From 92ba0436bd7adcd2eeb22aa1a4efd3a98df566e5 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 5 May 2025 18:35:15 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-7f8x-63vw-v3v9.json | 1 + .../GHSA-f82m-qq46-pcww.json | 2 +- .../GHSA-g639-f2rm-mp66.json | 2 +- .../GHSA-ggwq-rh53-chpg.json | 1 + .../GHSA-m6p5-m5xh-8xgm.json | 2 +- .../GHSA-4jx7-c67v-r2v7.json | 18 ++++++- .../GHSA-8f84-fgc5-c52x.json | 2 +- .../GHSA-m7hv-7hvq-q3xx.json | 2 +- .../GHSA-q9qj-gqmf-73c2.json | 2 +- .../GHSA-wwff-24hj-g6pw.json | 18 ++++++- .../GHSA-xjxr-x4h8-946x.json | 22 +++++++- .../GHSA-9522-4c39-hgpv.json | 2 +- .../GHSA-crr5-mf4p-x3rf.json | 2 +- .../GHSA-wwxv-fc92-xrw3.json | 2 +- .../GHSA-x62c-6mxr-74fh.json | 7 ++- .../GHSA-2mwm-hhv7-v7hx.json | 2 +- .../GHSA-6mrw-wxgj-q727.json | 2 +- .../GHSA-gmq2-cvj2-8hwx.json | 2 +- .../GHSA-rr22-pq25-c964.json | 2 +- .../GHSA-rw9q-5p4j-cc4j.json | 2 +- .../GHSA-wq7v-mxjw-fp8v.json | 2 +- .../GHSA-3xc8-4p8r-q7hj.json | 2 +- .../GHSA-7mc5-x7xh-682h.json | 14 ++++- .../GHSA-f93p-vc52-m3wg.json | 2 +- .../GHSA-hvm4-7p57-c7mx.json | 3 +- .../GHSA-jv46-73g5-gg89.json | 2 +- .../GHSA-q472-4r55-2p86.json | 4 +- .../GHSA-8j6x-r8x6-r4vg.json | 4 +- .../GHSA-f5v3-qm6r-5p3w.json | 2 +- .../GHSA-gg4c-vq6j-h4hr.json | 2 +- .../GHSA-j33c-mrwq-fprw.json | 14 ++++- .../GHSA-mjhv-4xgh-4wx2.json | 14 ++++- .../GHSA-pccv-xjc7-m5qv.json | 2 +- .../GHSA-993x-6558-2xmj.json | 2 +- .../GHSA-x49m-v7mv-3wvx.json | 6 ++- .../GHSA-49rq-5w7r-4rrp.json | 2 +- .../GHSA-4mgq-wm39-mv73.json | 10 +++- .../GHSA-grmq-x6cq-3wxv.json | 2 +- .../GHSA-h6gj-8ffr-cxm9.json | 6 ++- .../GHSA-m2q7-9c76-qc45.json | 2 +- .../GHSA-qpqg-8rvq-f5c4.json | 10 +++- .../GHSA-r26p-gh73-qgq9.json | 2 +- .../GHSA-rcgr-qvjp-p7c5.json | 2 +- .../GHSA-w2w6-xp88-5cvw.json | 6 ++- .../GHSA-wp8x-2wq9-8f64.json | 2 +- .../GHSA-5cww-gpqh-ggqj.json | 2 +- .../GHSA-68gq-fqpm-jw4j.json | 2 +- .../GHSA-7797-6fvm-v8xw.json | 2 +- .../GHSA-9gjv-mqxv-j44m.json | 2 +- .../GHSA-c4fp-wmv9-q4cr.json | 2 +- .../GHSA-j5rv-3m5p-q6rc.json | 2 +- .../GHSA-m73q-fj49-fjhp.json | 2 +- .../GHSA-mv5m-45gv-gh97.json | 2 +- .../GHSA-2rpx-x37c-9w5p.json | 2 +- .../GHSA-4297-fx5c-x987.json | 2 +- .../GHSA-5rw6-vf4w-p4j3.json | 2 +- .../GHSA-687w-wqw8-qq8j.json | 6 ++- .../GHSA-943x-93ff-jr62.json | 2 +- .../GHSA-f35r-mcw4-gg3w.json | 2 +- .../GHSA-h296-3g4r-f68j.json | 2 +- .../GHSA-jr8c-7w56-v2rh.json | 2 +- .../GHSA-638m-xxfq-rm3j.json | 4 +- .../GHSA-p785-479c-32q6.json | 2 +- .../GHSA-rq4v-7hxq-wpm5.json | 2 +- .../GHSA-vp8r-986v-6qj4.json | 2 +- .../GHSA-xrw8-8992-37w4.json | 2 +- .../GHSA-6xcr-xqjv-c7jp.json | 6 ++- .../GHSA-w5hv-g8p5-vwjr.json | 2 +- .../GHSA-cwg9-5f2g-87h2.json | 4 +- .../GHSA-gjwh-9473-rcfm.json | 4 +- .../GHSA-qr26-2mpm-7j4x.json | 14 ++++- .../GHSA-vhh4-7pjp-752m.json | 4 +- .../GHSA-xv7q-36g9-3jc5.json | 4 +- .../GHSA-3g3h-99q7-v8x2.json | 4 +- .../GHSA-68mr-468g-4wmg.json | 9 +++- .../GHSA-8c9g-w38h-qxj2.json | 4 +- .../GHSA-qgc7-3qhr-fr4g.json | 3 +- .../GHSA-2pgc-776h-4jhr.json | 33 ++++++++++++ .../GHSA-2xf7-h82x-mhhg.json | 33 ++++++++++++ .../GHSA-38cq-p272-v993.json | 36 +++++++++++++ .../GHSA-39hv-4jx8-pggm.json | 36 +++++++++++++ .../GHSA-3hrf-pq5f-6637.json | 33 ++++++++++++ .../GHSA-42mr-jpwh-m9rv.json | 40 ++++++++++++++ .../GHSA-4v2j-gjc9-p494.json | 44 ++++++++++++++++ .../GHSA-4x3p-5fw4-h8vm.json | 33 ++++++++++++ .../GHSA-5ggr-xpwv-2fq3.json | 40 ++++++++++++++ .../GHSA-66q6-24vw-2g98.json | 40 ++++++++++++++ .../GHSA-9vv4-43m2-mhhp.json | 36 +++++++++++++ .../GHSA-9wf6-v4mm-mrhf.json | 33 ++++++++++++ .../GHSA-g6mm-233p-269r.json | 52 +++++++++++++++++++ .../GHSA-gc92-8qg7-j9qw.json | 36 +++++++++++++ .../GHSA-gwf3-h435-h929.json | 36 +++++++++++++ .../GHSA-h28c-39h5-c348.json | 36 +++++++++++++ .../GHSA-h8x6-pcq3-5wvw.json | 40 ++++++++++++++ .../GHSA-hcf7-pvq8-wh55.json | 40 ++++++++++++++ .../GHSA-hf7x-p9xq-fhxq.json | 40 ++++++++++++++ .../GHSA-hwmq-r762-46wq.json | 36 +++++++++++++ .../GHSA-j8p7-4x6h-98g9.json | 52 +++++++++++++++++++ .../GHSA-m46c-2xgf-gfrv.json | 36 +++++++++++++ .../GHSA-p576-652x-gvvh.json | 36 +++++++++++++ .../GHSA-phfm-cgq2-xvp6.json | 36 +++++++++++++ .../GHSA-pxrf-vj27-hg76.json | 36 +++++++++++++ .../GHSA-qppj-mpvf-fhqg.json | 36 +++++++++++++ .../GHSA-r773-hh48-f8mc.json | 36 +++++++++++++ .../GHSA-v248-84wv-hjm5.json | 33 ++++++++++++ .../GHSA-v9xg-688g-r69h.json | 35 +++++++++++++ .../GHSA-vvqw-r3vv-46ph.json | 33 ++++++++++++ .../GHSA-w64c-qgh2-qj9c.json | 29 +++++++++++ .../GHSA-x4jf-gq5v-q6vw.json | 37 +++++++++++++ 109 files changed, 1431 insertions(+), 77 deletions(-) create mode 100644 advisories/unreviewed/2025/05/GHSA-2pgc-776h-4jhr/GHSA-2pgc-776h-4jhr.json create mode 100644 advisories/unreviewed/2025/05/GHSA-2xf7-h82x-mhhg/GHSA-2xf7-h82x-mhhg.json create mode 100644 advisories/unreviewed/2025/05/GHSA-38cq-p272-v993/GHSA-38cq-p272-v993.json create mode 100644 advisories/unreviewed/2025/05/GHSA-39hv-4jx8-pggm/GHSA-39hv-4jx8-pggm.json create mode 100644 advisories/unreviewed/2025/05/GHSA-3hrf-pq5f-6637/GHSA-3hrf-pq5f-6637.json create mode 100644 advisories/unreviewed/2025/05/GHSA-42mr-jpwh-m9rv/GHSA-42mr-jpwh-m9rv.json create mode 100644 advisories/unreviewed/2025/05/GHSA-4v2j-gjc9-p494/GHSA-4v2j-gjc9-p494.json create mode 100644 advisories/unreviewed/2025/05/GHSA-4x3p-5fw4-h8vm/GHSA-4x3p-5fw4-h8vm.json create mode 100644 advisories/unreviewed/2025/05/GHSA-5ggr-xpwv-2fq3/GHSA-5ggr-xpwv-2fq3.json create mode 100644 advisories/unreviewed/2025/05/GHSA-66q6-24vw-2g98/GHSA-66q6-24vw-2g98.json create mode 100644 advisories/unreviewed/2025/05/GHSA-9vv4-43m2-mhhp/GHSA-9vv4-43m2-mhhp.json create mode 100644 advisories/unreviewed/2025/05/GHSA-9wf6-v4mm-mrhf/GHSA-9wf6-v4mm-mrhf.json create mode 100644 advisories/unreviewed/2025/05/GHSA-g6mm-233p-269r/GHSA-g6mm-233p-269r.json create mode 100644 advisories/unreviewed/2025/05/GHSA-gc92-8qg7-j9qw/GHSA-gc92-8qg7-j9qw.json create mode 100644 advisories/unreviewed/2025/05/GHSA-gwf3-h435-h929/GHSA-gwf3-h435-h929.json create mode 100644 advisories/unreviewed/2025/05/GHSA-h28c-39h5-c348/GHSA-h28c-39h5-c348.json create mode 100644 advisories/unreviewed/2025/05/GHSA-h8x6-pcq3-5wvw/GHSA-h8x6-pcq3-5wvw.json create mode 100644 advisories/unreviewed/2025/05/GHSA-hcf7-pvq8-wh55/GHSA-hcf7-pvq8-wh55.json create mode 100644 advisories/unreviewed/2025/05/GHSA-hf7x-p9xq-fhxq/GHSA-hf7x-p9xq-fhxq.json create mode 100644 advisories/unreviewed/2025/05/GHSA-hwmq-r762-46wq/GHSA-hwmq-r762-46wq.json create mode 100644 advisories/unreviewed/2025/05/GHSA-j8p7-4x6h-98g9/GHSA-j8p7-4x6h-98g9.json create mode 100644 advisories/unreviewed/2025/05/GHSA-m46c-2xgf-gfrv/GHSA-m46c-2xgf-gfrv.json create mode 100644 advisories/unreviewed/2025/05/GHSA-p576-652x-gvvh/GHSA-p576-652x-gvvh.json create mode 100644 advisories/unreviewed/2025/05/GHSA-phfm-cgq2-xvp6/GHSA-phfm-cgq2-xvp6.json create mode 100644 advisories/unreviewed/2025/05/GHSA-pxrf-vj27-hg76/GHSA-pxrf-vj27-hg76.json create mode 100644 advisories/unreviewed/2025/05/GHSA-qppj-mpvf-fhqg/GHSA-qppj-mpvf-fhqg.json create mode 100644 advisories/unreviewed/2025/05/GHSA-r773-hh48-f8mc/GHSA-r773-hh48-f8mc.json create mode 100644 advisories/unreviewed/2025/05/GHSA-v248-84wv-hjm5/GHSA-v248-84wv-hjm5.json create mode 100644 advisories/unreviewed/2025/05/GHSA-v9xg-688g-r69h/GHSA-v9xg-688g-r69h.json create mode 100644 advisories/unreviewed/2025/05/GHSA-vvqw-r3vv-46ph/GHSA-vvqw-r3vv-46ph.json create mode 100644 advisories/unreviewed/2025/05/GHSA-w64c-qgh2-qj9c/GHSA-w64c-qgh2-qj9c.json create mode 100644 advisories/unreviewed/2025/05/GHSA-x4jf-gq5v-q6vw/GHSA-x4jf-gq5v-q6vw.json diff --git a/advisories/unreviewed/2022/05/GHSA-7f8x-63vw-v3v9/GHSA-7f8x-63vw-v3v9.json b/advisories/unreviewed/2022/05/GHSA-7f8x-63vw-v3v9/GHSA-7f8x-63vw-v3v9.json index 5ed66dd5608..83d49e1aba0 100644 --- a/advisories/unreviewed/2022/05/GHSA-7f8x-63vw-v3v9/GHSA-7f8x-63vw-v3v9.json +++ b/advisories/unreviewed/2022/05/GHSA-7f8x-63vw-v3v9/GHSA-7f8x-63vw-v3v9.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1188", "CWE-665" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/05/GHSA-f82m-qq46-pcww/GHSA-f82m-qq46-pcww.json b/advisories/unreviewed/2022/05/GHSA-f82m-qq46-pcww/GHSA-f82m-qq46-pcww.json index 61987279989..a12ef1314a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-f82m-qq46-pcww/GHSA-f82m-qq46-pcww.json +++ b/advisories/unreviewed/2022/05/GHSA-f82m-qq46-pcww/GHSA-f82m-qq46-pcww.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f82m-qq46-pcww", - "modified": "2022-06-02T00:00:29Z", + "modified": "2025-05-05T18:32:06Z", "published": "2022-05-13T00:00:48Z", "aliases": [ "CVE-2022-21151" diff --git a/advisories/unreviewed/2022/05/GHSA-g639-f2rm-mp66/GHSA-g639-f2rm-mp66.json b/advisories/unreviewed/2022/05/GHSA-g639-f2rm-mp66/GHSA-g639-f2rm-mp66.json index 4dbe6368a48..4c2cf656b8d 100644 --- a/advisories/unreviewed/2022/05/GHSA-g639-f2rm-mp66/GHSA-g639-f2rm-mp66.json +++ b/advisories/unreviewed/2022/05/GHSA-g639-f2rm-mp66/GHSA-g639-f2rm-mp66.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g639-f2rm-mp66", - "modified": "2022-05-27T00:01:46Z", + "modified": "2025-05-05T18:32:04Z", "published": "2022-05-13T00:00:47Z", "aliases": [ "CVE-2021-33124" diff --git a/advisories/unreviewed/2022/05/GHSA-ggwq-rh53-chpg/GHSA-ggwq-rh53-chpg.json b/advisories/unreviewed/2022/05/GHSA-ggwq-rh53-chpg/GHSA-ggwq-rh53-chpg.json index ce1312ef4f3..295140a45ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-ggwq-rh53-chpg/GHSA-ggwq-rh53-chpg.json +++ b/advisories/unreviewed/2022/05/GHSA-ggwq-rh53-chpg/GHSA-ggwq-rh53-chpg.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-319", "CWE-668" ], "severity": "LOW", diff --git a/advisories/unreviewed/2022/05/GHSA-m6p5-m5xh-8xgm/GHSA-m6p5-m5xh-8xgm.json b/advisories/unreviewed/2022/05/GHSA-m6p5-m5xh-8xgm/GHSA-m6p5-m5xh-8xgm.json index 17f46cb6762..b3153fec1e7 100644 --- a/advisories/unreviewed/2022/05/GHSA-m6p5-m5xh-8xgm/GHSA-m6p5-m5xh-8xgm.json +++ b/advisories/unreviewed/2022/05/GHSA-m6p5-m5xh-8xgm/GHSA-m6p5-m5xh-8xgm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m6p5-m5xh-8xgm", - "modified": "2022-05-24T00:00:24Z", + "modified": "2025-05-05T18:31:59Z", "published": "2022-05-13T00:00:47Z", "aliases": [ "CVE-2021-33149" diff --git a/advisories/unreviewed/2022/06/GHSA-4jx7-c67v-r2v7/GHSA-4jx7-c67v-r2v7.json b/advisories/unreviewed/2022/06/GHSA-4jx7-c67v-r2v7/GHSA-4jx7-c67v-r2v7.json index c69a4aa8ad8..0752d2bad43 100644 --- a/advisories/unreviewed/2022/06/GHSA-4jx7-c67v-r2v7/GHSA-4jx7-c67v-r2v7.json +++ b/advisories/unreviewed/2022/06/GHSA-4jx7-c67v-r2v7/GHSA-4jx7-c67v-r2v7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4jx7-c67v-r2v7", - "modified": "2022-06-25T00:00:51Z", + "modified": "2025-05-05T18:32:08Z", "published": "2022-06-16T00:00:20Z", "aliases": [ "CVE-2022-21123" @@ -23,6 +23,22 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2022/07/msg00000.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FHTEW3RXU2GW6S3RCPQG4VNCZGI3TOSV" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MCVOMHBQRH4KP7IN6U24CW7F2D2L5KBS" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RKRXZ4LHGCGMOG24ZCEJNY6R2BTS4S2Q" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4P2KJYL74KGLHE4JZETVW7PZH6ZIABA" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FHTEW3RXU2GW6S3RCPQG4VNCZGI3TOSV" diff --git a/advisories/unreviewed/2022/06/GHSA-8f84-fgc5-c52x/GHSA-8f84-fgc5-c52x.json b/advisories/unreviewed/2022/06/GHSA-8f84-fgc5-c52x/GHSA-8f84-fgc5-c52x.json index 3b22d9cfad7..d105387e975 100644 --- a/advisories/unreviewed/2022/06/GHSA-8f84-fgc5-c52x/GHSA-8f84-fgc5-c52x.json +++ b/advisories/unreviewed/2022/06/GHSA-8f84-fgc5-c52x/GHSA-8f84-fgc5-c52x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8f84-fgc5-c52x", - "modified": "2022-06-30T00:00:36Z", + "modified": "2025-05-05T18:32:11Z", "published": "2022-06-16T00:00:19Z", "aliases": [ "CVE-2022-21180" diff --git a/advisories/unreviewed/2022/06/GHSA-m7hv-7hvq-q3xx/GHSA-m7hv-7hvq-q3xx.json b/advisories/unreviewed/2022/06/GHSA-m7hv-7hvq-q3xx/GHSA-m7hv-7hvq-q3xx.json index 08023cf1dca..b552fd23965 100644 --- a/advisories/unreviewed/2022/06/GHSA-m7hv-7hvq-q3xx/GHSA-m7hv-7hvq-q3xx.json +++ b/advisories/unreviewed/2022/06/GHSA-m7hv-7hvq-q3xx/GHSA-m7hv-7hvq-q3xx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m7hv-7hvq-q3xx", - "modified": "2022-06-29T00:00:29Z", + "modified": "2025-05-05T18:32:10Z", "published": "2022-06-16T00:00:19Z", "aliases": [ "CVE-2022-24436" diff --git a/advisories/unreviewed/2022/06/GHSA-q9qj-gqmf-73c2/GHSA-q9qj-gqmf-73c2.json b/advisories/unreviewed/2022/06/GHSA-q9qj-gqmf-73c2/GHSA-q9qj-gqmf-73c2.json index 425cf1621d7..114404514f6 100644 --- a/advisories/unreviewed/2022/06/GHSA-q9qj-gqmf-73c2/GHSA-q9qj-gqmf-73c2.json +++ b/advisories/unreviewed/2022/06/GHSA-q9qj-gqmf-73c2/GHSA-q9qj-gqmf-73c2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q9qj-gqmf-73c2", - "modified": "2022-06-27T00:00:20Z", + "modified": "2025-05-05T18:32:07Z", "published": "2022-06-16T00:00:20Z", "aliases": [ "CVE-2022-21127" diff --git a/advisories/unreviewed/2022/06/GHSA-wwff-24hj-g6pw/GHSA-wwff-24hj-g6pw.json b/advisories/unreviewed/2022/06/GHSA-wwff-24hj-g6pw/GHSA-wwff-24hj-g6pw.json index 698a7ae7fdf..37cfd3d3b45 100644 --- a/advisories/unreviewed/2022/06/GHSA-wwff-24hj-g6pw/GHSA-wwff-24hj-g6pw.json +++ b/advisories/unreviewed/2022/06/GHSA-wwff-24hj-g6pw/GHSA-wwff-24hj-g6pw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wwff-24hj-g6pw", - "modified": "2022-06-27T00:00:20Z", + "modified": "2025-05-05T18:32:08Z", "published": "2022-06-16T00:00:20Z", "aliases": [ "CVE-2022-21125" @@ -23,6 +23,22 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2022/07/msg00000.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FHTEW3RXU2GW6S3RCPQG4VNCZGI3TOSV" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MCVOMHBQRH4KP7IN6U24CW7F2D2L5KBS" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RKRXZ4LHGCGMOG24ZCEJNY6R2BTS4S2Q" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4P2KJYL74KGLHE4JZETVW7PZH6ZIABA" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FHTEW3RXU2GW6S3RCPQG4VNCZGI3TOSV" diff --git a/advisories/unreviewed/2022/06/GHSA-xjxr-x4h8-946x/GHSA-xjxr-x4h8-946x.json b/advisories/unreviewed/2022/06/GHSA-xjxr-x4h8-946x/GHSA-xjxr-x4h8-946x.json index 7e22daa6efb..ec8bd634207 100644 --- a/advisories/unreviewed/2022/06/GHSA-xjxr-x4h8-946x/GHSA-xjxr-x4h8-946x.json +++ b/advisories/unreviewed/2022/06/GHSA-xjxr-x4h8-946x/GHSA-xjxr-x4h8-946x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xjxr-x4h8-946x", - "modified": "2022-06-30T00:00:33Z", + "modified": "2025-05-05T18:32:10Z", "published": "2022-06-22T00:00:54Z", "aliases": [ "CVE-2022-2068" @@ -23,6 +23,18 @@ "type": "WEB", "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-332410.pdf" }, + { + "type": "WEB", + "url": "https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=2c9c35870601b4a44d86ddbf512b38df38285cfa" + }, + { + "type": "WEB", + "url": "https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=7a9c027159fe9e1bbc2cd38a8a2914bff0d5abd9" + }, + { + "type": "WEB", + "url": "https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=9639817dac8bbbaa64d09efad7464ccc405527c7" + }, { "type": "WEB", "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=2c9c35870601b4a44d86ddbf512b38df38285cfa" @@ -35,6 +47,14 @@ "type": "WEB", "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=9639817dac8bbbaa64d09efad7464ccc405527c7" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6WZZBKUHQFGSKGNXXKICSRPL7AMVW5M5" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VCMNWKERPBKOEBNL7CLTTX3ZZCZLH7XA" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6WZZBKUHQFGSKGNXXKICSRPL7AMVW5M5" diff --git a/advisories/unreviewed/2022/07/GHSA-9522-4c39-hgpv/GHSA-9522-4c39-hgpv.json b/advisories/unreviewed/2022/07/GHSA-9522-4c39-hgpv/GHSA-9522-4c39-hgpv.json index 64dc7a2098f..6c78cdccd6e 100644 --- a/advisories/unreviewed/2022/07/GHSA-9522-4c39-hgpv/GHSA-9522-4c39-hgpv.json +++ b/advisories/unreviewed/2022/07/GHSA-9522-4c39-hgpv/GHSA-9522-4c39-hgpv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9522-4c39-hgpv", - "modified": "2022-07-22T00:00:40Z", + "modified": "2025-05-05T18:32:12Z", "published": "2022-07-15T00:00:18Z", "aliases": [ "CVE-2022-29593" diff --git a/advisories/unreviewed/2022/07/GHSA-crr5-mf4p-x3rf/GHSA-crr5-mf4p-x3rf.json b/advisories/unreviewed/2022/07/GHSA-crr5-mf4p-x3rf/GHSA-crr5-mf4p-x3rf.json index cfb6e66c6e2..d4bf4e4657b 100644 --- a/advisories/unreviewed/2022/07/GHSA-crr5-mf4p-x3rf/GHSA-crr5-mf4p-x3rf.json +++ b/advisories/unreviewed/2022/07/GHSA-crr5-mf4p-x3rf/GHSA-crr5-mf4p-x3rf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-crr5-mf4p-x3rf", - "modified": "2022-07-26T00:01:04Z", + "modified": "2025-05-05T18:32:11Z", "published": "2022-07-19T00:00:25Z", "aliases": [ "CVE-2022-2001" diff --git a/advisories/unreviewed/2022/07/GHSA-wwxv-fc92-xrw3/GHSA-wwxv-fc92-xrw3.json b/advisories/unreviewed/2022/07/GHSA-wwxv-fc92-xrw3/GHSA-wwxv-fc92-xrw3.json index ef7e433efad..ca388fe6025 100644 --- a/advisories/unreviewed/2022/07/GHSA-wwxv-fc92-xrw3/GHSA-wwxv-fc92-xrw3.json +++ b/advisories/unreviewed/2022/07/GHSA-wwxv-fc92-xrw3/GHSA-wwxv-fc92-xrw3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wwxv-fc92-xrw3", - "modified": "2022-08-03T00:00:54Z", + "modified": "2025-05-05T18:32:15Z", "published": "2022-07-28T00:00:53Z", "aliases": [ "CVE-2022-36879" diff --git a/advisories/unreviewed/2022/07/GHSA-x62c-6mxr-74fh/GHSA-x62c-6mxr-74fh.json b/advisories/unreviewed/2022/07/GHSA-x62c-6mxr-74fh/GHSA-x62c-6mxr-74fh.json index 9da02da35c4..c0dc88d287a 100644 --- a/advisories/unreviewed/2022/07/GHSA-x62c-6mxr-74fh/GHSA-x62c-6mxr-74fh.json +++ b/advisories/unreviewed/2022/07/GHSA-x62c-6mxr-74fh/GHSA-x62c-6mxr-74fh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x62c-6mxr-74fh", - "modified": "2022-08-02T00:00:25Z", + "modified": "2025-05-05T18:32:12Z", "published": "2022-07-21T00:00:34Z", "aliases": [ "CVE-2021-46828" @@ -35,6 +35,10 @@ "type": "WEB", "url": "https://www.debian.org/security/2022/dsa-5200" }, + { + "type": "WEB", + "url": "http://git.linux-nfs.org/?p=steved/libtirpc.git%3Ba=commit%3Bh=86529758570cef4c73fb9b9c4104fdc510f701ed" + }, { "type": "WEB", "url": "http://git.linux-nfs.org/?p=steved/libtirpc.git;a=commit;h=86529758570cef4c73fb9b9c4104fdc510f701ed" @@ -42,6 +46,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-755", "CWE-770" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/08/GHSA-2mwm-hhv7-v7hx/GHSA-2mwm-hhv7-v7hx.json b/advisories/unreviewed/2022/08/GHSA-2mwm-hhv7-v7hx/GHSA-2mwm-hhv7-v7hx.json index 4cfac025ec1..79d1a363804 100644 --- a/advisories/unreviewed/2022/08/GHSA-2mwm-hhv7-v7hx/GHSA-2mwm-hhv7-v7hx.json +++ b/advisories/unreviewed/2022/08/GHSA-2mwm-hhv7-v7hx/GHSA-2mwm-hhv7-v7hx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2mwm-hhv7-v7hx", - "modified": "2022-08-22T00:00:58Z", + "modified": "2025-05-05T18:32:23Z", "published": "2022-08-19T00:00:17Z", "aliases": [ "CVE-2022-30601" diff --git a/advisories/unreviewed/2022/08/GHSA-6mrw-wxgj-q727/GHSA-6mrw-wxgj-q727.json b/advisories/unreviewed/2022/08/GHSA-6mrw-wxgj-q727/GHSA-6mrw-wxgj-q727.json index 45908e0f713..2539ecc026e 100644 --- a/advisories/unreviewed/2022/08/GHSA-6mrw-wxgj-q727/GHSA-6mrw-wxgj-q727.json +++ b/advisories/unreviewed/2022/08/GHSA-6mrw-wxgj-q727/GHSA-6mrw-wxgj-q727.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6mrw-wxgj-q727", - "modified": "2022-08-24T00:00:29Z", + "modified": "2025-05-05T18:32:20Z", "published": "2022-08-19T00:00:18Z", "aliases": [ "CVE-2022-26074" diff --git a/advisories/unreviewed/2022/08/GHSA-gmq2-cvj2-8hwx/GHSA-gmq2-cvj2-8hwx.json b/advisories/unreviewed/2022/08/GHSA-gmq2-cvj2-8hwx/GHSA-gmq2-cvj2-8hwx.json index 1d2715444f9..0e80c5e0242 100644 --- a/advisories/unreviewed/2022/08/GHSA-gmq2-cvj2-8hwx/GHSA-gmq2-cvj2-8hwx.json +++ b/advisories/unreviewed/2022/08/GHSA-gmq2-cvj2-8hwx/GHSA-gmq2-cvj2-8hwx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gmq2-cvj2-8hwx", - "modified": "2022-08-22T00:00:58Z", + "modified": "2025-05-05T18:32:22Z", "published": "2022-08-19T00:00:17Z", "aliases": [ "CVE-2022-28697" diff --git a/advisories/unreviewed/2022/08/GHSA-rr22-pq25-c964/GHSA-rr22-pq25-c964.json b/advisories/unreviewed/2022/08/GHSA-rr22-pq25-c964/GHSA-rr22-pq25-c964.json index 2b4ff86c388..e90b4ef5868 100644 --- a/advisories/unreviewed/2022/08/GHSA-rr22-pq25-c964/GHSA-rr22-pq25-c964.json +++ b/advisories/unreviewed/2022/08/GHSA-rr22-pq25-c964/GHSA-rr22-pq25-c964.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rr22-pq25-c964", - "modified": "2022-08-22T00:00:58Z", + "modified": "2025-05-05T18:32:23Z", "published": "2022-08-19T00:00:17Z", "aliases": [ "CVE-2022-30944" diff --git a/advisories/unreviewed/2022/08/GHSA-rw9q-5p4j-cc4j/GHSA-rw9q-5p4j-cc4j.json b/advisories/unreviewed/2022/08/GHSA-rw9q-5p4j-cc4j/GHSA-rw9q-5p4j-cc4j.json index f6d6273b955..67854b681c1 100644 --- a/advisories/unreviewed/2022/08/GHSA-rw9q-5p4j-cc4j/GHSA-rw9q-5p4j-cc4j.json +++ b/advisories/unreviewed/2022/08/GHSA-rw9q-5p4j-cc4j/GHSA-rw9q-5p4j-cc4j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rw9q-5p4j-cc4j", - "modified": "2022-08-27T00:00:47Z", + "modified": "2025-05-05T18:32:23Z", "published": "2022-08-19T00:00:18Z", "aliases": [ "CVE-2022-26373" diff --git a/advisories/unreviewed/2022/08/GHSA-wq7v-mxjw-fp8v/GHSA-wq7v-mxjw-fp8v.json b/advisories/unreviewed/2022/08/GHSA-wq7v-mxjw-fp8v/GHSA-wq7v-mxjw-fp8v.json index 068e4dc4fdf..c4ec6a445be 100644 --- a/advisories/unreviewed/2022/08/GHSA-wq7v-mxjw-fp8v/GHSA-wq7v-mxjw-fp8v.json +++ b/advisories/unreviewed/2022/08/GHSA-wq7v-mxjw-fp8v/GHSA-wq7v-mxjw-fp8v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wq7v-mxjw-fp8v", - "modified": "2022-08-20T00:00:39Z", + "modified": "2025-05-05T18:32:16Z", "published": "2022-08-19T00:00:19Z", "aliases": [ "CVE-2021-33060" diff --git a/advisories/unreviewed/2022/09/GHSA-3xc8-4p8r-q7hj/GHSA-3xc8-4p8r-q7hj.json b/advisories/unreviewed/2022/09/GHSA-3xc8-4p8r-q7hj/GHSA-3xc8-4p8r-q7hj.json index 978b0cdfb69..ffab4671f2e 100644 --- a/advisories/unreviewed/2022/09/GHSA-3xc8-4p8r-q7hj/GHSA-3xc8-4p8r-q7hj.json +++ b/advisories/unreviewed/2022/09/GHSA-3xc8-4p8r-q7hj/GHSA-3xc8-4p8r-q7hj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3xc8-4p8r-q7hj", - "modified": "2022-09-10T00:00:26Z", + "modified": "2025-05-05T18:32:24Z", "published": "2022-09-07T00:01:52Z", "aliases": [ "CVE-2022-2461" diff --git a/advisories/unreviewed/2022/09/GHSA-7mc5-x7xh-682h/GHSA-7mc5-x7xh-682h.json b/advisories/unreviewed/2022/09/GHSA-7mc5-x7xh-682h/GHSA-7mc5-x7xh-682h.json index 1f4fa08c3c2..32021efab13 100644 --- a/advisories/unreviewed/2022/09/GHSA-7mc5-x7xh-682h/GHSA-7mc5-x7xh-682h.json +++ b/advisories/unreviewed/2022/09/GHSA-7mc5-x7xh-682h/GHSA-7mc5-x7xh-682h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7mc5-x7xh-682h", - "modified": "2022-09-29T00:00:21Z", + "modified": "2025-05-05T18:32:25Z", "published": "2022-09-27T00:00:21Z", "aliases": [ "CVE-2022-3204" @@ -23,6 +23,18 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/03/msg00024.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/35QGS5FBQTG3DBSK7QV67PA64P24ABHY" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3G2HS6CYPSIGAKO6QLEZPG3RD6AMPB7B" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4S4EU6DMJXQFMAIE6SLAH4H5RNRU6VQL" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/35QGS5FBQTG3DBSK7QV67PA64P24ABHY" diff --git a/advisories/unreviewed/2022/09/GHSA-f93p-vc52-m3wg/GHSA-f93p-vc52-m3wg.json b/advisories/unreviewed/2022/09/GHSA-f93p-vc52-m3wg/GHSA-f93p-vc52-m3wg.json index 421033b534d..169b19c87eb 100644 --- a/advisories/unreviewed/2022/09/GHSA-f93p-vc52-m3wg/GHSA-f93p-vc52-m3wg.json +++ b/advisories/unreviewed/2022/09/GHSA-f93p-vc52-m3wg/GHSA-f93p-vc52-m3wg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f93p-vc52-m3wg", - "modified": "2022-09-09T00:00:56Z", + "modified": "2025-05-05T18:32:23Z", "published": "2022-09-03T00:00:24Z", "aliases": [ "CVE-2022-39189" diff --git a/advisories/unreviewed/2022/09/GHSA-hvm4-7p57-c7mx/GHSA-hvm4-7p57-c7mx.json b/advisories/unreviewed/2022/09/GHSA-hvm4-7p57-c7mx/GHSA-hvm4-7p57-c7mx.json index 08a9afa2ed3..264f0b42068 100644 --- a/advisories/unreviewed/2022/09/GHSA-hvm4-7p57-c7mx/GHSA-hvm4-7p57-c7mx.json +++ b/advisories/unreviewed/2022/09/GHSA-hvm4-7p57-c7mx/GHSA-hvm4-7p57-c7mx.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-20" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/09/GHSA-jv46-73g5-gg89/GHSA-jv46-73g5-gg89.json b/advisories/unreviewed/2022/09/GHSA-jv46-73g5-gg89/GHSA-jv46-73g5-gg89.json index 0e4ecdaf15c..04e6e672410 100644 --- a/advisories/unreviewed/2022/09/GHSA-jv46-73g5-gg89/GHSA-jv46-73g5-gg89.json +++ b/advisories/unreviewed/2022/09/GHSA-jv46-73g5-gg89/GHSA-jv46-73g5-gg89.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jv46-73g5-gg89", - "modified": "2022-09-10T00:00:24Z", + "modified": "2025-05-05T18:32:24Z", "published": "2022-09-07T00:01:52Z", "aliases": [ "CVE-2022-2518" diff --git a/advisories/unreviewed/2022/09/GHSA-q472-4r55-2p86/GHSA-q472-4r55-2p86.json b/advisories/unreviewed/2022/09/GHSA-q472-4r55-2p86/GHSA-q472-4r55-2p86.json index 2744d1b9a67..6f7bacf33e4 100644 --- a/advisories/unreviewed/2022/09/GHSA-q472-4r55-2p86/GHSA-q472-4r55-2p86.json +++ b/advisories/unreviewed/2022/09/GHSA-q472-4r55-2p86/GHSA-q472-4r55-2p86.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-20" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-8j6x-r8x6-r4vg/GHSA-8j6x-r8x6-r4vg.json b/advisories/unreviewed/2022/11/GHSA-8j6x-r8x6-r4vg/GHSA-8j6x-r8x6-r4vg.json index 5b1cdf9d93e..ef549388bfb 100644 --- a/advisories/unreviewed/2022/11/GHSA-8j6x-r8x6-r4vg/GHSA-8j6x-r8x6-r4vg.json +++ b/advisories/unreviewed/2022/11/GHSA-8j6x-r8x6-r4vg/GHSA-8j6x-r8x6-r4vg.json @@ -49,7 +49,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-119" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-f5v3-qm6r-5p3w/GHSA-f5v3-qm6r-5p3w.json b/advisories/unreviewed/2022/11/GHSA-f5v3-qm6r-5p3w/GHSA-f5v3-qm6r-5p3w.json index c8b8a6138e8..8486255c82a 100644 --- a/advisories/unreviewed/2022/11/GHSA-f5v3-qm6r-5p3w/GHSA-f5v3-qm6r-5p3w.json +++ b/advisories/unreviewed/2022/11/GHSA-f5v3-qm6r-5p3w/GHSA-f5v3-qm6r-5p3w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f5v3-qm6r-5p3w", - "modified": "2022-11-03T19:00:25Z", + "modified": "2025-05-05T18:32:26Z", "published": "2022-11-01T19:00:30Z", "aliases": [ "CVE-2022-42326" diff --git a/advisories/unreviewed/2022/11/GHSA-gg4c-vq6j-h4hr/GHSA-gg4c-vq6j-h4hr.json b/advisories/unreviewed/2022/11/GHSA-gg4c-vq6j-h4hr/GHSA-gg4c-vq6j-h4hr.json index 0b5265c5a37..3d441198dc1 100644 --- a/advisories/unreviewed/2022/11/GHSA-gg4c-vq6j-h4hr/GHSA-gg4c-vq6j-h4hr.json +++ b/advisories/unreviewed/2022/11/GHSA-gg4c-vq6j-h4hr/GHSA-gg4c-vq6j-h4hr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gg4c-vq6j-h4hr", - "modified": "2022-11-08T12:00:18Z", + "modified": "2025-05-05T18:32:28Z", "published": "2022-11-07T12:00:34Z", "aliases": [ "CVE-2022-44793" diff --git a/advisories/unreviewed/2022/11/GHSA-j33c-mrwq-fprw/GHSA-j33c-mrwq-fprw.json b/advisories/unreviewed/2022/11/GHSA-j33c-mrwq-fprw/GHSA-j33c-mrwq-fprw.json index e846dca213a..630306c49d4 100644 --- a/advisories/unreviewed/2022/11/GHSA-j33c-mrwq-fprw/GHSA-j33c-mrwq-fprw.json +++ b/advisories/unreviewed/2022/11/GHSA-j33c-mrwq-fprw/GHSA-j33c-mrwq-fprw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j33c-mrwq-fprw", - "modified": "2022-11-03T19:00:28Z", + "modified": "2025-05-05T18:32:26Z", "published": "2022-11-01T19:00:31Z", "aliases": [ "CVE-2022-42318" @@ -19,6 +19,18 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-42318" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YTMITQBGC23MSDHUCAPCVGLMVXIBXQTQ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YZVXG7OOOXCX6VIPEMLFDPIPUTFAYWPE" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZLI2NPNEH7CNJO3VZGQNOI4M4EWLNKPZ" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YTMITQBGC23MSDHUCAPCVGLMVXIBXQTQ" diff --git a/advisories/unreviewed/2022/11/GHSA-mjhv-4xgh-4wx2/GHSA-mjhv-4xgh-4wx2.json b/advisories/unreviewed/2022/11/GHSA-mjhv-4xgh-4wx2/GHSA-mjhv-4xgh-4wx2.json index 1a5063215f1..8e95814a37a 100644 --- a/advisories/unreviewed/2022/11/GHSA-mjhv-4xgh-4wx2/GHSA-mjhv-4xgh-4wx2.json +++ b/advisories/unreviewed/2022/11/GHSA-mjhv-4xgh-4wx2/GHSA-mjhv-4xgh-4wx2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mjhv-4xgh-4wx2", - "modified": "2022-11-03T12:00:27Z", + "modified": "2025-05-05T18:32:28Z", "published": "2022-11-02T12:00:43Z", "aliases": [ "CVE-2022-42799" @@ -23,6 +23,18 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2022/11/msg00010.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5LF4LYP725XZ7RWOPFUV6DGPN4Q5DUU4" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AQKLEGJK3LHAKUQOLBHNR2DI3IUGLLTY" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JOFKX6BUEJFECSVFV6P5INQCOYQBB4NZ" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5LF4LYP725XZ7RWOPFUV6DGPN4Q5DUU4" diff --git a/advisories/unreviewed/2022/11/GHSA-pccv-xjc7-m5qv/GHSA-pccv-xjc7-m5qv.json b/advisories/unreviewed/2022/11/GHSA-pccv-xjc7-m5qv/GHSA-pccv-xjc7-m5qv.json index c8e3f33a966..8463f5a848c 100644 --- a/advisories/unreviewed/2022/11/GHSA-pccv-xjc7-m5qv/GHSA-pccv-xjc7-m5qv.json +++ b/advisories/unreviewed/2022/11/GHSA-pccv-xjc7-m5qv/GHSA-pccv-xjc7-m5qv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pccv-xjc7-m5qv", - "modified": "2022-11-08T12:00:18Z", + "modified": "2025-05-05T18:32:28Z", "published": "2022-11-07T12:00:34Z", "aliases": [ "CVE-2022-44792" diff --git a/advisories/unreviewed/2022/12/GHSA-993x-6558-2xmj/GHSA-993x-6558-2xmj.json b/advisories/unreviewed/2022/12/GHSA-993x-6558-2xmj/GHSA-993x-6558-2xmj.json index 85c600444ad..71e604bc6bb 100644 --- a/advisories/unreviewed/2022/12/GHSA-993x-6558-2xmj/GHSA-993x-6558-2xmj.json +++ b/advisories/unreviewed/2022/12/GHSA-993x-6558-2xmj/GHSA-993x-6558-2xmj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-993x-6558-2xmj", - "modified": "2022-12-12T21:31:08Z", + "modified": "2025-05-05T18:32:30Z", "published": "2022-12-12T06:30:15Z", "aliases": [ "CVE-2022-46908" diff --git a/advisories/unreviewed/2023/01/GHSA-x49m-v7mv-3wvx/GHSA-x49m-v7mv-3wvx.json b/advisories/unreviewed/2023/01/GHSA-x49m-v7mv-3wvx/GHSA-x49m-v7mv-3wvx.json index a6202ef4701..f1b761aa08d 100644 --- a/advisories/unreviewed/2023/01/GHSA-x49m-v7mv-3wvx/GHSA-x49m-v7mv-3wvx.json +++ b/advisories/unreviewed/2023/01/GHSA-x49m-v7mv-3wvx/GHSA-x49m-v7mv-3wvx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x49m-v7mv-3wvx", - "modified": "2023-01-19T18:30:21Z", + "modified": "2025-05-05T18:32:31Z", "published": "2023-01-11T15:30:26Z", "aliases": [ "CVE-2022-4415" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://github.com/systemd/systemd/commit/b7641425659243c09473cd8fb3aef2c0d4a3eb9c" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20230216-0010" + }, { "type": "WEB", "url": "https://www.openwall.com/lists/oss-security/2022/12/21/3" diff --git a/advisories/unreviewed/2023/02/GHSA-49rq-5w7r-4rrp/GHSA-49rq-5w7r-4rrp.json b/advisories/unreviewed/2023/02/GHSA-49rq-5w7r-4rrp/GHSA-49rq-5w7r-4rrp.json index 2ef63b32658..6dd611acbfa 100644 --- a/advisories/unreviewed/2023/02/GHSA-49rq-5w7r-4rrp/GHSA-49rq-5w7r-4rrp.json +++ b/advisories/unreviewed/2023/02/GHSA-49rq-5w7r-4rrp/GHSA-49rq-5w7r-4rrp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-49rq-5w7r-4rrp", - "modified": "2023-03-08T18:30:25Z", + "modified": "2025-05-05T18:32:34Z", "published": "2023-02-28T06:30:25Z", "aliases": [ "CVE-2023-22995" diff --git a/advisories/unreviewed/2023/03/GHSA-4mgq-wm39-mv73/GHSA-4mgq-wm39-mv73.json b/advisories/unreviewed/2023/03/GHSA-4mgq-wm39-mv73/GHSA-4mgq-wm39-mv73.json index 19f70185449..528e5795f22 100644 --- a/advisories/unreviewed/2023/03/GHSA-4mgq-wm39-mv73/GHSA-4mgq-wm39-mv73.json +++ b/advisories/unreviewed/2023/03/GHSA-4mgq-wm39-mv73/GHSA-4mgq-wm39-mv73.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4mgq-wm39-mv73", - "modified": "2023-03-27T18:30:27Z", + "modified": "2025-05-05T18:32:35Z", "published": "2023-03-23T15:30:26Z", "aliases": [ "CVE-2023-28772" @@ -27,10 +27,18 @@ "type": "WEB", "url": "https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.13.3" }, + { + "type": "WEB", + "url": "https://lkml.kernel.org/r/20210626032156.47889-1-yun.zhou%40windriver.com" + }, { "type": "WEB", "url": "https://lkml.kernel.org/r/20210626032156.47889-1-yun.zhou@windriver.com" }, + { + "type": "WEB", + "url": "https://lore.kernel.org/lkml/20210625122453.5e2fe304%40oasis.local.home" + }, { "type": "WEB", "url": "https://lore.kernel.org/lkml/20210625122453.5e2fe304@oasis.local.home" diff --git a/advisories/unreviewed/2023/03/GHSA-grmq-x6cq-3wxv/GHSA-grmq-x6cq-3wxv.json b/advisories/unreviewed/2023/03/GHSA-grmq-x6cq-3wxv/GHSA-grmq-x6cq-3wxv.json index ef795fa7a60..fff3cafb0f3 100644 --- a/advisories/unreviewed/2023/03/GHSA-grmq-x6cq-3wxv/GHSA-grmq-x6cq-3wxv.json +++ b/advisories/unreviewed/2023/03/GHSA-grmq-x6cq-3wxv/GHSA-grmq-x6cq-3wxv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-grmq-x6cq-3wxv", - "modified": "2023-04-05T15:30:25Z", + "modified": "2025-05-05T18:32:36Z", "published": "2023-03-29T18:30:28Z", "aliases": [ "CVE-2023-27167" diff --git a/advisories/unreviewed/2023/03/GHSA-h6gj-8ffr-cxm9/GHSA-h6gj-8ffr-cxm9.json b/advisories/unreviewed/2023/03/GHSA-h6gj-8ffr-cxm9/GHSA-h6gj-8ffr-cxm9.json index d944e19db56..7b528687bd7 100644 --- a/advisories/unreviewed/2023/03/GHSA-h6gj-8ffr-cxm9/GHSA-h6gj-8ffr-cxm9.json +++ b/advisories/unreviewed/2023/03/GHSA-h6gj-8ffr-cxm9/GHSA-h6gj-8ffr-cxm9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h6gj-8ffr-cxm9", - "modified": "2023-03-24T18:30:25Z", + "modified": "2025-05-05T18:32:34Z", "published": "2023-03-17T21:30:24Z", "aliases": [ "CVE-2023-24678" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://github.com/iot-sec23/IoT-CVE/blob/main/Centralite%20Pearl%20Thermostat%20Vulnerability%20Report.pdf" }, + { + "type": "WEB", + "url": "https://www.centralite.com/%3B" + }, { "type": "WEB", "url": "https://www.centralite.com/;" diff --git a/advisories/unreviewed/2023/03/GHSA-m2q7-9c76-qc45/GHSA-m2q7-9c76-qc45.json b/advisories/unreviewed/2023/03/GHSA-m2q7-9c76-qc45/GHSA-m2q7-9c76-qc45.json index 438b773a226..aedd3f0e7d9 100644 --- a/advisories/unreviewed/2023/03/GHSA-m2q7-9c76-qc45/GHSA-m2q7-9c76-qc45.json +++ b/advisories/unreviewed/2023/03/GHSA-m2q7-9c76-qc45/GHSA-m2q7-9c76-qc45.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m2q7-9c76-qc45", - "modified": "2023-04-10T18:30:22Z", + "modified": "2025-05-05T18:32:36Z", "published": "2023-03-30T18:30:30Z", "aliases": [ "CVE-2023-29059" diff --git a/advisories/unreviewed/2023/03/GHSA-qpqg-8rvq-f5c4/GHSA-qpqg-8rvq-f5c4.json b/advisories/unreviewed/2023/03/GHSA-qpqg-8rvq-f5c4/GHSA-qpqg-8rvq-f5c4.json index 3e46e2ce01a..a3f497f7c31 100644 --- a/advisories/unreviewed/2023/03/GHSA-qpqg-8rvq-f5c4/GHSA-qpqg-8rvq-f5c4.json +++ b/advisories/unreviewed/2023/03/GHSA-qpqg-8rvq-f5c4/GHSA-qpqg-8rvq-f5c4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qpqg-8rvq-f5c4", - "modified": "2023-04-03T15:30:16Z", + "modified": "2025-05-05T18:32:36Z", "published": "2023-03-27T03:30:16Z", "aliases": [ "CVE-2023-28866" @@ -23,10 +23,18 @@ "type": "WEB", "url": "https://git.kernel.org/pub/scm/linux/kernel/git/bluetooth/bluetooth-next.git/commit/?id=95084403f8c070ccf5d7cbe72352519c1798a40a" }, + { + "type": "WEB", + "url": "https://lore.kernel.org/lkml/20230321015018.1759683-1-iam%40sung-woo.kim" + }, { "type": "WEB", "url": "https://lore.kernel.org/lkml/20230321015018.1759683-1-iam@sung-woo.kim" }, + { + "type": "WEB", + "url": "https://patchwork.kernel.org/project/bluetooth/patch/20230322232543.3079578-1-luiz.dentz%40gmail.com" + }, { "type": "WEB", "url": "https://patchwork.kernel.org/project/bluetooth/patch/20230322232543.3079578-1-luiz.dentz@gmail.com" diff --git a/advisories/unreviewed/2023/03/GHSA-r26p-gh73-qgq9/GHSA-r26p-gh73-qgq9.json b/advisories/unreviewed/2023/03/GHSA-r26p-gh73-qgq9/GHSA-r26p-gh73-qgq9.json index 0c5d6595913..8cf121f0f70 100644 --- a/advisories/unreviewed/2023/03/GHSA-r26p-gh73-qgq9/GHSA-r26p-gh73-qgq9.json +++ b/advisories/unreviewed/2023/03/GHSA-r26p-gh73-qgq9/GHSA-r26p-gh73-qgq9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r26p-gh73-qgq9", - "modified": "2023-04-03T21:32:47Z", + "modified": "2025-05-05T18:32:36Z", "published": "2023-03-27T21:30:25Z", "aliases": [ "CVE-2023-1078" diff --git a/advisories/unreviewed/2023/03/GHSA-rcgr-qvjp-p7c5/GHSA-rcgr-qvjp-p7c5.json b/advisories/unreviewed/2023/03/GHSA-rcgr-qvjp-p7c5/GHSA-rcgr-qvjp-p7c5.json index 2017c7db4f3..667a5f60976 100644 --- a/advisories/unreviewed/2023/03/GHSA-rcgr-qvjp-p7c5/GHSA-rcgr-qvjp-p7c5.json +++ b/advisories/unreviewed/2023/03/GHSA-rcgr-qvjp-p7c5/GHSA-rcgr-qvjp-p7c5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rcgr-qvjp-p7c5", - "modified": "2023-03-23T18:30:20Z", + "modified": "2025-05-05T18:32:35Z", "published": "2023-03-21T21:30:18Z", "aliases": [ "CVE-2023-1530" diff --git a/advisories/unreviewed/2023/03/GHSA-w2w6-xp88-5cvw/GHSA-w2w6-xp88-5cvw.json b/advisories/unreviewed/2023/03/GHSA-w2w6-xp88-5cvw/GHSA-w2w6-xp88-5cvw.json index 79a983d4b77..40bdf6f9150 100644 --- a/advisories/unreviewed/2023/03/GHSA-w2w6-xp88-5cvw/GHSA-w2w6-xp88-5cvw.json +++ b/advisories/unreviewed/2023/03/GHSA-w2w6-xp88-5cvw/GHSA-w2w6-xp88-5cvw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w2w6-xp88-5cvw", - "modified": "2024-06-21T21:33:52Z", + "modified": "2025-05-05T18:32:35Z", "published": "2023-03-22T18:30:37Z", "aliases": [ "CVE-2023-0464" @@ -43,6 +43,10 @@ "type": "WEB", "url": "https://security.gentoo.org/glsa/202402-08" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20230406-0006" + }, { "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20240621-0006" diff --git a/advisories/unreviewed/2023/03/GHSA-wp8x-2wq9-8f64/GHSA-wp8x-2wq9-8f64.json b/advisories/unreviewed/2023/03/GHSA-wp8x-2wq9-8f64/GHSA-wp8x-2wq9-8f64.json index 50a1b25f365..7742312a57c 100644 --- a/advisories/unreviewed/2023/03/GHSA-wp8x-2wq9-8f64/GHSA-wp8x-2wq9-8f64.json +++ b/advisories/unreviewed/2023/03/GHSA-wp8x-2wq9-8f64/GHSA-wp8x-2wq9-8f64.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wp8x-2wq9-8f64", - "modified": "2023-03-21T18:30:20Z", + "modified": "2025-05-05T18:32:34Z", "published": "2023-03-16T00:32:42Z", "aliases": [ "CVE-2023-28466" diff --git a/advisories/unreviewed/2023/05/GHSA-5cww-gpqh-ggqj/GHSA-5cww-gpqh-ggqj.json b/advisories/unreviewed/2023/05/GHSA-5cww-gpqh-ggqj/GHSA-5cww-gpqh-ggqj.json index ac48ab96220..054062ee3bd 100644 --- a/advisories/unreviewed/2023/05/GHSA-5cww-gpqh-ggqj/GHSA-5cww-gpqh-ggqj.json +++ b/advisories/unreviewed/2023/05/GHSA-5cww-gpqh-ggqj/GHSA-5cww-gpqh-ggqj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5cww-gpqh-ggqj", - "modified": "2023-11-25T12:30:21Z", + "modified": "2025-05-05T18:32:38Z", "published": "2023-05-16T21:30:22Z", "aliases": [ "CVE-2023-2721" diff --git a/advisories/unreviewed/2023/05/GHSA-68gq-fqpm-jw4j/GHSA-68gq-fqpm-jw4j.json b/advisories/unreviewed/2023/05/GHSA-68gq-fqpm-jw4j/GHSA-68gq-fqpm-jw4j.json index ce0e54c6290..8d73a27f947 100644 --- a/advisories/unreviewed/2023/05/GHSA-68gq-fqpm-jw4j/GHSA-68gq-fqpm-jw4j.json +++ b/advisories/unreviewed/2023/05/GHSA-68gq-fqpm-jw4j/GHSA-68gq-fqpm-jw4j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-68gq-fqpm-jw4j", - "modified": "2023-11-25T12:30:21Z", + "modified": "2025-05-05T18:32:39Z", "published": "2023-05-16T21:30:23Z", "aliases": [ "CVE-2023-2726" diff --git a/advisories/unreviewed/2023/05/GHSA-7797-6fvm-v8xw/GHSA-7797-6fvm-v8xw.json b/advisories/unreviewed/2023/05/GHSA-7797-6fvm-v8xw/GHSA-7797-6fvm-v8xw.json index aa8a7e2f457..c8365ca86cf 100644 --- a/advisories/unreviewed/2023/05/GHSA-7797-6fvm-v8xw/GHSA-7797-6fvm-v8xw.json +++ b/advisories/unreviewed/2023/05/GHSA-7797-6fvm-v8xw/GHSA-7797-6fvm-v8xw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7797-6fvm-v8xw", - "modified": "2023-11-25T12:30:21Z", + "modified": "2025-05-05T18:32:39Z", "published": "2023-05-16T21:30:22Z", "aliases": [ "CVE-2023-2723" diff --git a/advisories/unreviewed/2023/05/GHSA-9gjv-mqxv-j44m/GHSA-9gjv-mqxv-j44m.json b/advisories/unreviewed/2023/05/GHSA-9gjv-mqxv-j44m/GHSA-9gjv-mqxv-j44m.json index 3a0a1493537..4441dab61ad 100644 --- a/advisories/unreviewed/2023/05/GHSA-9gjv-mqxv-j44m/GHSA-9gjv-mqxv-j44m.json +++ b/advisories/unreviewed/2023/05/GHSA-9gjv-mqxv-j44m/GHSA-9gjv-mqxv-j44m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9gjv-mqxv-j44m", - "modified": "2023-11-25T12:30:21Z", + "modified": "2025-05-05T18:32:38Z", "published": "2023-05-16T21:30:22Z", "aliases": [ "CVE-2023-2722" diff --git a/advisories/unreviewed/2023/05/GHSA-c4fp-wmv9-q4cr/GHSA-c4fp-wmv9-q4cr.json b/advisories/unreviewed/2023/05/GHSA-c4fp-wmv9-q4cr/GHSA-c4fp-wmv9-q4cr.json index fd436e23a8f..a5b3c6fea81 100644 --- a/advisories/unreviewed/2023/05/GHSA-c4fp-wmv9-q4cr/GHSA-c4fp-wmv9-q4cr.json +++ b/advisories/unreviewed/2023/05/GHSA-c4fp-wmv9-q4cr/GHSA-c4fp-wmv9-q4cr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c4fp-wmv9-q4cr", - "modified": "2023-11-25T12:30:21Z", + "modified": "2025-05-05T18:32:39Z", "published": "2023-05-16T21:30:23Z", "aliases": [ "CVE-2023-2725" diff --git a/advisories/unreviewed/2023/05/GHSA-j5rv-3m5p-q6rc/GHSA-j5rv-3m5p-q6rc.json b/advisories/unreviewed/2023/05/GHSA-j5rv-3m5p-q6rc/GHSA-j5rv-3m5p-q6rc.json index 4559c76b609..468eabb18cb 100644 --- a/advisories/unreviewed/2023/05/GHSA-j5rv-3m5p-q6rc/GHSA-j5rv-3m5p-q6rc.json +++ b/advisories/unreviewed/2023/05/GHSA-j5rv-3m5p-q6rc/GHSA-j5rv-3m5p-q6rc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j5rv-3m5p-q6rc", - "modified": "2023-11-25T12:30:21Z", + "modified": "2025-05-05T18:32:39Z", "published": "2023-05-16T21:30:23Z", "aliases": [ "CVE-2023-2724" diff --git a/advisories/unreviewed/2023/05/GHSA-m73q-fj49-fjhp/GHSA-m73q-fj49-fjhp.json b/advisories/unreviewed/2023/05/GHSA-m73q-fj49-fjhp/GHSA-m73q-fj49-fjhp.json index 901851ffdeb..7cc0a2acde1 100644 --- a/advisories/unreviewed/2023/05/GHSA-m73q-fj49-fjhp/GHSA-m73q-fj49-fjhp.json +++ b/advisories/unreviewed/2023/05/GHSA-m73q-fj49-fjhp/GHSA-m73q-fj49-fjhp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m73q-fj49-fjhp", - "modified": "2023-11-25T12:30:21Z", + "modified": "2025-05-05T18:32:40Z", "published": "2023-05-31T00:31:05Z", "aliases": [ "CVE-2023-2929" diff --git a/advisories/unreviewed/2023/05/GHSA-mv5m-45gv-gh97/GHSA-mv5m-45gv-gh97.json b/advisories/unreviewed/2023/05/GHSA-mv5m-45gv-gh97/GHSA-mv5m-45gv-gh97.json index 0889f44de7b..4098f083110 100644 --- a/advisories/unreviewed/2023/05/GHSA-mv5m-45gv-gh97/GHSA-mv5m-45gv-gh97.json +++ b/advisories/unreviewed/2023/05/GHSA-mv5m-45gv-gh97/GHSA-mv5m-45gv-gh97.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mv5m-45gv-gh97", - "modified": "2023-11-24T15:30:26Z", + "modified": "2025-05-05T18:32:38Z", "published": "2023-05-09T03:30:38Z", "aliases": [ "CVE-2021-31239" diff --git a/advisories/unreviewed/2023/06/GHSA-2rpx-x37c-9w5p/GHSA-2rpx-x37c-9w5p.json b/advisories/unreviewed/2023/06/GHSA-2rpx-x37c-9w5p/GHSA-2rpx-x37c-9w5p.json index 9c373ac79ba..d2aad82ffdd 100644 --- a/advisories/unreviewed/2023/06/GHSA-2rpx-x37c-9w5p/GHSA-2rpx-x37c-9w5p.json +++ b/advisories/unreviewed/2023/06/GHSA-2rpx-x37c-9w5p/GHSA-2rpx-x37c-9w5p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2rpx-x37c-9w5p", - "modified": "2023-11-25T12:30:22Z", + "modified": "2025-05-05T18:32:42Z", "published": "2023-06-13T18:30:40Z", "aliases": [ "CVE-2023-3217" diff --git a/advisories/unreviewed/2023/06/GHSA-4297-fx5c-x987/GHSA-4297-fx5c-x987.json b/advisories/unreviewed/2023/06/GHSA-4297-fx5c-x987/GHSA-4297-fx5c-x987.json index 25db0a47a4c..0910abb5b1c 100644 --- a/advisories/unreviewed/2023/06/GHSA-4297-fx5c-x987/GHSA-4297-fx5c-x987.json +++ b/advisories/unreviewed/2023/06/GHSA-4297-fx5c-x987/GHSA-4297-fx5c-x987.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4297-fx5c-x987", - "modified": "2024-01-31T18:31:17Z", + "modified": "2025-05-05T18:32:42Z", "published": "2023-06-26T21:31:00Z", "aliases": [ "CVE-2023-3420" diff --git a/advisories/unreviewed/2023/06/GHSA-5rw6-vf4w-p4j3/GHSA-5rw6-vf4w-p4j3.json b/advisories/unreviewed/2023/06/GHSA-5rw6-vf4w-p4j3/GHSA-5rw6-vf4w-p4j3.json index 0293b7874f1..88a806cd097 100644 --- a/advisories/unreviewed/2023/06/GHSA-5rw6-vf4w-p4j3/GHSA-5rw6-vf4w-p4j3.json +++ b/advisories/unreviewed/2023/06/GHSA-5rw6-vf4w-p4j3/GHSA-5rw6-vf4w-p4j3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5rw6-vf4w-p4j3", - "modified": "2023-11-25T12:30:22Z", + "modified": "2025-05-05T18:32:41Z", "published": "2023-06-13T18:30:40Z", "aliases": [ "CVE-2023-3215" diff --git a/advisories/unreviewed/2023/06/GHSA-687w-wqw8-qq8j/GHSA-687w-wqw8-qq8j.json b/advisories/unreviewed/2023/06/GHSA-687w-wqw8-qq8j/GHSA-687w-wqw8-qq8j.json index 684c447a8b5..c49efbf166f 100644 --- a/advisories/unreviewed/2023/06/GHSA-687w-wqw8-qq8j/GHSA-687w-wqw8-qq8j.json +++ b/advisories/unreviewed/2023/06/GHSA-687w-wqw8-qq8j/GHSA-687w-wqw8-qq8j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-687w-wqw8-qq8j", - "modified": "2024-04-04T04:29:20Z", + "modified": "2025-05-05T18:32:41Z", "published": "2023-06-02T18:30:18Z", "aliases": [ "CVE-2023-0767" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1804640" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20230324-0008" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2023-05" diff --git a/advisories/unreviewed/2023/06/GHSA-943x-93ff-jr62/GHSA-943x-93ff-jr62.json b/advisories/unreviewed/2023/06/GHSA-943x-93ff-jr62/GHSA-943x-93ff-jr62.json index f9a555a62ed..5836895a70c 100644 --- a/advisories/unreviewed/2023/06/GHSA-943x-93ff-jr62/GHSA-943x-93ff-jr62.json +++ b/advisories/unreviewed/2023/06/GHSA-943x-93ff-jr62/GHSA-943x-93ff-jr62.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-943x-93ff-jr62", - "modified": "2024-01-31T18:31:17Z", + "modified": "2025-05-05T18:32:42Z", "published": "2023-06-26T21:31:00Z", "aliases": [ "CVE-2023-3421" diff --git a/advisories/unreviewed/2023/06/GHSA-f35r-mcw4-gg3w/GHSA-f35r-mcw4-gg3w.json b/advisories/unreviewed/2023/06/GHSA-f35r-mcw4-gg3w/GHSA-f35r-mcw4-gg3w.json index 75c0afe409c..d7acac5f37a 100644 --- a/advisories/unreviewed/2023/06/GHSA-f35r-mcw4-gg3w/GHSA-f35r-mcw4-gg3w.json +++ b/advisories/unreviewed/2023/06/GHSA-f35r-mcw4-gg3w/GHSA-f35r-mcw4-gg3w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f35r-mcw4-gg3w", - "modified": "2023-11-25T12:30:22Z", + "modified": "2025-05-05T18:32:42Z", "published": "2023-06-13T18:30:40Z", "aliases": [ "CVE-2023-3216" diff --git a/advisories/unreviewed/2023/06/GHSA-h296-3g4r-f68j/GHSA-h296-3g4r-f68j.json b/advisories/unreviewed/2023/06/GHSA-h296-3g4r-f68j/GHSA-h296-3g4r-f68j.json index 00d57c5d533..6a9f02f3908 100644 --- a/advisories/unreviewed/2023/06/GHSA-h296-3g4r-f68j/GHSA-h296-3g4r-f68j.json +++ b/advisories/unreviewed/2023/06/GHSA-h296-3g4r-f68j/GHSA-h296-3g4r-f68j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h296-3g4r-f68j", - "modified": "2023-11-25T12:30:22Z", + "modified": "2025-05-05T18:32:41Z", "published": "2023-06-13T18:30:40Z", "aliases": [ "CVE-2023-3214" diff --git a/advisories/unreviewed/2023/06/GHSA-jr8c-7w56-v2rh/GHSA-jr8c-7w56-v2rh.json b/advisories/unreviewed/2023/06/GHSA-jr8c-7w56-v2rh/GHSA-jr8c-7w56-v2rh.json index 3756881db97..6a43bef71ad 100644 --- a/advisories/unreviewed/2023/06/GHSA-jr8c-7w56-v2rh/GHSA-jr8c-7w56-v2rh.json +++ b/advisories/unreviewed/2023/06/GHSA-jr8c-7w56-v2rh/GHSA-jr8c-7w56-v2rh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jr8c-7w56-v2rh", - "modified": "2024-01-07T12:30:29Z", + "modified": "2025-05-05T18:32:41Z", "published": "2023-06-19T12:30:22Z", "aliases": [ "CVE-2023-34417" diff --git a/advisories/unreviewed/2023/07/GHSA-638m-xxfq-rm3j/GHSA-638m-xxfq-rm3j.json b/advisories/unreviewed/2023/07/GHSA-638m-xxfq-rm3j/GHSA-638m-xxfq-rm3j.json index be04640d288..3faa25686a9 100644 --- a/advisories/unreviewed/2023/07/GHSA-638m-xxfq-rm3j/GHSA-638m-xxfq-rm3j.json +++ b/advisories/unreviewed/2023/07/GHSA-638m-xxfq-rm3j/GHSA-638m-xxfq-rm3j.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-638m-xxfq-rm3j", - "modified": "2024-04-04T05:19:24Z", + "modified": "2025-05-05T18:32:42Z", "published": "2023-07-01T00:30:45Z", "aliases": [ "CVE-2023-28323" ], - "details": "A deserialization of untrusted data exists in EPM 2022 Su3 and all prior versions that allows an unauthenticated user to elevate rights. This exploit could potentially be used in conjunction with other OS (Operating System) vulnerabilities to escalate privileges on the machine or be used as a stepping stone to get to other network attached machines.\n", + "details": "A deserialization of untrusted data exists in EPM 2022 Su3 and all prior versions that allows an unauthenticated user to elevate rights. This exploit could potentially be used in conjunction with other OS (Operating System) vulnerabilities to escalate privileges on the machine or be used as a stepping stone to get to other network attached machines.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/07/GHSA-p785-479c-32q6/GHSA-p785-479c-32q6.json b/advisories/unreviewed/2023/07/GHSA-p785-479c-32q6/GHSA-p785-479c-32q6.json index 1add5b92773..68f67705dda 100644 --- a/advisories/unreviewed/2023/07/GHSA-p785-479c-32q6/GHSA-p785-479c-32q6.json +++ b/advisories/unreviewed/2023/07/GHSA-p785-479c-32q6/GHSA-p785-479c-32q6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p785-479c-32q6", - "modified": "2024-01-05T15:30:23Z", + "modified": "2025-05-05T18:32:43Z", "published": "2023-07-27T03:30:29Z", "aliases": [ "CVE-2023-38600" diff --git a/advisories/unreviewed/2023/08/GHSA-rq4v-7hxq-wpm5/GHSA-rq4v-7hxq-wpm5.json b/advisories/unreviewed/2023/08/GHSA-rq4v-7hxq-wpm5/GHSA-rq4v-7hxq-wpm5.json index bdfdc08c769..3741fe71696 100644 --- a/advisories/unreviewed/2023/08/GHSA-rq4v-7hxq-wpm5/GHSA-rq4v-7hxq-wpm5.json +++ b/advisories/unreviewed/2023/08/GHSA-rq4v-7hxq-wpm5/GHSA-rq4v-7hxq-wpm5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rq4v-7hxq-wpm5", - "modified": "2024-01-31T18:31:19Z", + "modified": "2025-05-05T18:32:45Z", "published": "2023-08-15T18:31:33Z", "aliases": [ "CVE-2023-4354" diff --git a/advisories/unreviewed/2023/08/GHSA-vp8r-986v-6qj4/GHSA-vp8r-986v-6qj4.json b/advisories/unreviewed/2023/08/GHSA-vp8r-986v-6qj4/GHSA-vp8r-986v-6qj4.json index c7d20f3d8dc..0890c0bb8e2 100644 --- a/advisories/unreviewed/2023/08/GHSA-vp8r-986v-6qj4/GHSA-vp8r-986v-6qj4.json +++ b/advisories/unreviewed/2023/08/GHSA-vp8r-986v-6qj4/GHSA-vp8r-986v-6qj4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vp8r-986v-6qj4", - "modified": "2024-01-31T18:31:19Z", + "modified": "2025-05-05T18:32:45Z", "published": "2023-08-15T18:31:33Z", "aliases": [ "CVE-2023-4352" diff --git a/advisories/unreviewed/2023/08/GHSA-xrw8-8992-37w4/GHSA-xrw8-8992-37w4.json b/advisories/unreviewed/2023/08/GHSA-xrw8-8992-37w4/GHSA-xrw8-8992-37w4.json index 22fdd878588..8807753ce52 100644 --- a/advisories/unreviewed/2023/08/GHSA-xrw8-8992-37w4/GHSA-xrw8-8992-37w4.json +++ b/advisories/unreviewed/2023/08/GHSA-xrw8-8992-37w4/GHSA-xrw8-8992-37w4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xrw8-8992-37w4", - "modified": "2024-01-31T18:31:19Z", + "modified": "2025-05-05T18:32:46Z", "published": "2023-08-15T18:31:33Z", "aliases": [ "CVE-2023-4355" diff --git a/advisories/unreviewed/2023/09/GHSA-6xcr-xqjv-c7jp/GHSA-6xcr-xqjv-c7jp.json b/advisories/unreviewed/2023/09/GHSA-6xcr-xqjv-c7jp/GHSA-6xcr-xqjv-c7jp.json index 20e5c5d77d0..f6fa01fd7e6 100644 --- a/advisories/unreviewed/2023/09/GHSA-6xcr-xqjv-c7jp/GHSA-6xcr-xqjv-c7jp.json +++ b/advisories/unreviewed/2023/09/GHSA-6xcr-xqjv-c7jp/GHSA-6xcr-xqjv-c7jp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6xcr-xqjv-c7jp", - "modified": "2024-01-31T15:30:18Z", + "modified": "2025-05-05T18:32:47Z", "published": "2023-09-27T15:30:34Z", "aliases": [ "CVE-2023-35074" @@ -47,6 +47,10 @@ "type": "WEB", "url": "https://support.apple.com/en-us/HT213941" }, + { + "type": "WEB", + "url": "https://webkitgtk.org/security/WSA-2023-0009.html" + }, { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2023/Oct/10" diff --git a/advisories/unreviewed/2023/09/GHSA-w5hv-g8p5-vwjr/GHSA-w5hv-g8p5-vwjr.json b/advisories/unreviewed/2023/09/GHSA-w5hv-g8p5-vwjr/GHSA-w5hv-g8p5-vwjr.json index 0b0a7a38356..26b75f60c5b 100644 --- a/advisories/unreviewed/2023/09/GHSA-w5hv-g8p5-vwjr/GHSA-w5hv-g8p5-vwjr.json +++ b/advisories/unreviewed/2023/09/GHSA-w5hv-g8p5-vwjr/GHSA-w5hv-g8p5-vwjr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w5hv-g8p5-vwjr", - "modified": "2023-11-25T12:30:23Z", + "modified": "2025-05-05T18:32:47Z", "published": "2023-09-06T00:30:15Z", "aliases": [ "CVE-2023-4763" diff --git a/advisories/unreviewed/2024/03/GHSA-cwg9-5f2g-87h2/GHSA-cwg9-5f2g-87h2.json b/advisories/unreviewed/2024/03/GHSA-cwg9-5f2g-87h2/GHSA-cwg9-5f2g-87h2.json index a25e64a7dad..fedb62438e3 100644 --- a/advisories/unreviewed/2024/03/GHSA-cwg9-5f2g-87h2/GHSA-cwg9-5f2g-87h2.json +++ b/advisories/unreviewed/2024/03/GHSA-cwg9-5f2g-87h2/GHSA-cwg9-5f2g-87h2.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-gjwh-9473-rcfm/GHSA-gjwh-9473-rcfm.json b/advisories/unreviewed/2024/03/GHSA-gjwh-9473-rcfm/GHSA-gjwh-9473-rcfm.json index 1fabda7b65d..d47830c1d12 100644 --- a/advisories/unreviewed/2024/03/GHSA-gjwh-9473-rcfm/GHSA-gjwh-9473-rcfm.json +++ b/advisories/unreviewed/2024/03/GHSA-gjwh-9473-rcfm/GHSA-gjwh-9473-rcfm.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-qr26-2mpm-7j4x/GHSA-qr26-2mpm-7j4x.json b/advisories/unreviewed/2024/03/GHSA-qr26-2mpm-7j4x/GHSA-qr26-2mpm-7j4x.json index f2d9e10e485..877ff76958e 100644 --- a/advisories/unreviewed/2024/03/GHSA-qr26-2mpm-7j4x/GHSA-qr26-2mpm-7j4x.json +++ b/advisories/unreviewed/2024/03/GHSA-qr26-2mpm-7j4x/GHSA-qr26-2mpm-7j4x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qr26-2mpm-7j4x", - "modified": "2024-08-27T00:31:32Z", + "modified": "2025-05-05T18:32:47Z", "published": "2024-03-04T03:30:25Z", "aliases": [ "CVE-2024-20017" @@ -19,9 +19,21 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20017" }, + { + "type": "WEB", + "url": "https://blog.coffinsec.com/0day/2024/08/30/exploiting-CVE-2024-20017-four-different-ways.html" + }, + { + "type": "WEB", + "url": "https://blog.sonicwall.com/en-us/2024/09/critical-exploit-in-mediatek-wi-fi-chipsets-zero-click-vulnerability-cve-2024-20017-threatens-routers-and-smartphones" + }, { "type": "WEB", "url": "https://corp.mediatek.com/product-security-bulletin/March-2024" + }, + { + "type": "WEB", + "url": "https://news.ycombinator.com/item?id=41605680" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/03/GHSA-vhh4-7pjp-752m/GHSA-vhh4-7pjp-752m.json b/advisories/unreviewed/2024/03/GHSA-vhh4-7pjp-752m/GHSA-vhh4-7pjp-752m.json index 2a3609031fe..bf493785b1e 100644 --- a/advisories/unreviewed/2024/03/GHSA-vhh4-7pjp-752m/GHSA-vhh4-7pjp-752m.json +++ b/advisories/unreviewed/2024/03/GHSA-vhh4-7pjp-752m/GHSA-vhh4-7pjp-752m.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-xv7q-36g9-3jc5/GHSA-xv7q-36g9-3jc5.json b/advisories/unreviewed/2024/03/GHSA-xv7q-36g9-3jc5/GHSA-xv7q-36g9-3jc5.json index 13de49a2704..7e0f1a2fe6d 100644 --- a/advisories/unreviewed/2024/03/GHSA-xv7q-36g9-3jc5/GHSA-xv7q-36g9-3jc5.json +++ b/advisories/unreviewed/2024/03/GHSA-xv7q-36g9-3jc5/GHSA-xv7q-36g9-3jc5.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-3g3h-99q7-v8x2/GHSA-3g3h-99q7-v8x2.json b/advisories/unreviewed/2024/05/GHSA-3g3h-99q7-v8x2/GHSA-3g3h-99q7-v8x2.json index cf1c61a7527..2d1a2fd6981 100644 --- a/advisories/unreviewed/2024/05/GHSA-3g3h-99q7-v8x2/GHSA-3g3h-99q7-v8x2.json +++ b/advisories/unreviewed/2024/05/GHSA-3g3h-99q7-v8x2/GHSA-3g3h-99q7-v8x2.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-68mr-468g-4wmg/GHSA-68mr-468g-4wmg.json b/advisories/unreviewed/2024/05/GHSA-68mr-468g-4wmg/GHSA-68mr-468g-4wmg.json index 608c8903141..0f02b01e674 100644 --- a/advisories/unreviewed/2024/05/GHSA-68mr-468g-4wmg/GHSA-68mr-468g-4wmg.json +++ b/advisories/unreviewed/2024/05/GHSA-68mr-468g-4wmg/GHSA-68mr-468g-4wmg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-68mr-468g-4wmg", - "modified": "2024-05-20T12:30:30Z", + "modified": "2025-05-05T18:32:51Z", "published": "2024-05-20T12:30:30Z", "aliases": [ "CVE-2024-4323" @@ -26,11 +26,16 @@ { "type": "WEB", "url": "https://tenable.com/security/research/tra-2024-17" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/linguistic-lumberjack-memory-corruption-in-fluent-bit-cve-2024-4323" } ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-8c9g-w38h-qxj2/GHSA-8c9g-w38h-qxj2.json b/advisories/unreviewed/2024/05/GHSA-8c9g-w38h-qxj2/GHSA-8c9g-w38h-qxj2.json index eaa791a655e..67a13360179 100644 --- a/advisories/unreviewed/2024/05/GHSA-8c9g-w38h-qxj2/GHSA-8c9g-w38h-qxj2.json +++ b/advisories/unreviewed/2024/05/GHSA-8c9g-w38h-qxj2/GHSA-8c9g-w38h-qxj2.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-qgc7-3qhr-fr4g/GHSA-qgc7-3qhr-fr4g.json b/advisories/unreviewed/2024/05/GHSA-qgc7-3qhr-fr4g/GHSA-qgc7-3qhr-fr4g.json index 2feb5adf9c4..b1312d2b885 100644 --- a/advisories/unreviewed/2024/05/GHSA-qgc7-3qhr-fr4g/GHSA-qgc7-3qhr-fr4g.json +++ b/advisories/unreviewed/2024/05/GHSA-qgc7-3qhr-fr4g/GHSA-qgc7-3qhr-fr4g.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-391" + "CWE-391", + "CWE-754" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-2pgc-776h-4jhr/GHSA-2pgc-776h-4jhr.json b/advisories/unreviewed/2025/05/GHSA-2pgc-776h-4jhr/GHSA-2pgc-776h-4jhr.json new file mode 100644 index 00000000000..9450100c3f2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2pgc-776h-4jhr/GHSA-2pgc-776h-4jhr.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2pgc-776h-4jhr", + "modified": "2025-05-05T18:32:54Z", + "published": "2025-05-05T18:32:54Z", + "aliases": [ + "CVE-2025-4052" + ], + "details": "Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Low)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4052" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2025/04/stable-channel-update-for-desktop_29.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/401927528" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T18:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2xf7-h82x-mhhg/GHSA-2xf7-h82x-mhhg.json b/advisories/unreviewed/2025/05/GHSA-2xf7-h82x-mhhg/GHSA-2xf7-h82x-mhhg.json new file mode 100644 index 00000000000..21babb7a3dd --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2xf7-h82x-mhhg/GHSA-2xf7-h82x-mhhg.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2xf7-h82x-mhhg", + "modified": "2025-05-05T18:32:54Z", + "published": "2025-05-05T18:32:53Z", + "aliases": [ + "CVE-2025-4051" + ], + "details": "Insufficient data validation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Medium)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4051" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2025/04/stable-channel-update-for-desktop_29.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/404000989" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T18:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-38cq-p272-v993/GHSA-38cq-p272-v993.json b/advisories/unreviewed/2025/05/GHSA-38cq-p272-v993/GHSA-38cq-p272-v993.json new file mode 100644 index 00000000000..6a1bc771c7f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-38cq-p272-v993/GHSA-38cq-p272-v993.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-38cq-p272-v993", + "modified": "2025-05-05T18:32:52Z", + "published": "2025-05-05T18:32:52Z", + "aliases": [ + "CVE-2024-57230" + ], + "details": "NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pin_wps function.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57230" + }, + { + "type": "WEB", + "url": "https://github.com/yanggao017/vuln/blob/main/NETGEAR/RAX5/CI_3_apcli_do_enr_pin_wps/README.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T17:18:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-39hv-4jx8-pggm/GHSA-39hv-4jx8-pggm.json b/advisories/unreviewed/2025/05/GHSA-39hv-4jx8-pggm/GHSA-39hv-4jx8-pggm.json new file mode 100644 index 00000000000..ac20be4da40 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-39hv-4jx8-pggm/GHSA-39hv-4jx8-pggm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-39hv-4jx8-pggm", + "modified": "2025-05-05T18:32:52Z", + "published": "2025-05-05T18:32:52Z", + "aliases": [ + "CVE-2025-45321" + ], + "details": "kashipara Online Service Management Portal V1.0 is vulnerable to SQL Injection in /osms/Requester/Requesterchangepass.php via the parameter: rPassword.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45321" + }, + { + "type": "WEB", + "url": "https://github.com/0xBhushan/Writeups/blob/main/CVE/Kashipara/Online%20Service%20Management%20Portal/SQL%20Injection-Requesterchangepass.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T16:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3hrf-pq5f-6637/GHSA-3hrf-pq5f-6637.json b/advisories/unreviewed/2025/05/GHSA-3hrf-pq5f-6637/GHSA-3hrf-pq5f-6637.json new file mode 100644 index 00000000000..1891590b92e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3hrf-pq5f-6637/GHSA-3hrf-pq5f-6637.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3hrf-pq5f-6637", + "modified": "2025-05-05T18:32:54Z", + "published": "2025-05-05T18:32:54Z", + "aliases": [ + "CVE-2025-45237" + ], + "details": "Incorrect access control in the component /config/download of DBSyncer v2.0.6 allows attackers to access the JSON file containing sensitive account information, including the encrypted password.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45237" + }, + { + "type": "WEB", + "url": "https://gist.github.com/chao112122/11cd0cc46f0c806856f375f9f3f410c6" + }, + { + "type": "WEB", + "url": "https://github.com/86dbs/dbsyncer" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T18:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-42mr-jpwh-m9rv/GHSA-42mr-jpwh-m9rv.json b/advisories/unreviewed/2025/05/GHSA-42mr-jpwh-m9rv/GHSA-42mr-jpwh-m9rv.json new file mode 100644 index 00000000000..8c99e747931 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-42mr-jpwh-m9rv/GHSA-42mr-jpwh-m9rv.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-42mr-jpwh-m9rv", + "modified": "2025-05-05T18:32:53Z", + "published": "2025-05-05T18:32:53Z", + "aliases": [ + "CVE-2025-43915" + ], + "details": "In Buoyant Edge releases before edge-25.2.1 and Enterprise for Linkerd releases 2.16.* before 2.16.5, 2.17.* before 2.17.2, and 2.18.* before 2.18.0, resource exhaustion can occur for Linkerd proxy metrics.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43915" + }, + { + "type": "WEB", + "url": "https://docs.buoyant.io/security/advisories/2025-01" + }, + { + "type": "WEB", + "url": "https://www.buoyant.io/resources" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T17:18:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4v2j-gjc9-p494/GHSA-4v2j-gjc9-p494.json b/advisories/unreviewed/2025/05/GHSA-4v2j-gjc9-p494/GHSA-4v2j-gjc9-p494.json new file mode 100644 index 00000000000..56015ea6b49 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4v2j-gjc9-p494/GHSA-4v2j-gjc9-p494.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4v2j-gjc9-p494", + "modified": "2025-05-05T18:32:53Z", + "published": "2025-05-05T18:32:53Z", + "aliases": [ + "CVE-2025-45242" + ], + "details": "Rhymix v2.1.22 was discovered to contain an arbitrary file deletion vulnerability via the procFileAdminEditImage method in /file/file.admin.controller.php.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45242" + }, + { + "type": "WEB", + "url": "https://gist.github.com/chao112122/536a55fece5f578b90cee2c841eecdce" + }, + { + "type": "WEB", + "url": "https://github.com/rhymix/rhymix" + }, + { + "type": "WEB", + "url": "http://rhymix.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-922" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T17:18:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4x3p-5fw4-h8vm/GHSA-4x3p-5fw4-h8vm.json b/advisories/unreviewed/2025/05/GHSA-4x3p-5fw4-h8vm/GHSA-4x3p-5fw4-h8vm.json new file mode 100644 index 00000000000..87637d3074a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4x3p-5fw4-h8vm/GHSA-4x3p-5fw4-h8vm.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4x3p-5fw4-h8vm", + "modified": "2025-05-05T18:32:54Z", + "published": "2025-05-05T18:32:54Z", + "aliases": [ + "CVE-2025-45239" + ], + "details": "An issue in the restores method (DataBackup.php) of foxcms v2.0.6 allows attackers to execute a directory traversal.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45239" + }, + { + "type": "WEB", + "url": "https://gist.github.com/chao112122/350e1af42ccea185206f8a8b9e4906e1" + }, + { + "type": "WEB", + "url": "https://gitee.com/qianfox/foxcms/tree/V1.2.5" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T18:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5ggr-xpwv-2fq3/GHSA-5ggr-xpwv-2fq3.json b/advisories/unreviewed/2025/05/GHSA-5ggr-xpwv-2fq3/GHSA-5ggr-xpwv-2fq3.json new file mode 100644 index 00000000000..2450e5da1b7 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5ggr-xpwv-2fq3/GHSA-5ggr-xpwv-2fq3.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5ggr-xpwv-2fq3", + "modified": "2025-05-05T18:32:52Z", + "published": "2025-05-05T18:32:52Z", + "aliases": [ + "CVE-2025-25504" + ], + "details": "An issue in the /usr/local/bin/jncs.sh script of Gefen WebFWC (In AV over IP products) v1.85h, v1.86v, and v1.70 allows attackers with network access to connect to the device over TCP port 4444 without authentication and execute arbitrary commands with root privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25504" + }, + { + "type": "WEB", + "url": "https://www.troy-wilson.com/cve-2025-25504.html" + }, + { + "type": "WEB", + "url": "http://gefen.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T16:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-66q6-24vw-2g98/GHSA-66q6-24vw-2g98.json b/advisories/unreviewed/2025/05/GHSA-66q6-24vw-2g98/GHSA-66q6-24vw-2g98.json new file mode 100644 index 00000000000..c333a5e6b01 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-66q6-24vw-2g98/GHSA-66q6-24vw-2g98.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-66q6-24vw-2g98", + "modified": "2025-05-05T18:32:52Z", + "published": "2025-05-05T18:32:52Z", + "aliases": [ + "CVE-2025-27920" + ], + "details": "Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling. By using ../ sequences in parameters, attackers could access sensitive files outside the intended directory, potentially leading to configuration leakage or arbitrary file access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27920" + }, + { + "type": "WEB", + "url": "https://www.outputmessenger.com/cve-2025-27920" + }, + { + "type": "WEB", + "url": "https://www.srimax.com/products-2/output-messenger" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T16:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9vv4-43m2-mhhp/GHSA-9vv4-43m2-mhhp.json b/advisories/unreviewed/2025/05/GHSA-9vv4-43m2-mhhp/GHSA-9vv4-43m2-mhhp.json new file mode 100644 index 00000000000..70bef8aa13e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9vv4-43m2-mhhp/GHSA-9vv4-43m2-mhhp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9vv4-43m2-mhhp", + "modified": "2025-05-05T18:32:53Z", + "published": "2025-05-05T18:32:53Z", + "aliases": [ + "CVE-2024-57231" + ], + "details": "NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pbc_wps function.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57231" + }, + { + "type": "WEB", + "url": "https://github.com/yanggao017/vuln/blob/main/NETGEAR/RAX5/CI_4_apcli_do_enr_pbc_wps/README.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T17:18:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9wf6-v4mm-mrhf/GHSA-9wf6-v4mm-mrhf.json b/advisories/unreviewed/2025/05/GHSA-9wf6-v4mm-mrhf/GHSA-9wf6-v4mm-mrhf.json new file mode 100644 index 00000000000..afcbfe82a04 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9wf6-v4mm-mrhf/GHSA-9wf6-v4mm-mrhf.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9wf6-v4mm-mrhf", + "modified": "2025-05-05T18:32:54Z", + "published": "2025-05-05T18:32:54Z", + "aliases": [ + "CVE-2025-45238" + ], + "details": "foxcms v1.2.5 was discovered to contain an arbitrary file deletion vulnerability via the delRestoreSerie method.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45238" + }, + { + "type": "WEB", + "url": "https://gist.github.com/chao112122/27010786774f2bb584cc715fb027b95c" + }, + { + "type": "WEB", + "url": "https://gitee.com/qianfox/foxcms" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T18:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g6mm-233p-269r/GHSA-g6mm-233p-269r.json b/advisories/unreviewed/2025/05/GHSA-g6mm-233p-269r/GHSA-g6mm-233p-269r.json new file mode 100644 index 00000000000..39e348485c8 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g6mm-233p-269r/GHSA-g6mm-233p-269r.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g6mm-233p-269r", + "modified": "2025-05-05T18:32:54Z", + "published": "2025-05-05T18:32:54Z", + "aliases": [ + "CVE-2025-4282" + ], + "details": "A vulnerability has been found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /classes/Users.php?f=save. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4282" + }, + { + "type": "WEB", + "url": "https://github.com/th3w0lf-1337/Vulnerabilities/blob/main/SMS-PHP/CSRF/info.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.307390" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.307390" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.563102" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T18:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gc92-8qg7-j9qw/GHSA-gc92-8qg7-j9qw.json b/advisories/unreviewed/2025/05/GHSA-gc92-8qg7-j9qw/GHSA-gc92-8qg7-j9qw.json new file mode 100644 index 00000000000..1dfb63a4e77 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gc92-8qg7-j9qw/GHSA-gc92-8qg7-j9qw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gc92-8qg7-j9qw", + "modified": "2025-05-05T18:32:52Z", + "published": "2025-05-05T18:32:52Z", + "aliases": [ + "CVE-2025-45322" + ], + "details": "kashipara Online Service Management Portal V1.0 is vulnerable to SQL Injection in osms/Requester/CheckStatus.php via the checkid parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45322" + }, + { + "type": "WEB", + "url": "https://github.com/0xBhushan/Writeups/blob/main/CVE/Kashipara/Online%20Service%20Management%20Portal/SQL%20Injection-CheckStatus.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T16:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gwf3-h435-h929/GHSA-gwf3-h435-h929.json b/advisories/unreviewed/2025/05/GHSA-gwf3-h435-h929/GHSA-gwf3-h435-h929.json new file mode 100644 index 00000000000..fd642b1f3c1 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gwf3-h435-h929/GHSA-gwf3-h435-h929.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gwf3-h435-h929", + "modified": "2025-05-05T18:32:53Z", + "published": "2025-05-05T18:32:53Z", + "aliases": [ + "CVE-2024-57233" + ], + "details": "NETGEAR RAX5 (AX1600 WiFi Router) v1.0.2.26 was discovered to contain a command injection vulnerability via the iface parameter in the vif_disable function.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57233" + }, + { + "type": "WEB", + "url": "https://github.com/yanggao017/vuln/blob/main/NETGEAR/RAX5/CI_1_vif_disable/README.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T17:18:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h28c-39h5-c348/GHSA-h28c-39h5-c348.json b/advisories/unreviewed/2025/05/GHSA-h28c-39h5-c348/GHSA-h28c-39h5-c348.json new file mode 100644 index 00000000000..3342623d72d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h28c-39h5-c348/GHSA-h28c-39h5-c348.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h28c-39h5-c348", + "modified": "2025-05-05T18:32:53Z", + "published": "2025-05-05T18:32:53Z", + "aliases": [ + "CVE-2025-0217" + ], + "details": "BeyondTrust Privileged Remote Access (PRA) versions prior to 25.1 are vulnerable to a local authentication bypass. A local authenticated attacker can view the connection details of a ShellJump session that was initiated with external tools, allowing unauthorized access to connected sessions.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0217" + }, + { + "type": "WEB", + "url": "https://www.beyondtrust.com/trust-center/security-advisories/bt25-03" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T17:18:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h8x6-pcq3-5wvw/GHSA-h8x6-pcq3-5wvw.json b/advisories/unreviewed/2025/05/GHSA-h8x6-pcq3-5wvw/GHSA-h8x6-pcq3-5wvw.json new file mode 100644 index 00000000000..f63c243638b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h8x6-pcq3-5wvw/GHSA-h8x6-pcq3-5wvw.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h8x6-pcq3-5wvw", + "modified": "2025-05-05T18:32:53Z", + "published": "2025-05-05T18:32:52Z", + "aliases": [ + "CVE-2025-27921" + ], + "details": "A reflected cross-site scripting (XSS) vulnerability was discovered in Output Messenger before 2.0.63, where unsanitized input could be injected into the web application’s response. This vulnerability occurs when user-controlled input is reflected back into the browser without proper sanitization or encoding.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27921" + }, + { + "type": "WEB", + "url": "https://www.outputmessenger.com/cve-2025-27921" + }, + { + "type": "WEB", + "url": "https://www.srimax.com/products-2/output-messenger" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T16:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hcf7-pvq8-wh55/GHSA-hcf7-pvq8-wh55.json b/advisories/unreviewed/2025/05/GHSA-hcf7-pvq8-wh55/GHSA-hcf7-pvq8-wh55.json new file mode 100644 index 00000000000..58bc843545b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hcf7-pvq8-wh55/GHSA-hcf7-pvq8-wh55.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hcf7-pvq8-wh55", + "modified": "2025-05-05T18:32:53Z", + "published": "2025-05-05T18:32:52Z", + "aliases": [ + "CVE-2024-11615" + ], + "details": "The Envolve Plugin plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 1.0 via the 'zetra_deleteLanguageFile' and 'zetra_deleteFontsFile' functions. This is due to the plugin not properly validating a file or its path prior to deleting it. This makes it possible for unauthenticated attackers to delete language files.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11615" + }, + { + "type": "WEB", + "url": "https://themeforest.net/item/envolve-consulting-business-wordpress-theme/28748459" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/05909e9c-4f57-4556-bae9-b0b63a9a43ba?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T17:18:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hf7x-p9xq-fhxq/GHSA-hf7x-p9xq-fhxq.json b/advisories/unreviewed/2025/05/GHSA-hf7x-p9xq-fhxq/GHSA-hf7x-p9xq-fhxq.json new file mode 100644 index 00000000000..0f61febd280 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hf7x-p9xq-fhxq/GHSA-hf7x-p9xq-fhxq.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hf7x-p9xq-fhxq", + "modified": "2025-05-05T18:32:53Z", + "published": "2025-05-05T18:32:53Z", + "aliases": [ + "CVE-2025-45240" + ], + "details": "foxcms v1.2.5 was discovered to contain a SQL injection vulnerability via the executeCommand method in DataBackup.php.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45240" + }, + { + "type": "WEB", + "url": "https://gist.github.com/chao112122/648033972709fb50b3c89363cd64a9a4" + }, + { + "type": "WEB", + "url": "https://gitee.com/qianfox/foxcms" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T17:18:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hwmq-r762-46wq/GHSA-hwmq-r762-46wq.json b/advisories/unreviewed/2025/05/GHSA-hwmq-r762-46wq/GHSA-hwmq-r762-46wq.json new file mode 100644 index 00000000000..d5ce7d86b29 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hwmq-r762-46wq/GHSA-hwmq-r762-46wq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwmq-r762-46wq", + "modified": "2025-05-05T18:32:53Z", + "published": "2025-05-05T18:32:53Z", + "aliases": [ + "CVE-2024-57229" + ], + "details": "NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the devname parameter in the reset_wifi function.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57229" + }, + { + "type": "WEB", + "url": "https://github.com/yanggao017/vuln/blob/main/NETGEAR/RAX5/CI_7_reset_wifi/README.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T17:18:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-j8p7-4x6h-98g9/GHSA-j8p7-4x6h-98g9.json b/advisories/unreviewed/2025/05/GHSA-j8p7-4x6h-98g9/GHSA-j8p7-4x6h-98g9.json new file mode 100644 index 00000000000..b92b1beb3eb --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-j8p7-4x6h-98g9/GHSA-j8p7-4x6h-98g9.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j8p7-4x6h-98g9", + "modified": "2025-05-05T18:32:53Z", + "published": "2025-05-05T18:32:52Z", + "aliases": [ + "CVE-2025-4281" + ], + "details": "A vulnerability, which was classified as problematic, was found in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 7. This affects an unknown part of the file /api/GylOperator/LoadData. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4281" + }, + { + "type": "WEB", + "url": "https://github.com/zhangbuneng/an-unauthorized-vulnerability-in-the-business-management-system-of-Wisdom-7-Group/issues/1" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.307389" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.307389" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.563515" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T16:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-m46c-2xgf-gfrv/GHSA-m46c-2xgf-gfrv.json b/advisories/unreviewed/2025/05/GHSA-m46c-2xgf-gfrv/GHSA-m46c-2xgf-gfrv.json new file mode 100644 index 00000000000..2e62a44eed4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-m46c-2xgf-gfrv/GHSA-m46c-2xgf-gfrv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m46c-2xgf-gfrv", + "modified": "2025-05-05T18:32:52Z", + "published": "2025-05-05T18:32:52Z", + "aliases": [ + "CVE-2025-45042" + ], + "details": "Tenda AC9 v15.03.05.14 was discovered to contain a command injection vulnerability via the Telnet function.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45042" + }, + { + "type": "WEB", + "url": "https://github.com/Ghostsuzhijian/Iot-/blob/main/ac9_telnetd/rx3_telnetd.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T16:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p576-652x-gvvh/GHSA-p576-652x-gvvh.json b/advisories/unreviewed/2025/05/GHSA-p576-652x-gvvh/GHSA-p576-652x-gvvh.json new file mode 100644 index 00000000000..9a9b30dd8c6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p576-652x-gvvh/GHSA-p576-652x-gvvh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p576-652x-gvvh", + "modified": "2025-05-05T18:32:52Z", + "published": "2025-05-05T18:32:52Z", + "aliases": [ + "CVE-2025-26241" + ], + "details": "A SQL injection vulnerability in the \"Search\" functionality of \"tickets.php\" page in osTicket <=1.17.5 allows authenticated attackers to execute arbitrary SQL commands via the \"keywords\" and \"topic_id\" URL parameters combination.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26241" + }, + { + "type": "WEB", + "url": "https://members.backbox.org/osticket-sql-injection-bypass" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T16:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-phfm-cgq2-xvp6/GHSA-phfm-cgq2-xvp6.json b/advisories/unreviewed/2025/05/GHSA-phfm-cgq2-xvp6/GHSA-phfm-cgq2-xvp6.json new file mode 100644 index 00000000000..92b29686096 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-phfm-cgq2-xvp6/GHSA-phfm-cgq2-xvp6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phfm-cgq2-xvp6", + "modified": "2025-05-05T18:32:53Z", + "published": "2025-05-05T18:32:53Z", + "aliases": [ + "CVE-2024-57235" + ], + "details": "NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the iface parameter in the vif_enable function.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57235" + }, + { + "type": "WEB", + "url": "https://github.com/yanggao017/vuln/blob/main/NETGEAR/RAX5/CI_2_vif_enable/README.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T17:18:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-pxrf-vj27-hg76/GHSA-pxrf-vj27-hg76.json b/advisories/unreviewed/2025/05/GHSA-pxrf-vj27-hg76/GHSA-pxrf-vj27-hg76.json new file mode 100644 index 00000000000..ef92d44a789 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pxrf-vj27-hg76/GHSA-pxrf-vj27-hg76.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pxrf-vj27-hg76", + "modified": "2025-05-05T18:32:53Z", + "published": "2025-05-05T18:32:53Z", + "aliases": [ + "CVE-2025-1992" + ], + "details": "IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 could allow an authenticated user, under non default configurations, to cause a denial of service due to insufficient release of allocated memory after usage.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1992" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7232515" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T17:18:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qppj-mpvf-fhqg/GHSA-qppj-mpvf-fhqg.json b/advisories/unreviewed/2025/05/GHSA-qppj-mpvf-fhqg/GHSA-qppj-mpvf-fhqg.json new file mode 100644 index 00000000000..7fa0cbfbbfb --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qppj-mpvf-fhqg/GHSA-qppj-mpvf-fhqg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qppj-mpvf-fhqg", + "modified": "2025-05-05T18:32:53Z", + "published": "2025-05-05T18:32:53Z", + "aliases": [ + "CVE-2024-57234" + ], + "details": "NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps function.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57234" + }, + { + "type": "WEB", + "url": "https://github.com/yanggao017/vuln/blob/main/NETGEAR/RAX5/CI_5_apcli_cancel_wps/README.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T17:18:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-r773-hh48-f8mc/GHSA-r773-hh48-f8mc.json b/advisories/unreviewed/2025/05/GHSA-r773-hh48-f8mc/GHSA-r773-hh48-f8mc.json new file mode 100644 index 00000000000..e9fcd4950a9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-r773-hh48-f8mc/GHSA-r773-hh48-f8mc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r773-hh48-f8mc", + "modified": "2025-05-05T18:32:52Z", + "published": "2025-05-05T18:32:52Z", + "aliases": [ + "CVE-2024-57232" + ], + "details": "NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen_pincode function.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57232" + }, + { + "type": "WEB", + "url": "https://github.com/yanggao017/vuln/blob/main/NETGEAR/RAX5/CI_6_apcli_wps_gen_pincode/README.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T17:18:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v248-84wv-hjm5/GHSA-v248-84wv-hjm5.json b/advisories/unreviewed/2025/05/GHSA-v248-84wv-hjm5/GHSA-v248-84wv-hjm5.json new file mode 100644 index 00000000000..e87ff9aa5e4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v248-84wv-hjm5/GHSA-v248-84wv-hjm5.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v248-84wv-hjm5", + "modified": "2025-05-05T18:32:52Z", + "published": "2025-05-05T18:32:52Z", + "aliases": [ + "CVE-2025-28062" + ], + "details": "A Cross-Site Request Forgery (CSRF) vulnerability was discovered in ERPNEXT 14.82.1 and 14.74.3. The vulnerability allows an attacker to perform unauthorized actions such as user deletion, password resets, and privilege escalation due to missing CSRF protections.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28062" + }, + { + "type": "WEB", + "url": "https://github.com/Thvt0ne/CVE-2025-28062" + }, + { + "type": "WEB", + "url": "https://github.com/frappe/erpnext" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T16:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v9xg-688g-r69h/GHSA-v9xg-688g-r69h.json b/advisories/unreviewed/2025/05/GHSA-v9xg-688g-r69h/GHSA-v9xg-688g-r69h.json new file mode 100644 index 00000000000..c94d3173aeb --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v9xg-688g-r69h/GHSA-v9xg-688g-r69h.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v9xg-688g-r69h", + "modified": "2025-05-05T18:32:54Z", + "published": "2025-05-05T18:32:54Z", + "aliases": [ + "CVE-2025-4096" + ], + "details": "Heap buffer overflow in HTML in Google Chrome prior to 136.0.7103.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4096" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2025/04/stable-channel-update-for-desktop_29.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/409911705" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T18:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vvqw-r3vv-46ph/GHSA-vvqw-r3vv-46ph.json b/advisories/unreviewed/2025/05/GHSA-vvqw-r3vv-46ph/GHSA-vvqw-r3vv-46ph.json new file mode 100644 index 00000000000..e24cb45c89a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vvqw-r3vv-46ph/GHSA-vvqw-r3vv-46ph.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vvqw-r3vv-46ph", + "modified": "2025-05-05T18:32:54Z", + "published": "2025-05-05T18:32:53Z", + "aliases": [ + "CVE-2025-4050" + ], + "details": "Out of bounds memory access in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4050" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2025/04/stable-channel-update-for-desktop_29.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/409342999" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T18:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w64c-qgh2-qj9c/GHSA-w64c-qgh2-qj9c.json b/advisories/unreviewed/2025/05/GHSA-w64c-qgh2-qj9c/GHSA-w64c-qgh2-qj9c.json new file mode 100644 index 00000000000..13ce533dfc2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w64c-qgh2-qj9c/GHSA-w64c-qgh2-qj9c.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w64c-qgh2-qj9c", + "modified": "2025-05-05T18:32:52Z", + "published": "2025-05-05T18:32:52Z", + "aliases": [ + "CVE-2025-45320" + ], + "details": "A Directory Listing Vulnerability was found in the /osms/Requester/ directory of the Kashipara Online Service Management Portal V1.0.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45320" + }, + { + "type": "WEB", + "url": "https://github.com/0xBhushan/Writeups/blob/main/CVE/Kashipara/Online%20Service%20Management%20Portal/Directory%20Listing_Requester.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T16:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-x4jf-gq5v-q6vw/GHSA-x4jf-gq5v-q6vw.json b/advisories/unreviewed/2025/05/GHSA-x4jf-gq5v-q6vw/GHSA-x4jf-gq5v-q6vw.json new file mode 100644 index 00000000000..2396918862f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-x4jf-gq5v-q6vw/GHSA-x4jf-gq5v-q6vw.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x4jf-gq5v-q6vw", + "modified": "2025-05-05T18:32:54Z", + "published": "2025-05-05T18:32:53Z", + "aliases": [ + "CVE-2025-45236" + ], + "details": "A stored cross-site scripting (XSS) vulnerability in the Edit Profile feature of DBSyncer v2.0.6 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Nickname parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45236" + }, + { + "type": "WEB", + "url": "https://gist.github.com/chao112122/504e224e63c9a966ba233df1d523ce4f" + }, + { + "type": "WEB", + "url": "https://github.com/86dbs/dbsyncer" + }, + { + "type": "WEB", + "url": "http://dbsyncer.com" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T18:15:43Z" + } +} \ No newline at end of file