diff --git a/advisories/unreviewed/2022/10/GHSA-38gp-2mrc-f9cj/GHSA-38gp-2mrc-f9cj.json b/advisories/unreviewed/2022/10/GHSA-38gp-2mrc-f9cj/GHSA-38gp-2mrc-f9cj.json index a17d6fb318d..b59d9371a03 100644 --- a/advisories/unreviewed/2022/10/GHSA-38gp-2mrc-f9cj/GHSA-38gp-2mrc-f9cj.json +++ b/advisories/unreviewed/2022/10/GHSA-38gp-2mrc-f9cj/GHSA-38gp-2mrc-f9cj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-38gp-2mrc-f9cj", - "modified": "2022-10-20T19:00:29Z", + "modified": "2025-05-13T15:32:00Z", "published": "2022-10-18T12:00:29Z", "aliases": [ "CVE-2021-3305" @@ -38,6 +38,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-426", "CWE-428" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/10/GHSA-cg66-23q8-4x4p/GHSA-cg66-23q8-4x4p.json b/advisories/unreviewed/2022/10/GHSA-cg66-23q8-4x4p/GHSA-cg66-23q8-4x4p.json index 6d898ccdefa..4e68e0aa850 100644 --- a/advisories/unreviewed/2022/10/GHSA-cg66-23q8-4x4p/GHSA-cg66-23q8-4x4p.json +++ b/advisories/unreviewed/2022/10/GHSA-cg66-23q8-4x4p/GHSA-cg66-23q8-4x4p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cg66-23q8-4x4p", - "modified": "2022-10-20T19:00:29Z", + "modified": "2025-05-13T15:32:00Z", "published": "2022-10-18T19:00:35Z", "aliases": [ "CVE-2022-36439" @@ -23,13 +23,19 @@ "type": "WEB", "url": "https://asus-my.sharepoint.com/personal/carinacw_li_asus_com/_layouts/15/onedrive.aspx?id=%2Fpersonal%2Fcarinacw%5Fli%5Fasus%5Fcom%2FDocuments%2FSecurity%2FCase%2D220713%2FAsus%20Arbitary%20File%20Deletion%2Epdf&parent=%2Fpersonal%2Fcarinacw%5Fli%5Fasus%5Fcom%2FDocuments%2FSecurity%2FCase%2D220713&ga=1" }, + { + "type": "WEB", + "url": "https://asus-my.sharepoint.com/personal/carinacw_li_asus_com/_layouts/15/onedrive.aspx?id=%2Fpersonal%2Fcarinacw_li_asus_com%2FDocuments%2FSecurity%2FCase-220713%2FAsus%20Arbitary%20File%20Deletion.pdf&parent=%2Fpersonal%2Fcarinacw_li_asus_com%2FDocuments%2FSecurity%2FCase-220713&ga=1" + }, { "type": "WEB", "url": "https://asus.com" } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-ggp9-5cp6-gwqr/GHSA-ggp9-5cp6-gwqr.json b/advisories/unreviewed/2022/10/GHSA-ggp9-5cp6-gwqr/GHSA-ggp9-5cp6-gwqr.json index 16839d26c1d..1e0c0ade731 100644 --- a/advisories/unreviewed/2022/10/GHSA-ggp9-5cp6-gwqr/GHSA-ggp9-5cp6-gwqr.json +++ b/advisories/unreviewed/2022/10/GHSA-ggp9-5cp6-gwqr/GHSA-ggp9-5cp6-gwqr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-hhj4-852g-8rg5/GHSA-hhj4-852g-8rg5.json b/advisories/unreviewed/2022/10/GHSA-hhj4-852g-8rg5/GHSA-hhj4-852g-8rg5.json index c727dbe1048..451370a9dd9 100644 --- a/advisories/unreviewed/2022/10/GHSA-hhj4-852g-8rg5/GHSA-hhj4-852g-8rg5.json +++ b/advisories/unreviewed/2022/10/GHSA-hhj4-852g-8rg5/GHSA-hhj4-852g-8rg5.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-j474-2x28-2gg2/GHSA-j474-2x28-2gg2.json b/advisories/unreviewed/2022/10/GHSA-j474-2x28-2gg2/GHSA-j474-2x28-2gg2.json index dbdaacac447..e9acbc2a914 100644 --- a/advisories/unreviewed/2022/10/GHSA-j474-2x28-2gg2/GHSA-j474-2x28-2gg2.json +++ b/advisories/unreviewed/2022/10/GHSA-j474-2x28-2gg2/GHSA-j474-2x28-2gg2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j474-2x28-2gg2", - "modified": "2022-10-20T19:00:29Z", + "modified": "2025-05-13T15:32:00Z", "published": "2022-10-18T19:00:35Z", "aliases": [ "CVE-2022-36438" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://asus-my.sharepoint.com/personal/carinacw_li_asus_com/_layouts/15/onedrive.aspx?id=%2Fpersonal%2Fcarinacw%5Fli%5Fasus%5Fcom%2FDocuments%2FSecurity%2FCase%2D220713%2FAsus%20Switch%20LPE%2Epdf&parent=%2Fpersonal%2Fcarinacw%5Fli%5Fasus%5Fcom%2FDocuments%2FSecurity%2FCase%2D220713&ga=1" }, + { + "type": "WEB", + "url": "https://asus-my.sharepoint.com/personal/carinacw_li_asus_com/_layouts/15/onedrive.aspx?id=%2Fpersonal%2Fcarinacw_li_asus_com%2FDocuments%2FSecurity%2FCase-220713%2FAsus%20Switch%20LPE.pdf&parent=%2Fpersonal%2Fcarinacw_li_asus_com%2FDocuments%2FSecurity%2FCase-220713&ga=1" + }, { "type": "WEB", "url": "https://asus.com" diff --git a/advisories/unreviewed/2024/03/GHSA-fgc2-xxg6-h24v/GHSA-fgc2-xxg6-h24v.json b/advisories/unreviewed/2024/03/GHSA-fgc2-xxg6-h24v/GHSA-fgc2-xxg6-h24v.json index 7b0b08ce033..0bdc119d5d7 100644 --- a/advisories/unreviewed/2024/03/GHSA-fgc2-xxg6-h24v/GHSA-fgc2-xxg6-h24v.json +++ b/advisories/unreviewed/2024/03/GHSA-fgc2-xxg6-h24v/GHSA-fgc2-xxg6-h24v.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-fgc2-xxg6-h24v", - "modified": "2024-03-27T15:30:37Z", + "modified": "2025-05-13T15:32:02Z", "published": "2024-03-27T15:30:37Z", "aliases": [ "CVE-2024-23510" ], - "details": "Cross-Site Request Forgery (CSRF) vulnerability in Martyn Chamberlin Don't Muck My Markup.This issue affects Don't Muck My Markup: from n/a through 1.8.\n\n", + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Martyn Chamberlin Don't Muck My Markup.This issue affects Don't Muck My Markup: from n/a through 1.8.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-mch6-3hjm-3qj2/GHSA-mch6-3hjm-3qj2.json b/advisories/unreviewed/2024/03/GHSA-mch6-3hjm-3qj2/GHSA-mch6-3hjm-3qj2.json index 524920eb428..1c944a4661e 100644 --- a/advisories/unreviewed/2024/03/GHSA-mch6-3hjm-3qj2/GHSA-mch6-3hjm-3qj2.json +++ b/advisories/unreviewed/2024/03/GHSA-mch6-3hjm-3qj2/GHSA-mch6-3hjm-3qj2.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-mch6-3hjm-3qj2", - "modified": "2024-03-27T15:30:37Z", + "modified": "2025-05-13T15:32:01Z", "published": "2024-03-27T15:30:37Z", "aliases": [ "CVE-2023-39311" ], - "details": "Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Fusion Builder.This issue affects Fusion Builder: from n/a through 3.11.1.\n\n", + "details": "Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Fusion Builder.This issue affects Fusion Builder: from n/a through 3.11.1.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-w26h-g22f-g53g/GHSA-w26h-g22f-g53g.json b/advisories/unreviewed/2024/03/GHSA-w26h-g22f-g53g/GHSA-w26h-g22f-g53g.json index 29a17c9aeed..0eb220b63f5 100644 --- a/advisories/unreviewed/2024/03/GHSA-w26h-g22f-g53g/GHSA-w26h-g22f-g53g.json +++ b/advisories/unreviewed/2024/03/GHSA-w26h-g22f-g53g/GHSA-w26h-g22f-g53g.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-w26h-g22f-g53g", - "modified": "2024-03-27T15:30:37Z", + "modified": "2025-05-13T15:32:01Z", "published": "2024-03-27T15:30:37Z", "aliases": [ "CVE-2023-34020" ], - "details": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Uncanny Owl Uncanny Toolkit for LearnDash.This issue affects Uncanny Toolkit for LearnDash: from n/a through 3.6.4.3.\n\n", + "details": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Uncanny Owl Uncanny Toolkit for LearnDash.This issue affects Uncanny Toolkit for LearnDash: from n/a through 3.6.4.3.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/05/GHSA-29pr-hmrg-229w/GHSA-29pr-hmrg-229w.json b/advisories/unreviewed/2024/05/GHSA-29pr-hmrg-229w/GHSA-29pr-hmrg-229w.json index 3622f36025b..52e6f5d8704 100644 --- a/advisories/unreviewed/2024/05/GHSA-29pr-hmrg-229w/GHSA-29pr-hmrg-229w.json +++ b/advisories/unreviewed/2024/05/GHSA-29pr-hmrg-229w/GHSA-29pr-hmrg-229w.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-2qj7-3x7p-9jgf/GHSA-2qj7-3x7p-9jgf.json b/advisories/unreviewed/2024/05/GHSA-2qj7-3x7p-9jgf/GHSA-2qj7-3x7p-9jgf.json index 81f7e536e5b..9fe48931964 100644 --- a/advisories/unreviewed/2024/05/GHSA-2qj7-3x7p-9jgf/GHSA-2qj7-3x7p-9jgf.json +++ b/advisories/unreviewed/2024/05/GHSA-2qj7-3x7p-9jgf/GHSA-2qj7-3x7p-9jgf.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-2xcg-h5x6-gp8h/GHSA-2xcg-h5x6-gp8h.json b/advisories/unreviewed/2024/05/GHSA-2xcg-h5x6-gp8h/GHSA-2xcg-h5x6-gp8h.json index a694a82debf..10bc49561ce 100644 --- a/advisories/unreviewed/2024/05/GHSA-2xcg-h5x6-gp8h/GHSA-2xcg-h5x6-gp8h.json +++ b/advisories/unreviewed/2024/05/GHSA-2xcg-h5x6-gp8h/GHSA-2xcg-h5x6-gp8h.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-385j-3cf6-7qjj/GHSA-385j-3cf6-7qjj.json b/advisories/unreviewed/2024/05/GHSA-385j-3cf6-7qjj/GHSA-385j-3cf6-7qjj.json index b68ae6fb866..3d1c97b9a92 100644 --- a/advisories/unreviewed/2024/05/GHSA-385j-3cf6-7qjj/GHSA-385j-3cf6-7qjj.json +++ b/advisories/unreviewed/2024/05/GHSA-385j-3cf6-7qjj/GHSA-385j-3cf6-7qjj.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-3gr6-26j4-g5xq/GHSA-3gr6-26j4-g5xq.json b/advisories/unreviewed/2024/05/GHSA-3gr6-26j4-g5xq/GHSA-3gr6-26j4-g5xq.json index 7bced61332b..050b0aef6e0 100644 --- a/advisories/unreviewed/2024/05/GHSA-3gr6-26j4-g5xq/GHSA-3gr6-26j4-g5xq.json +++ b/advisories/unreviewed/2024/05/GHSA-3gr6-26j4-g5xq/GHSA-3gr6-26j4-g5xq.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-4322-j82q-j25q/GHSA-4322-j82q-j25q.json b/advisories/unreviewed/2024/05/GHSA-4322-j82q-j25q/GHSA-4322-j82q-j25q.json index 39628e79f10..442befa5219 100644 --- a/advisories/unreviewed/2024/05/GHSA-4322-j82q-j25q/GHSA-4322-j82q-j25q.json +++ b/advisories/unreviewed/2024/05/GHSA-4322-j82q-j25q/GHSA-4322-j82q-j25q.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-4wfj-w835-wr77/GHSA-4wfj-w835-wr77.json b/advisories/unreviewed/2024/05/GHSA-4wfj-w835-wr77/GHSA-4wfj-w835-wr77.json index 18e1f4548d6..4a83360cc68 100644 --- a/advisories/unreviewed/2024/05/GHSA-4wfj-w835-wr77/GHSA-4wfj-w835-wr77.json +++ b/advisories/unreviewed/2024/05/GHSA-4wfj-w835-wr77/GHSA-4wfj-w835-wr77.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-4xr8-m8jw-38p5/GHSA-4xr8-m8jw-38p5.json b/advisories/unreviewed/2024/05/GHSA-4xr8-m8jw-38p5/GHSA-4xr8-m8jw-38p5.json index 09ee366c6bb..14886669e0f 100644 --- a/advisories/unreviewed/2024/05/GHSA-4xr8-m8jw-38p5/GHSA-4xr8-m8jw-38p5.json +++ b/advisories/unreviewed/2024/05/GHSA-4xr8-m8jw-38p5/GHSA-4xr8-m8jw-38p5.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-5357-pj4w-wrc7/GHSA-5357-pj4w-wrc7.json b/advisories/unreviewed/2024/05/GHSA-5357-pj4w-wrc7/GHSA-5357-pj4w-wrc7.json index 81fc9877016..a3b8ea82d19 100644 --- a/advisories/unreviewed/2024/05/GHSA-5357-pj4w-wrc7/GHSA-5357-pj4w-wrc7.json +++ b/advisories/unreviewed/2024/05/GHSA-5357-pj4w-wrc7/GHSA-5357-pj4w-wrc7.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-5789-f25c-9hq9/GHSA-5789-f25c-9hq9.json b/advisories/unreviewed/2024/05/GHSA-5789-f25c-9hq9/GHSA-5789-f25c-9hq9.json index d50b0ea5cf3..e5ac37415e7 100644 --- a/advisories/unreviewed/2024/05/GHSA-5789-f25c-9hq9/GHSA-5789-f25c-9hq9.json +++ b/advisories/unreviewed/2024/05/GHSA-5789-f25c-9hq9/GHSA-5789-f25c-9hq9.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-6663-87fp-x34j/GHSA-6663-87fp-x34j.json b/advisories/unreviewed/2024/05/GHSA-6663-87fp-x34j/GHSA-6663-87fp-x34j.json index 2128aaf8117..d0da43afb19 100644 --- a/advisories/unreviewed/2024/05/GHSA-6663-87fp-x34j/GHSA-6663-87fp-x34j.json +++ b/advisories/unreviewed/2024/05/GHSA-6663-87fp-x34j/GHSA-6663-87fp-x34j.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-7crq-fr5p-gw4f/GHSA-7crq-fr5p-gw4f.json b/advisories/unreviewed/2024/05/GHSA-7crq-fr5p-gw4f/GHSA-7crq-fr5p-gw4f.json index 132855fbcde..9000ec11736 100644 --- a/advisories/unreviewed/2024/05/GHSA-7crq-fr5p-gw4f/GHSA-7crq-fr5p-gw4f.json +++ b/advisories/unreviewed/2024/05/GHSA-7crq-fr5p-gw4f/GHSA-7crq-fr5p-gw4f.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-7v3w-wv8q-896w/GHSA-7v3w-wv8q-896w.json b/advisories/unreviewed/2024/05/GHSA-7v3w-wv8q-896w/GHSA-7v3w-wv8q-896w.json index 59c2f2797f7..3b4cb275e96 100644 --- a/advisories/unreviewed/2024/05/GHSA-7v3w-wv8q-896w/GHSA-7v3w-wv8q-896w.json +++ b/advisories/unreviewed/2024/05/GHSA-7v3w-wv8q-896w/GHSA-7v3w-wv8q-896w.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-89cr-w6g3-2vxm/GHSA-89cr-w6g3-2vxm.json b/advisories/unreviewed/2024/05/GHSA-89cr-w6g3-2vxm/GHSA-89cr-w6g3-2vxm.json index 65c6638805e..04780d5680d 100644 --- a/advisories/unreviewed/2024/05/GHSA-89cr-w6g3-2vxm/GHSA-89cr-w6g3-2vxm.json +++ b/advisories/unreviewed/2024/05/GHSA-89cr-w6g3-2vxm/GHSA-89cr-w6g3-2vxm.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-8p2g-vwvp-x9g3/GHSA-8p2g-vwvp-x9g3.json b/advisories/unreviewed/2024/05/GHSA-8p2g-vwvp-x9g3/GHSA-8p2g-vwvp-x9g3.json index 4dd4c0e184d..2f4a1c3d552 100644 --- a/advisories/unreviewed/2024/05/GHSA-8p2g-vwvp-x9g3/GHSA-8p2g-vwvp-x9g3.json +++ b/advisories/unreviewed/2024/05/GHSA-8p2g-vwvp-x9g3/GHSA-8p2g-vwvp-x9g3.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-8x2f-hxv4-x362/GHSA-8x2f-hxv4-x362.json b/advisories/unreviewed/2024/05/GHSA-8x2f-hxv4-x362/GHSA-8x2f-hxv4-x362.json index d0edfe9d68f..21a93e9e03b 100644 --- a/advisories/unreviewed/2024/05/GHSA-8x2f-hxv4-x362/GHSA-8x2f-hxv4-x362.json +++ b/advisories/unreviewed/2024/05/GHSA-8x2f-hxv4-x362/GHSA-8x2f-hxv4-x362.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-984v-8qpj-2vq3/GHSA-984v-8qpj-2vq3.json b/advisories/unreviewed/2024/05/GHSA-984v-8qpj-2vq3/GHSA-984v-8qpj-2vq3.json index c306a09ca9e..6c6e70f9738 100644 --- a/advisories/unreviewed/2024/05/GHSA-984v-8qpj-2vq3/GHSA-984v-8qpj-2vq3.json +++ b/advisories/unreviewed/2024/05/GHSA-984v-8qpj-2vq3/GHSA-984v-8qpj-2vq3.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-9jgf-m9xh-v64q/GHSA-9jgf-m9xh-v64q.json b/advisories/unreviewed/2024/05/GHSA-9jgf-m9xh-v64q/GHSA-9jgf-m9xh-v64q.json index 41ccc0bc2be..7a2febf1b89 100644 --- a/advisories/unreviewed/2024/05/GHSA-9jgf-m9xh-v64q/GHSA-9jgf-m9xh-v64q.json +++ b/advisories/unreviewed/2024/05/GHSA-9jgf-m9xh-v64q/GHSA-9jgf-m9xh-v64q.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-9mc3-x6rh-hrgg/GHSA-9mc3-x6rh-hrgg.json b/advisories/unreviewed/2024/05/GHSA-9mc3-x6rh-hrgg/GHSA-9mc3-x6rh-hrgg.json index 15370bb1574..f17215c429b 100644 --- a/advisories/unreviewed/2024/05/GHSA-9mc3-x6rh-hrgg/GHSA-9mc3-x6rh-hrgg.json +++ b/advisories/unreviewed/2024/05/GHSA-9mc3-x6rh-hrgg/GHSA-9mc3-x6rh-hrgg.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-9w3w-6xhh-85vw/GHSA-9w3w-6xhh-85vw.json b/advisories/unreviewed/2024/05/GHSA-9w3w-6xhh-85vw/GHSA-9w3w-6xhh-85vw.json index f44797ab469..06657039b30 100644 --- a/advisories/unreviewed/2024/05/GHSA-9w3w-6xhh-85vw/GHSA-9w3w-6xhh-85vw.json +++ b/advisories/unreviewed/2024/05/GHSA-9w3w-6xhh-85vw/GHSA-9w3w-6xhh-85vw.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-c33g-f5fp-rpcq/GHSA-c33g-f5fp-rpcq.json b/advisories/unreviewed/2024/05/GHSA-c33g-f5fp-rpcq/GHSA-c33g-f5fp-rpcq.json index 2ea49c9bdf8..aebb04167cc 100644 --- a/advisories/unreviewed/2024/05/GHSA-c33g-f5fp-rpcq/GHSA-c33g-f5fp-rpcq.json +++ b/advisories/unreviewed/2024/05/GHSA-c33g-f5fp-rpcq/GHSA-c33g-f5fp-rpcq.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-f94j-w2gr-ff6h/GHSA-f94j-w2gr-ff6h.json b/advisories/unreviewed/2024/05/GHSA-f94j-w2gr-ff6h/GHSA-f94j-w2gr-ff6h.json index 473a502edc1..283c7873b3a 100644 --- a/advisories/unreviewed/2024/05/GHSA-f94j-w2gr-ff6h/GHSA-f94j-w2gr-ff6h.json +++ b/advisories/unreviewed/2024/05/GHSA-f94j-w2gr-ff6h/GHSA-f94j-w2gr-ff6h.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-fgjm-mh7r-2q22/GHSA-fgjm-mh7r-2q22.json b/advisories/unreviewed/2024/05/GHSA-fgjm-mh7r-2q22/GHSA-fgjm-mh7r-2q22.json index 93bf9950fdf..80866e9fbef 100644 --- a/advisories/unreviewed/2024/05/GHSA-fgjm-mh7r-2q22/GHSA-fgjm-mh7r-2q22.json +++ b/advisories/unreviewed/2024/05/GHSA-fgjm-mh7r-2q22/GHSA-fgjm-mh7r-2q22.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-g4f9-8rcm-7rmj/GHSA-g4f9-8rcm-7rmj.json b/advisories/unreviewed/2024/05/GHSA-g4f9-8rcm-7rmj/GHSA-g4f9-8rcm-7rmj.json index 2616e2e47d4..9ff9e5ea691 100644 --- a/advisories/unreviewed/2024/05/GHSA-g4f9-8rcm-7rmj/GHSA-g4f9-8rcm-7rmj.json +++ b/advisories/unreviewed/2024/05/GHSA-g4f9-8rcm-7rmj/GHSA-g4f9-8rcm-7rmj.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-g6xj-5g63-h824/GHSA-g6xj-5g63-h824.json b/advisories/unreviewed/2024/05/GHSA-g6xj-5g63-h824/GHSA-g6xj-5g63-h824.json index a72010cf9c8..b6ccffa76db 100644 --- a/advisories/unreviewed/2024/05/GHSA-g6xj-5g63-h824/GHSA-g6xj-5g63-h824.json +++ b/advisories/unreviewed/2024/05/GHSA-g6xj-5g63-h824/GHSA-g6xj-5g63-h824.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-hhvm-xh54-j277/GHSA-hhvm-xh54-j277.json b/advisories/unreviewed/2024/05/GHSA-hhvm-xh54-j277/GHSA-hhvm-xh54-j277.json index 596fd0ff91e..53f28f07460 100644 --- a/advisories/unreviewed/2024/05/GHSA-hhvm-xh54-j277/GHSA-hhvm-xh54-j277.json +++ b/advisories/unreviewed/2024/05/GHSA-hhvm-xh54-j277/GHSA-hhvm-xh54-j277.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-hj9r-q6x8-gpf5/GHSA-hj9r-q6x8-gpf5.json b/advisories/unreviewed/2024/05/GHSA-hj9r-q6x8-gpf5/GHSA-hj9r-q6x8-gpf5.json index 73d20f8b401..a0d23758e36 100644 --- a/advisories/unreviewed/2024/05/GHSA-hj9r-q6x8-gpf5/GHSA-hj9r-q6x8-gpf5.json +++ b/advisories/unreviewed/2024/05/GHSA-hj9r-q6x8-gpf5/GHSA-hj9r-q6x8-gpf5.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-j9m8-qg4j-ww52/GHSA-j9m8-qg4j-ww52.json b/advisories/unreviewed/2024/05/GHSA-j9m8-qg4j-ww52/GHSA-j9m8-qg4j-ww52.json index 13f8951996c..09ccc1a128c 100644 --- a/advisories/unreviewed/2024/05/GHSA-j9m8-qg4j-ww52/GHSA-j9m8-qg4j-ww52.json +++ b/advisories/unreviewed/2024/05/GHSA-j9m8-qg4j-ww52/GHSA-j9m8-qg4j-ww52.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-jw44-pw3q-q93x/GHSA-jw44-pw3q-q93x.json b/advisories/unreviewed/2024/05/GHSA-jw44-pw3q-q93x/GHSA-jw44-pw3q-q93x.json index b7e596d4a25..e75479125d3 100644 --- a/advisories/unreviewed/2024/05/GHSA-jw44-pw3q-q93x/GHSA-jw44-pw3q-q93x.json +++ b/advisories/unreviewed/2024/05/GHSA-jw44-pw3q-q93x/GHSA-jw44-pw3q-q93x.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-m53q-66x7-v5m2/GHSA-m53q-66x7-v5m2.json b/advisories/unreviewed/2024/05/GHSA-m53q-66x7-v5m2/GHSA-m53q-66x7-v5m2.json index 1bb1d32843e..11b3558f4f4 100644 --- a/advisories/unreviewed/2024/05/GHSA-m53q-66x7-v5m2/GHSA-m53q-66x7-v5m2.json +++ b/advisories/unreviewed/2024/05/GHSA-m53q-66x7-v5m2/GHSA-m53q-66x7-v5m2.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-mg36-pmfg-w8g5/GHSA-mg36-pmfg-w8g5.json b/advisories/unreviewed/2024/05/GHSA-mg36-pmfg-w8g5/GHSA-mg36-pmfg-w8g5.json index 63059eb313f..451e13367e7 100644 --- a/advisories/unreviewed/2024/05/GHSA-mg36-pmfg-w8g5/GHSA-mg36-pmfg-w8g5.json +++ b/advisories/unreviewed/2024/05/GHSA-mg36-pmfg-w8g5/GHSA-mg36-pmfg-w8g5.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-mx33-2ph8-j8cq/GHSA-mx33-2ph8-j8cq.json b/advisories/unreviewed/2024/05/GHSA-mx33-2ph8-j8cq/GHSA-mx33-2ph8-j8cq.json index 93c85f63244..aa05466809f 100644 --- a/advisories/unreviewed/2024/05/GHSA-mx33-2ph8-j8cq/GHSA-mx33-2ph8-j8cq.json +++ b/advisories/unreviewed/2024/05/GHSA-mx33-2ph8-j8cq/GHSA-mx33-2ph8-j8cq.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-p26m-m4q9-gcfv/GHSA-p26m-m4q9-gcfv.json b/advisories/unreviewed/2024/05/GHSA-p26m-m4q9-gcfv/GHSA-p26m-m4q9-gcfv.json index 1596a84b096..77bb5a5452e 100644 --- a/advisories/unreviewed/2024/05/GHSA-p26m-m4q9-gcfv/GHSA-p26m-m4q9-gcfv.json +++ b/advisories/unreviewed/2024/05/GHSA-p26m-m4q9-gcfv/GHSA-p26m-m4q9-gcfv.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-p3jm-9qcf-m97r/GHSA-p3jm-9qcf-m97r.json b/advisories/unreviewed/2024/05/GHSA-p3jm-9qcf-m97r/GHSA-p3jm-9qcf-m97r.json index befa2a2c91b..c64fdc8d0b5 100644 --- a/advisories/unreviewed/2024/05/GHSA-p3jm-9qcf-m97r/GHSA-p3jm-9qcf-m97r.json +++ b/advisories/unreviewed/2024/05/GHSA-p3jm-9qcf-m97r/GHSA-p3jm-9qcf-m97r.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-pm6f-qc2w-5rvq/GHSA-pm6f-qc2w-5rvq.json b/advisories/unreviewed/2024/05/GHSA-pm6f-qc2w-5rvq/GHSA-pm6f-qc2w-5rvq.json index 9a70e8f8c8b..1dfe312183c 100644 --- a/advisories/unreviewed/2024/05/GHSA-pm6f-qc2w-5rvq/GHSA-pm6f-qc2w-5rvq.json +++ b/advisories/unreviewed/2024/05/GHSA-pm6f-qc2w-5rvq/GHSA-pm6f-qc2w-5rvq.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-q962-h3cw-427p/GHSA-q962-h3cw-427p.json b/advisories/unreviewed/2024/05/GHSA-q962-h3cw-427p/GHSA-q962-h3cw-427p.json index c112d3d2fed..5eff8fd1e39 100644 --- a/advisories/unreviewed/2024/05/GHSA-q962-h3cw-427p/GHSA-q962-h3cw-427p.json +++ b/advisories/unreviewed/2024/05/GHSA-q962-h3cw-427p/GHSA-q962-h3cw-427p.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-qm4h-mqq2-vc43/GHSA-qm4h-mqq2-vc43.json b/advisories/unreviewed/2024/05/GHSA-qm4h-mqq2-vc43/GHSA-qm4h-mqq2-vc43.json index 57dc56522da..8038ee98664 100644 --- a/advisories/unreviewed/2024/05/GHSA-qm4h-mqq2-vc43/GHSA-qm4h-mqq2-vc43.json +++ b/advisories/unreviewed/2024/05/GHSA-qm4h-mqq2-vc43/GHSA-qm4h-mqq2-vc43.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-qwwj-hfjx-97wv/GHSA-qwwj-hfjx-97wv.json b/advisories/unreviewed/2024/05/GHSA-qwwj-hfjx-97wv/GHSA-qwwj-hfjx-97wv.json index 5c1da761ed2..b5c1c7bffb3 100644 --- a/advisories/unreviewed/2024/05/GHSA-qwwj-hfjx-97wv/GHSA-qwwj-hfjx-97wv.json +++ b/advisories/unreviewed/2024/05/GHSA-qwwj-hfjx-97wv/GHSA-qwwj-hfjx-97wv.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-qx3c-9xx3-55gj/GHSA-qx3c-9xx3-55gj.json b/advisories/unreviewed/2024/05/GHSA-qx3c-9xx3-55gj/GHSA-qx3c-9xx3-55gj.json index 146487554a1..e155aeec562 100644 --- a/advisories/unreviewed/2024/05/GHSA-qx3c-9xx3-55gj/GHSA-qx3c-9xx3-55gj.json +++ b/advisories/unreviewed/2024/05/GHSA-qx3c-9xx3-55gj/GHSA-qx3c-9xx3-55gj.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-rr83-9h8w-qx92/GHSA-rr83-9h8w-qx92.json b/advisories/unreviewed/2024/05/GHSA-rr83-9h8w-qx92/GHSA-rr83-9h8w-qx92.json index f7920b4133a..5a49d2110b2 100644 --- a/advisories/unreviewed/2024/05/GHSA-rr83-9h8w-qx92/GHSA-rr83-9h8w-qx92.json +++ b/advisories/unreviewed/2024/05/GHSA-rr83-9h8w-qx92/GHSA-rr83-9h8w-qx92.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-rvw6-x7cr-h3hg/GHSA-rvw6-x7cr-h3hg.json b/advisories/unreviewed/2024/05/GHSA-rvw6-x7cr-h3hg/GHSA-rvw6-x7cr-h3hg.json index 0a8b7314ab2..730b291e711 100644 --- a/advisories/unreviewed/2024/05/GHSA-rvw6-x7cr-h3hg/GHSA-rvw6-x7cr-h3hg.json +++ b/advisories/unreviewed/2024/05/GHSA-rvw6-x7cr-h3hg/GHSA-rvw6-x7cr-h3hg.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-rwpf-gxxr-mm7g/GHSA-rwpf-gxxr-mm7g.json b/advisories/unreviewed/2024/05/GHSA-rwpf-gxxr-mm7g/GHSA-rwpf-gxxr-mm7g.json index 571972a461f..94c1148847d 100644 --- a/advisories/unreviewed/2024/05/GHSA-rwpf-gxxr-mm7g/GHSA-rwpf-gxxr-mm7g.json +++ b/advisories/unreviewed/2024/05/GHSA-rwpf-gxxr-mm7g/GHSA-rwpf-gxxr-mm7g.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-w78j-w263-gjwc/GHSA-w78j-w263-gjwc.json b/advisories/unreviewed/2024/05/GHSA-w78j-w263-gjwc/GHSA-w78j-w263-gjwc.json index 5c57480ce6d..9fbd7b31294 100644 --- a/advisories/unreviewed/2024/05/GHSA-w78j-w263-gjwc/GHSA-w78j-w263-gjwc.json +++ b/advisories/unreviewed/2024/05/GHSA-w78j-w263-gjwc/GHSA-w78j-w263-gjwc.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-wchc-gwpx-chqh/GHSA-wchc-gwpx-chqh.json b/advisories/unreviewed/2024/05/GHSA-wchc-gwpx-chqh/GHSA-wchc-gwpx-chqh.json index 00a5004f8ba..3a827f33633 100644 --- a/advisories/unreviewed/2024/05/GHSA-wchc-gwpx-chqh/GHSA-wchc-gwpx-chqh.json +++ b/advisories/unreviewed/2024/05/GHSA-wchc-gwpx-chqh/GHSA-wchc-gwpx-chqh.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-x44v-rq9f-9r47/GHSA-x44v-rq9f-9r47.json b/advisories/unreviewed/2024/05/GHSA-x44v-rq9f-9r47/GHSA-x44v-rq9f-9r47.json index 801bdafb282..f506eb9aa5e 100644 --- a/advisories/unreviewed/2024/05/GHSA-x44v-rq9f-9r47/GHSA-x44v-rq9f-9r47.json +++ b/advisories/unreviewed/2024/05/GHSA-x44v-rq9f-9r47/GHSA-x44v-rq9f-9r47.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-x94x-r6x8-8hc2/GHSA-x94x-r6x8-8hc2.json b/advisories/unreviewed/2024/05/GHSA-x94x-r6x8-8hc2/GHSA-x94x-r6x8-8hc2.json index 1e4e45ddc0b..c8e4531ada3 100644 --- a/advisories/unreviewed/2024/05/GHSA-x94x-r6x8-8hc2/GHSA-x94x-r6x8-8hc2.json +++ b/advisories/unreviewed/2024/05/GHSA-x94x-r6x8-8hc2/GHSA-x94x-r6x8-8hc2.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-xr3f-rqv7-h627/GHSA-xr3f-rqv7-h627.json b/advisories/unreviewed/2024/05/GHSA-xr3f-rqv7-h627/GHSA-xr3f-rqv7-h627.json index 54cad2cc6e8..bf0cb2cb690 100644 --- a/advisories/unreviewed/2024/05/GHSA-xr3f-rqv7-h627/GHSA-xr3f-rqv7-h627.json +++ b/advisories/unreviewed/2024/05/GHSA-xr3f-rqv7-h627/GHSA-xr3f-rqv7-h627.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-6635-48h4-87x3/GHSA-6635-48h4-87x3.json b/advisories/unreviewed/2024/07/GHSA-6635-48h4-87x3/GHSA-6635-48h4-87x3.json index c047bb77481..c1722ed7d65 100644 --- a/advisories/unreviewed/2024/07/GHSA-6635-48h4-87x3/GHSA-6635-48h4-87x3.json +++ b/advisories/unreviewed/2024/07/GHSA-6635-48h4-87x3/GHSA-6635-48h4-87x3.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-9x99-hv56-3hj6/GHSA-9x99-hv56-3hj6.json b/advisories/unreviewed/2024/07/GHSA-9x99-hv56-3hj6/GHSA-9x99-hv56-3hj6.json index ddb96772439..fa25b1690df 100644 --- a/advisories/unreviewed/2024/07/GHSA-9x99-hv56-3hj6/GHSA-9x99-hv56-3hj6.json +++ b/advisories/unreviewed/2024/07/GHSA-9x99-hv56-3hj6/GHSA-9x99-hv56-3hj6.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-cf3c-mjjg-mw7c/GHSA-cf3c-mjjg-mw7c.json b/advisories/unreviewed/2024/07/GHSA-cf3c-mjjg-mw7c/GHSA-cf3c-mjjg-mw7c.json index 305601387cf..c547a32786d 100644 --- a/advisories/unreviewed/2024/07/GHSA-cf3c-mjjg-mw7c/GHSA-cf3c-mjjg-mw7c.json +++ b/advisories/unreviewed/2024/07/GHSA-cf3c-mjjg-mw7c/GHSA-cf3c-mjjg-mw7c.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-fxfr-fmvq-qcv6/GHSA-fxfr-fmvq-qcv6.json b/advisories/unreviewed/2024/07/GHSA-fxfr-fmvq-qcv6/GHSA-fxfr-fmvq-qcv6.json index 4080e77e9e3..b2f14eb5c55 100644 --- a/advisories/unreviewed/2024/07/GHSA-fxfr-fmvq-qcv6/GHSA-fxfr-fmvq-qcv6.json +++ b/advisories/unreviewed/2024/07/GHSA-fxfr-fmvq-qcv6/GHSA-fxfr-fmvq-qcv6.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-j4vv-h88w-gmv9/GHSA-j4vv-h88w-gmv9.json b/advisories/unreviewed/2024/07/GHSA-j4vv-h88w-gmv9/GHSA-j4vv-h88w-gmv9.json index 53dc3314b51..3672d43cdee 100644 --- a/advisories/unreviewed/2024/07/GHSA-j4vv-h88w-gmv9/GHSA-j4vv-h88w-gmv9.json +++ b/advisories/unreviewed/2024/07/GHSA-j4vv-h88w-gmv9/GHSA-j4vv-h88w-gmv9.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-xrmh-26m7-8f7p/GHSA-xrmh-26m7-8f7p.json b/advisories/unreviewed/2024/07/GHSA-xrmh-26m7-8f7p/GHSA-xrmh-26m7-8f7p.json index 4e37c844d36..7413f443b73 100644 --- a/advisories/unreviewed/2024/07/GHSA-xrmh-26m7-8f7p/GHSA-xrmh-26m7-8f7p.json +++ b/advisories/unreviewed/2024/07/GHSA-xrmh-26m7-8f7p/GHSA-xrmh-26m7-8f7p.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/08/GHSA-cr76-6p9f-9963/GHSA-cr76-6p9f-9963.json b/advisories/unreviewed/2024/08/GHSA-cr76-6p9f-9963/GHSA-cr76-6p9f-9963.json index 519a3168cc8..0d46cf0ccf5 100644 --- a/advisories/unreviewed/2024/08/GHSA-cr76-6p9f-9963/GHSA-cr76-6p9f-9963.json +++ b/advisories/unreviewed/2024/08/GHSA-cr76-6p9f-9963/GHSA-cr76-6p9f-9963.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/10/GHSA-cjcf-6ch6-g3rx/GHSA-cjcf-6ch6-g3rx.json b/advisories/unreviewed/2024/10/GHSA-cjcf-6ch6-g3rx/GHSA-cjcf-6ch6-g3rx.json index b284cdae9d9..d32550a94a2 100644 --- a/advisories/unreviewed/2024/10/GHSA-cjcf-6ch6-g3rx/GHSA-cjcf-6ch6-g3rx.json +++ b/advisories/unreviewed/2024/10/GHSA-cjcf-6ch6-g3rx/GHSA-cjcf-6ch6-g3rx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cjcf-6ch6-g3rx", - "modified": "2024-11-21T21:33:31Z", + "modified": "2025-05-13T15:32:09Z", "published": "2024-10-30T09:30:48Z", "aliases": [ "CVE-2024-9632" @@ -21,51 +21,7 @@ }, { "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:10090" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:8798" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:9540" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:9579" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:9601" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:9690" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:9816" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:9818" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:9819" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:9820" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:9901" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/security/cve/CVE-2024-9632" + "url": "https://lists.debian.org/debian-lts-announce/2024/10/msg00031.html" }, { "type": "WEB", @@ -73,7 +29,59 @@ }, { "type": "WEB", - "url": "https://lists.debian.org/debian-lts-announce/2024/10/msg00031.html" + "url": "https://access.redhat.com/security/cve/CVE-2024-9632" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7165" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7163" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:9901" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:9820" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:9819" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:9818" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:9816" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:9690" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:9601" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:9579" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:9540" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:8798" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:10090" }, { "type": "WEB", diff --git a/advisories/unreviewed/2025/02/GHSA-7q4p-93g6-4wf9/GHSA-7q4p-93g6-4wf9.json b/advisories/unreviewed/2025/02/GHSA-7q4p-93g6-4wf9/GHSA-7q4p-93g6-4wf9.json index c9fbdec92c7..6924e884c86 100644 --- a/advisories/unreviewed/2025/02/GHSA-7q4p-93g6-4wf9/GHSA-7q4p-93g6-4wf9.json +++ b/advisories/unreviewed/2025/02/GHSA-7q4p-93g6-4wf9/GHSA-7q4p-93g6-4wf9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7q4p-93g6-4wf9", - "modified": "2025-03-17T06:30:24Z", + "modified": "2025-05-13T15:32:10Z", "published": "2025-02-25T18:31:24Z", "aliases": [ "CVE-2025-26600" @@ -63,6 +63,14 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2880" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7163" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7165" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-26600" diff --git a/advisories/unreviewed/2025/02/GHSA-7qjx-378m-p8hm/GHSA-7qjx-378m-p8hm.json b/advisories/unreviewed/2025/02/GHSA-7qjx-378m-p8hm/GHSA-7qjx-378m-p8hm.json index 2655d919e95..c44b45e2e95 100644 --- a/advisories/unreviewed/2025/02/GHSA-7qjx-378m-p8hm/GHSA-7qjx-378m-p8hm.json +++ b/advisories/unreviewed/2025/02/GHSA-7qjx-378m-p8hm/GHSA-7qjx-378m-p8hm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7qjx-378m-p8hm", - "modified": "2025-03-17T06:30:24Z", + "modified": "2025-05-13T15:32:10Z", "published": "2025-02-25T18:31:24Z", "aliases": [ "CVE-2025-26597" @@ -63,6 +63,14 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2880" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7163" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7165" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-26597" diff --git a/advisories/unreviewed/2025/02/GHSA-c28h-3w95-v6xg/GHSA-c28h-3w95-v6xg.json b/advisories/unreviewed/2025/02/GHSA-c28h-3w95-v6xg/GHSA-c28h-3w95-v6xg.json index 118322f8867..83d54e3f69f 100644 --- a/advisories/unreviewed/2025/02/GHSA-c28h-3w95-v6xg/GHSA-c28h-3w95-v6xg.json +++ b/advisories/unreviewed/2025/02/GHSA-c28h-3w95-v6xg/GHSA-c28h-3w95-v6xg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c28h-3w95-v6xg", - "modified": "2025-03-17T06:30:24Z", + "modified": "2025-05-13T15:32:10Z", "published": "2025-02-25T18:31:24Z", "aliases": [ "CVE-2025-26598" @@ -63,6 +63,14 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2880" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7163" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7165" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-26598" diff --git a/advisories/unreviewed/2025/02/GHSA-c52f-45m8-h2r6/GHSA-c52f-45m8-h2r6.json b/advisories/unreviewed/2025/02/GHSA-c52f-45m8-h2r6/GHSA-c52f-45m8-h2r6.json index 453fa19eeb5..efa36ed9dc7 100644 --- a/advisories/unreviewed/2025/02/GHSA-c52f-45m8-h2r6/GHSA-c52f-45m8-h2r6.json +++ b/advisories/unreviewed/2025/02/GHSA-c52f-45m8-h2r6/GHSA-c52f-45m8-h2r6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c52f-45m8-h2r6", - "modified": "2025-03-17T06:30:24Z", + "modified": "2025-05-13T15:32:10Z", "published": "2025-02-25T18:31:24Z", "aliases": [ "CVE-2025-26596" @@ -63,6 +63,14 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2880" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7163" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7165" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-26596" diff --git a/advisories/unreviewed/2025/02/GHSA-gc32-fmf5-c742/GHSA-gc32-fmf5-c742.json b/advisories/unreviewed/2025/02/GHSA-gc32-fmf5-c742/GHSA-gc32-fmf5-c742.json index a0bcd1d98f3..b89d3bfe0f6 100644 --- a/advisories/unreviewed/2025/02/GHSA-gc32-fmf5-c742/GHSA-gc32-fmf5-c742.json +++ b/advisories/unreviewed/2025/02/GHSA-gc32-fmf5-c742/GHSA-gc32-fmf5-c742.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gc32-fmf5-c742", - "modified": "2025-03-17T06:30:24Z", + "modified": "2025-05-13T15:32:09Z", "published": "2025-02-25T18:31:24Z", "aliases": [ "CVE-2025-26594" @@ -63,6 +63,14 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2880" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7163" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7165" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-26594" diff --git a/advisories/unreviewed/2025/02/GHSA-gf8x-6jh7-3mjv/GHSA-gf8x-6jh7-3mjv.json b/advisories/unreviewed/2025/02/GHSA-gf8x-6jh7-3mjv/GHSA-gf8x-6jh7-3mjv.json index 00930a66c15..63d8d6760d1 100644 --- a/advisories/unreviewed/2025/02/GHSA-gf8x-6jh7-3mjv/GHSA-gf8x-6jh7-3mjv.json +++ b/advisories/unreviewed/2025/02/GHSA-gf8x-6jh7-3mjv/GHSA-gf8x-6jh7-3mjv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gf8x-6jh7-3mjv", - "modified": "2025-03-17T06:30:25Z", + "modified": "2025-05-13T15:32:10Z", "published": "2025-02-25T18:31:24Z", "aliases": [ "CVE-2025-26601" @@ -63,6 +63,14 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2880" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7163" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7165" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-26601" diff --git a/advisories/unreviewed/2025/02/GHSA-hp9r-wcfh-72pr/GHSA-hp9r-wcfh-72pr.json b/advisories/unreviewed/2025/02/GHSA-hp9r-wcfh-72pr/GHSA-hp9r-wcfh-72pr.json index 18eef13e9f6..0548f1c667d 100644 --- a/advisories/unreviewed/2025/02/GHSA-hp9r-wcfh-72pr/GHSA-hp9r-wcfh-72pr.json +++ b/advisories/unreviewed/2025/02/GHSA-hp9r-wcfh-72pr/GHSA-hp9r-wcfh-72pr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hp9r-wcfh-72pr", - "modified": "2025-03-17T06:30:24Z", + "modified": "2025-05-13T15:32:10Z", "published": "2025-02-25T18:31:24Z", "aliases": [ "CVE-2025-26595" @@ -63,6 +63,14 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2880" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7163" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7165" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-26595" diff --git a/advisories/unreviewed/2025/02/GHSA-wv34-xcj8-f3mq/GHSA-wv34-xcj8-f3mq.json b/advisories/unreviewed/2025/02/GHSA-wv34-xcj8-f3mq/GHSA-wv34-xcj8-f3mq.json index c72af7e9c61..6b431a09434 100644 --- a/advisories/unreviewed/2025/02/GHSA-wv34-xcj8-f3mq/GHSA-wv34-xcj8-f3mq.json +++ b/advisories/unreviewed/2025/02/GHSA-wv34-xcj8-f3mq/GHSA-wv34-xcj8-f3mq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wv34-xcj8-f3mq", - "modified": "2025-03-17T06:30:24Z", + "modified": "2025-05-13T15:32:10Z", "published": "2025-02-25T18:31:24Z", "aliases": [ "CVE-2025-26599" @@ -63,6 +63,14 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2880" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7163" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7165" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-26599" diff --git a/advisories/unreviewed/2025/03/GHSA-33fh-4pvq-9x35/GHSA-33fh-4pvq-9x35.json b/advisories/unreviewed/2025/03/GHSA-33fh-4pvq-9x35/GHSA-33fh-4pvq-9x35.json index c2a2b043fc3..23de91c1d3e 100644 --- a/advisories/unreviewed/2025/03/GHSA-33fh-4pvq-9x35/GHSA-33fh-4pvq-9x35.json +++ b/advisories/unreviewed/2025/03/GHSA-33fh-4pvq-9x35/GHSA-33fh-4pvq-9x35.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-33fh-4pvq-9x35", - "modified": "2025-05-06T03:30:24Z", + "modified": "2025-05-13T15:32:10Z", "published": "2025-03-18T18:30:50Z", "aliases": [ "CVE-2025-2487" @@ -31,6 +31,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:4491" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7395" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-2487" diff --git a/advisories/unreviewed/2025/03/GHSA-qj2m-5369-jwf3/GHSA-qj2m-5369-jwf3.json b/advisories/unreviewed/2025/03/GHSA-qj2m-5369-jwf3/GHSA-qj2m-5369-jwf3.json index 4e1e369f7c4..aafb80e5409 100644 --- a/advisories/unreviewed/2025/03/GHSA-qj2m-5369-jwf3/GHSA-qj2m-5369-jwf3.json +++ b/advisories/unreviewed/2025/03/GHSA-qj2m-5369-jwf3/GHSA-qj2m-5369-jwf3.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-r3r3-hjgr-8x9f/GHSA-r3r3-hjgr-8x9f.json b/advisories/unreviewed/2025/03/GHSA-r3r3-hjgr-8x9f/GHSA-r3r3-hjgr-8x9f.json index 3d50a56c745..bcb04912227 100644 --- a/advisories/unreviewed/2025/03/GHSA-r3r3-hjgr-8x9f/GHSA-r3r3-hjgr-8x9f.json +++ b/advisories/unreviewed/2025/03/GHSA-r3r3-hjgr-8x9f/GHSA-r3r3-hjgr-8x9f.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-9589-mpwg-8xq6/GHSA-9589-mpwg-8xq6.json b/advisories/unreviewed/2025/04/GHSA-9589-mpwg-8xq6/GHSA-9589-mpwg-8xq6.json index 5716e697099..abaeae66c5b 100644 --- a/advisories/unreviewed/2025/04/GHSA-9589-mpwg-8xq6/GHSA-9589-mpwg-8xq6.json +++ b/advisories/unreviewed/2025/04/GHSA-9589-mpwg-8xq6/GHSA-9589-mpwg-8xq6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9589-mpwg-8xq6", - "modified": "2025-05-07T09:31:17Z", + "modified": "2025-05-13T15:32:11Z", "published": "2025-04-14T15:31:58Z", "aliases": [ "CVE-2025-32913" @@ -51,6 +51,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:4624" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7436" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-32913" diff --git a/advisories/unreviewed/2025/04/GHSA-f4vp-qjpg-x8wq/GHSA-f4vp-qjpg-x8wq.json b/advisories/unreviewed/2025/04/GHSA-f4vp-qjpg-x8wq/GHSA-f4vp-qjpg-x8wq.json index ef1a550a0f0..a1a65014c26 100644 --- a/advisories/unreviewed/2025/04/GHSA-f4vp-qjpg-x8wq/GHSA-f4vp-qjpg-x8wq.json +++ b/advisories/unreviewed/2025/04/GHSA-f4vp-qjpg-x8wq/GHSA-f4vp-qjpg-x8wq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f4vp-qjpg-x8wq", - "modified": "2025-05-07T09:31:17Z", + "modified": "2025-05-13T15:32:11Z", "published": "2025-04-14T15:31:58Z", "aliases": [ "CVE-2025-32906" @@ -51,6 +51,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:4624" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7436" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-32906" diff --git a/advisories/unreviewed/2025/04/GHSA-fp4x-j6ch-w8q5/GHSA-fp4x-j6ch-w8q5.json b/advisories/unreviewed/2025/04/GHSA-fp4x-j6ch-w8q5/GHSA-fp4x-j6ch-w8q5.json index f97a3ca205a..24b8bee3658 100644 --- a/advisories/unreviewed/2025/04/GHSA-fp4x-j6ch-w8q5/GHSA-fp4x-j6ch-w8q5.json +++ b/advisories/unreviewed/2025/04/GHSA-fp4x-j6ch-w8q5/GHSA-fp4x-j6ch-w8q5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fp4x-j6ch-w8q5", - "modified": "2025-05-07T09:31:17Z", + "modified": "2025-05-13T15:32:11Z", "published": "2025-04-15T18:31:45Z", "aliases": [ "CVE-2025-32911" @@ -51,6 +51,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:4624" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7436" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-32911" diff --git a/advisories/unreviewed/2025/04/GHSA-h7mx-548v-cr9r/GHSA-h7mx-548v-cr9r.json b/advisories/unreviewed/2025/04/GHSA-h7mx-548v-cr9r/GHSA-h7mx-548v-cr9r.json index 63d5ab6f758..137f258561c 100644 --- a/advisories/unreviewed/2025/04/GHSA-h7mx-548v-cr9r/GHSA-h7mx-548v-cr9r.json +++ b/advisories/unreviewed/2025/04/GHSA-h7mx-548v-cr9r/GHSA-h7mx-548v-cr9r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h7mx-548v-cr9r", - "modified": "2025-05-06T15:30:55Z", + "modified": "2025-05-13T15:32:11Z", "published": "2025-04-03T15:31:19Z", "aliases": [ "CVE-2025-3155" @@ -47,6 +47,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:4532" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7430" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-3155" diff --git a/advisories/unreviewed/2025/04/GHSA-mwx3-c2hq-28xw/GHSA-mwx3-c2hq-28xw.json b/advisories/unreviewed/2025/04/GHSA-mwx3-c2hq-28xw/GHSA-mwx3-c2hq-28xw.json index 6176f5d35f3..b2a58ab7ef6 100644 --- a/advisories/unreviewed/2025/04/GHSA-mwx3-c2hq-28xw/GHSA-mwx3-c2hq-28xw.json +++ b/advisories/unreviewed/2025/04/GHSA-mwx3-c2hq-28xw/GHSA-mwx3-c2hq-28xw.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-74", "CWE-749" ], "severity": "LOW", diff --git a/advisories/unreviewed/2025/04/GHSA-x238-v9f9-93g8/GHSA-x238-v9f9-93g8.json b/advisories/unreviewed/2025/04/GHSA-x238-v9f9-93g8/GHSA-x238-v9f9-93g8.json index dc11c85080c..937ca3d2b74 100644 --- a/advisories/unreviewed/2025/04/GHSA-x238-v9f9-93g8/GHSA-x238-v9f9-93g8.json +++ b/advisories/unreviewed/2025/04/GHSA-x238-v9f9-93g8/GHSA-x238-v9f9-93g8.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-1336" + "CWE-1336", + "CWE-94" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-2fgw-qh65-pxv5/GHSA-2fgw-qh65-pxv5.json b/advisories/unreviewed/2025/05/GHSA-2fgw-qh65-pxv5/GHSA-2fgw-qh65-pxv5.json index b0b75cf6c74..e2e5cc38c74 100644 --- a/advisories/unreviewed/2025/05/GHSA-2fgw-qh65-pxv5/GHSA-2fgw-qh65-pxv5.json +++ b/advisories/unreviewed/2025/05/GHSA-2fgw-qh65-pxv5/GHSA-2fgw-qh65-pxv5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2fgw-qh65-pxv5", - "modified": "2025-05-13T00:31:13Z", + "modified": "2025-05-13T15:32:15Z", "published": "2025-05-13T00:31:13Z", "aliases": [ "CVE-2025-30442" ], "details": "The issue was addressed with improved input sanitization. This issue is fixed in macOS Sequoia 15.4, macOS Ventura 13.7.6, macOS Sonoma 14.7.6. An app may be able to gain elevated privileges.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:21Z" diff --git a/advisories/unreviewed/2025/05/GHSA-2r69-79fj-p7wm/GHSA-2r69-79fj-p7wm.json b/advisories/unreviewed/2025/05/GHSA-2r69-79fj-p7wm/GHSA-2r69-79fj-p7wm.json index c74a95a9960..9fbc1649e78 100644 --- a/advisories/unreviewed/2025/05/GHSA-2r69-79fj-p7wm/GHSA-2r69-79fj-p7wm.json +++ b/advisories/unreviewed/2025/05/GHSA-2r69-79fj-p7wm/GHSA-2r69-79fj-p7wm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2r69-79fj-p7wm", - "modified": "2025-05-13T06:30:24Z", + "modified": "2025-05-13T15:32:16Z", "published": "2025-05-13T06:30:24Z", "aliases": [ "CVE-2025-22249" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-3cfh-hf3f-2p3x/GHSA-3cfh-hf3f-2p3x.json b/advisories/unreviewed/2025/05/GHSA-3cfh-hf3f-2p3x/GHSA-3cfh-hf3f-2p3x.json new file mode 100644 index 00000000000..443ccb98bc1 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3cfh-hf3f-2p3x/GHSA-3cfh-hf3f-2p3x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3cfh-hf3f-2p3x", + "modified": "2025-05-13T15:32:16Z", + "published": "2025-05-13T15:32:16Z", + "aliases": [ + "CVE-2024-36340" + ], + "details": "A junction point vulnerability within AMD uProf can allow a local low-privileged attacker to create junction points, potentially resulting in arbitrary file deletion or disclosure.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36340" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-9013.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1386" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T14:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-53gq-27mh-rqhg/GHSA-53gq-27mh-rqhg.json b/advisories/unreviewed/2025/05/GHSA-53gq-27mh-rqhg/GHSA-53gq-27mh-rqhg.json index 9f0aa4d3aa3..65909848c24 100644 --- a/advisories/unreviewed/2025/05/GHSA-53gq-27mh-rqhg/GHSA-53gq-27mh-rqhg.json +++ b/advisories/unreviewed/2025/05/GHSA-53gq-27mh-rqhg/GHSA-53gq-27mh-rqhg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-53gq-27mh-rqhg", - "modified": "2025-05-13T00:31:14Z", + "modified": "2025-05-13T15:32:16Z", "published": "2025-05-13T00:31:14Z", "aliases": [ "CVE-2025-31222" ], "details": "A correctness issue was addressed with improved checks. This issue is fixed in watchOS 11.5, macOS Sonoma 14.7.6, tvOS 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, macOS Ventura 13.7.6. A user may be able to elevate privileges.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:22Z" diff --git a/advisories/unreviewed/2025/05/GHSA-5f3f-773x-9jx9/GHSA-5f3f-773x-9jx9.json b/advisories/unreviewed/2025/05/GHSA-5f3f-773x-9jx9/GHSA-5f3f-773x-9jx9.json index 923ed6ce79e..057d99cee19 100644 --- a/advisories/unreviewed/2025/05/GHSA-5f3f-773x-9jx9/GHSA-5f3f-773x-9jx9.json +++ b/advisories/unreviewed/2025/05/GHSA-5f3f-773x-9jx9/GHSA-5f3f-773x-9jx9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5f3f-773x-9jx9", - "modified": "2025-05-13T00:31:15Z", + "modified": "2025-05-13T15:32:16Z", "published": "2025-05-13T00:31:15Z", "aliases": [ "CVE-2025-31246" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6. Connecting to a malicious AFP server may corrupt kernel memory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:24Z" diff --git a/advisories/unreviewed/2025/05/GHSA-765g-9g68-wg84/GHSA-765g-9g68-wg84.json b/advisories/unreviewed/2025/05/GHSA-765g-9g68-wg84/GHSA-765g-9g68-wg84.json index 9c9a64d78b0..c349f7db3ca 100644 --- a/advisories/unreviewed/2025/05/GHSA-765g-9g68-wg84/GHSA-765g-9g68-wg84.json +++ b/advisories/unreviewed/2025/05/GHSA-765g-9g68-wg84/GHSA-765g-9g68-wg84.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-765g-9g68-wg84", - "modified": "2025-05-08T18:30:42Z", + "modified": "2025-05-13T15:32:15Z", "published": "2025-05-08T18:30:42Z", "aliases": [ "CVE-2025-45846" ], "details": "ALFA AIP-W512 v3.2.2.2.3 was discovered to contain an authenticated stack overflow via the torrentsindex parameter in the formBTClinetSetting function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-08T16:15:26Z" diff --git a/advisories/unreviewed/2025/05/GHSA-7mch-v7x5-pxc4/GHSA-7mch-v7x5-pxc4.json b/advisories/unreviewed/2025/05/GHSA-7mch-v7x5-pxc4/GHSA-7mch-v7x5-pxc4.json index 39466793e32..d78b8925ae6 100644 --- a/advisories/unreviewed/2025/05/GHSA-7mch-v7x5-pxc4/GHSA-7mch-v7x5-pxc4.json +++ b/advisories/unreviewed/2025/05/GHSA-7mch-v7x5-pxc4/GHSA-7mch-v7x5-pxc4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7mch-v7x5-pxc4", - "modified": "2025-05-13T00:31:12Z", + "modified": "2025-05-13T15:32:15Z", "published": "2025-05-13T00:31:12Z", "aliases": [ "CVE-2025-24223" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in watchOS 11.5, tvOS 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, Safari 18.5. Processing maliciously crafted web content may lead to memory corruption.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:20Z" diff --git a/advisories/unreviewed/2025/05/GHSA-7r5r-3362-27j8/GHSA-7r5r-3362-27j8.json b/advisories/unreviewed/2025/05/GHSA-7r5r-3362-27j8/GHSA-7r5r-3362-27j8.json index 042715595d7..75c7cf49c43 100644 --- a/advisories/unreviewed/2025/05/GHSA-7r5r-3362-27j8/GHSA-7r5r-3362-27j8.json +++ b/advisories/unreviewed/2025/05/GHSA-7r5r-3362-27j8/GHSA-7r5r-3362-27j8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7r5r-3362-27j8", - "modified": "2025-05-13T00:31:16Z", + "modified": "2025-05-13T15:32:16Z", "published": "2025-05-13T00:31:16Z", "aliases": [ "CVE-2025-31259" ], "details": "The issue was addressed with improved input sanitization. This issue is fixed in macOS Sequoia 15.5. An app may be able to gain elevated privileges.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:25Z" diff --git a/advisories/unreviewed/2025/05/GHSA-829j-v57j-p8jf/GHSA-829j-v57j-p8jf.json b/advisories/unreviewed/2025/05/GHSA-829j-v57j-p8jf/GHSA-829j-v57j-p8jf.json new file mode 100644 index 00000000000..8ad575cf498 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-829j-v57j-p8jf/GHSA-829j-v57j-p8jf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-829j-v57j-p8jf", + "modified": "2025-05-13T15:32:16Z", + "published": "2025-05-13T15:32:16Z", + "aliases": [ + "CVE-2024-12533" + ], + "details": "Improper Check for Unusual or Exceptional Conditions vulnerability in Phoenix SecureCore Technology 4 allows Input Data Manipulation.This issue affects SecureCore Technology 4: from 4.0.1.0 before 4.0.1.1018, from 4.1.0.1 before 4.1.0.573, from 4.2.0.1 before 4.2.0.338, from 4.2.1.1 before 4.2.1.300, from 4.3.0.1 before 4.3.0.244, from 4.3.1.1 before 4.3.1.187, from 4.4.0.1 before 4.4.0.299, from 4.5.0.1 before 4.5.0.231, from 4.5.1.1 before 4.5.1.103, from 4.5.5.1 before 4.5.5.36, from 4.6.0.1 before 4.6.0.67.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12533" + }, + { + "type": "WEB", + "url": "https://www.phoenix.com/security-notifications/cve-2024-12533" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-754" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T15:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-88m5-wrqh-4w9g/GHSA-88m5-wrqh-4w9g.json b/advisories/unreviewed/2025/05/GHSA-88m5-wrqh-4w9g/GHSA-88m5-wrqh-4w9g.json index 9ba9afdac88..d0487b793e9 100644 --- a/advisories/unreviewed/2025/05/GHSA-88m5-wrqh-4w9g/GHSA-88m5-wrqh-4w9g.json +++ b/advisories/unreviewed/2025/05/GHSA-88m5-wrqh-4w9g/GHSA-88m5-wrqh-4w9g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-88m5-wrqh-4w9g", - "modified": "2025-05-08T18:30:42Z", + "modified": "2025-05-13T15:32:15Z", "published": "2025-05-08T18:30:42Z", "aliases": [ "CVE-2025-45844" ], "details": "TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid parameter in the setWiFiBasicCfg function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-08T16:15:26Z" diff --git a/advisories/unreviewed/2025/05/GHSA-9589-rvqc-62cg/GHSA-9589-rvqc-62cg.json b/advisories/unreviewed/2025/05/GHSA-9589-rvqc-62cg/GHSA-9589-rvqc-62cg.json new file mode 100644 index 00000000000..f7cf28a27d9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9589-rvqc-62cg/GHSA-9589-rvqc-62cg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9589-rvqc-62cg", + "modified": "2025-05-13T15:32:16Z", + "published": "2025-05-13T15:32:16Z", + "aliases": [ + "CVE-2025-22460" + ], + "details": "Default credentials in Ivanti Cloud Services Application before version 5.0.5 allows a local authenticated attacker to escalate their privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22460" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Cloud-Services-Application-CVE-2025-22460" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1392" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T15:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9qx4-7755-7gxr/GHSA-9qx4-7755-7gxr.json b/advisories/unreviewed/2025/05/GHSA-9qx4-7755-7gxr/GHSA-9qx4-7755-7gxr.json new file mode 100644 index 00000000000..25c535e214b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9qx4-7755-7gxr/GHSA-9qx4-7755-7gxr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qx4-7755-7gxr", + "modified": "2025-05-13T15:32:16Z", + "published": "2025-05-13T15:32:16Z", + "aliases": [ + "CVE-2024-35281" + ], + "details": "An improper isolation or compartmentalization vulnerability [CWE-653] in FortiClientMac version 7.4.2 and below, version 7.2.8 and below, 7.0 all versions and FortiVoiceUCDesktop 3.0 all versions desktop application may allow an authenticated attacker to inject code via Electron environment variables.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35281" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-025" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-653" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T15:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-f42p-pxc9-254g/GHSA-f42p-pxc9-254g.json b/advisories/unreviewed/2025/05/GHSA-f42p-pxc9-254g/GHSA-f42p-pxc9-254g.json index 6f566a026b2..0fb1dac0192 100644 --- a/advisories/unreviewed/2025/05/GHSA-f42p-pxc9-254g/GHSA-f42p-pxc9-254g.json +++ b/advisories/unreviewed/2025/05/GHSA-f42p-pxc9-254g/GHSA-f42p-pxc9-254g.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-532" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-fcpx-h44g-vx2x/GHSA-fcpx-h44g-vx2x.json b/advisories/unreviewed/2025/05/GHSA-fcpx-h44g-vx2x/GHSA-fcpx-h44g-vx2x.json new file mode 100644 index 00000000000..3d66a1f0004 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fcpx-h44g-vx2x/GHSA-fcpx-h44g-vx2x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fcpx-h44g-vx2x", + "modified": "2025-05-13T15:32:16Z", + "published": "2025-05-13T15:32:16Z", + "aliases": [ + "CVE-2025-32756" + ], + "details": "A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiVoice versions 7.2.0, 7.0.0 through 7.0.6, 6.4.0 through 6.4.10, FortiRecorder versions 7.2.0 through 7.2.3, 7.0.0 through 7.0.5, 6.4.0 through 6.4.5, FortiMail versions 7.6.0 through 7.6.2, 7.4.0 through 7.4.4, 7.2.0 through 7.2.7, 7.0.0 through 7.0.8, FortiNDR versions 7.6.0, 7.4.0 through 7.4.7, 7.2.0 through 7.2.4, 7.0.0 through 7.0.6, FortiCamera versions 2.1.0 through 2.1.3, 2.0 all versions, 1.1 all versions, allows a remote unauthenticated attacker to execute arbitrary code or commands via sending HTTP requests with specially crafted hash cookie.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32756" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-25-254" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T15:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fppm-pf9p-6ph2/GHSA-fppm-pf9p-6ph2.json b/advisories/unreviewed/2025/05/GHSA-fppm-pf9p-6ph2/GHSA-fppm-pf9p-6ph2.json index 15301f06073..cae12c0b42f 100644 --- a/advisories/unreviewed/2025/05/GHSA-fppm-pf9p-6ph2/GHSA-fppm-pf9p-6ph2.json +++ b/advisories/unreviewed/2025/05/GHSA-fppm-pf9p-6ph2/GHSA-fppm-pf9p-6ph2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fppm-pf9p-6ph2", - "modified": "2025-05-13T00:31:14Z", + "modified": "2025-05-13T15:32:16Z", "published": "2025-05-13T00:31:14Z", "aliases": [ "CVE-2025-31223" ], "details": "The issue was addressed with improved checks. This issue is fixed in watchOS 11.5, tvOS 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, Safari 18.5. Processing maliciously crafted web content may lead to memory corruption.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:23Z" diff --git a/advisories/unreviewed/2025/05/GHSA-fxw3-rq5v-qr7h/GHSA-fxw3-rq5v-qr7h.json b/advisories/unreviewed/2025/05/GHSA-fxw3-rq5v-qr7h/GHSA-fxw3-rq5v-qr7h.json new file mode 100644 index 00000000000..77d6a1da973 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fxw3-rq5v-qr7h/GHSA-fxw3-rq5v-qr7h.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fxw3-rq5v-qr7h", + "modified": "2025-05-13T15:32:17Z", + "published": "2025-05-13T15:32:17Z", + "aliases": [ + "CVE-2025-45867" + ], + "details": "TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the static_dns1 parameter in the formIpv6Setup interface.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45867" + }, + { + "type": "WEB", + "url": "https://github.com/Jiangxiazhe/IOT_hack/blob/main/TOTOLINK/A3002R/10/overflow.md" + }, + { + "type": "WEB", + "url": "https://www.totolink.net/home/menu/detail/menu_listtpl/download/id/258/ids/36.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T15:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hchm-h33q-qp26/GHSA-hchm-h33q-qp26.json b/advisories/unreviewed/2025/05/GHSA-hchm-h33q-qp26/GHSA-hchm-h33q-qp26.json new file mode 100644 index 00000000000..5c4b5ddd0bc --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hchm-h33q-qp26/GHSA-hchm-h33q-qp26.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hchm-h33q-qp26", + "modified": "2025-05-13T15:32:17Z", + "published": "2025-05-13T15:32:16Z", + "aliases": [ + "CVE-2025-45864" + ], + "details": "TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolStart parameter in the formDhcpv6s interface.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45864" + }, + { + "type": "WEB", + "url": "https://github.com/Jiangxiazhe/IOT_hack/blob/main/TOTOLINK/A3002R/8/overflow.md" + }, + { + "type": "WEB", + "url": "https://www.totolink.net/home/menu/detail/menu_listtpl/download/id/258/ids/36.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T15:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hghc-8hvx-7rrx/GHSA-hghc-8hvx-7rrx.json b/advisories/unreviewed/2025/05/GHSA-hghc-8hvx-7rrx/GHSA-hghc-8hvx-7rrx.json new file mode 100644 index 00000000000..064c7e71a46 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hghc-8hvx-7rrx/GHSA-hghc-8hvx-7rrx.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hghc-8hvx-7rrx", + "modified": "2025-05-13T15:32:17Z", + "published": "2025-05-13T15:32:17Z", + "aliases": [ + "CVE-2025-45866" + ], + "details": "TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolEnd parameter in the formDhcpv6s interface.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45866" + }, + { + "type": "WEB", + "url": "https://github.com/Jiangxiazhe/IOT_hack/blob/main/TOTOLINK/A3002R/9/overflow.md" + }, + { + "type": "WEB", + "url": "https://www.totolink.net/home/menu/detail/menu_listtpl/download/id/258/ids/36.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T15:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mfx3-9vhp-h958/GHSA-mfx3-9vhp-h958.json b/advisories/unreviewed/2025/05/GHSA-mfx3-9vhp-h958/GHSA-mfx3-9vhp-h958.json index 79eb3813d9e..6ef08903bc0 100644 --- a/advisories/unreviewed/2025/05/GHSA-mfx3-9vhp-h958/GHSA-mfx3-9vhp-h958.json +++ b/advisories/unreviewed/2025/05/GHSA-mfx3-9vhp-h958/GHSA-mfx3-9vhp-h958.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-p2j9-hh6h-8mxx/GHSA-p2j9-hh6h-8mxx.json b/advisories/unreviewed/2025/05/GHSA-p2j9-hh6h-8mxx/GHSA-p2j9-hh6h-8mxx.json index 71eabd68bd5..00711f74a05 100644 --- a/advisories/unreviewed/2025/05/GHSA-p2j9-hh6h-8mxx/GHSA-p2j9-hh6h-8mxx.json +++ b/advisories/unreviewed/2025/05/GHSA-p2j9-hh6h-8mxx/GHSA-p2j9-hh6h-8mxx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p2j9-hh6h-8mxx", - "modified": "2025-05-09T15:31:43Z", + "modified": "2025-05-13T15:32:15Z", "published": "2025-05-09T15:31:43Z", "aliases": [ "CVE-2024-12442" ], "details": "EnerSys AMPA versions 24.04 through 24.16, inclusive, are vulnerable to command injection leading to privileged remote shell access.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-77" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-09T14:15:36Z" diff --git a/advisories/unreviewed/2025/05/GHSA-pc2j-fvgw-h6vh/GHSA-pc2j-fvgw-h6vh.json b/advisories/unreviewed/2025/05/GHSA-pc2j-fvgw-h6vh/GHSA-pc2j-fvgw-h6vh.json index c85d38db5a4..d4ce17970e4 100644 --- a/advisories/unreviewed/2025/05/GHSA-pc2j-fvgw-h6vh/GHSA-pc2j-fvgw-h6vh.json +++ b/advisories/unreviewed/2025/05/GHSA-pc2j-fvgw-h6vh/GHSA-pc2j-fvgw-h6vh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pc2j-fvgw-h6vh", - "modified": "2025-05-13T00:31:13Z", + "modified": "2025-05-13T15:32:15Z", "published": "2025-05-13T00:31:13Z", "aliases": [ "CVE-2025-30453" ], "details": "The issue was addressed with additional permissions checks. This issue is fixed in macOS Sequoia 15.4, macOS Ventura 13.7.6, macOS Sonoma 14.7.6. A malicious app may be able to gain root privileges.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-280" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:21Z" diff --git a/advisories/unreviewed/2025/05/GHSA-pgm8-5pfj-3v9h/GHSA-pgm8-5pfj-3v9h.json b/advisories/unreviewed/2025/05/GHSA-pgm8-5pfj-3v9h/GHSA-pgm8-5pfj-3v9h.json new file mode 100644 index 00000000000..23db9f2bf3c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pgm8-5pfj-3v9h/GHSA-pgm8-5pfj-3v9h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pgm8-5pfj-3v9h", + "modified": "2025-05-13T15:32:16Z", + "published": "2025-05-13T15:32:16Z", + "aliases": [ + "CVE-2024-42446" + ], + "details": "APTIOV contains a vulnerability in BIOS where an attacker may cause a Time-of-check Time-of-use (TOCTOU) Race Condition by local means. Successful exploitation of this vulnerability may lead to arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42446" + }, + { + "type": "WEB", + "url": "https://go.ami.com/hubfs/Security%20Advisories/2025/AMI-SA-2025004.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T14:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-pwv6-v269-632r/GHSA-pwv6-v269-632r.json b/advisories/unreviewed/2025/05/GHSA-pwv6-v269-632r/GHSA-pwv6-v269-632r.json new file mode 100644 index 00000000000..8f5f412ed0b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pwv6-v269-632r/GHSA-pwv6-v269-632r.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pwv6-v269-632r", + "modified": "2025-05-13T15:32:17Z", + "published": "2025-05-13T15:32:17Z", + "aliases": [ + "CVE-2025-44039" + ], + "details": "CP-XR-DE21-S -4G Router Firmware version 1.031.022 was discovered to contain insecure protections for its UART console. This vulnerability allows local attackers to connect to the UART port via a serial connection, read all boot sequence, and revealing internal system details and sensitive information without any authentication.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44039" + }, + { + "type": "WEB", + "url": "https://github.com/Yashodhanvivek/CP-XR-DE21-S--4G-Router-Vulnerabilities/blob/main/input.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T15:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q7rh-46fc-x4wh/GHSA-q7rh-46fc-x4wh.json b/advisories/unreviewed/2025/05/GHSA-q7rh-46fc-x4wh/GHSA-q7rh-46fc-x4wh.json new file mode 100644 index 00000000000..b2342a5bcb7 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q7rh-46fc-x4wh/GHSA-q7rh-46fc-x4wh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q7rh-46fc-x4wh", + "modified": "2025-05-13T15:32:16Z", + "published": "2025-05-13T15:32:16Z", + "aliases": [ + "CVE-2025-22859" + ], + "details": "A Relative Path Traversal vulnerability [CWE-23] in FortiClientEMS 7.4.0 through 7.4.1 and FortiClientEMS Cloud 7.4.0 through 7.4.1 may allow a remote unauthenticated attacker to perform a limited arbitrary file write on the system via upload requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22859" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-552" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-23" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T15:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qfr5-98gw-pmcj/GHSA-qfr5-98gw-pmcj.json b/advisories/unreviewed/2025/05/GHSA-qfr5-98gw-pmcj/GHSA-qfr5-98gw-pmcj.json index d87c1d7fd33..f541573b24d 100644 --- a/advisories/unreviewed/2025/05/GHSA-qfr5-98gw-pmcj/GHSA-qfr5-98gw-pmcj.json +++ b/advisories/unreviewed/2025/05/GHSA-qfr5-98gw-pmcj/GHSA-qfr5-98gw-pmcj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qfr5-98gw-pmcj", - "modified": "2025-05-13T00:31:15Z", + "modified": "2025-05-13T15:32:16Z", "published": "2025-05-13T00:31:15Z", "aliases": [ "CVE-2025-31239" ], "details": "A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 11.5, macOS Sonoma 14.7.6, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, macOS Ventura 13.7.6. Parsing a file may lead to an unexpected app termination.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:24Z" diff --git a/advisories/unreviewed/2025/05/GHSA-qqq6-x3jw-9c7x/GHSA-qqq6-x3jw-9c7x.json b/advisories/unreviewed/2025/05/GHSA-qqq6-x3jw-9c7x/GHSA-qqq6-x3jw-9c7x.json new file mode 100644 index 00000000000..a5e93f7b1ac --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qqq6-x3jw-9c7x/GHSA-qqq6-x3jw-9c7x.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qqq6-x3jw-9c7x", + "modified": "2025-05-13T15:32:16Z", + "published": "2025-05-13T15:32:16Z", + "aliases": [ + "CVE-2025-28057" + ], + "details": "owl-admin v3.2.2~ to v4.10.2 is vulnerable to SQL Injection in /admin-api/system/admin_menus/save_order.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28057" + }, + { + "type": "WEB", + "url": "https://github.com/slowlyo/owl-admin/issues/182" + }, + { + "type": "WEB", + "url": "https://gist.github.com/LTLTLXEY/8f8ea23290f45fbc5cb2191a39cc74e8" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T15:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v7jj-p23v-hq9f/GHSA-v7jj-p23v-hq9f.json b/advisories/unreviewed/2025/05/GHSA-v7jj-p23v-hq9f/GHSA-v7jj-p23v-hq9f.json index c181347888d..a0195c0ba1f 100644 --- a/advisories/unreviewed/2025/05/GHSA-v7jj-p23v-hq9f/GHSA-v7jj-p23v-hq9f.json +++ b/advisories/unreviewed/2025/05/GHSA-v7jj-p23v-hq9f/GHSA-v7jj-p23v-hq9f.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-v8vh-f89p-82w5/GHSA-v8vh-f89p-82w5.json b/advisories/unreviewed/2025/05/GHSA-v8vh-f89p-82w5/GHSA-v8vh-f89p-82w5.json index 0d3ebf8a81d..7312a817ebc 100644 --- a/advisories/unreviewed/2025/05/GHSA-v8vh-f89p-82w5/GHSA-v8vh-f89p-82w5.json +++ b/advisories/unreviewed/2025/05/GHSA-v8vh-f89p-82w5/GHSA-v8vh-f89p-82w5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v8vh-f89p-82w5", - "modified": "2025-05-13T00:31:15Z", + "modified": "2025-05-13T15:32:16Z", "published": "2025-05-13T00:31:15Z", "aliases": [ "CVE-2025-31244" ], "details": "A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.5. An app may be able to break out of its sandbox.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-693" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:24Z" diff --git a/advisories/unreviewed/2025/05/GHSA-vghf-926w-cc55/GHSA-vghf-926w-cc55.json b/advisories/unreviewed/2025/05/GHSA-vghf-926w-cc55/GHSA-vghf-926w-cc55.json new file mode 100644 index 00000000000..284fb748cfd --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vghf-926w-cc55/GHSA-vghf-926w-cc55.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vghf-926w-cc55", + "modified": "2025-05-13T15:32:17Z", + "published": "2025-05-13T15:32:17Z", + "aliases": [ + "CVE-2025-44831" + ], + "details": "EngineerCMS v1.02 through v2.0.5 has a SQL injection vulnerability in the /project/addproject interface.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44831" + }, + { + "type": "WEB", + "url": "https://github.com/3xxx/engineercms/issues/91" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T15:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w7v2-r8f5-7h23/GHSA-w7v2-r8f5-7h23.json b/advisories/unreviewed/2025/05/GHSA-w7v2-r8f5-7h23/GHSA-w7v2-r8f5-7h23.json index 2fe75e60d95..20fa3f16bbd 100644 --- a/advisories/unreviewed/2025/05/GHSA-w7v2-r8f5-7h23/GHSA-w7v2-r8f5-7h23.json +++ b/advisories/unreviewed/2025/05/GHSA-w7v2-r8f5-7h23/GHSA-w7v2-r8f5-7h23.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w7v2-r8f5-7h23", - "modified": "2025-05-08T18:30:42Z", + "modified": "2025-05-13T15:32:15Z", "published": "2025-05-08T18:30:42Z", "aliases": [ "CVE-2025-45845" ], "details": "TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid5g parameter in the setWiFiEasyGuestCfg function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-08T16:15:26Z" diff --git a/advisories/unreviewed/2025/05/GHSA-wfjv-29vm-jrfq/GHSA-wfjv-29vm-jrfq.json b/advisories/unreviewed/2025/05/GHSA-wfjv-29vm-jrfq/GHSA-wfjv-29vm-jrfq.json new file mode 100644 index 00000000000..4aebce0d355 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wfjv-29vm-jrfq/GHSA-wfjv-29vm-jrfq.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wfjv-29vm-jrfq", + "modified": "2025-05-13T15:32:17Z", + "published": "2025-05-13T15:32:17Z", + "aliases": [ + "CVE-2025-45859" + ], + "details": "TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the bandstr parameter in the formMapDelDevice interface.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45859" + }, + { + "type": "WEB", + "url": "https://github.com/Jiangxiazhe/IOT_hack/blob/main/TOTOLINK/A3002R/4/overflow.md" + }, + { + "type": "WEB", + "url": "https://www.totolink.net/home/menu/detail/menu_listtpl/download/id/258/ids/36.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T15:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-whm5-2rx4-qhv5/GHSA-whm5-2rx4-qhv5.json b/advisories/unreviewed/2025/05/GHSA-whm5-2rx4-qhv5/GHSA-whm5-2rx4-qhv5.json index e4eb2facc97..94a906c0809 100644 --- a/advisories/unreviewed/2025/05/GHSA-whm5-2rx4-qhv5/GHSA-whm5-2rx4-qhv5.json +++ b/advisories/unreviewed/2025/05/GHSA-whm5-2rx4-qhv5/GHSA-whm5-2rx4-qhv5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-whm5-2rx4-qhv5", - "modified": "2025-05-13T00:31:14Z", + "modified": "2025-05-13T15:32:16Z", "published": "2025-05-13T00:31:14Z", "aliases": [ "CVE-2025-31224" ], "details": "A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. An app may be able to bypass certain Privacy preferences.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-693" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:23Z" diff --git a/advisories/unreviewed/2025/05/GHSA-xh5p-rm5r-7f82/GHSA-xh5p-rm5r-7f82.json b/advisories/unreviewed/2025/05/GHSA-xh5p-rm5r-7f82/GHSA-xh5p-rm5r-7f82.json index bbed9420bc1..6db1c2c5cac 100644 --- a/advisories/unreviewed/2025/05/GHSA-xh5p-rm5r-7f82/GHSA-xh5p-rm5r-7f82.json +++ b/advisories/unreviewed/2025/05/GHSA-xh5p-rm5r-7f82/GHSA-xh5p-rm5r-7f82.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xh5p-rm5r-7f82", - "modified": "2025-05-13T00:31:15Z", + "modified": "2025-05-13T15:32:16Z", "published": "2025-05-13T00:31:15Z", "aliases": [ "CVE-2025-31235" ], "details": "A double free issue was addressed with improved memory management. This issue is fixed in iPadOS 17.7.7, macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. An app may be able to cause unexpected system termination.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-415" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:23Z"