52e --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-x8wm-pq66-9pp3/GHSA-x8wm-pq66-9pp3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x8wm-pq66-9pp3", + "modified": "2025-06-11T15:30:29Z", + "published": "2025-06-11T15:30:29Z", + "aliases": [ + "CVE-2025-4605" + ], + "details": "A maliciously crafted .usdc file, when loaded through Autodesk Maya, can force an uncontrolled memory allocation vulnerability. A malicious actor may leverage this vulnerability to cause a denial-of-service (DoS), or cause data corruption.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4605" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0011" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-789" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T14:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-xqpf-p6qg-xgxp/GHSA-xqpf-p6qg-xgxp.json b/advisories/unreviewed/2025/06/GHSA-xqpf-p6qg-xgxp/GHSA-xqpf-p6qg-xgxp.json new file mode 100644 index 00000000000..4faa4bcf8d3 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-xqpf-p6qg-xgxp/GHSA-xqpf-p6qg-xgxp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xqpf-p6qg-xgxp", + "modified": "2025-06-11T15:30:29Z", + "published": "2025-06-11T15:30:29Z", + "aliases": [ + "CVE-2025-35941" + ], + "details": "A password is exposed locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-35941" + }, + { + "type": "WEB", + "url": "https://www.tenable.com/security/research/tra-2025-18" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-522" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T14:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-xwv7-xr8f-pf75/GHSA-xwv7-xr8f-pf75.json b/advisories/unreviewed/2025/06/GHSA-xwv7-xr8f-pf75/GHSA-xwv7-xr8f-pf75.json index efe4b8992f1..4f25d97f263 100644 --- a/advisories/unreviewed/2025/06/GHSA-xwv7-xr8f-pf75/GHSA-xwv7-xr8f-pf75.json +++ b/advisories/unreviewed/2025/06/GHSA-xwv7-xr8f-pf75/GHSA-xwv7-xr8f-pf75.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xwv7-xr8f-pf75", - "modified": "2025-06-10T21:31:24Z", + "modified": "2025-06-11T15:30:27Z", "published": "2025-06-10T21:31:24Z", "aliases": [ "CVE-2025-5978" @@ -23,6 +23,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5978" }, + { + "type": "WEB", + "url": "https://lavender-bicycle-a5a.notion.site/Tenda-FH1202-fromVirtualSer-20b53a41781f80b7a6c7e727f93d7d9f" + }, { "type": "WEB", "url": "https://lavender-bicycle-a5a.notion.site/Tenda-FH1202-fromVirtualSer-20b53a41781f80b7a6c7e727f93d7d9f?source=copy_link"