diff --git a/advisories/unreviewed/2022/10/GHSA-339r-94ww-rwcq/GHSA-339r-94ww-rwcq.json b/advisories/unreviewed/2022/10/GHSA-339r-94ww-rwcq/GHSA-339r-94ww-rwcq.json index 1532ef9fca2..e2c74708304 100644 --- a/advisories/unreviewed/2022/10/GHSA-339r-94ww-rwcq/GHSA-339r-94ww-rwcq.json +++ b/advisories/unreviewed/2022/10/GHSA-339r-94ww-rwcq/GHSA-339r-94ww-rwcq.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-732" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/10/GHSA-35vc-3vm2-6c46/GHSA-35vc-3vm2-6c46.json b/advisories/unreviewed/2022/10/GHSA-35vc-3vm2-6c46/GHSA-35vc-3vm2-6c46.json index a05a9b3a82b..daba0e1c293 100644 --- a/advisories/unreviewed/2022/10/GHSA-35vc-3vm2-6c46/GHSA-35vc-3vm2-6c46.json +++ b/advisories/unreviewed/2022/10/GHSA-35vc-3vm2-6c46/GHSA-35vc-3vm2-6c46.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-36p7-jqv6-r5mj/GHSA-36p7-jqv6-r5mj.json b/advisories/unreviewed/2022/10/GHSA-36p7-jqv6-r5mj/GHSA-36p7-jqv6-r5mj.json index 008adee1c58..6dba5905269 100644 --- a/advisories/unreviewed/2022/10/GHSA-36p7-jqv6-r5mj/GHSA-36p7-jqv6-r5mj.json +++ b/advisories/unreviewed/2022/10/GHSA-36p7-jqv6-r5mj/GHSA-36p7-jqv6-r5mj.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-8m3f-vphm-cjhj/GHSA-8m3f-vphm-cjhj.json b/advisories/unreviewed/2022/10/GHSA-8m3f-vphm-cjhj/GHSA-8m3f-vphm-cjhj.json index 60709a0590b..8c29a2dfc61 100644 --- a/advisories/unreviewed/2022/10/GHSA-8m3f-vphm-cjhj/GHSA-8m3f-vphm-cjhj.json +++ b/advisories/unreviewed/2022/10/GHSA-8m3f-vphm-cjhj/GHSA-8m3f-vphm-cjhj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8m3f-vphm-cjhj", - "modified": "2022-10-20T19:00:36Z", + "modified": "2025-05-13T18:30:42Z", "published": "2022-10-17T19:00:25Z", "aliases": [ "CVE-2022-41751" @@ -35,6 +35,18 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2022/12/msg00004.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5NM6FET4ZNWV4EQGKZTLZFWTNVODGVOK" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EG26AD7KJAY5B6L6OERSGL4FRXJE3GOB" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TAVB3ZX7E5ULEXESU5NXZIAHY6CVGCHB" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5NM6FET4ZNWV4EQGKZTLZFWTNVODGVOK" diff --git a/advisories/unreviewed/2022/10/GHSA-g5cm-j62r-w7f5/GHSA-g5cm-j62r-w7f5.json b/advisories/unreviewed/2022/10/GHSA-g5cm-j62r-w7f5/GHSA-g5cm-j62r-w7f5.json index 1497e1f4e52..bfc4e41cee3 100644 --- a/advisories/unreviewed/2022/10/GHSA-g5cm-j62r-w7f5/GHSA-g5cm-j62r-w7f5.json +++ b/advisories/unreviewed/2022/10/GHSA-g5cm-j62r-w7f5/GHSA-g5cm-j62r-w7f5.json @@ -34,6 +34,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-74" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/10/GHSA-h6g4-mv38-wh4g/GHSA-h6g4-mv38-wh4g.json b/advisories/unreviewed/2022/10/GHSA-h6g4-mv38-wh4g/GHSA-h6g4-mv38-wh4g.json index ec7ff841dd3..427b6bc349d 100644 --- a/advisories/unreviewed/2022/10/GHSA-h6g4-mv38-wh4g/GHSA-h6g4-mv38-wh4g.json +++ b/advisories/unreviewed/2022/10/GHSA-h6g4-mv38-wh4g/GHSA-h6g4-mv38-wh4g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h6g4-mv38-wh4g", - "modified": "2022-10-19T19:00:23Z", + "modified": "2025-05-13T18:30:40Z", "published": "2022-10-17T19:00:29Z", "aliases": [ "CVE-2022-41542" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://devhubapp.com" }, + { + "type": "WEB", + "url": "https://medium.com/%40sc0p3hacker/cve-2022-41542-session-mis-configuration-in-devhub-application-ca956bb9027a" + }, { "type": "WEB", "url": "https://medium.com/@sc0p3hacker/cve-2022-41542-session-mis-configuration-in-devhub-application-ca956bb9027a" diff --git a/advisories/unreviewed/2022/10/GHSA-hchv-vv89-9pxp/GHSA-hchv-vv89-9pxp.json b/advisories/unreviewed/2022/10/GHSA-hchv-vv89-9pxp/GHSA-hchv-vv89-9pxp.json index 10cfb84f401..da637f4cee6 100644 --- a/advisories/unreviewed/2022/10/GHSA-hchv-vv89-9pxp/GHSA-hchv-vv89-9pxp.json +++ b/advisories/unreviewed/2022/10/GHSA-hchv-vv89-9pxp/GHSA-hchv-vv89-9pxp.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-307" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-mqfg-2r7h-3f8c/GHSA-mqfg-2r7h-3f8c.json b/advisories/unreviewed/2022/10/GHSA-mqfg-2r7h-3f8c/GHSA-mqfg-2r7h-3f8c.json index 8d2be8fb9df..d271ef6ce17 100644 --- a/advisories/unreviewed/2022/10/GHSA-mqfg-2r7h-3f8c/GHSA-mqfg-2r7h-3f8c.json +++ b/advisories/unreviewed/2022/10/GHSA-mqfg-2r7h-3f8c/GHSA-mqfg-2r7h-3f8c.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-p38j-fpm5-5w57/GHSA-p38j-fpm5-5w57.json b/advisories/unreviewed/2022/10/GHSA-p38j-fpm5-5w57/GHSA-p38j-fpm5-5w57.json index 846d8f8649b..a8d88ee960b 100644 --- a/advisories/unreviewed/2022/10/GHSA-p38j-fpm5-5w57/GHSA-p38j-fpm5-5w57.json +++ b/advisories/unreviewed/2022/10/GHSA-p38j-fpm5-5w57/GHSA-p38j-fpm5-5w57.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-q9g6-jf2g-r26w/GHSA-q9g6-jf2g-r26w.json b/advisories/unreviewed/2022/10/GHSA-q9g6-jf2g-r26w/GHSA-q9g6-jf2g-r26w.json index 3a1c27b3991..f54514df090 100644 --- a/advisories/unreviewed/2022/10/GHSA-q9g6-jf2g-r26w/GHSA-q9g6-jf2g-r26w.json +++ b/advisories/unreviewed/2022/10/GHSA-q9g6-jf2g-r26w/GHSA-q9g6-jf2g-r26w.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-471" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-4h74-g7f9-v39f/GHSA-4h74-g7f9-v39f.json b/advisories/unreviewed/2024/03/GHSA-4h74-g7f9-v39f/GHSA-4h74-g7f9-v39f.json index 8b6483c7b40..a900e3e4cdc 100644 --- a/advisories/unreviewed/2024/03/GHSA-4h74-g7f9-v39f/GHSA-4h74-g7f9-v39f.json +++ b/advisories/unreviewed/2024/03/GHSA-4h74-g7f9-v39f/GHSA-4h74-g7f9-v39f.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-4h74-g7f9-v39f", - "modified": "2024-03-27T15:30:37Z", + "modified": "2025-05-13T18:30:44Z", "published": "2024-03-27T15:30:37Z", "aliases": [ "CVE-2024-29804" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Team Heateor Fancy Comments WordPress allows Stored XSS.This issue affects Fancy Comments WordPress: from n/a through 1.2.14.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Team Heateor Fancy Comments WordPress allows Stored XSS.This issue affects Fancy Comments WordPress: from n/a through 1.2.14.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-6h2j-v372-jc7f/GHSA-6h2j-v372-jc7f.json b/advisories/unreviewed/2024/03/GHSA-6h2j-v372-jc7f/GHSA-6h2j-v372-jc7f.json index ca7dec61413..59523444efe 100644 --- a/advisories/unreviewed/2024/03/GHSA-6h2j-v372-jc7f/GHSA-6h2j-v372-jc7f.json +++ b/advisories/unreviewed/2024/03/GHSA-6h2j-v372-jc7f/GHSA-6h2j-v372-jc7f.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-6h2j-v372-jc7f", - "modified": "2024-03-27T15:30:37Z", + "modified": "2025-05-13T18:30:45Z", "published": "2024-03-27T15:30:37Z", "aliases": [ "CVE-2024-29812" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ReviewX allows Stored XSS.This issue affects ReviewX: from n/a through 1.6.22.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ReviewX allows Stored XSS.This issue affects ReviewX: from n/a through 1.6.22.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-7ccw-86xw-4rp5/GHSA-7ccw-86xw-4rp5.json b/advisories/unreviewed/2024/03/GHSA-7ccw-86xw-4rp5/GHSA-7ccw-86xw-4rp5.json index 60b58fa75bb..2b7c6cdc956 100644 --- a/advisories/unreviewed/2024/03/GHSA-7ccw-86xw-4rp5/GHSA-7ccw-86xw-4rp5.json +++ b/advisories/unreviewed/2024/03/GHSA-7ccw-86xw-4rp5/GHSA-7ccw-86xw-4rp5.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-7ccw-86xw-4rp5", - "modified": "2024-03-27T15:30:37Z", + "modified": "2025-05-13T18:30:44Z", "published": "2024-03-27T15:30:37Z", "aliases": [ "CVE-2024-29806" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Reservation Diary ReDi Restaurant Reservation allows Reflected XSS.This issue affects ReDi Restaurant Reservation: from n/a through 24.0128.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Reservation Diary ReDi Restaurant Reservation allows Reflected XSS.This issue affects ReDi Restaurant Reservation: from n/a through 24.0128.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-pjmw-m62h-r3g5/GHSA-pjmw-m62h-r3g5.json b/advisories/unreviewed/2024/03/GHSA-pjmw-m62h-r3g5/GHSA-pjmw-m62h-r3g5.json index 53144a8cb51..dfbab63287b 100644 --- a/advisories/unreviewed/2024/03/GHSA-pjmw-m62h-r3g5/GHSA-pjmw-m62h-r3g5.json +++ b/advisories/unreviewed/2024/03/GHSA-pjmw-m62h-r3g5/GHSA-pjmw-m62h-r3g5.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-pjmw-m62h-r3g5", - "modified": "2024-03-27T15:30:37Z", + "modified": "2025-05-13T18:30:44Z", "published": "2024-03-27T15:30:37Z", "aliases": [ "CVE-2024-29805" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShopUp Shipping with Venipak for WooCommerce allows Reflected XSS.This issue affects Shipping with Venipak for WooCommerce: from n/a through 1.19.5.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShopUp Shipping with Venipak for WooCommerce allows Reflected XSS.This issue affects Shipping with Venipak for WooCommerce: from n/a through 1.19.5.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-v8pj-77q3-8742/GHSA-v8pj-77q3-8742.json b/advisories/unreviewed/2024/03/GHSA-v8pj-77q3-8742/GHSA-v8pj-77q3-8742.json index 2ba61c34a3c..6524d2bfdeb 100644 --- a/advisories/unreviewed/2024/03/GHSA-v8pj-77q3-8742/GHSA-v8pj-77q3-8742.json +++ b/advisories/unreviewed/2024/03/GHSA-v8pj-77q3-8742/GHSA-v8pj-77q3-8742.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-v8pj-77q3-8742", - "modified": "2024-03-27T15:30:37Z", + "modified": "2025-05-13T18:30:45Z", "published": "2024-03-27T15:30:37Z", "aliases": [ "CVE-2024-29811" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SoftLab Radio Player allows Stored XSS.This issue affects Radio Player: from n/a through 2.0.73.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SoftLab Radio Player allows Stored XSS.This issue affects Radio Player: from n/a through 2.0.73.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-w23c-wpw6-cxpq/GHSA-w23c-wpw6-cxpq.json b/advisories/unreviewed/2024/03/GHSA-w23c-wpw6-cxpq/GHSA-w23c-wpw6-cxpq.json index c1c029cb616..a9c2ce5770d 100644 --- a/advisories/unreviewed/2024/03/GHSA-w23c-wpw6-cxpq/GHSA-w23c-wpw6-cxpq.json +++ b/advisories/unreviewed/2024/03/GHSA-w23c-wpw6-cxpq/GHSA-w23c-wpw6-cxpq.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-w23c-wpw6-cxpq", - "modified": "2024-03-27T15:30:37Z", + "modified": "2025-05-13T18:30:45Z", "published": "2024-03-27T15:30:37Z", "aliases": [ "CVE-2024-29807" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DearHive DearFlip allows Stored XSS.This issue affects DearFlip: from n/a through 2.2.26.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DearHive DearFlip allows Stored XSS.This issue affects DearFlip: from n/a through 2.2.26.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/07/GHSA-238h-vq9j-vxxx/GHSA-238h-vq9j-vxxx.json b/advisories/unreviewed/2024/07/GHSA-238h-vq9j-vxxx/GHSA-238h-vq9j-vxxx.json index 7497125e2ba..b96910f84f1 100644 --- a/advisories/unreviewed/2024/07/GHSA-238h-vq9j-vxxx/GHSA-238h-vq9j-vxxx.json +++ b/advisories/unreviewed/2024/07/GHSA-238h-vq9j-vxxx/GHSA-238h-vq9j-vxxx.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-33v5-9rfm-w3f4/GHSA-33v5-9rfm-w3f4.json b/advisories/unreviewed/2024/07/GHSA-33v5-9rfm-w3f4/GHSA-33v5-9rfm-w3f4.json index 4dd39fedd43..d3cbc452a13 100644 --- a/advisories/unreviewed/2024/07/GHSA-33v5-9rfm-w3f4/GHSA-33v5-9rfm-w3f4.json +++ b/advisories/unreviewed/2024/07/GHSA-33v5-9rfm-w3f4/GHSA-33v5-9rfm-w3f4.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-4m87-f24p-8vjc/GHSA-4m87-f24p-8vjc.json b/advisories/unreviewed/2024/07/GHSA-4m87-f24p-8vjc/GHSA-4m87-f24p-8vjc.json index 5e53a42fa00..d048931fed1 100644 --- a/advisories/unreviewed/2024/07/GHSA-4m87-f24p-8vjc/GHSA-4m87-f24p-8vjc.json +++ b/advisories/unreviewed/2024/07/GHSA-4m87-f24p-8vjc/GHSA-4m87-f24p-8vjc.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-8j2q-4vwg-3xfh/GHSA-8j2q-4vwg-3xfh.json b/advisories/unreviewed/2024/07/GHSA-8j2q-4vwg-3xfh/GHSA-8j2q-4vwg-3xfh.json index 8cea00c3db2..a1b1156bf65 100644 --- a/advisories/unreviewed/2024/07/GHSA-8j2q-4vwg-3xfh/GHSA-8j2q-4vwg-3xfh.json +++ b/advisories/unreviewed/2024/07/GHSA-8j2q-4vwg-3xfh/GHSA-8j2q-4vwg-3xfh.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-434" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-c9r8-cg3x-whrc/GHSA-c9r8-cg3x-whrc.json b/advisories/unreviewed/2024/07/GHSA-c9r8-cg3x-whrc/GHSA-c9r8-cg3x-whrc.json index 3366dfacc67..fa679405a09 100644 --- a/advisories/unreviewed/2024/07/GHSA-c9r8-cg3x-whrc/GHSA-c9r8-cg3x-whrc.json +++ b/advisories/unreviewed/2024/07/GHSA-c9r8-cg3x-whrc/GHSA-c9r8-cg3x-whrc.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-cwpg-2qv7-g34j/GHSA-cwpg-2qv7-g34j.json b/advisories/unreviewed/2024/07/GHSA-cwpg-2qv7-g34j/GHSA-cwpg-2qv7-g34j.json index b4a3d5611f7..38943308b57 100644 --- a/advisories/unreviewed/2024/07/GHSA-cwpg-2qv7-g34j/GHSA-cwpg-2qv7-g34j.json +++ b/advisories/unreviewed/2024/07/GHSA-cwpg-2qv7-g34j/GHSA-cwpg-2qv7-g34j.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-ggxx-7xgm-c5m6/GHSA-ggxx-7xgm-c5m6.json b/advisories/unreviewed/2024/07/GHSA-ggxx-7xgm-c5m6/GHSA-ggxx-7xgm-c5m6.json index c3d3036907c..0cb767bfc6d 100644 --- a/advisories/unreviewed/2024/07/GHSA-ggxx-7xgm-c5m6/GHSA-ggxx-7xgm-c5m6.json +++ b/advisories/unreviewed/2024/07/GHSA-ggxx-7xgm-c5m6/GHSA-ggxx-7xgm-c5m6.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-p9mv-wfx3-mx37/GHSA-p9mv-wfx3-mx37.json b/advisories/unreviewed/2024/07/GHSA-p9mv-wfx3-mx37/GHSA-p9mv-wfx3-mx37.json index 464914f2053..ffcec4194ef 100644 --- a/advisories/unreviewed/2024/07/GHSA-p9mv-wfx3-mx37/GHSA-p9mv-wfx3-mx37.json +++ b/advisories/unreviewed/2024/07/GHSA-p9mv-wfx3-mx37/GHSA-p9mv-wfx3-mx37.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-pc76-wwrm-9rgw/GHSA-pc76-wwrm-9rgw.json b/advisories/unreviewed/2024/07/GHSA-pc76-wwrm-9rgw/GHSA-pc76-wwrm-9rgw.json index b4dbcc23b9b..832a08462af 100644 --- a/advisories/unreviewed/2024/07/GHSA-pc76-wwrm-9rgw/GHSA-pc76-wwrm-9rgw.json +++ b/advisories/unreviewed/2024/07/GHSA-pc76-wwrm-9rgw/GHSA-pc76-wwrm-9rgw.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-qjg9-jffj-g754/GHSA-qjg9-jffj-g754.json b/advisories/unreviewed/2024/07/GHSA-qjg9-jffj-g754/GHSA-qjg9-jffj-g754.json index 0faa4928b24..5cd18d81bc1 100644 --- a/advisories/unreviewed/2024/07/GHSA-qjg9-jffj-g754/GHSA-qjg9-jffj-g754.json +++ b/advisories/unreviewed/2024/07/GHSA-qjg9-jffj-g754/GHSA-qjg9-jffj-g754.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-hgx5-vhrf-2496/GHSA-hgx5-vhrf-2496.json b/advisories/unreviewed/2025/01/GHSA-hgx5-vhrf-2496/GHSA-hgx5-vhrf-2496.json index 72228d5cb64..328547322c4 100644 --- a/advisories/unreviewed/2025/01/GHSA-hgx5-vhrf-2496/GHSA-hgx5-vhrf-2496.json +++ b/advisories/unreviewed/2025/01/GHSA-hgx5-vhrf-2496/GHSA-hgx5-vhrf-2496.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-p7wf-qqfr-f6xp/GHSA-p7wf-qqfr-f6xp.json b/advisories/unreviewed/2025/04/GHSA-p7wf-qqfr-f6xp/GHSA-p7wf-qqfr-f6xp.json index e20392ddd1d..66a7f41318a 100644 --- a/advisories/unreviewed/2025/04/GHSA-p7wf-qqfr-f6xp/GHSA-p7wf-qqfr-f6xp.json +++ b/advisories/unreviewed/2025/04/GHSA-p7wf-qqfr-f6xp/GHSA-p7wf-qqfr-f6xp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p7wf-qqfr-f6xp", - "modified": "2025-04-03T18:30:57Z", + "modified": "2025-05-13T18:30:47Z", "published": "2025-04-01T00:30:38Z", "aliases": [ "CVE-2025-24213" @@ -38,6 +38,34 @@ { "type": "WEB", "url": "https://support.apple.com/en-us/122379" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122404" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122405" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122716" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122719" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122720" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122721" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122722" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/05/GHSA-22fv-h3f5-g95w/GHSA-22fv-h3f5-g95w.json b/advisories/unreviewed/2025/05/GHSA-22fv-h3f5-g95w/GHSA-22fv-h3f5-g95w.json new file mode 100644 index 00000000000..996252d48e9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-22fv-h3f5-g95w/GHSA-22fv-h3f5-g95w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-22fv-h3f5-g95w", + "modified": "2025-05-13T18:30:53Z", + "published": "2025-05-13T18:30:53Z", + "aliases": [ + "CVE-2025-26685" + ], + "details": "Improper authentication in Microsoft Defender for Identity allows an unauthorized attacker to perform spoofing over an adjacent network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26685" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26685" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-289j-qjv7-62fr/GHSA-289j-qjv7-62fr.json b/advisories/unreviewed/2025/05/GHSA-289j-qjv7-62fr/GHSA-289j-qjv7-62fr.json index 3108801e866..17f7c85f5c0 100644 --- a/advisories/unreviewed/2025/05/GHSA-289j-qjv7-62fr/GHSA-289j-qjv7-62fr.json +++ b/advisories/unreviewed/2025/05/GHSA-289j-qjv7-62fr/GHSA-289j-qjv7-62fr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-289j-qjv7-62fr", - "modified": "2025-05-13T00:31:15Z", + "modified": "2025-05-13T18:30:51Z", "published": "2025-05-13T00:31:15Z", "aliases": [ "CVE-2025-31257" ], "details": "This issue was addressed with improved memory handling. This issue is fixed in watchOS 11.5, tvOS 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, Safari 18.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:L" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:25Z" diff --git a/advisories/unreviewed/2025/05/GHSA-296p-gcc5-5329/GHSA-296p-gcc5-5329.json b/advisories/unreviewed/2025/05/GHSA-296p-gcc5-5329/GHSA-296p-gcc5-5329.json new file mode 100644 index 00000000000..2e3b24f8239 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-296p-gcc5-5329/GHSA-296p-gcc5-5329.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-296p-gcc5-5329", + "modified": "2025-05-13T18:30:54Z", + "published": "2025-05-13T18:30:54Z", + "aliases": [ + "CVE-2025-29839" + ], + "details": "Out-of-bounds read in Windows File Server allows an unauthorized attacker to disclose information locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29839" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29839" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2c3j-mwh6-x6f2/GHSA-2c3j-mwh6-x6f2.json b/advisories/unreviewed/2025/05/GHSA-2c3j-mwh6-x6f2/GHSA-2c3j-mwh6-x6f2.json new file mode 100644 index 00000000000..9614c8c712d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2c3j-mwh6-x6f2/GHSA-2c3j-mwh6-x6f2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2c3j-mwh6-x6f2", + "modified": "2025-05-13T18:30:55Z", + "published": "2025-05-13T18:30:55Z", + "aliases": [ + "CVE-2025-29973" + ], + "details": "Improper access control in Azure File Sync allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29973" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29973" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2j86-v657-3w4j/GHSA-2j86-v657-3w4j.json b/advisories/unreviewed/2025/05/GHSA-2j86-v657-3w4j/GHSA-2j86-v657-3w4j.json new file mode 100644 index 00000000000..0dceff9f632 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2j86-v657-3w4j/GHSA-2j86-v657-3w4j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2j86-v657-3w4j", + "modified": "2025-05-13T18:30:54Z", + "published": "2025-05-13T18:30:54Z", + "aliases": [ + "CVE-2025-29966" + ], + "details": "Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29966" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29966" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2qg3-px2c-m64g/GHSA-2qg3-px2c-m64g.json b/advisories/unreviewed/2025/05/GHSA-2qg3-px2c-m64g/GHSA-2qg3-px2c-m64g.json index 8aaa6d2a5d3..8d3660d9fc0 100644 --- a/advisories/unreviewed/2025/05/GHSA-2qg3-px2c-m64g/GHSA-2qg3-px2c-m64g.json +++ b/advisories/unreviewed/2025/05/GHSA-2qg3-px2c-m64g/GHSA-2qg3-px2c-m64g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2qg3-px2c-m64g", - "modified": "2025-05-12T21:31:09Z", + "modified": "2025-05-13T18:30:51Z", "published": "2025-05-12T21:31:09Z", "aliases": [ "CVE-2024-55466" ], "details": "An arbitrary file upload vulnerability in the Image Gallery of ThingsBoard Community, ThingsBoard Cloud and ThingsBoard Professional v3.8.1 allows attackers to execute arbitrary code via uploading a crafted file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T19:15:48Z" diff --git a/advisories/unreviewed/2025/05/GHSA-2xwv-25cq-66xr/GHSA-2xwv-25cq-66xr.json b/advisories/unreviewed/2025/05/GHSA-2xwv-25cq-66xr/GHSA-2xwv-25cq-66xr.json index 1e6ead8def8..b9676eb344c 100644 --- a/advisories/unreviewed/2025/05/GHSA-2xwv-25cq-66xr/GHSA-2xwv-25cq-66xr.json +++ b/advisories/unreviewed/2025/05/GHSA-2xwv-25cq-66xr/GHSA-2xwv-25cq-66xr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2xwv-25cq-66xr", - "modified": "2025-05-12T18:31:48Z", + "modified": "2025-05-13T18:30:50Z", "published": "2025-05-12T18:31:48Z", "aliases": [ "CVE-2023-34732" ], "details": "An issue in the userId parameter in the change password function of Flytxt NEON-dX v0.0.1-SNAPSHOT-6.9-qa-2-9-g5502a0c allows attackers to execute brute force attacks to discover user passwords.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-307" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T18:15:43Z" diff --git a/advisories/unreviewed/2025/05/GHSA-3qp4-7wm4-9hhr/GHSA-3qp4-7wm4-9hhr.json b/advisories/unreviewed/2025/05/GHSA-3qp4-7wm4-9hhr/GHSA-3qp4-7wm4-9hhr.json new file mode 100644 index 00000000000..01576621c5f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3qp4-7wm4-9hhr/GHSA-3qp4-7wm4-9hhr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qp4-7wm4-9hhr", + "modified": "2025-05-13T18:30:52Z", + "published": "2025-05-13T18:30:52Z", + "aliases": [ + "CVE-2024-46506" + ], + "details": "NetAlertX 23.01.14 through 24.x before 24.10.12 allows unauthenticated command injection via settings update because function=savesettings lacks an authentication requirement, as exploited in the wild in May 2025. This is related to settings.php and util.php.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46506" + }, + { + "type": "WEB", + "url": "https://rhinosecuritylabs.com/research/cve-2024-46506-rce-in-netalertx" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-48v5-2vrv-8g64/GHSA-48v5-2vrv-8g64.json b/advisories/unreviewed/2025/05/GHSA-48v5-2vrv-8g64/GHSA-48v5-2vrv-8g64.json new file mode 100644 index 00000000000..d8c8de88930 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-48v5-2vrv-8g64/GHSA-48v5-2vrv-8g64.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-48v5-2vrv-8g64", + "modified": "2025-05-13T18:30:54Z", + "published": "2025-05-13T18:30:54Z", + "aliases": [ + "CVE-2025-29962" + ], + "details": "Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29962" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29962" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4m72-w697-5gpc/GHSA-4m72-w697-5gpc.json b/advisories/unreviewed/2025/05/GHSA-4m72-w697-5gpc/GHSA-4m72-w697-5gpc.json new file mode 100644 index 00000000000..4543b70e19f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4m72-w697-5gpc/GHSA-4m72-w697-5gpc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4m72-w697-5gpc", + "modified": "2025-05-13T18:30:56Z", + "published": "2025-05-13T18:30:56Z", + "aliases": [ + "CVE-2025-30383" + ], + "details": "Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30383" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-30383" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-843" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4pm3-q78x-r7p2/GHSA-4pm3-q78x-r7p2.json b/advisories/unreviewed/2025/05/GHSA-4pm3-q78x-r7p2/GHSA-4pm3-q78x-r7p2.json new file mode 100644 index 00000000000..c2728a6734b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4pm3-q78x-r7p2/GHSA-4pm3-q78x-r7p2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4pm3-q78x-r7p2", + "modified": "2025-05-13T18:30:54Z", + "published": "2025-05-13T18:30:54Z", + "aliases": [ + "CVE-2025-29829" + ], + "details": "Use of uninitialized resource in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose information locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29829" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29829" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-908" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4v3j-f48c-mxfv/GHSA-4v3j-f48c-mxfv.json b/advisories/unreviewed/2025/05/GHSA-4v3j-f48c-mxfv/GHSA-4v3j-f48c-mxfv.json new file mode 100644 index 00000000000..1cb31c8e9b6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4v3j-f48c-mxfv/GHSA-4v3j-f48c-mxfv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4v3j-f48c-mxfv", + "modified": "2025-05-13T18:30:54Z", + "published": "2025-05-13T18:30:54Z", + "aliases": [ + "CVE-2025-29836" + ], + "details": "Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29836" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29836" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5293-3c98-r4fm/GHSA-5293-3c98-r4fm.json b/advisories/unreviewed/2025/05/GHSA-5293-3c98-r4fm/GHSA-5293-3c98-r4fm.json new file mode 100644 index 00000000000..fbbb10a17f6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5293-3c98-r4fm/GHSA-5293-3c98-r4fm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5293-3c98-r4fm", + "modified": "2025-05-13T18:30:54Z", + "published": "2025-05-13T18:30:53Z", + "aliases": [ + "CVE-2025-29830" + ], + "details": "Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29830" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29830" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-908" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-535q-vmc8-386p/GHSA-535q-vmc8-386p.json b/advisories/unreviewed/2025/05/GHSA-535q-vmc8-386p/GHSA-535q-vmc8-386p.json new file mode 100644 index 00000000000..c9451151450 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-535q-vmc8-386p/GHSA-535q-vmc8-386p.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-535q-vmc8-386p", + "modified": "2025-05-13T18:30:52Z", + "published": "2025-05-13T18:30:52Z", + "aliases": [ + "CVE-2025-28055" + ], + "details": "upset-gal-web v7.1.0 /api/music/v1/cover.ts contains an arbitrary file read vulnerabilit", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28055" + }, + { + "type": "WEB", + "url": "https://github.com/shinnku-nikaidou/upset-gal-web/issues/132" + }, + { + "type": "WEB", + "url": "https://gist.github.com/LTLTLXEY/eb5e07436e0fcaca9747cd4467055f14" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-538q-pgq4-6rw9/GHSA-538q-pgq4-6rw9.json b/advisories/unreviewed/2025/05/GHSA-538q-pgq4-6rw9/GHSA-538q-pgq4-6rw9.json new file mode 100644 index 00000000000..ba4c18bfa32 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-538q-pgq4-6rw9/GHSA-538q-pgq4-6rw9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-538q-pgq4-6rw9", + "modified": "2025-05-13T18:30:57Z", + "published": "2025-05-13T18:30:57Z", + "aliases": [ + "CVE-2025-32705" + ], + "details": "Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32705" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-32705" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-57q8-vxgg-mfqw/GHSA-57q8-vxgg-mfqw.json b/advisories/unreviewed/2025/05/GHSA-57q8-vxgg-mfqw/GHSA-57q8-vxgg-mfqw.json new file mode 100644 index 00000000000..c670d869241 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-57q8-vxgg-mfqw/GHSA-57q8-vxgg-mfqw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-57q8-vxgg-mfqw", + "modified": "2025-05-13T18:30:55Z", + "published": "2025-05-13T18:30:55Z", + "aliases": [ + "CVE-2025-29971" + ], + "details": "Out-of-bounds read in Web Threat Defense (WTD.sys) allows an unauthorized attacker to deny service over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29971" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29971" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5949-gw2m-qrqx/GHSA-5949-gw2m-qrqx.json b/advisories/unreviewed/2025/05/GHSA-5949-gw2m-qrqx/GHSA-5949-gw2m-qrqx.json new file mode 100644 index 00000000000..86a6093f924 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5949-gw2m-qrqx/GHSA-5949-gw2m-qrqx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5949-gw2m-qrqx", + "modified": "2025-05-13T18:30:55Z", + "published": "2025-05-13T18:30:55Z", + "aliases": [ + "CVE-2025-29977" + ], + "details": "Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29977" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29977" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-59ch-hp3c-w6qw/GHSA-59ch-hp3c-w6qw.json b/advisories/unreviewed/2025/05/GHSA-59ch-hp3c-w6qw/GHSA-59ch-hp3c-w6qw.json index 15d66a5a420..5ce1c8afd54 100644 --- a/advisories/unreviewed/2025/05/GHSA-59ch-hp3c-w6qw/GHSA-59ch-hp3c-w6qw.json +++ b/advisories/unreviewed/2025/05/GHSA-59ch-hp3c-w6qw/GHSA-59ch-hp3c-w6qw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-59ch-hp3c-w6qw", - "modified": "2025-05-13T00:31:14Z", + "modified": "2025-05-13T18:30:51Z", "published": "2025-05-13T00:31:14Z", "aliases": [ "CVE-2025-31219" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in watchOS 11.5, macOS Sonoma 14.7.6, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, macOS Ventura 13.7.6. An attacker may be able to cause unexpected system termination or corrupt kernel memory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:22Z" diff --git a/advisories/unreviewed/2025/05/GHSA-5cxq-3w6r-vj7g/GHSA-5cxq-3w6r-vj7g.json b/advisories/unreviewed/2025/05/GHSA-5cxq-3w6r-vj7g/GHSA-5cxq-3w6r-vj7g.json new file mode 100644 index 00000000000..03784e754ae --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5cxq-3w6r-vj7g/GHSA-5cxq-3w6r-vj7g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5cxq-3w6r-vj7g", + "modified": "2025-05-13T18:30:55Z", + "published": "2025-05-13T18:30:55Z", + "aliases": [ + "CVE-2025-30310" + ], + "details": "Dreamweaver Desktop versions 21.4 and earlier are affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30310" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dreamweaver/apsb25-35.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-843" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5gpw-v5hf-2wg2/GHSA-5gpw-v5hf-2wg2.json b/advisories/unreviewed/2025/05/GHSA-5gpw-v5hf-2wg2/GHSA-5gpw-v5hf-2wg2.json new file mode 100644 index 00000000000..0af5109342b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5gpw-v5hf-2wg2/GHSA-5gpw-v5hf-2wg2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5gpw-v5hf-2wg2", + "modified": "2025-05-13T18:30:56Z", + "published": "2025-05-13T18:30:56Z", + "aliases": [ + "CVE-2025-30381" + ], + "details": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30381" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-30381" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5xjr-6vjm-xc96/GHSA-5xjr-6vjm-xc96.json b/advisories/unreviewed/2025/05/GHSA-5xjr-6vjm-xc96/GHSA-5xjr-6vjm-xc96.json new file mode 100644 index 00000000000..5947216af43 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5xjr-6vjm-xc96/GHSA-5xjr-6vjm-xc96.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5xjr-6vjm-xc96", + "modified": "2025-05-13T18:30:54Z", + "published": "2025-05-13T18:30:53Z", + "aliases": [ + "CVE-2025-24063" + ], + "details": "Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24063" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24063" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-646h-jwxp-6x9w/GHSA-646h-jwxp-6x9w.json b/advisories/unreviewed/2025/05/GHSA-646h-jwxp-6x9w/GHSA-646h-jwxp-6x9w.json new file mode 100644 index 00000000000..aacc16ce094 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-646h-jwxp-6x9w/GHSA-646h-jwxp-6x9w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-646h-jwxp-6x9w", + "modified": "2025-05-13T18:30:58Z", + "published": "2025-05-13T18:30:58Z", + "aliases": [ + "CVE-2025-30322" + ], + "details": "Substance3D - Painter versions 11.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30322" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_painter/apsb25-38.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T18:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-693h-v7jp-h34f/GHSA-693h-v7jp-h34f.json b/advisories/unreviewed/2025/05/GHSA-693h-v7jp-h34f/GHSA-693h-v7jp-h34f.json new file mode 100644 index 00000000000..be167cb0136 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-693h-v7jp-h34f/GHSA-693h-v7jp-h34f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-693h-v7jp-h34f", + "modified": "2025-05-13T18:30:55Z", + "published": "2025-05-13T18:30:55Z", + "aliases": [ + "CVE-2025-29975" + ], + "details": "Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29975" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29975" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6h82-gp3x-grfp/GHSA-6h82-gp3x-grfp.json b/advisories/unreviewed/2025/05/GHSA-6h82-gp3x-grfp/GHSA-6h82-gp3x-grfp.json new file mode 100644 index 00000000000..4d15f3a7952 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6h82-gp3x-grfp/GHSA-6h82-gp3x-grfp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6h82-gp3x-grfp", + "modified": "2025-05-13T18:30:58Z", + "published": "2025-05-13T18:30:58Z", + "aliases": [ + "CVE-2023-31359" + ], + "details": "Incorrect default permissions in the AMD Manageability API could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31359" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-9015.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T18:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6m2f-83vf-p7fj/GHSA-6m2f-83vf-p7fj.json b/advisories/unreviewed/2025/05/GHSA-6m2f-83vf-p7fj/GHSA-6m2f-83vf-p7fj.json index 0f6a4f5c05c..0c66dde509d 100644 --- a/advisories/unreviewed/2025/05/GHSA-6m2f-83vf-p7fj/GHSA-6m2f-83vf-p7fj.json +++ b/advisories/unreviewed/2025/05/GHSA-6m2f-83vf-p7fj/GHSA-6m2f-83vf-p7fj.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6m2f-83vf-p7fj", - "modified": "2025-05-08T15:31:12Z", + "modified": "2025-05-13T18:30:48Z", "published": "2025-05-08T15:31:12Z", "aliases": [ "CVE-2024-6648" ], "details": "Absolute Path Traversal vulnerability in AP Page Builder versions prior to 4.0.0 could allow an unauthenticated remote user to modify the 'product_item_path' within the 'config' JSON file, allowing them to read any file on the system.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2025/05/GHSA-6mmm-6mq6-xv92/GHSA-6mmm-6mq6-xv92.json b/advisories/unreviewed/2025/05/GHSA-6mmm-6mq6-xv92/GHSA-6mmm-6mq6-xv92.json new file mode 100644 index 00000000000..4988e19c5f3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6mmm-6mq6-xv92/GHSA-6mmm-6mq6-xv92.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6mmm-6mq6-xv92", + "modified": "2025-05-13T18:30:56Z", + "published": "2025-05-13T18:30:56Z", + "aliases": [ + "CVE-2025-30382" + ], + "details": "Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30382" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-30382" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7492-x955-c45q/GHSA-7492-x955-c45q.json b/advisories/unreviewed/2025/05/GHSA-7492-x955-c45q/GHSA-7492-x955-c45q.json new file mode 100644 index 00000000000..fd2eff08fb4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7492-x955-c45q/GHSA-7492-x955-c45q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7492-x955-c45q", + "modified": "2025-05-13T18:30:57Z", + "published": "2025-05-13T18:30:57Z", + "aliases": [ + "CVE-2025-32706" + ], + "details": "Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32706" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-32706" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-787m-4j9v-v659/GHSA-787m-4j9v-v659.json b/advisories/unreviewed/2025/05/GHSA-787m-4j9v-v659/GHSA-787m-4j9v-v659.json new file mode 100644 index 00000000000..1eeeff8d7f9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-787m-4j9v-v659/GHSA-787m-4j9v-v659.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-787m-4j9v-v659", + "modified": "2025-05-13T18:30:57Z", + "published": "2025-05-13T18:30:57Z", + "aliases": [ + "CVE-2025-30394" + ], + "details": "Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to deny service over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30394" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-30394" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-591" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-799h-p6qr-g4rf/GHSA-799h-p6qr-g4rf.json b/advisories/unreviewed/2025/05/GHSA-799h-p6qr-g4rf/GHSA-799h-p6qr-g4rf.json new file mode 100644 index 00000000000..a1d2307ef2a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-799h-p6qr-g4rf/GHSA-799h-p6qr-g4rf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-799h-p6qr-g4rf", + "modified": "2025-05-13T18:30:54Z", + "published": "2025-05-13T18:30:54Z", + "aliases": [ + "CVE-2025-29831" + ], + "details": "Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29831" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29831" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7j7h-p7m5-p62q/GHSA-7j7h-p7m5-p62q.json b/advisories/unreviewed/2025/05/GHSA-7j7h-p7m5-p62q/GHSA-7j7h-p7m5-p62q.json index f378a6aa403..392237b8536 100644 --- a/advisories/unreviewed/2025/05/GHSA-7j7h-p7m5-p62q/GHSA-7j7h-p7m5-p62q.json +++ b/advisories/unreviewed/2025/05/GHSA-7j7h-p7m5-p62q/GHSA-7j7h-p7m5-p62q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7j7h-p7m5-p62q", - "modified": "2025-05-13T00:31:14Z", + "modified": "2025-05-13T18:30:51Z", "published": "2025-05-13T00:31:14Z", "aliases": [ "CVE-2025-31220" ], "details": "A privacy issue was addressed by removing sensitive data. This issue is fixed in iPadOS 17.7.7, macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. A malicious app may be able to read sensitive location information.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:22Z" diff --git a/advisories/unreviewed/2025/05/GHSA-7vmv-4hv7-j7v8/GHSA-7vmv-4hv7-j7v8.json b/advisories/unreviewed/2025/05/GHSA-7vmv-4hv7-j7v8/GHSA-7vmv-4hv7-j7v8.json new file mode 100644 index 00000000000..1c4223c3bdb --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7vmv-4hv7-j7v8/GHSA-7vmv-4hv7-j7v8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7vmv-4hv7-j7v8", + "modified": "2025-05-13T18:30:54Z", + "published": "2025-05-13T18:30:54Z", + "aliases": [ + "CVE-2025-29961" + ], + "details": "Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29961" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29961" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7vqr-m343-4f5x/GHSA-7vqr-m343-4f5x.json b/advisories/unreviewed/2025/05/GHSA-7vqr-m343-4f5x/GHSA-7vqr-m343-4f5x.json new file mode 100644 index 00000000000..eb91a80747b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7vqr-m343-4f5x/GHSA-7vqr-m343-4f5x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7vqr-m343-4f5x", + "modified": "2025-05-13T18:30:56Z", + "published": "2025-05-13T18:30:56Z", + "aliases": [ + "CVE-2025-30375" + ], + "details": "Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30375" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-30375" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-843" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-86hh-vf96-78cw/GHSA-86hh-vf96-78cw.json b/advisories/unreviewed/2025/05/GHSA-86hh-vf96-78cw/GHSA-86hh-vf96-78cw.json new file mode 100644 index 00000000000..730157738b3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-86hh-vf96-78cw/GHSA-86hh-vf96-78cw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-86hh-vf96-78cw", + "modified": "2025-05-13T18:30:59Z", + "published": "2025-05-13T18:30:58Z", + "aliases": [ + "CVE-2025-43547" + ], + "details": "Bridge versions 15.0.3, 14.1.6 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43547" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/bridge/apsb25-44.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T18:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-86pc-jx85-mvrw/GHSA-86pc-jx85-mvrw.json b/advisories/unreviewed/2025/05/GHSA-86pc-jx85-mvrw/GHSA-86pc-jx85-mvrw.json new file mode 100644 index 00000000000..cad4e173284 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-86pc-jx85-mvrw/GHSA-86pc-jx85-mvrw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-86pc-jx85-mvrw", + "modified": "2025-05-13T18:30:59Z", + "published": "2025-05-13T18:30:58Z", + "aliases": [ + "CVE-2025-4660" + ], + "details": "A remote code execution vulnerability exists in the Windows agent component of SecureConnector due to improper access controls on a named pipe. The pipe is accessible to the Everyone group and does not restrict remote connections, allowing any network-based attacker to connect without authentication. By interacting with this pipe, an attacker can redirect the agent to communicate with a rogue server that can issue commands via the SecureConnector Agent. \n\n\n\nThis does not impact Linux or OSX Secure Connector.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:M/U:Amber" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4660" + }, + { + "type": "WEB", + "url": "https://forescout.my.site.com/support/s/article/High-Severity-Vulnerability-in-Secure-Connector-HPS-Inspection-Engine-v11-3-5-and-lower" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T18:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-88m4-xjxp-h8hj/GHSA-88m4-xjxp-h8hj.json b/advisories/unreviewed/2025/05/GHSA-88m4-xjxp-h8hj/GHSA-88m4-xjxp-h8hj.json new file mode 100644 index 00000000000..be40d78d92f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-88m4-xjxp-h8hj/GHSA-88m4-xjxp-h8hj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-88m4-xjxp-h8hj", + "modified": "2025-05-13T18:30:54Z", + "published": "2025-05-13T18:30:54Z", + "aliases": [ + "CVE-2025-29841" + ], + "details": "Concurrent execution using shared resource with improper synchronization ('race condition') in Universal Print Management Service allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29841" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29841" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8h2p-ffrc-w7hm/GHSA-8h2p-ffrc-w7hm.json b/advisories/unreviewed/2025/05/GHSA-8h2p-ffrc-w7hm/GHSA-8h2p-ffrc-w7hm.json new file mode 100644 index 00000000000..c9bc9bfd6d6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8h2p-ffrc-w7hm/GHSA-8h2p-ffrc-w7hm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8h2p-ffrc-w7hm", + "modified": "2025-05-13T18:30:57Z", + "published": "2025-05-13T18:30:57Z", + "aliases": [ + "CVE-2025-32701" + ], + "details": "Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32701" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-32701" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8j8v-gr46-3787/GHSA-8j8v-gr46-3787.json b/advisories/unreviewed/2025/05/GHSA-8j8v-gr46-3787/GHSA-8j8v-gr46-3787.json new file mode 100644 index 00000000000..6b8bfdc51ea --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8j8v-gr46-3787/GHSA-8j8v-gr46-3787.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8j8v-gr46-3787", + "modified": "2025-05-13T18:30:56Z", + "published": "2025-05-13T18:30:56Z", + "aliases": [ + "CVE-2025-30386" + ], + "details": "Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30386" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-30386" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8q24-v8v4-g622/GHSA-8q24-v8v4-g622.json b/advisories/unreviewed/2025/05/GHSA-8q24-v8v4-g622/GHSA-8q24-v8v4-g622.json new file mode 100644 index 00000000000..c17e22ab47d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8q24-v8v4-g622/GHSA-8q24-v8v4-g622.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8q24-v8v4-g622", + "modified": "2025-05-13T18:30:55Z", + "published": "2025-05-13T18:30:55Z", + "aliases": [ + "CVE-2025-29970" + ], + "details": "Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29970" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29970" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8q84-3937-w4rx/GHSA-8q84-3937-w4rx.json b/advisories/unreviewed/2025/05/GHSA-8q84-3937-w4rx/GHSA-8q84-3937-w4rx.json new file mode 100644 index 00000000000..4ed2982391c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8q84-3937-w4rx/GHSA-8q84-3937-w4rx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8q84-3937-w4rx", + "modified": "2025-05-13T18:30:56Z", + "published": "2025-05-13T18:30:56Z", + "aliases": [ + "CVE-2025-30376" + ], + "details": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30376" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-30376" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8r3p-2qf3-52qp/GHSA-8r3p-2qf3-52qp.json b/advisories/unreviewed/2025/05/GHSA-8r3p-2qf3-52qp/GHSA-8r3p-2qf3-52qp.json new file mode 100644 index 00000000000..8dcacc03a92 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8r3p-2qf3-52qp/GHSA-8r3p-2qf3-52qp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8r3p-2qf3-52qp", + "modified": "2025-05-13T18:30:56Z", + "published": "2025-05-13T18:30:56Z", + "aliases": [ + "CVE-2025-30384" + ], + "details": "Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30384" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-30384" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-938p-4c9x-3mpw/GHSA-938p-4c9x-3mpw.json b/advisories/unreviewed/2025/05/GHSA-938p-4c9x-3mpw/GHSA-938p-4c9x-3mpw.json new file mode 100644 index 00000000000..936389db8b5 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-938p-4c9x-3mpw/GHSA-938p-4c9x-3mpw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-938p-4c9x-3mpw", + "modified": "2025-05-13T18:30:55Z", + "published": "2025-05-13T18:30:54Z", + "aliases": [ + "CVE-2025-29967" + ], + "details": "Heap-based buffer overflow in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29967" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29967" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-955m-4443-8f7r/GHSA-955m-4443-8f7r.json b/advisories/unreviewed/2025/05/GHSA-955m-4443-8f7r/GHSA-955m-4443-8f7r.json index 990b3d9b3e9..f0be6ecb059 100644 --- a/advisories/unreviewed/2025/05/GHSA-955m-4443-8f7r/GHSA-955m-4443-8f7r.json +++ b/advisories/unreviewed/2025/05/GHSA-955m-4443-8f7r/GHSA-955m-4443-8f7r.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-77" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-9j2q-rv22-36xm/GHSA-9j2q-rv22-36xm.json b/advisories/unreviewed/2025/05/GHSA-9j2q-rv22-36xm/GHSA-9j2q-rv22-36xm.json new file mode 100644 index 00000000000..d4434f3b066 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9j2q-rv22-36xm/GHSA-9j2q-rv22-36xm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9j2q-rv22-36xm", + "modified": "2025-05-13T18:30:57Z", + "published": "2025-05-13T18:30:57Z", + "aliases": [ + "CVE-2025-30388" + ], + "details": "Heap-based buffer overflow in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30388" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-30388" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9wcp-q959-7mq8/GHSA-9wcp-q959-7mq8.json b/advisories/unreviewed/2025/05/GHSA-9wcp-q959-7mq8/GHSA-9wcp-q959-7mq8.json new file mode 100644 index 00000000000..3bff1f74ab7 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9wcp-q959-7mq8/GHSA-9wcp-q959-7mq8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9wcp-q959-7mq8", + "modified": "2025-05-13T18:30:53Z", + "published": "2025-05-13T18:30:53Z", + "aliases": [ + "CVE-2025-4427" + ], + "details": "An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4427" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T16:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c3xm-4wh2-jmcg/GHSA-c3xm-4wh2-jmcg.json b/advisories/unreviewed/2025/05/GHSA-c3xm-4wh2-jmcg/GHSA-c3xm-4wh2-jmcg.json new file mode 100644 index 00000000000..adfdb42fc14 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c3xm-4wh2-jmcg/GHSA-c3xm-4wh2-jmcg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c3xm-4wh2-jmcg", + "modified": "2025-05-13T18:30:52Z", + "published": "2025-05-13T18:30:52Z", + "aliases": [ + "CVE-2025-22462" + ], + "details": "An authentication bypass in Ivanti Neurons for ITSM (on-prem only) before 2023.4, 2024.2 and 2024.3 with the May 2025 Security Patch allows a remote unauthenticated attacker to gain administrative access to the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22462" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-on-premises-only-CVE-2025-22462" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c5qx-gcrc-9fpj/GHSA-c5qx-gcrc-9fpj.json b/advisories/unreviewed/2025/05/GHSA-c5qx-gcrc-9fpj/GHSA-c5qx-gcrc-9fpj.json new file mode 100644 index 00000000000..48d31283075 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c5qx-gcrc-9fpj/GHSA-c5qx-gcrc-9fpj.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c5qx-gcrc-9fpj", + "modified": "2025-05-13T18:30:53Z", + "published": "2025-05-13T18:30:53Z", + "aliases": [ + "CVE-2025-45858" + ], + "details": "TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability via the FUN_00459fdc function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45858" + }, + { + "type": "WEB", + "url": "https://github.com/Jiangxiazhe/IOT_hack/blob/main/TOTOLINK/A3002R/injection1.md" + }, + { + "type": "WEB", + "url": "https://www.totolink.net/home/menu/detail/menu_listtpl/download/id/258/ids/36.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T16:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c6v5-8q58-3543/GHSA-c6v5-8q58-3543.json b/advisories/unreviewed/2025/05/GHSA-c6v5-8q58-3543/GHSA-c6v5-8q58-3543.json new file mode 100644 index 00000000000..87ca9a0b6ef --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c6v5-8q58-3543/GHSA-c6v5-8q58-3543.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c6v5-8q58-3543", + "modified": "2025-05-13T18:30:57Z", + "published": "2025-05-13T18:30:57Z", + "aliases": [ + "CVE-2025-32703" + ], + "details": "Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32703" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-32703" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c86v-xr5g-xjhx/GHSA-c86v-xr5g-xjhx.json b/advisories/unreviewed/2025/05/GHSA-c86v-xr5g-xjhx/GHSA-c86v-xr5g-xjhx.json new file mode 100644 index 00000000000..b7b321d7d1f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c86v-xr5g-xjhx/GHSA-c86v-xr5g-xjhx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c86v-xr5g-xjhx", + "modified": "2025-05-13T18:30:55Z", + "published": "2025-05-13T18:30:55Z", + "aliases": [ + "CVE-2025-29976" + ], + "details": "Improper privilege management in Microsoft Office SharePoint allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29976" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29976" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c876-c6qg-3cq5/GHSA-c876-c6qg-3cq5.json b/advisories/unreviewed/2025/05/GHSA-c876-c6qg-3cq5/GHSA-c876-c6qg-3cq5.json new file mode 100644 index 00000000000..f922a21c422 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c876-c6qg-3cq5/GHSA-c876-c6qg-3cq5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c876-c6qg-3cq5", + "modified": "2025-05-13T18:30:54Z", + "published": "2025-05-13T18:30:54Z", + "aliases": [ + "CVE-2025-29959" + ], + "details": "Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29959" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29959" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-908" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-chx2-gcq9-6mv7/GHSA-chx2-gcq9-6mv7.json b/advisories/unreviewed/2025/05/GHSA-chx2-gcq9-6mv7/GHSA-chx2-gcq9-6mv7.json new file mode 100644 index 00000000000..5e3686b2c1f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-chx2-gcq9-6mv7/GHSA-chx2-gcq9-6mv7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-chx2-gcq9-6mv7", + "modified": "2025-05-13T18:30:56Z", + "published": "2025-05-13T18:30:56Z", + "aliases": [ + "CVE-2025-30320" + ], + "details": "InDesign Desktop versions ID19.5.2, ID20.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption in service. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30320" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/indesign/apsb25-37.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-cq8m-2x25-mgg8/GHSA-cq8m-2x25-mgg8.json b/advisories/unreviewed/2025/05/GHSA-cq8m-2x25-mgg8/GHSA-cq8m-2x25-mgg8.json new file mode 100644 index 00000000000..a54735f9406 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-cq8m-2x25-mgg8/GHSA-cq8m-2x25-mgg8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cq8m-2x25-mgg8", + "modified": "2025-05-13T18:30:54Z", + "published": "2025-05-13T18:30:54Z", + "aliases": [ + "CVE-2025-29842" + ], + "details": "Acceptance of extraneous untrusted data with trusted data in UrlMon allows an unauthorized attacker to bypass a security feature over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29842" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29842" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-349" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-cq97-8j47-5p59/GHSA-cq97-8j47-5p59.json b/advisories/unreviewed/2025/05/GHSA-cq97-8j47-5p59/GHSA-cq97-8j47-5p59.json new file mode 100644 index 00000000000..bb2fb634132 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-cq97-8j47-5p59/GHSA-cq97-8j47-5p59.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cq97-8j47-5p59", + "modified": "2025-05-13T18:30:58Z", + "published": "2025-05-13T18:30:58Z", + "aliases": [ + "CVE-2025-43546" + ], + "details": "Bridge versions 15.0.3, 14.1.6 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43546" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/bridge/apsb25-44.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-191" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T18:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-crh6-cv2h-f3xm/GHSA-crh6-cv2h-f3xm.json b/advisories/unreviewed/2025/05/GHSA-crh6-cv2h-f3xm/GHSA-crh6-cv2h-f3xm.json new file mode 100644 index 00000000000..5ec7959d4c2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-crh6-cv2h-f3xm/GHSA-crh6-cv2h-f3xm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crh6-cv2h-f3xm", + "modified": "2025-05-13T18:30:58Z", + "published": "2025-05-13T18:30:58Z", + "aliases": [ + "CVE-2025-43545" + ], + "details": "Bridge versions 15.0.3, 14.1.6 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43545" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/bridge/apsb25-44.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-824" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T18:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-f2w6-r722-5fr8/GHSA-f2w6-r722-5fr8.json b/advisories/unreviewed/2025/05/GHSA-f2w6-r722-5fr8/GHSA-f2w6-r722-5fr8.json index f6c7638c996..7cbf28dc411 100644 --- a/advisories/unreviewed/2025/05/GHSA-f2w6-r722-5fr8/GHSA-f2w6-r722-5fr8.json +++ b/advisories/unreviewed/2025/05/GHSA-f2w6-r722-5fr8/GHSA-f2w6-r722-5fr8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f2w6-r722-5fr8", - "modified": "2025-05-13T03:31:13Z", + "modified": "2025-05-13T18:30:48Z", "published": "2025-05-07T18:30:50Z", "aliases": [ "CVE-2025-47203" @@ -38,6 +38,10 @@ { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2025/05/13/1" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/05/13/3" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/05/GHSA-f3gp-77fq-586m/GHSA-f3gp-77fq-586m.json b/advisories/unreviewed/2025/05/GHSA-f3gp-77fq-586m/GHSA-f3gp-77fq-586m.json new file mode 100644 index 00000000000..a0b2bb3e3d0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-f3gp-77fq-586m/GHSA-f3gp-77fq-586m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f3gp-77fq-586m", + "modified": "2025-05-13T18:30:53Z", + "published": "2025-05-13T18:30:53Z", + "aliases": [ + "CVE-2024-36321" + ], + "details": "Unquoted search path within AIM-T Manageability Service can allow a local attacker to escalate privileges, potentially resulting in arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36321" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-9015.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-428" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fpjq-79p8-3p6w/GHSA-fpjq-79p8-3p6w.json b/advisories/unreviewed/2025/05/GHSA-fpjq-79p8-3p6w/GHSA-fpjq-79p8-3p6w.json new file mode 100644 index 00000000000..e203dd9c73d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fpjq-79p8-3p6w/GHSA-fpjq-79p8-3p6w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fpjq-79p8-3p6w", + "modified": "2025-05-13T18:30:55Z", + "published": "2025-05-13T18:30:55Z", + "aliases": [ + "CVE-2025-29969" + ], + "details": "Time-of-check time-of-use (toctou) race condition in Windows Fundamentals allows an authorized attacker to execute code over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29969" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29969" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fw33-q9gh-rp77/GHSA-fw33-q9gh-rp77.json b/advisories/unreviewed/2025/05/GHSA-fw33-q9gh-rp77/GHSA-fw33-q9gh-rp77.json new file mode 100644 index 00000000000..eedf6e94eae --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fw33-q9gh-rp77/GHSA-fw33-q9gh-rp77.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fw33-q9gh-rp77", + "modified": "2025-05-13T18:30:57Z", + "published": "2025-05-13T18:30:57Z", + "aliases": [ + "CVE-2025-32707" + ], + "details": "Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32707" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-32707" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fxh5-h665-pxfj/GHSA-fxh5-h665-pxfj.json b/advisories/unreviewed/2025/05/GHSA-fxh5-h665-pxfj/GHSA-fxh5-h665-pxfj.json new file mode 100644 index 00000000000..93c9f869999 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fxh5-h665-pxfj/GHSA-fxh5-h665-pxfj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fxh5-h665-pxfj", + "modified": "2025-05-13T18:30:53Z", + "published": "2025-05-13T18:30:53Z", + "aliases": [ + "CVE-2025-27468" + ], + "details": "Improper privilege management in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27468" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27468" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fxw3-rq5v-qr7h/GHSA-fxw3-rq5v-qr7h.json b/advisories/unreviewed/2025/05/GHSA-fxw3-rq5v-qr7h/GHSA-fxw3-rq5v-qr7h.json index 77d6a1da973..67586e17b92 100644 --- a/advisories/unreviewed/2025/05/GHSA-fxw3-rq5v-qr7h/GHSA-fxw3-rq5v-qr7h.json +++ b/advisories/unreviewed/2025/05/GHSA-fxw3-rq5v-qr7h/GHSA-fxw3-rq5v-qr7h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fxw3-rq5v-qr7h", - "modified": "2025-05-13T15:32:17Z", + "modified": "2025-05-13T18:30:52Z", "published": "2025-05-13T15:32:17Z", "aliases": [ "CVE-2025-45867" ], "details": "TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the static_dns1 parameter in the formIpv6Setup interface.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-13T15:15:58Z" diff --git a/advisories/unreviewed/2025/05/GHSA-g4m9-9h4j-22xx/GHSA-g4m9-9h4j-22xx.json b/advisories/unreviewed/2025/05/GHSA-g4m9-9h4j-22xx/GHSA-g4m9-9h4j-22xx.json new file mode 100644 index 00000000000..2e5cbc8698f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g4m9-9h4j-22xx/GHSA-g4m9-9h4j-22xx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g4m9-9h4j-22xx", + "modified": "2025-05-13T18:30:53Z", + "published": "2025-05-13T18:30:53Z", + "aliases": [ + "CVE-2025-4428" + ], + "details": "Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via crafted API requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4428" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T16:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g8cq-pwcv-27g6/GHSA-g8cq-pwcv-27g6.json b/advisories/unreviewed/2025/05/GHSA-g8cq-pwcv-27g6/GHSA-g8cq-pwcv-27g6.json new file mode 100644 index 00000000000..3ec082d9898 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g8cq-pwcv-27g6/GHSA-g8cq-pwcv-27g6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g8cq-pwcv-27g6", + "modified": "2025-05-13T18:30:58Z", + "published": "2025-05-13T18:30:58Z", + "aliases": [ + "CVE-2025-30324" + ], + "details": "Photoshop Desktop versions 26.5, 25.12.2 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30324" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/photoshop/apsb25-40.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-191" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T18:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gc6c-44mm-v3cj/GHSA-gc6c-44mm-v3cj.json b/advisories/unreviewed/2025/05/GHSA-gc6c-44mm-v3cj/GHSA-gc6c-44mm-v3cj.json new file mode 100644 index 00000000000..30d459dd6a5 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gc6c-44mm-v3cj/GHSA-gc6c-44mm-v3cj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gc6c-44mm-v3cj", + "modified": "2025-05-13T18:30:58Z", + "published": "2025-05-13T18:30:58Z", + "aliases": [ + "CVE-2025-30330" + ], + "details": "Illustrator versions 29.3, 28.7.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30330" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/illustrator/apsb25-43.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T18:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gfrm-669r-42x9/GHSA-gfrm-669r-42x9.json b/advisories/unreviewed/2025/05/GHSA-gfrm-669r-42x9/GHSA-gfrm-669r-42x9.json new file mode 100644 index 00000000000..71f78f7588b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gfrm-669r-42x9/GHSA-gfrm-669r-42x9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gfrm-669r-42x9", + "modified": "2025-05-13T18:30:54Z", + "published": "2025-05-13T18:30:54Z", + "aliases": [ + "CVE-2025-29958" + ], + "details": "Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29958" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29958" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-908" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-ggh3-rx92-gffh/GHSA-ggh3-rx92-gffh.json b/advisories/unreviewed/2025/05/GHSA-ggh3-rx92-gffh/GHSA-ggh3-rx92-gffh.json new file mode 100644 index 00000000000..bbb9c2f8ad9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-ggh3-rx92-gffh/GHSA-ggh3-rx92-gffh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ggh3-rx92-gffh", + "modified": "2025-05-13T18:30:57Z", + "published": "2025-05-13T18:30:57Z", + "aliases": [ + "CVE-2025-32704" + ], + "details": "Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32704" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-32704" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-ggw4-9fpp-hfv4/GHSA-ggw4-9fpp-hfv4.json b/advisories/unreviewed/2025/05/GHSA-ggw4-9fpp-hfv4/GHSA-ggw4-9fpp-hfv4.json index 978e950226b..ad6fe95ecd4 100644 --- a/advisories/unreviewed/2025/05/GHSA-ggw4-9fpp-hfv4/GHSA-ggw4-9fpp-hfv4.json +++ b/advisories/unreviewed/2025/05/GHSA-ggw4-9fpp-hfv4/GHSA-ggw4-9fpp-hfv4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-ggw4-9fpp-hfv4", - "modified": "2025-05-12T18:31:48Z", + "modified": "2025-05-13T18:30:50Z", "published": "2025-05-12T18:31:48Z", "aliases": [ "CVE-2025-44175" ], "details": "Tenda AC10 v4 V16.03.10.13 is vulnerable to Buffer Overflow in the GetParentControlInfo function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T18:15:45Z" diff --git a/advisories/unreviewed/2025/05/GHSA-gv5r-9gxr-v74w/GHSA-gv5r-9gxr-v74w.json b/advisories/unreviewed/2025/05/GHSA-gv5r-9gxr-v74w/GHSA-gv5r-9gxr-v74w.json new file mode 100644 index 00000000000..cb56226f213 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gv5r-9gxr-v74w/GHSA-gv5r-9gxr-v74w.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gv5r-9gxr-v74w", + "modified": "2025-05-13T18:30:53Z", + "published": "2025-05-13T18:30:53Z", + "aliases": [ + "CVE-2025-47204" + ], + "details": "An issue was discovered in post.php in bootstrap-multiselect (aka Bootstrap Multiselect) 1.1.2. A PHP script in the source code echoes arbitrary POST data. If a developer adopts this structure wholesale in a live application, it could create a Reflective Cross-Site Scripting (XSS) vulnerability exploitable through Cross-Site Request Forgery (CSRF).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47204" + }, + { + "type": "WEB", + "url": "https://github.com/projectdiscovery/nuclei-templates/commit/11e1a6c11d3954f44acfb0274b6dad4bd8045103" + }, + { + "type": "WEB", + "url": "https://github.com/davidstutz/bootstrap-multiselect/releases" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T16:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gvqh-2pg4-fc8q/GHSA-gvqh-2pg4-fc8q.json b/advisories/unreviewed/2025/05/GHSA-gvqh-2pg4-fc8q/GHSA-gvqh-2pg4-fc8q.json new file mode 100644 index 00000000000..6fef1151d9d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gvqh-2pg4-fc8q/GHSA-gvqh-2pg4-fc8q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gvqh-2pg4-fc8q", + "modified": "2025-05-13T18:30:54Z", + "published": "2025-05-13T18:30:54Z", + "aliases": [ + "CVE-2025-29838" + ], + "details": "Null pointer dereference in Windows Drivers allows an unauthorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29838" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29838" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gw88-vjjm-8vp4/GHSA-gw88-vjjm-8vp4.json b/advisories/unreviewed/2025/05/GHSA-gw88-vjjm-8vp4/GHSA-gw88-vjjm-8vp4.json index 6dc2e68b8c0..7099cb6c8e5 100644 --- a/advisories/unreviewed/2025/05/GHSA-gw88-vjjm-8vp4/GHSA-gw88-vjjm-8vp4.json +++ b/advisories/unreviewed/2025/05/GHSA-gw88-vjjm-8vp4/GHSA-gw88-vjjm-8vp4.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-h2rx-58r6-57ch/GHSA-h2rx-58r6-57ch.json b/advisories/unreviewed/2025/05/GHSA-h2rx-58r6-57ch/GHSA-h2rx-58r6-57ch.json new file mode 100644 index 00000000000..19a59949ac9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h2rx-58r6-57ch/GHSA-h2rx-58r6-57ch.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h2rx-58r6-57ch", + "modified": "2025-05-13T18:30:56Z", + "published": "2025-05-13T18:30:56Z", + "aliases": [ + "CVE-2025-30319" + ], + "details": "InDesign Desktop versions ID19.5.2, ID20.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing a disruption in service. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30319" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/indesign/apsb25-37.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h8f3-6m5h-w36c/GHSA-h8f3-6m5h-w36c.json b/advisories/unreviewed/2025/05/GHSA-h8f3-6m5h-w36c/GHSA-h8f3-6m5h-w36c.json new file mode 100644 index 00000000000..00ef08768b5 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h8f3-6m5h-w36c/GHSA-h8f3-6m5h-w36c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h8f3-6m5h-w36c", + "modified": "2025-05-13T18:30:58Z", + "published": "2025-05-13T18:30:58Z", + "aliases": [ + "CVE-2025-43556" + ], + "details": "Animate versions 24.0.8, 23.0.11 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43556" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/animate/apsb25-42.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T18:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h96f-qxw6-vq8x/GHSA-h96f-qxw6-vq8x.json b/advisories/unreviewed/2025/05/GHSA-h96f-qxw6-vq8x/GHSA-h96f-qxw6-vq8x.json new file mode 100644 index 00000000000..cec77470413 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h96f-qxw6-vq8x/GHSA-h96f-qxw6-vq8x.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h96f-qxw6-vq8x", + "modified": "2025-05-13T18:30:52Z", + "published": "2025-05-13T18:30:52Z", + "aliases": [ + "CVE-2024-48766" + ], + "details": "NetAlertX 24.7.18 before 24.10.12 allows unauthenticated file reading because an HTTP client can ignore a redirect, and because of factors related to strpos and directory traversal, as exploited in the wild in May 2025. This is related to components/logs.php.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48766" + }, + { + "type": "WEB", + "url": "https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/auxiliary/scanner/http/netalertx_file_read.rb" + }, + { + "type": "WEB", + "url": "https://rhinosecuritylabs.com/research/cve-2024-46506-rce-in-netalertx" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-698" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h9ff-79xg-32pf/GHSA-h9ff-79xg-32pf.json b/advisories/unreviewed/2025/05/GHSA-h9ff-79xg-32pf/GHSA-h9ff-79xg-32pf.json new file mode 100644 index 00000000000..233b18881e2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h9ff-79xg-32pf/GHSA-h9ff-79xg-32pf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9ff-79xg-32pf", + "modified": "2025-05-13T18:30:58Z", + "published": "2025-05-13T18:30:58Z", + "aliases": [ + "CVE-2025-30325" + ], + "details": "Photoshop Desktop versions 26.5, 25.12.2 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30325" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/photoshop/apsb25-40.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T18:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hc27-mggf-jwj2/GHSA-hc27-mggf-jwj2.json b/advisories/unreviewed/2025/05/GHSA-hc27-mggf-jwj2/GHSA-hc27-mggf-jwj2.json new file mode 100644 index 00000000000..7677cad5dea --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hc27-mggf-jwj2/GHSA-hc27-mggf-jwj2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hc27-mggf-jwj2", + "modified": "2025-05-13T18:30:56Z", + "published": "2025-05-13T18:30:56Z", + "aliases": [ + "CVE-2025-30377" + ], + "details": "Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30377" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-30377" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hchm-h33q-qp26/GHSA-hchm-h33q-qp26.json b/advisories/unreviewed/2025/05/GHSA-hchm-h33q-qp26/GHSA-hchm-h33q-qp26.json index 5c4b5ddd0bc..ccddf9d440b 100644 --- a/advisories/unreviewed/2025/05/GHSA-hchm-h33q-qp26/GHSA-hchm-h33q-qp26.json +++ b/advisories/unreviewed/2025/05/GHSA-hchm-h33q-qp26/GHSA-hchm-h33q-qp26.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hchm-h33q-qp26", - "modified": "2025-05-13T15:32:17Z", + "modified": "2025-05-13T18:30:52Z", "published": "2025-05-13T15:32:16Z", "aliases": [ "CVE-2025-45864" ], "details": "TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolStart parameter in the formDhcpv6s interface.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-13T15:15:58Z" diff --git a/advisories/unreviewed/2025/05/GHSA-hghc-8hvx-7rrx/GHSA-hghc-8hvx-7rrx.json b/advisories/unreviewed/2025/05/GHSA-hghc-8hvx-7rrx/GHSA-hghc-8hvx-7rrx.json index 064c7e71a46..01f46bff877 100644 --- a/advisories/unreviewed/2025/05/GHSA-hghc-8hvx-7rrx/GHSA-hghc-8hvx-7rrx.json +++ b/advisories/unreviewed/2025/05/GHSA-hghc-8hvx-7rrx/GHSA-hghc-8hvx-7rrx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hghc-8hvx-7rrx", - "modified": "2025-05-13T15:32:17Z", + "modified": "2025-05-13T18:30:51Z", "published": "2025-05-13T15:32:17Z", "aliases": [ "CVE-2025-45866" ], "details": "TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolEnd parameter in the formDhcpv6s interface.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-13T15:15:58Z" diff --git a/advisories/unreviewed/2025/05/GHSA-hhpv-c9vh-9v76/GHSA-hhpv-c9vh-9v76.json b/advisories/unreviewed/2025/05/GHSA-hhpv-c9vh-9v76/GHSA-hhpv-c9vh-9v76.json index 89465b35697..4557b3e4e40 100644 --- a/advisories/unreviewed/2025/05/GHSA-hhpv-c9vh-9v76/GHSA-hhpv-c9vh-9v76.json +++ b/advisories/unreviewed/2025/05/GHSA-hhpv-c9vh-9v76/GHSA-hhpv-c9vh-9v76.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hhpv-c9vh-9v76", - "modified": "2025-05-13T00:31:15Z", + "modified": "2025-05-13T18:30:51Z", "published": "2025-05-13T00:31:15Z", "aliases": [ "CVE-2025-31241" ], "details": "A double free issue was addressed with improved memory management. This issue is fixed in watchOS 11.5, macOS Sonoma 14.7.6, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, macOS Ventura 13.7.6. A remote attacker may cause an unexpected app termination.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-415" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:24Z" diff --git a/advisories/unreviewed/2025/05/GHSA-hj49-gv4m-x7jm/GHSA-hj49-gv4m-x7jm.json b/advisories/unreviewed/2025/05/GHSA-hj49-gv4m-x7jm/GHSA-hj49-gv4m-x7jm.json index 171de4b3b10..868b0874b10 100644 --- a/advisories/unreviewed/2025/05/GHSA-hj49-gv4m-x7jm/GHSA-hj49-gv4m-x7jm.json +++ b/advisories/unreviewed/2025/05/GHSA-hj49-gv4m-x7jm/GHSA-hj49-gv4m-x7jm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hj49-gv4m-x7jm", - "modified": "2025-05-13T00:31:13Z", + "modified": "2025-05-13T18:30:51Z", "published": "2025-05-13T00:31:13Z", "aliases": [ "CVE-2025-31213" ], "details": "A logging issue was addressed with improved data redaction. This issue is fixed in iPadOS 17.7.7, macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. An app may be able to access associated usernames and websites in a user's iCloud Keychain.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-532" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:22Z" diff --git a/advisories/unreviewed/2025/05/GHSA-hmx3-4jmc-jf5r/GHSA-hmx3-4jmc-jf5r.json b/advisories/unreviewed/2025/05/GHSA-hmx3-4jmc-jf5r/GHSA-hmx3-4jmc-jf5r.json index fe73696fd63..d796477f91b 100644 --- a/advisories/unreviewed/2025/05/GHSA-hmx3-4jmc-jf5r/GHSA-hmx3-4jmc-jf5r.json +++ b/advisories/unreviewed/2025/05/GHSA-hmx3-4jmc-jf5r/GHSA-hmx3-4jmc-jf5r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hmx3-4jmc-jf5r", - "modified": "2025-05-13T00:31:15Z", + "modified": "2025-05-13T18:30:51Z", "published": "2025-05-13T00:31:15Z", "aliases": [ "CVE-2025-31258" ], "details": "This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.5. An app may be able to break out of its sandbox.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:25Z" diff --git a/advisories/unreviewed/2025/05/GHSA-j4rr-85rg-j4q3/GHSA-j4rr-85rg-j4q3.json b/advisories/unreviewed/2025/05/GHSA-j4rr-85rg-j4q3/GHSA-j4rr-85rg-j4q3.json new file mode 100644 index 00000000000..e562b0b130c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-j4rr-85rg-j4q3/GHSA-j4rr-85rg-j4q3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j4rr-85rg-j4q3", + "modified": "2025-05-13T18:30:56Z", + "published": "2025-05-13T18:30:56Z", + "aliases": [ + "CVE-2025-30318" + ], + "details": "InDesign Desktop versions ID19.5.2, ID20.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30318" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/indesign/apsb25-37.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-j6rg-7hcj-wfx3/GHSA-j6rg-7hcj-wfx3.json b/advisories/unreviewed/2025/05/GHSA-j6rg-7hcj-wfx3/GHSA-j6rg-7hcj-wfx3.json new file mode 100644 index 00000000000..9e670df0448 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-j6rg-7hcj-wfx3/GHSA-j6rg-7hcj-wfx3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6rg-7hcj-wfx3", + "modified": "2025-05-13T18:30:53Z", + "published": "2025-05-13T18:30:53Z", + "aliases": [ + "CVE-2024-36339" + ], + "details": "A DLL hijacking vulnerability in the AMD Optimizing CPU Libraries could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36339" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-9014.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-j6rm-rh5c-35fw/GHSA-j6rm-rh5c-35fw.json b/advisories/unreviewed/2025/05/GHSA-j6rm-rh5c-35fw/GHSA-j6rm-rh5c-35fw.json new file mode 100644 index 00000000000..0f3ce01d689 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-j6rm-rh5c-35fw/GHSA-j6rm-rh5c-35fw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6rm-rh5c-35fw", + "modified": "2025-05-13T18:30:57Z", + "published": "2025-05-13T18:30:57Z", + "aliases": [ + "CVE-2025-30387" + ], + "details": "Improper limitation of a pathname to a restricted directory ('path traversal') in Azure allows an unauthorized attacker to elevate privileges over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30387" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-30387" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jfxw-jpwh-7j8j/GHSA-jfxw-jpwh-7j8j.json b/advisories/unreviewed/2025/05/GHSA-jfxw-jpwh-7j8j/GHSA-jfxw-jpwh-7j8j.json index 91ef712d5ce..7250b3160f5 100644 --- a/advisories/unreviewed/2025/05/GHSA-jfxw-jpwh-7j8j/GHSA-jfxw-jpwh-7j8j.json +++ b/advisories/unreviewed/2025/05/GHSA-jfxw-jpwh-7j8j/GHSA-jfxw-jpwh-7j8j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jfxw-jpwh-7j8j", - "modified": "2025-05-13T00:31:13Z", + "modified": "2025-05-13T18:30:51Z", "published": "2025-05-13T00:31:13Z", "aliases": [ "CVE-2025-31205" ], "details": "The issue was addressed with improved checks. This issue is fixed in watchOS 11.5, tvOS 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, Safari 18.5. A malicious website may exfiltrate data cross-origin.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:21Z" diff --git a/advisories/unreviewed/2025/05/GHSA-jmqx-9m4w-qghh/GHSA-jmqx-9m4w-qghh.json b/advisories/unreviewed/2025/05/GHSA-jmqx-9m4w-qghh/GHSA-jmqx-9m4w-qghh.json new file mode 100644 index 00000000000..aaba033871a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jmqx-9m4w-qghh/GHSA-jmqx-9m4w-qghh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jmqx-9m4w-qghh", + "modified": "2025-05-13T18:30:53Z", + "published": "2025-05-13T18:30:53Z", + "aliases": [ + "CVE-2025-27488" + ], + "details": "Use of hard-coded credentials in Windows Hardware Lab Kit allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27488" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27488" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-798" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jwq6-vvcv-h2px/GHSA-jwq6-vvcv-h2px.json b/advisories/unreviewed/2025/05/GHSA-jwq6-vvcv-h2px/GHSA-jwq6-vvcv-h2px.json new file mode 100644 index 00000000000..1440d1e6aea --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jwq6-vvcv-h2px/GHSA-jwq6-vvcv-h2px.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jwq6-vvcv-h2px", + "modified": "2025-05-13T18:30:57Z", + "published": "2025-05-13T18:30:57Z", + "aliases": [ + "CVE-2025-32709" + ], + "details": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32709" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-32709" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-m297-xg5f-f8hv/GHSA-m297-xg5f-f8hv.json b/advisories/unreviewed/2025/05/GHSA-m297-xg5f-f8hv/GHSA-m297-xg5f-f8hv.json new file mode 100644 index 00000000000..6fc2ba1f833 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-m297-xg5f-f8hv/GHSA-m297-xg5f-f8hv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m297-xg5f-f8hv", + "modified": "2025-05-13T18:30:58Z", + "published": "2025-05-13T18:30:58Z", + "aliases": [ + "CVE-2025-30328" + ], + "details": "Animate versions 24.0.8, 23.0.11 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30328" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/animate/apsb25-42.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T18:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-m49r-wcx2-5jg3/GHSA-m49r-wcx2-5jg3.json b/advisories/unreviewed/2025/05/GHSA-m49r-wcx2-5jg3/GHSA-m49r-wcx2-5jg3.json new file mode 100644 index 00000000000..df0a611f501 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-m49r-wcx2-5jg3/GHSA-m49r-wcx2-5jg3.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m49r-wcx2-5jg3", + "modified": "2025-05-13T18:30:52Z", + "published": "2025-05-13T18:30:52Z", + "aliases": [ + "CVE-2025-28056" + ], + "details": "rebuild v3.9.0 through v3.9.3 has a SQL injection vulnerability in /admin/admin-cli/exec component.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28056" + }, + { + "type": "WEB", + "url": "https://github.com/getrebuild/rebuild/issues/866" + }, + { + "type": "WEB", + "url": "https://gist.github.com/LTLTLXEY/c34dc785fc24f4cbb026e2ef3d7660c4" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T16:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-m5vp-hqc5-ggg7/GHSA-m5vp-hqc5-ggg7.json b/advisories/unreviewed/2025/05/GHSA-m5vp-hqc5-ggg7/GHSA-m5vp-hqc5-ggg7.json index b380adc34b8..b20777b731e 100644 --- a/advisories/unreviewed/2025/05/GHSA-m5vp-hqc5-ggg7/GHSA-m5vp-hqc5-ggg7.json +++ b/advisories/unreviewed/2025/05/GHSA-m5vp-hqc5-ggg7/GHSA-m5vp-hqc5-ggg7.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-mjqj-43pc-37r9/GHSA-mjqj-43pc-37r9.json b/advisories/unreviewed/2025/05/GHSA-mjqj-43pc-37r9/GHSA-mjqj-43pc-37r9.json new file mode 100644 index 00000000000..b5dfe642d7f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mjqj-43pc-37r9/GHSA-mjqj-43pc-37r9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mjqj-43pc-37r9", + "modified": "2025-05-13T18:30:54Z", + "published": "2025-05-13T18:30:54Z", + "aliases": [ + "CVE-2025-29956" + ], + "details": "Buffer over-read in Windows SMB allows an authorized attacker to disclose information over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29956" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29956" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mvcg-wm83-c67x/GHSA-mvcg-wm83-c67x.json b/advisories/unreviewed/2025/05/GHSA-mvcg-wm83-c67x/GHSA-mvcg-wm83-c67x.json new file mode 100644 index 00000000000..bbc8fd3a2e6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mvcg-wm83-c67x/GHSA-mvcg-wm83-c67x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mvcg-wm83-c67x", + "modified": "2025-05-13T18:30:56Z", + "published": "2025-05-13T18:30:56Z", + "aliases": [ + "CVE-2025-30385" + ], + "details": "Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30385" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-30385" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p9jx-jr54-2xq2/GHSA-p9jx-jr54-2xq2.json b/advisories/unreviewed/2025/05/GHSA-p9jx-jr54-2xq2/GHSA-p9jx-jr54-2xq2.json new file mode 100644 index 00000000000..cbd2a42d356 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p9jx-jr54-2xq2/GHSA-p9jx-jr54-2xq2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p9jx-jr54-2xq2", + "modified": "2025-05-13T18:30:53Z", + "published": "2025-05-13T18:30:53Z", + "aliases": [ + "CVE-2025-26677" + ], + "details": "Uncontrolled resource consumption in Remote Desktop Gateway Service allows an unauthorized attacker to deny service over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26677" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26677" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-pfwf-7j6g-wp9x/GHSA-pfwf-7j6g-wp9x.json b/advisories/unreviewed/2025/05/GHSA-pfwf-7j6g-wp9x/GHSA-pfwf-7j6g-wp9x.json new file mode 100644 index 00000000000..979360d316b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pfwf-7j6g-wp9x/GHSA-pfwf-7j6g-wp9x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pfwf-7j6g-wp9x", + "modified": "2025-05-13T18:30:58Z", + "published": "2025-05-13T18:30:58Z", + "aliases": [ + "CVE-2025-43557" + ], + "details": "Animate versions 24.0.8, 23.0.11 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43557" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/animate/apsb25-42.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-824" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T18:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-pw39-c9gh-q6gr/GHSA-pw39-c9gh-q6gr.json b/advisories/unreviewed/2025/05/GHSA-pw39-c9gh-q6gr/GHSA-pw39-c9gh-q6gr.json new file mode 100644 index 00000000000..a8941a75e24 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pw39-c9gh-q6gr/GHSA-pw39-c9gh-q6gr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pw39-c9gh-q6gr", + "modified": "2025-05-13T18:30:56Z", + "published": "2025-05-13T18:30:55Z", + "aliases": [ + "CVE-2025-29978" + ], + "details": "Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29978" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29978" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-pwv6-v269-632r/GHSA-pwv6-v269-632r.json b/advisories/unreviewed/2025/05/GHSA-pwv6-v269-632r/GHSA-pwv6-v269-632r.json index 8f5f412ed0b..3f15908a568 100644 --- a/advisories/unreviewed/2025/05/GHSA-pwv6-v269-632r/GHSA-pwv6-v269-632r.json +++ b/advisories/unreviewed/2025/05/GHSA-pwv6-v269-632r/GHSA-pwv6-v269-632r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pwv6-v269-632r", - "modified": "2025-05-13T15:32:17Z", + "modified": "2025-05-13T18:30:51Z", "published": "2025-05-13T15:32:17Z", "aliases": [ "CVE-2025-44039" ], "details": "CP-XR-DE21-S -4G Router Firmware version 1.031.022 was discovered to contain insecure protections for its UART console. This vulnerability allows local attackers to connect to the UART port via a serial connection, read all boot sequence, and revealing internal system details and sensitive information without any authentication.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-306" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-13T15:15:57Z" diff --git a/advisories/unreviewed/2025/05/GHSA-pwxw-rg6p-2vjx/GHSA-pwxw-rg6p-2vjx.json b/advisories/unreviewed/2025/05/GHSA-pwxw-rg6p-2vjx/GHSA-pwxw-rg6p-2vjx.json new file mode 100644 index 00000000000..6a720ab76cb --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pwxw-rg6p-2vjx/GHSA-pwxw-rg6p-2vjx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pwxw-rg6p-2vjx", + "modified": "2025-05-13T18:30:54Z", + "published": "2025-05-13T18:30:54Z", + "aliases": [ + "CVE-2025-29963" + ], + "details": "Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29963" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29963" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q2x2-x5wc-3cp8/GHSA-q2x2-x5wc-3cp8.json b/advisories/unreviewed/2025/05/GHSA-q2x2-x5wc-3cp8/GHSA-q2x2-x5wc-3cp8.json new file mode 100644 index 00000000000..d645eccf0c9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q2x2-x5wc-3cp8/GHSA-q2x2-x5wc-3cp8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q2x2-x5wc-3cp8", + "modified": "2025-05-13T18:30:55Z", + "published": "2025-05-13T18:30:55Z", + "aliases": [ + "CVE-2025-29979" + ], + "details": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29979" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29979" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q3wm-48q6-668m/GHSA-q3wm-48q6-668m.json b/advisories/unreviewed/2025/05/GHSA-q3wm-48q6-668m/GHSA-q3wm-48q6-668m.json new file mode 100644 index 00000000000..cb581aae508 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q3wm-48q6-668m/GHSA-q3wm-48q6-668m.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q3wm-48q6-668m", + "modified": "2025-05-13T18:30:53Z", + "published": "2025-05-13T18:30:53Z", + "aliases": [ + "CVE-2025-45857" + ], + "details": "EDIMAX CV7428NS v1.20 was discovered to contain a remote code execution (RCE) vulnerability via the command parameter in the mp function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45857" + }, + { + "type": "WEB", + "url": "https://github.com/Jiangxiazhe/IOT_hack/blob/main/EDIMAX/CV7428NS/1.md" + }, + { + "type": "WEB", + "url": "https://www.edimax.com" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T16:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q752-7x5m-gqgm/GHSA-q752-7x5m-gqgm.json b/advisories/unreviewed/2025/05/GHSA-q752-7x5m-gqgm/GHSA-q752-7x5m-gqgm.json index df63f514103..0c7336448df 100644 --- a/advisories/unreviewed/2025/05/GHSA-q752-7x5m-gqgm/GHSA-q752-7x5m-gqgm.json +++ b/advisories/unreviewed/2025/05/GHSA-q752-7x5m-gqgm/GHSA-q752-7x5m-gqgm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q752-7x5m-gqgm", - "modified": "2025-05-12T18:31:48Z", + "modified": "2025-05-13T18:30:51Z", "published": "2025-05-12T18:31:48Z", "aliases": [ "CVE-2025-44176" ], "details": "Tenda FH451 V1.0.0.9 is vulnerable to Remote Code Execution in the formSafeEmailFilter function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T18:15:45Z" diff --git a/advisories/unreviewed/2025/05/GHSA-qfj5-rcvf-98cf/GHSA-qfj5-rcvf-98cf.json b/advisories/unreviewed/2025/05/GHSA-qfj5-rcvf-98cf/GHSA-qfj5-rcvf-98cf.json new file mode 100644 index 00000000000..ac2c8c59ee3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qfj5-rcvf-98cf/GHSA-qfj5-rcvf-98cf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qfj5-rcvf-98cf", + "modified": "2025-05-13T18:30:58Z", + "published": "2025-05-13T18:30:58Z", + "aliases": [ + "CVE-2025-30329" + ], + "details": "Animate versions 24.0.8, 23.0.11 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption of service. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30329" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/animate/apsb25-42.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T18:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qm39-vp2h-cc4j/GHSA-qm39-vp2h-cc4j.json b/advisories/unreviewed/2025/05/GHSA-qm39-vp2h-cc4j/GHSA-qm39-vp2h-cc4j.json new file mode 100644 index 00000000000..069d9c5a33b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qm39-vp2h-cc4j/GHSA-qm39-vp2h-cc4j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qm39-vp2h-cc4j", + "modified": "2025-05-13T18:30:58Z", + "published": "2025-05-13T18:30:58Z", + "aliases": [ + "CVE-2025-27197" + ], + "details": "Lightroom Desktop versions 8.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27197" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/lightroom/apsb25-29.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T18:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qm3x-73px-64cm/GHSA-qm3x-73px-64cm.json b/advisories/unreviewed/2025/05/GHSA-qm3x-73px-64cm/GHSA-qm3x-73px-64cm.json new file mode 100644 index 00000000000..d88bb3c9a26 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qm3x-73px-64cm/GHSA-qm3x-73px-64cm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qm3x-73px-64cm", + "modified": "2025-05-13T18:30:56Z", + "published": "2025-05-13T18:30:56Z", + "aliases": [ + "CVE-2025-30379" + ], + "details": "Release of invalid pointer or reference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30379" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-30379" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-763" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qqcr-9jfc-35c4/GHSA-qqcr-9jfc-35c4.json b/advisories/unreviewed/2025/05/GHSA-qqcr-9jfc-35c4/GHSA-qqcr-9jfc-35c4.json new file mode 100644 index 00000000000..33991f720f3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qqcr-9jfc-35c4/GHSA-qqcr-9jfc-35c4.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qqcr-9jfc-35c4", + "modified": "2025-05-13T18:30:52Z", + "published": "2025-05-13T18:30:52Z", + "aliases": [ + "CVE-2024-56526" + ], + "details": "An issue was discovered in OXID eShop before 7. CMS pages in combination with Smarty may display user information if a CMS page contains a Smarty syntax error.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56526" + }, + { + "type": "WEB", + "url": "https://bugs.oxid-esales.com/view.php?id=7743" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qw9p-xh57-vvwj/GHSA-qw9p-xh57-vvwj.json b/advisories/unreviewed/2025/05/GHSA-qw9p-xh57-vvwj/GHSA-qw9p-xh57-vvwj.json new file mode 100644 index 00000000000..784729cd545 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qw9p-xh57-vvwj/GHSA-qw9p-xh57-vvwj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qw9p-xh57-vvwj", + "modified": "2025-05-13T18:30:55Z", + "published": "2025-05-13T18:30:55Z", + "aliases": [ + "CVE-2025-29974" + ], + "details": "Integer underflow (wrap or wraparound) in Windows Kernel allows an unauthorized attacker to disclose information over an adjacent network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29974" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29974" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qxp8-q6wp-7mq2/GHSA-qxp8-q6wp-7mq2.json b/advisories/unreviewed/2025/05/GHSA-qxp8-q6wp-7mq2/GHSA-qxp8-q6wp-7mq2.json index b292c4ed69a..164b436bfc2 100644 --- a/advisories/unreviewed/2025/05/GHSA-qxp8-q6wp-7mq2/GHSA-qxp8-q6wp-7mq2.json +++ b/advisories/unreviewed/2025/05/GHSA-qxp8-q6wp-7mq2/GHSA-qxp8-q6wp-7mq2.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-r7hj-5f27-q8xw/GHSA-r7hj-5f27-q8xw.json b/advisories/unreviewed/2025/05/GHSA-r7hj-5f27-q8xw/GHSA-r7hj-5f27-q8xw.json new file mode 100644 index 00000000000..4a8afb864ce --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-r7hj-5f27-q8xw/GHSA-r7hj-5f27-q8xw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r7hj-5f27-q8xw", + "modified": "2025-05-13T18:30:57Z", + "published": "2025-05-13T18:30:57Z", + "aliases": [ + "CVE-2025-30397" + ], + "details": "Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30397" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-30397" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-843" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rc73-qvhv-5j87/GHSA-rc73-qvhv-5j87.json b/advisories/unreviewed/2025/05/GHSA-rc73-qvhv-5j87/GHSA-rc73-qvhv-5j87.json new file mode 100644 index 00000000000..17db8615425 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rc73-qvhv-5j87/GHSA-rc73-qvhv-5j87.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rc73-qvhv-5j87", + "modified": "2025-05-13T18:30:56Z", + "published": "2025-05-13T18:30:56Z", + "aliases": [ + "CVE-2025-30378" + ], + "details": "Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30378" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-30378" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rgp7-w7cx-xxg6/GHSA-rgp7-w7cx-xxg6.json b/advisories/unreviewed/2025/05/GHSA-rgp7-w7cx-xxg6/GHSA-rgp7-w7cx-xxg6.json new file mode 100644 index 00000000000..bb2e6f81ac2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rgp7-w7cx-xxg6/GHSA-rgp7-w7cx-xxg6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rgp7-w7cx-xxg6", + "modified": "2025-05-13T18:30:53Z", + "published": "2025-05-13T18:30:53Z", + "aliases": [ + "CVE-2024-21960" + ], + "details": "Incorrect default permissions in the AMD Optimizing CPU Libraries (AOCL) installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21960" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-9014.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rgq9-rg7j-xm4x/GHSA-rgq9-rg7j-xm4x.json b/advisories/unreviewed/2025/05/GHSA-rgq9-rg7j-xm4x/GHSA-rgq9-rg7j-xm4x.json index 0d036e2f641..12b32aef0c9 100644 --- a/advisories/unreviewed/2025/05/GHSA-rgq9-rg7j-xm4x/GHSA-rgq9-rg7j-xm4x.json +++ b/advisories/unreviewed/2025/05/GHSA-rgq9-rg7j-xm4x/GHSA-rgq9-rg7j-xm4x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rgq9-rg7j-xm4x", - "modified": "2025-05-13T03:31:14Z", + "modified": "2025-05-13T18:30:51Z", "published": "2025-05-13T03:31:14Z", "aliases": [ "CVE-2025-42999" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://me.sap.com/notes/3604119" }, + { + "type": "WEB", + "url": "https://onapsis.com/blog/active-exploitation-of-sap-vulnerability-cve-2025-31324" + }, { "type": "WEB", "url": "https://url.sap/sapsecuritypatchday" diff --git a/advisories/unreviewed/2025/05/GHSA-rgrg-qwpp-28j8/GHSA-rgrg-qwpp-28j8.json b/advisories/unreviewed/2025/05/GHSA-rgrg-qwpp-28j8/GHSA-rgrg-qwpp-28j8.json new file mode 100644 index 00000000000..bbe29f22c21 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rgrg-qwpp-28j8/GHSA-rgrg-qwpp-28j8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rgrg-qwpp-28j8", + "modified": "2025-05-13T18:30:54Z", + "published": "2025-05-13T18:30:54Z", + "aliases": [ + "CVE-2025-29957" + ], + "details": "Uncontrolled resource consumption in Windows Deployment Services allows an unauthorized attacker to deny service locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29957" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29957" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rmx6-3w23-whmj/GHSA-rmx6-3w23-whmj.json b/advisories/unreviewed/2025/05/GHSA-rmx6-3w23-whmj/GHSA-rmx6-3w23-whmj.json new file mode 100644 index 00000000000..342e003775a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rmx6-3w23-whmj/GHSA-rmx6-3w23-whmj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rmx6-3w23-whmj", + "modified": "2025-05-13T18:30:53Z", + "published": "2025-05-13T18:30:53Z", + "aliases": [ + "CVE-2024-6364" + ], + "details": "A vulnerability in Absolute Persistence® versions before 2.8 exists when it is not activated. This may allow a skilled attacker with both physical access to the device, and full hostile network control, to initiate OS commands on the device. To remediate this vulnerability, update the device firmware to the latest available version. Please contact the device manufacturer for upgrade instructions or contact Absolute Security, see reference below.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:P/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6364" + }, + { + "type": "WEB", + "url": "https://www.absolute.com/platform/vulnerability-archive/cve-2024-6364" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rq2m-phmg-c2mq/GHSA-rq2m-phmg-c2mq.json b/advisories/unreviewed/2025/05/GHSA-rq2m-phmg-c2mq/GHSA-rq2m-phmg-c2mq.json new file mode 100644 index 00000000000..c59ae3d6c88 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rq2m-phmg-c2mq/GHSA-rq2m-phmg-c2mq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rq2m-phmg-c2mq", + "modified": "2025-05-13T18:30:54Z", + "published": "2025-05-13T18:30:54Z", + "aliases": [ + "CVE-2025-29832" + ], + "details": "Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29832" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29832" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rr7h-9jrx-7pvf/GHSA-rr7h-9jrx-7pvf.json b/advisories/unreviewed/2025/05/GHSA-rr7h-9jrx-7pvf/GHSA-rr7h-9jrx-7pvf.json new file mode 100644 index 00000000000..46ec5aaea17 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rr7h-9jrx-7pvf/GHSA-rr7h-9jrx-7pvf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rr7h-9jrx-7pvf", + "modified": "2025-05-13T18:30:57Z", + "published": "2025-05-13T18:30:57Z", + "aliases": [ + "CVE-2025-32702" + ], + "details": "Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an unauthorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32702" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-32702" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v3p9-8pg7-47cq/GHSA-v3p9-8pg7-47cq.json b/advisories/unreviewed/2025/05/GHSA-v3p9-8pg7-47cq/GHSA-v3p9-8pg7-47cq.json new file mode 100644 index 00000000000..bb42238d079 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v3p9-8pg7-47cq/GHSA-v3p9-8pg7-47cq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v3p9-8pg7-47cq", + "modified": "2025-05-13T18:30:53Z", + "published": "2025-05-13T18:30:53Z", + "aliases": [ + "CVE-2025-0035" + ], + "details": "Unquoted search path within AMD Cloud Manageability Service can allow a local attacker to escalate privileges, potentially resulting in arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0035" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-9015.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-428" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v3r8-whq5-7fhg/GHSA-v3r8-whq5-7fhg.json b/advisories/unreviewed/2025/05/GHSA-v3r8-whq5-7fhg/GHSA-v3r8-whq5-7fhg.json new file mode 100644 index 00000000000..b42f788addd --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v3r8-whq5-7fhg/GHSA-v3r8-whq5-7fhg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v3r8-whq5-7fhg", + "modified": "2025-05-13T18:30:58Z", + "published": "2025-05-13T18:30:58Z", + "aliases": [ + "CVE-2025-30326" + ], + "details": "Photoshop Desktop versions 26.5, 25.12.2 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30326" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/photoshop/apsb25-40.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-824" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T18:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v487-rh87-cwxh/GHSA-v487-rh87-cwxh.json b/advisories/unreviewed/2025/05/GHSA-v487-rh87-cwxh/GHSA-v487-rh87-cwxh.json new file mode 100644 index 00000000000..0a232c1a9b7 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v487-rh87-cwxh/GHSA-v487-rh87-cwxh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v487-rh87-cwxh", + "modified": "2025-05-13T18:30:54Z", + "published": "2025-05-13T18:30:54Z", + "aliases": [ + "CVE-2025-29955" + ], + "details": "Improper input validation in Windows Hyper-V allows an unauthorized attacker to deny service locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29955" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29955" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v54c-h56f-jw8m/GHSA-v54c-h56f-jw8m.json b/advisories/unreviewed/2025/05/GHSA-v54c-h56f-jw8m/GHSA-v54c-h56f-jw8m.json new file mode 100644 index 00000000000..63d024bf8aa --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v54c-h56f-jw8m/GHSA-v54c-h56f-jw8m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v54c-h56f-jw8m", + "modified": "2025-05-13T18:30:54Z", + "published": "2025-05-13T18:30:54Z", + "aliases": [ + "CVE-2025-29833" + ], + "details": "Time-of-check time-of-use (toctou) race condition in Windows Virtual Machine Bus allows an authorized attacker to execute code over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29833" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29833" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v5r4-h46j-mc2j/GHSA-v5r4-h46j-mc2j.json b/advisories/unreviewed/2025/05/GHSA-v5r4-h46j-mc2j/GHSA-v5r4-h46j-mc2j.json new file mode 100644 index 00000000000..26a25a63c18 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v5r4-h46j-mc2j/GHSA-v5r4-h46j-mc2j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v5r4-h46j-mc2j", + "modified": "2025-05-13T18:30:57Z", + "published": "2025-05-13T18:30:57Z", + "aliases": [ + "CVE-2025-30393" + ], + "details": "Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30393" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-30393" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v8c3-r2xf-ghv6/GHSA-v8c3-r2xf-ghv6.json b/advisories/unreviewed/2025/05/GHSA-v8c3-r2xf-ghv6/GHSA-v8c3-r2xf-ghv6.json new file mode 100644 index 00000000000..5437ecfc899 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v8c3-r2xf-ghv6/GHSA-v8c3-r2xf-ghv6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v8c3-r2xf-ghv6", + "modified": "2025-05-13T18:30:58Z", + "published": "2025-05-13T18:30:58Z", + "aliases": [ + "CVE-2023-31358" + ], + "details": "A DLL hijacking vulnerability in the AMD Manageability API could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31358" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-9015.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T18:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vfg9-gh45-wrq2/GHSA-vfg9-gh45-wrq2.json b/advisories/unreviewed/2025/05/GHSA-vfg9-gh45-wrq2/GHSA-vfg9-gh45-wrq2.json new file mode 100644 index 00000000000..3bcf6bca90f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vfg9-gh45-wrq2/GHSA-vfg9-gh45-wrq2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vfg9-gh45-wrq2", + "modified": "2025-05-13T18:30:54Z", + "published": "2025-05-13T18:30:54Z", + "aliases": [ + "CVE-2025-29954" + ], + "details": "Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29954" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29954" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vm4g-9v9f-c5x3/GHSA-vm4g-9v9f-c5x3.json b/advisories/unreviewed/2025/05/GHSA-vm4g-9v9f-c5x3/GHSA-vm4g-9v9f-c5x3.json new file mode 100644 index 00000000000..74695395ef9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vm4g-9v9f-c5x3/GHSA-vm4g-9v9f-c5x3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vm4g-9v9f-c5x3", + "modified": "2025-05-13T18:30:55Z", + "published": "2025-05-13T18:30:55Z", + "aliases": [ + "CVE-2025-29964" + ], + "details": "Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29964" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29964" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vvr8-g6jj-jwrw/GHSA-vvr8-g6jj-jwrw.json b/advisories/unreviewed/2025/05/GHSA-vvr8-g6jj-jwrw/GHSA-vvr8-g6jj-jwrw.json new file mode 100644 index 00000000000..3dcc0c6605f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vvr8-g6jj-jwrw/GHSA-vvr8-g6jj-jwrw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vvr8-g6jj-jwrw", + "modified": "2025-05-13T18:30:57Z", + "published": "2025-05-13T18:30:57Z", + "aliases": [ + "CVE-2025-30400" + ], + "details": "Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30400" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-30400" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w2cm-pc9j-3m28/GHSA-w2cm-pc9j-3m28.json b/advisories/unreviewed/2025/05/GHSA-w2cm-pc9j-3m28/GHSA-w2cm-pc9j-3m28.json new file mode 100644 index 00000000000..9b9969d8695 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w2cm-pc9j-3m28/GHSA-w2cm-pc9j-3m28.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w2cm-pc9j-3m28", + "modified": "2025-05-13T18:30:53Z", + "published": "2025-05-13T18:30:53Z", + "aliases": [ + "CVE-2025-29826" + ], + "details": "Improper handling of insufficient permissions or privileges in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29826" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29826" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-280" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w988-x7hh-qmg5/GHSA-w988-x7hh-qmg5.json b/advisories/unreviewed/2025/05/GHSA-w988-x7hh-qmg5/GHSA-w988-x7hh-qmg5.json index 685a038af0a..c70c52f63cc 100644 --- a/advisories/unreviewed/2025/05/GHSA-w988-x7hh-qmg5/GHSA-w988-x7hh-qmg5.json +++ b/advisories/unreviewed/2025/05/GHSA-w988-x7hh-qmg5/GHSA-w988-x7hh-qmg5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w988-x7hh-qmg5", - "modified": "2025-05-03T03:30:28Z", + "modified": "2025-05-13T18:30:48Z", "published": "2025-05-03T03:30:28Z", "aliases": [ "CVE-2025-4222" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://plugins.trac.wordpress.org/browser/database-toolset/trunk/admin/class-database-toolset-backup.php#L76" }, + { + "type": "WEB", + "url": "https://www.guyshavit.com/post/cve-2025-4222" + }, { "type": "WEB", "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/fa452a9a-9e26-41a1-8dea-4bafaf735bee?source=cve" diff --git a/advisories/unreviewed/2025/05/GHSA-wfjv-29vm-jrfq/GHSA-wfjv-29vm-jrfq.json b/advisories/unreviewed/2025/05/GHSA-wfjv-29vm-jrfq/GHSA-wfjv-29vm-jrfq.json index 4aebce0d355..cd9cc1a5351 100644 --- a/advisories/unreviewed/2025/05/GHSA-wfjv-29vm-jrfq/GHSA-wfjv-29vm-jrfq.json +++ b/advisories/unreviewed/2025/05/GHSA-wfjv-29vm-jrfq/GHSA-wfjv-29vm-jrfq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wfjv-29vm-jrfq", - "modified": "2025-05-13T15:32:17Z", + "modified": "2025-05-13T18:30:51Z", "published": "2025-05-13T15:32:17Z", "aliases": [ "CVE-2025-45859" ], "details": "TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the bandstr parameter in the formMapDelDevice interface.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-13T15:15:58Z" diff --git a/advisories/unreviewed/2025/05/GHSA-xcxf-w65q-73xg/GHSA-xcxf-w65q-73xg.json b/advisories/unreviewed/2025/05/GHSA-xcxf-w65q-73xg/GHSA-xcxf-w65q-73xg.json new file mode 100644 index 00000000000..21324ea510a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xcxf-w65q-73xg/GHSA-xcxf-w65q-73xg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xcxf-w65q-73xg", + "modified": "2025-05-13T18:30:54Z", + "published": "2025-05-13T18:30:54Z", + "aliases": [ + "CVE-2025-29960" + ], + "details": "Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29960" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29960" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xh92-vqm9-v66r/GHSA-xh92-vqm9-v66r.json b/advisories/unreviewed/2025/05/GHSA-xh92-vqm9-v66r/GHSA-xh92-vqm9-v66r.json new file mode 100644 index 00000000000..244458fdd5f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xh92-vqm9-v66r/GHSA-xh92-vqm9-v66r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xh92-vqm9-v66r", + "modified": "2025-05-13T18:30:54Z", + "published": "2025-05-13T18:30:54Z", + "aliases": [ + "CVE-2025-29840" + ], + "details": "Stack-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29840" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29840" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xhg9-hf6j-8vpj/GHSA-xhg9-hf6j-8vpj.json b/advisories/unreviewed/2025/05/GHSA-xhg9-hf6j-8vpj/GHSA-xhg9-hf6j-8vpj.json new file mode 100644 index 00000000000..965b456c2ef --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xhg9-hf6j-8vpj/GHSA-xhg9-hf6j-8vpj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xhg9-hf6j-8vpj", + "modified": "2025-05-13T18:30:54Z", + "published": "2025-05-13T18:30:54Z", + "aliases": [ + "CVE-2025-29837" + ], + "details": "Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to disclose information locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29837" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29837" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xq63-2jcc-9gm3/GHSA-xq63-2jcc-9gm3.json b/advisories/unreviewed/2025/05/GHSA-xq63-2jcc-9gm3/GHSA-xq63-2jcc-9gm3.json index dc319c0000d..ee304cda0b6 100644 --- a/advisories/unreviewed/2025/05/GHSA-xq63-2jcc-9gm3/GHSA-xq63-2jcc-9gm3.json +++ b/advisories/unreviewed/2025/05/GHSA-xq63-2jcc-9gm3/GHSA-xq63-2jcc-9gm3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xq63-2jcc-9gm3", - "modified": "2025-05-13T00:31:12Z", + "modified": "2025-05-13T18:30:51Z", "published": "2025-05-13T00:31:12Z", "aliases": [ "CVE-2025-24258" ], "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Ventura 13.7.6, macOS Sonoma 14.7.6. An app may be able to gain root privileges.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:20Z" diff --git a/advisories/unreviewed/2025/05/GHSA-xq8j-rprv-xmq6/GHSA-xq8j-rprv-xmq6.json b/advisories/unreviewed/2025/05/GHSA-xq8j-rprv-xmq6/GHSA-xq8j-rprv-xmq6.json index 7043d799060..bc67dd492bc 100644 --- a/advisories/unreviewed/2025/05/GHSA-xq8j-rprv-xmq6/GHSA-xq8j-rprv-xmq6.json +++ b/advisories/unreviewed/2025/05/GHSA-xq8j-rprv-xmq6/GHSA-xq8j-rprv-xmq6.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-77" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-xrjq-mmx8-72h6/GHSA-xrjq-mmx8-72h6.json b/advisories/unreviewed/2025/05/GHSA-xrjq-mmx8-72h6/GHSA-xrjq-mmx8-72h6.json new file mode 100644 index 00000000000..5f3c80c7fba --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xrjq-mmx8-72h6/GHSA-xrjq-mmx8-72h6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xrjq-mmx8-72h6", + "modified": "2025-05-13T18:30:53Z", + "published": "2025-05-13T18:30:53Z", + "aliases": [ + "CVE-2025-26684" + ], + "details": "External control of file name or path in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26684" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26684" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-73" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xvfx-x2hm-pgf5/GHSA-xvfx-x2hm-pgf5.json b/advisories/unreviewed/2025/05/GHSA-xvfx-x2hm-pgf5/GHSA-xvfx-x2hm-pgf5.json new file mode 100644 index 00000000000..501466fba06 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xvfx-x2hm-pgf5/GHSA-xvfx-x2hm-pgf5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xvfx-x2hm-pgf5", + "modified": "2025-05-13T18:30:55Z", + "published": "2025-05-13T18:30:55Z", + "aliases": [ + "CVE-2025-29968" + ], + "details": "Improper input validation in Active Directory Certificate Services (AD CS) allows an authorized attacker to deny service over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29968" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29968" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xxg3-955j-2rj3/GHSA-xxg3-955j-2rj3.json b/advisories/unreviewed/2025/05/GHSA-xxg3-955j-2rj3/GHSA-xxg3-955j-2rj3.json new file mode 100644 index 00000000000..ecaffd7b684 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xxg3-955j-2rj3/GHSA-xxg3-955j-2rj3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xxg3-955j-2rj3", + "modified": "2025-05-13T18:30:54Z", + "published": "2025-05-13T18:30:54Z", + "aliases": [ + "CVE-2025-29835" + ], + "details": "Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29835" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29835" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T17:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xxxc-2fjg-mprw/GHSA-xxxc-2fjg-mprw.json b/advisories/unreviewed/2025/05/GHSA-xxxc-2fjg-mprw/GHSA-xxxc-2fjg-mprw.json new file mode 100644 index 00000000000..adf13b10c10 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xxxc-2fjg-mprw/GHSA-xxxc-2fjg-mprw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xxxc-2fjg-mprw", + "modified": "2025-05-13T18:30:59Z", + "published": "2025-05-13T18:30:58Z", + "aliases": [ + "CVE-2025-43555" + ], + "details": "Animate versions 24.0.8, 23.0.11 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43555" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/animate/apsb25-42.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-191" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T18:15:40Z" + } +} \ No newline at end of file