diff --git a/advisories/unreviewed/2022/01/GHSA-2f7f-fmwq-p66j/GHSA-2f7f-fmwq-p66j.json b/advisories/unreviewed/2022/01/GHSA-2f7f-fmwq-p66j/GHSA-2f7f-fmwq-p66j.json index d8a85a17008..9b465780992 100644 --- a/advisories/unreviewed/2022/01/GHSA-2f7f-fmwq-p66j/GHSA-2f7f-fmwq-p66j.json +++ b/advisories/unreviewed/2022/01/GHSA-2f7f-fmwq-p66j/GHSA-2f7f-fmwq-p66j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2f7f-fmwq-p66j", - "modified": "2023-08-08T15:31:30Z", + "modified": "2025-05-22T21:30:32Z", "published": "2022-01-04T00:00:33Z", "aliases": [ "CVE-2021-37133" diff --git a/advisories/unreviewed/2022/01/GHSA-45mw-x2rr-9wpc/GHSA-45mw-x2rr-9wpc.json b/advisories/unreviewed/2022/01/GHSA-45mw-x2rr-9wpc/GHSA-45mw-x2rr-9wpc.json index 47d7d1f464c..426e519c1c4 100644 --- a/advisories/unreviewed/2022/01/GHSA-45mw-x2rr-9wpc/GHSA-45mw-x2rr-9wpc.json +++ b/advisories/unreviewed/2022/01/GHSA-45mw-x2rr-9wpc/GHSA-45mw-x2rr-9wpc.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/01/GHSA-6vf7-35mx-fxf5/GHSA-6vf7-35mx-fxf5.json b/advisories/unreviewed/2022/01/GHSA-6vf7-35mx-fxf5/GHSA-6vf7-35mx-fxf5.json index b5f92fdd26c..86c812dbc2a 100644 --- a/advisories/unreviewed/2022/01/GHSA-6vf7-35mx-fxf5/GHSA-6vf7-35mx-fxf5.json +++ b/advisories/unreviewed/2022/01/GHSA-6vf7-35mx-fxf5/GHSA-6vf7-35mx-fxf5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6vf7-35mx-fxf5", - "modified": "2022-01-15T00:03:41Z", + "modified": "2025-05-22T21:30:32Z", "published": "2022-01-04T00:00:24Z", "aliases": [ "CVE-2021-39985" ], "details": "The HwNearbyMain module has a Improper Validation of Array Index vulnerability.Successful exploitation of this vulnerability may cause a process to restart.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/01/GHSA-89m3-rrvf-rq86/GHSA-89m3-rrvf-rq86.json b/advisories/unreviewed/2022/01/GHSA-89m3-rrvf-rq86/GHSA-89m3-rrvf-rq86.json index 0e42ab8ef59..e313db79fb0 100644 --- a/advisories/unreviewed/2022/01/GHSA-89m3-rrvf-rq86/GHSA-89m3-rrvf-rq86.json +++ b/advisories/unreviewed/2022/01/GHSA-89m3-rrvf-rq86/GHSA-89m3-rrvf-rq86.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-89m3-rrvf-rq86", - "modified": "2022-01-15T00:03:40Z", + "modified": "2025-05-22T21:30:33Z", "published": "2022-01-04T00:00:22Z", "aliases": [ "CVE-2021-39990" ], "details": "The screen lock module has a Stack-based Buffer Overflow vulnerability.Successful exploitation of this vulnerability may affect user experience.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/01/GHSA-8vhf-539p-8g5m/GHSA-8vhf-539p-8g5m.json b/advisories/unreviewed/2022/01/GHSA-8vhf-539p-8g5m/GHSA-8vhf-539p-8g5m.json index 427dc0309a6..012a7e5d66b 100644 --- a/advisories/unreviewed/2022/01/GHSA-8vhf-539p-8g5m/GHSA-8vhf-539p-8g5m.json +++ b/advisories/unreviewed/2022/01/GHSA-8vhf-539p-8g5m/GHSA-8vhf-539p-8g5m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8vhf-539p-8g5m", - "modified": "2022-01-14T00:03:16Z", + "modified": "2025-05-22T21:30:32Z", "published": "2022-01-04T00:00:23Z", "aliases": [ "CVE-2021-39984" ], "details": "Huawei idap module has a Out-of-bounds Read vulnerability.Successful exploitation of this vulnerability may cause Denial of Service.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/01/GHSA-c5qg-72q9-j764/GHSA-c5qg-72q9-j764.json b/advisories/unreviewed/2022/01/GHSA-c5qg-72q9-j764/GHSA-c5qg-72q9-j764.json index 5393a79e94e..4cfd86863e7 100644 --- a/advisories/unreviewed/2022/01/GHSA-c5qg-72q9-j764/GHSA-c5qg-72q9-j764.json +++ b/advisories/unreviewed/2022/01/GHSA-c5qg-72q9-j764/GHSA-c5qg-72q9-j764.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c5qg-72q9-j764", - "modified": "2022-01-14T00:03:23Z", + "modified": "2025-05-22T21:30:32Z", "published": "2022-01-04T00:00:27Z", "aliases": [ "CVE-2021-39967" ], "details": "There is a Vulnerability of obtaining broadcast information improperly due to improper broadcast permission settings in Smartphones.Successful exploitation of this vulnerability may affect service confidentiality.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/01/GHSA-fg4h-vrcg-56rq/GHSA-fg4h-vrcg-56rq.json b/advisories/unreviewed/2022/01/GHSA-fg4h-vrcg-56rq/GHSA-fg4h-vrcg-56rq.json index b3f5ef97d6b..c4a5f5a5105 100644 --- a/advisories/unreviewed/2022/01/GHSA-fg4h-vrcg-56rq/GHSA-fg4h-vrcg-56rq.json +++ b/advisories/unreviewed/2022/01/GHSA-fg4h-vrcg-56rq/GHSA-fg4h-vrcg-56rq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fg4h-vrcg-56rq", - "modified": "2022-01-09T00:00:24Z", + "modified": "2025-05-22T21:30:31Z", "published": "2022-01-04T00:00:51Z", "aliases": [ "CVE-2021-24964" ], "details": "The LiteSpeed Cache WordPress plugin before 4.4.4 does not properly verify that requests are coming from QUIC.cloud servers, allowing attackers to make requests to certain endpoints by using a specific X-Forwarded-For header value. In addition, one of the endpoint could be used to set CSS code if a setting is enabled, which will then be output in some pages without being sanitised and escaped. Combining those two issues, an unauthenticated attacker could put Cross-Site Scripting payloads in pages visited by users.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/01/GHSA-fhq9-4r6p-rfm7/GHSA-fhq9-4r6p-rfm7.json b/advisories/unreviewed/2022/01/GHSA-fhq9-4r6p-rfm7/GHSA-fhq9-4r6p-rfm7.json index 75d2c84f858..b6c0ef8889e 100644 --- a/advisories/unreviewed/2022/01/GHSA-fhq9-4r6p-rfm7/GHSA-fhq9-4r6p-rfm7.json +++ b/advisories/unreviewed/2022/01/GHSA-fhq9-4r6p-rfm7/GHSA-fhq9-4r6p-rfm7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fhq9-4r6p-rfm7", - "modified": "2022-01-15T00:03:41Z", + "modified": "2025-05-22T21:30:33Z", "published": "2022-01-04T00:00:23Z", "aliases": [ "CVE-2021-39988" ], "details": "The HwNearbyMain module has a NULL Pointer Dereference vulnerability.Successful exploitation of this vulnerability may cause a process to restart.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/01/GHSA-gg45-6m56-hjqc/GHSA-gg45-6m56-hjqc.json b/advisories/unreviewed/2022/01/GHSA-gg45-6m56-hjqc/GHSA-gg45-6m56-hjqc.json index 439eec4aab0..63cc07b1c9d 100644 --- a/advisories/unreviewed/2022/01/GHSA-gg45-6m56-hjqc/GHSA-gg45-6m56-hjqc.json +++ b/advisories/unreviewed/2022/01/GHSA-gg45-6m56-hjqc/GHSA-gg45-6m56-hjqc.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-20" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/01/GHSA-hfmq-f7g7-4h39/GHSA-hfmq-f7g7-4h39.json b/advisories/unreviewed/2022/01/GHSA-hfmq-f7g7-4h39/GHSA-hfmq-f7g7-4h39.json index 92f5b69e46a..60486e7adfd 100644 --- a/advisories/unreviewed/2022/01/GHSA-hfmq-f7g7-4h39/GHSA-hfmq-f7g7-4h39.json +++ b/advisories/unreviewed/2022/01/GHSA-hfmq-f7g7-4h39/GHSA-hfmq-f7g7-4h39.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hfmq-f7g7-4h39", - "modified": "2022-01-14T00:03:16Z", + "modified": "2025-05-22T21:30:32Z", "published": "2022-01-04T00:00:23Z", "aliases": [ "CVE-2021-39983" ], "details": "The HwNearbyMain module has a Data Processing Errors vulnerability.Successful exploitation of this vulnerability may cause a process to restart.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/01/GHSA-jjh4-9fxq-rj65/GHSA-jjh4-9fxq-rj65.json b/advisories/unreviewed/2022/01/GHSA-jjh4-9fxq-rj65/GHSA-jjh4-9fxq-rj65.json index 65a6881ab64..7dd99a02845 100644 --- a/advisories/unreviewed/2022/01/GHSA-jjh4-9fxq-rj65/GHSA-jjh4-9fxq-rj65.json +++ b/advisories/unreviewed/2022/01/GHSA-jjh4-9fxq-rj65/GHSA-jjh4-9fxq-rj65.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jjh4-9fxq-rj65", - "modified": "2022-01-09T00:00:23Z", + "modified": "2025-05-22T21:30:31Z", "published": "2022-01-04T00:00:47Z", "aliases": [ "CVE-2021-25022" ], "details": "The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.66 does not sanitise and escape the backup_timestamp and job_id parameter before outputting then back in admin pages, leading to Reflected Cross-Site Scripting issues", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/01/GHSA-jv32-h4vh-qfxx/GHSA-jv32-h4vh-qfxx.json b/advisories/unreviewed/2022/01/GHSA-jv32-h4vh-qfxx/GHSA-jv32-h4vh-qfxx.json index c75e047e377..da161ec9ec4 100644 --- a/advisories/unreviewed/2022/01/GHSA-jv32-h4vh-qfxx/GHSA-jv32-h4vh-qfxx.json +++ b/advisories/unreviewed/2022/01/GHSA-jv32-h4vh-qfxx/GHSA-jv32-h4vh-qfxx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jv32-h4vh-qfxx", - "modified": "2022-01-15T00:03:40Z", + "modified": "2025-05-22T21:30:33Z", "published": "2022-01-04T00:00:22Z", "aliases": [ "CVE-2021-39989" ], "details": "The HwNearbyMain module has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability.Successful exploitation of this vulnerability may cause a process to restart.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/01/GHSA-mp5j-h5hx-cfxc/GHSA-mp5j-h5hx-cfxc.json b/advisories/unreviewed/2022/01/GHSA-mp5j-h5hx-cfxc/GHSA-mp5j-h5hx-cfxc.json index 14f49c466a7..228f5a0db45 100644 --- a/advisories/unreviewed/2022/01/GHSA-mp5j-h5hx-cfxc/GHSA-mp5j-h5hx-cfxc.json +++ b/advisories/unreviewed/2022/01/GHSA-mp5j-h5hx-cfxc/GHSA-mp5j-h5hx-cfxc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mp5j-h5hx-cfxc", - "modified": "2022-01-15T00:03:39Z", + "modified": "2025-05-22T21:30:33Z", "published": "2022-01-05T00:00:56Z", "aliases": [ "CVE-2021-24042" ], "details": "The calling logic for WhatsApp for Android prior to v2.21.23, WhatsApp Business for Android prior to v2.21.23, WhatsApp for iOS prior to v2.21.230, WhatsApp Business for iOS prior to v2.21.230, WhatsApp for KaiOS prior to v2.2143, WhatsApp Desktop prior to v2.2146 could have allowed an out-of-bounds write if a user makes a 1:1 call to a malicious actor.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -21,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-122", "CWE-787" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2022/01/GHSA-qcc4-gjx4-jhph/GHSA-qcc4-gjx4-jhph.json b/advisories/unreviewed/2022/01/GHSA-qcc4-gjx4-jhph/GHSA-qcc4-gjx4-jhph.json index e9a441fd6d6..7a388aef73b 100644 --- a/advisories/unreviewed/2022/01/GHSA-qcc4-gjx4-jhph/GHSA-qcc4-gjx4-jhph.json +++ b/advisories/unreviewed/2022/01/GHSA-qcc4-gjx4-jhph/GHSA-qcc4-gjx4-jhph.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qcc4-gjx4-jhph", - "modified": "2022-01-14T00:03:19Z", + "modified": "2025-05-22T21:30:32Z", "published": "2022-01-04T00:00:25Z", "aliases": [ "CVE-2021-39977" ], "details": "The HwNearbyMain module has a NULL Pointer Dereference vulnerability.Successful exploitation of this vulnerability may cause a process to restart.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/01/GHSA-w67x-387h-w6cm/GHSA-w67x-387h-w6cm.json b/advisories/unreviewed/2022/01/GHSA-w67x-387h-w6cm/GHSA-w67x-387h-w6cm.json index 7f67d62e2ff..c33a9d1e112 100644 --- a/advisories/unreviewed/2022/01/GHSA-w67x-387h-w6cm/GHSA-w67x-387h-w6cm.json +++ b/advisories/unreviewed/2022/01/GHSA-w67x-387h-w6cm/GHSA-w67x-387h-w6cm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w67x-387h-w6cm", - "modified": "2022-01-12T00:01:51Z", + "modified": "2025-05-22T21:30:31Z", "published": "2022-01-04T00:01:07Z", "aliases": [ "CVE-2021-1918" ], "details": "Improper handling of resource allocation in virtual machines can lead to information exposure in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/01/GHSA-w6w3-wf72-pc3c/GHSA-w6w3-wf72-pc3c.json b/advisories/unreviewed/2022/01/GHSA-w6w3-wf72-pc3c/GHSA-w6w3-wf72-pc3c.json index d71bed39d1d..e9fd834caa6 100644 --- a/advisories/unreviewed/2022/01/GHSA-w6w3-wf72-pc3c/GHSA-w6w3-wf72-pc3c.json +++ b/advisories/unreviewed/2022/01/GHSA-w6w3-wf72-pc3c/GHSA-w6w3-wf72-pc3c.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-404" + "CWE-404", + "CWE-770" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/01/GHSA-x98r-f5pv-92p5/GHSA-x98r-f5pv-92p5.json b/advisories/unreviewed/2022/01/GHSA-x98r-f5pv-92p5/GHSA-x98r-f5pv-92p5.json index 53ee153ce53..203e4bf17f1 100644 --- a/advisories/unreviewed/2022/01/GHSA-x98r-f5pv-92p5/GHSA-x98r-f5pv-92p5.json +++ b/advisories/unreviewed/2022/01/GHSA-x98r-f5pv-92p5/GHSA-x98r-f5pv-92p5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x98r-f5pv-92p5", - "modified": "2022-01-15T00:03:41Z", + "modified": "2025-05-22T21:30:33Z", "published": "2022-01-04T00:00:23Z", "aliases": [ "CVE-2021-39987" ], "details": "The HwNearbyMain module has a Data Processing Errors vulnerability.Successful exploitation of this vulnerability may cause a process to restart.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/01/GHSA-xgj6-2p43-6fvx/GHSA-xgj6-2p43-6fvx.json b/advisories/unreviewed/2022/01/GHSA-xgj6-2p43-6fvx/GHSA-xgj6-2p43-6fvx.json index aee9df87372..c05726c8f84 100644 --- a/advisories/unreviewed/2022/01/GHSA-xgj6-2p43-6fvx/GHSA-xgj6-2p43-6fvx.json +++ b/advisories/unreviewed/2022/01/GHSA-xgj6-2p43-6fvx/GHSA-xgj6-2p43-6fvx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xgj6-2p43-6fvx", - "modified": "2022-01-12T00:01:49Z", + "modified": "2025-05-22T21:30:31Z", "published": "2022-01-04T00:00:54Z", "aliases": [ "CVE-2021-24786" ], "details": "The Download Monitor WordPress plugin before 4.4.5 does not properly validate and escape the \"orderby\" GET parameter before using it in a SQL statement when viewing the logs, leading to an SQL Injection issue", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-4m4f-3m29-78r8/GHSA-4m4f-3m29-78r8.json b/advisories/unreviewed/2022/05/GHSA-4m4f-3m29-78r8/GHSA-4m4f-3m29-78r8.json index b11076c40fa..8213d754a65 100644 --- a/advisories/unreviewed/2022/05/GHSA-4m4f-3m29-78r8/GHSA-4m4f-3m29-78r8.json +++ b/advisories/unreviewed/2022/05/GHSA-4m4f-3m29-78r8/GHSA-4m4f-3m29-78r8.json @@ -1,26 +1,40 @@ { "schema_version": "1.4.0", "id": "GHSA-4m4f-3m29-78r8", - "modified": "2022-05-24T17:36:17Z", + "modified": "2025-05-22T21:30:31Z", "published": "2022-05-24T17:36:17Z", "aliases": [ "CVE-2020-25187" ], "details": "Medtronic MyCareLink Smart 25000 all versions are vulnerable when an attacker who gains auth runs a debug command, which is sent to the reader causing heap overflow in the MCL Smart Reader stack. A heap overflow allows attacker to remotely execute code on the MCL Smart Reader, could lead to control of device.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-25187" }, + { + "type": "WEB", + "url": "https://global.medtronic.com/xg-en/product-security/security-bulletins/mycarelink-smart-security-vulnerability-patch.html" + }, { "type": "WEB", "url": "https://us-cert.cisa.gov/ics/advisories/icsma-20-345-01" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-20-345-01" } ], "database_specific": { "cwe_ids": [ + "CWE-122", "CWE-787" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2022/05/GHSA-54f2-q9g6-3cvc/GHSA-54f2-q9g6-3cvc.json b/advisories/unreviewed/2022/05/GHSA-54f2-q9g6-3cvc/GHSA-54f2-q9g6-3cvc.json index 3fb8aa53ebd..791afd32ecc 100644 --- a/advisories/unreviewed/2022/05/GHSA-54f2-q9g6-3cvc/GHSA-54f2-q9g6-3cvc.json +++ b/advisories/unreviewed/2022/05/GHSA-54f2-q9g6-3cvc/GHSA-54f2-q9g6-3cvc.json @@ -1,19 +1,32 @@ { "schema_version": "1.4.0", "id": "GHSA-54f2-q9g6-3cvc", - "modified": "2022-05-24T16:49:00Z", + "modified": "2025-05-22T21:30:31Z", "published": "2022-05-24T16:49:00Z", "aliases": [ "CVE-2019-10964" ], "details": "In Medtronic MinMed 508 and Medtronic Minimed Paradigm Insulin Pumps, Versions, MiniMed 508 pump ? All versions, MiniMed Paradigm 511 pump ? All versions, MiniMed Paradigm 512/712 pumps ? All versions, MiniMed Paradigm 712E pump?All versions, MiniMed Paradigm 515/715 pumps?All versions, MiniMed Paradigm 522/722 pumps ? All versions,MiniMed Paradigm 522K/722K pumps ? All versions, MiniMed Paradigm 523/723 pumps ? Software versions 2.4A or lower, MiniMed Paradigm 523K/723K pumps ? Software, versions 2.4A or lower, MiniMed Paradigm Veo 554/754 pumps ? Software versions 2.6A or lower, MiniMed Paradigm Veo 554CM and 754CM models only ? Software versions 2.7A or lower, the affected insulin pumps are designed to communicate using a wireless RF with other devices, such as blood glucose meters, glucose sensor transmitters, and CareLink USB devices. This wireless RF communication protocol does not properly implement authentication or authorization. An attacker with adjacent access to one of the affected insulin pump models can inject, replay, modify, and/or intercept data. This vulnerability could also allow attackers to change pump settings and control insulin delivery.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H" + } + ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-10964" }, + { + "type": "WEB", + "url": "https://global.medtronic.com/xg-en/product-security/security-bulletins/minimed-508-paradigm.html" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-19-178-01" + }, { "type": "WEB", "url": "https://www.us-cert.gov/ics/advisories/icsma-19-178-01" @@ -24,7 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284", + "CWE-287" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-56wm-53rq-h4x6/GHSA-56wm-53rq-h4x6.json b/advisories/unreviewed/2022/05/GHSA-56wm-53rq-h4x6/GHSA-56wm-53rq-h4x6.json index b01811b7206..ed98c4ca4c2 100644 --- a/advisories/unreviewed/2022/05/GHSA-56wm-53rq-h4x6/GHSA-56wm-53rq-h4x6.json +++ b/advisories/unreviewed/2022/05/GHSA-56wm-53rq-h4x6/GHSA-56wm-53rq-h4x6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-56wm-53rq-h4x6", - "modified": "2022-05-13T01:14:52Z", + "modified": "2025-05-22T21:30:30Z", "published": "2022-05-13T01:14:52Z", "aliases": [ "CVE-2019-6538" @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-306" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/05/GHSA-7j5v-9v3j-phg6/GHSA-7j5v-9v3j-phg6.json b/advisories/unreviewed/2022/05/GHSA-7j5v-9v3j-phg6/GHSA-7j5v-9v3j-phg6.json index c2527968a48..4f2258bc600 100644 --- a/advisories/unreviewed/2022/05/GHSA-7j5v-9v3j-phg6/GHSA-7j5v-9v3j-phg6.json +++ b/advisories/unreviewed/2022/05/GHSA-7j5v-9v3j-phg6/GHSA-7j5v-9v3j-phg6.json @@ -1,22 +1,35 @@ { "schema_version": "1.4.0", "id": "GHSA-7j5v-9v3j-phg6", - "modified": "2022-05-24T22:28:22Z", + "modified": "2025-05-22T21:30:31Z", "published": "2022-05-24T22:28:22Z", "aliases": [ "CVE-2020-25183" ], "details": "Medtronic MyCareLink Smart 25000 all versions contain an authentication protocol vuln where the method used to auth between MCL Smart Patient Reader and MyCareLink Smart mobile app is vulnerable to bypass. This vuln allows attacker to use other mobile device or malicious app on smartphone to auth to the patient’s Smart Reader, fools the device into thinking its communicating with the actual smart phone application when executed in range of Bluetooth.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-25183" }, + { + "type": "WEB", + "url": "https://global.medtronic.com/xg-en/product-security/security-bulletins/mycarelink-smart-security-vulnerability-patch.html" + }, { "type": "WEB", "url": "https://us-cert.cisa.gov/ics/advisories/icsma-20-345-01" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-20-345-01" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/05/GHSA-7jf7-367c-mvv4/GHSA-7jf7-367c-mvv4.json b/advisories/unreviewed/2022/05/GHSA-7jf7-367c-mvv4/GHSA-7jf7-367c-mvv4.json index 2cb34b5f2c5..6a9dd164d85 100644 --- a/advisories/unreviewed/2022/05/GHSA-7jf7-367c-mvv4/GHSA-7jf7-367c-mvv4.json +++ b/advisories/unreviewed/2022/05/GHSA-7jf7-367c-mvv4/GHSA-7jf7-367c-mvv4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7jf7-367c-mvv4", - "modified": "2022-05-13T01:31:44Z", + "modified": "2025-05-22T21:30:30Z", "published": "2022-05-13T01:31:44Z", "aliases": [ "CVE-2018-8870" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-8870" }, + { + "type": "WEB", + "url": "https://global.medtronic.com/xg-en/product-security/security-bulletins/mycarelink-6-28-18.html" + }, { "type": "WEB", "url": "https://ics-cert.us-cert.gov/advisories/ICSMA-18-179-01" @@ -26,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-259", "CWE-798" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/05/GHSA-9c58-qqp7-2wc2/GHSA-9c58-qqp7-2wc2.json b/advisories/unreviewed/2022/05/GHSA-9c58-qqp7-2wc2/GHSA-9c58-qqp7-2wc2.json index 95ba4fb5d81..5a502d8119e 100644 --- a/advisories/unreviewed/2022/05/GHSA-9c58-qqp7-2wc2/GHSA-9c58-qqp7-2wc2.json +++ b/advisories/unreviewed/2022/05/GHSA-9c58-qqp7-2wc2/GHSA-9c58-qqp7-2wc2.json @@ -1,26 +1,41 @@ { "schema_version": "1.4.0", "id": "GHSA-9c58-qqp7-2wc2", - "modified": "2022-05-24T22:01:05Z", + "modified": "2025-05-22T21:30:31Z", "published": "2022-05-24T22:01:05Z", "aliases": [ "CVE-2019-13543" ], "details": "Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4.0.0 and below, and Valleylab FX8 Energy Platform (VLFX8GEN) software version 1.1.0 and below use multiple sets of hard-coded credentials. If discovered, they can be used to read files on the device.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-13543" }, + { + "type": "WEB", + "url": "https://global.medtronic.com/xg-en/product-security/security-bulletins/valleylab-generator-rfid-vulnerabilities.html" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-19-311-02" + }, { "type": "WEB", "url": "https://www.us-cert.gov/ics/advisories/icsma-19-311-02" } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-798" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c9h8-j583-w6wh/GHSA-c9h8-j583-w6wh.json b/advisories/unreviewed/2022/05/GHSA-c9h8-j583-w6wh/GHSA-c9h8-j583-w6wh.json index 7b71faa210f..e4ba36a925b 100644 --- a/advisories/unreviewed/2022/05/GHSA-c9h8-j583-w6wh/GHSA-c9h8-j583-w6wh.json +++ b/advisories/unreviewed/2022/05/GHSA-c9h8-j583-w6wh/GHSA-c9h8-j583-w6wh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c9h8-j583-w6wh", - "modified": "2022-05-13T01:31:43Z", + "modified": "2025-05-22T21:30:30Z", "published": "2022-05-13T01:31:43Z", "aliases": [ "CVE-2018-8868" @@ -19,13 +19,19 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-8868" }, + { + "type": "WEB", + "url": "https://global.medtronic.com/xg-en/product-security/security-bulletins/mycarelink-6-28-18.html" + }, { "type": "WEB", "url": "https://ics-cert.us-cert.gov/advisories/ICSMA-18-179-01" } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-749" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hv9m-498v-fp67/GHSA-hv9m-498v-fp67.json b/advisories/unreviewed/2022/05/GHSA-hv9m-498v-fp67/GHSA-hv9m-498v-fp67.json index f24c1e23f51..1fec780c7e3 100644 --- a/advisories/unreviewed/2022/05/GHSA-hv9m-498v-fp67/GHSA-hv9m-498v-fp67.json +++ b/advisories/unreviewed/2022/05/GHSA-hv9m-498v-fp67/GHSA-hv9m-498v-fp67.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hv9m-498v-fp67", - "modified": "2024-04-04T03:07:23Z", + "modified": "2025-05-22T21:30:31Z", "published": "2022-05-24T22:01:05Z", "aliases": [ "CVE-2019-13539" @@ -19,6 +19,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-13539" }, + { + "type": "WEB", + "url": "https://global.medtronic.com/xg-en/product-security/security-bulletins/valleylab-generator-rfid-vulnerabilities.html" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-19-311-02" + }, { "type": "WEB", "url": "https://www.us-cert.gov/ics/advisories/icsma-19-311-02" diff --git a/advisories/unreviewed/2022/05/GHSA-jp54-39p3-825v/GHSA-jp54-39p3-825v.json b/advisories/unreviewed/2022/05/GHSA-jp54-39p3-825v/GHSA-jp54-39p3-825v.json index 25445662b63..623de649541 100644 --- a/advisories/unreviewed/2022/05/GHSA-jp54-39p3-825v/GHSA-jp54-39p3-825v.json +++ b/advisories/unreviewed/2022/05/GHSA-jp54-39p3-825v/GHSA-jp54-39p3-825v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jp54-39p3-825v", - "modified": "2024-04-04T02:38:39Z", + "modified": "2025-05-22T21:30:31Z", "published": "2022-05-24T17:00:41Z", "aliases": [ "CVE-2019-13531" @@ -19,6 +19,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-13531" }, + { + "type": "WEB", + "url": "https://global.medtronic.com/xg-en/product-security/security-bulletins/valleylab-generator-rfid-vulnerabilities.html" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-19-311-01" + }, { "type": "WEB", "url": "https://www.us-cert.gov/ics/advisories/icsma-19-311-01" diff --git a/advisories/unreviewed/2022/05/GHSA-pqmr-7wg9-jg7r/GHSA-pqmr-7wg9-jg7r.json b/advisories/unreviewed/2022/05/GHSA-pqmr-7wg9-jg7r/GHSA-pqmr-7wg9-jg7r.json index b1238ca1c48..dc4983c5c6d 100644 --- a/advisories/unreviewed/2022/05/GHSA-pqmr-7wg9-jg7r/GHSA-pqmr-7wg9-jg7r.json +++ b/advisories/unreviewed/2022/05/GHSA-pqmr-7wg9-jg7r/GHSA-pqmr-7wg9-jg7r.json @@ -1,26 +1,42 @@ { "schema_version": "1.4.0", "id": "GHSA-pqmr-7wg9-jg7r", - "modified": "2022-05-24T17:00:41Z", + "modified": "2025-05-22T21:30:31Z", "published": "2022-05-24T17:00:41Z", "aliases": [ "CVE-2019-13535" ], "details": "In Medtronic Valleylab FT10 Energy Platform (VLFT10GEN) version 2.1.0 and lower and version 2.0.3 and lower, and Valleylab LS10 Energy Platform (VLLS10GEN?not available in the United States) version 1.20.2 and lower, the RFID security mechanism does not apply read protection, allowing for full read access of the RFID security mechanism data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-13535" }, + { + "type": "WEB", + "url": "https://global.medtronic.com/xg-en/product-security/security-bulletins/valleylab-generator-rfid-vulnerabilities.html" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-19-311-01" + }, { "type": "WEB", "url": "https://www.us-cert.gov/ics/advisories/icsma-19-311-01" } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-693", + "CWE-732" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qmhj-wg3r-x2h5/GHSA-qmhj-wg3r-x2h5.json b/advisories/unreviewed/2022/05/GHSA-qmhj-wg3r-x2h5/GHSA-qmhj-wg3r-x2h5.json index 7551386b35b..cf2f4cb8e27 100644 --- a/advisories/unreviewed/2022/05/GHSA-qmhj-wg3r-x2h5/GHSA-qmhj-wg3r-x2h5.json +++ b/advisories/unreviewed/2022/05/GHSA-qmhj-wg3r-x2h5/GHSA-qmhj-wg3r-x2h5.json @@ -1,22 +1,35 @@ { "schema_version": "1.4.0", "id": "GHSA-qmhj-wg3r-x2h5", - "modified": "2022-05-24T17:36:18Z", + "modified": "2025-05-22T21:30:31Z", "published": "2022-05-24T17:36:18Z", "aliases": [ "CVE-2020-27252" ], "details": "Medtronic MyCareLink Smart 25000 all versions are vulnerable to a race condition in the MCL Smart Patient Reader software update system, which allows unsigned firmware to be uploaded and executed on the Patient Reader. If exploited an attacker could remotely execute code on the MCL Smart Patient Reader device, leading to control of the device.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-27252" }, + { + "type": "WEB", + "url": "https://global.medtronic.com/xg-en/product-security/security-bulletins/mycarelink-smart-security-vulnerability-patch.html" + }, { "type": "WEB", "url": "https://us-cert.cisa.gov/ics/advisories/icsma-20-345-01" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-20-345-01" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/09/GHSA-4c97-vhfm-xx23/GHSA-4c97-vhfm-xx23.json b/advisories/unreviewed/2022/09/GHSA-4c97-vhfm-xx23/GHSA-4c97-vhfm-xx23.json index 40eff9b7aab..7da7b26b913 100644 --- a/advisories/unreviewed/2022/09/GHSA-4c97-vhfm-xx23/GHSA-4c97-vhfm-xx23.json +++ b/advisories/unreviewed/2022/09/GHSA-4c97-vhfm-xx23/GHSA-4c97-vhfm-xx23.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-20" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-6fg9-5q9c-4fp2/GHSA-6fg9-5q9c-4fp2.json b/advisories/unreviewed/2022/09/GHSA-6fg9-5q9c-4fp2/GHSA-6fg9-5q9c-4fp2.json index 90f825a7e08..9995b829b91 100644 --- a/advisories/unreviewed/2022/09/GHSA-6fg9-5q9c-4fp2/GHSA-6fg9-5q9c-4fp2.json +++ b/advisories/unreviewed/2022/09/GHSA-6fg9-5q9c-4fp2/GHSA-6fg9-5q9c-4fp2.json @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-6mqr-f9rh-mggr/GHSA-6mqr-f9rh-mggr.json b/advisories/unreviewed/2022/09/GHSA-6mqr-f9rh-mggr/GHSA-6mqr-f9rh-mggr.json index bd6dcc8e452..6496d375e65 100644 --- a/advisories/unreviewed/2022/09/GHSA-6mqr-f9rh-mggr/GHSA-6mqr-f9rh-mggr.json +++ b/advisories/unreviewed/2022/09/GHSA-6mqr-f9rh-mggr/GHSA-6mqr-f9rh-mggr.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-84fw-3p4m-3vrc/GHSA-84fw-3p4m-3vrc.json b/advisories/unreviewed/2022/09/GHSA-84fw-3p4m-3vrc/GHSA-84fw-3p4m-3vrc.json index 8dc4125eae8..14c613633cd 100644 --- a/advisories/unreviewed/2022/09/GHSA-84fw-3p4m-3vrc/GHSA-84fw-3p4m-3vrc.json +++ b/advisories/unreviewed/2022/09/GHSA-84fw-3p4m-3vrc/GHSA-84fw-3p4m-3vrc.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-955x-77q4-5vqw/GHSA-955x-77q4-5vqw.json b/advisories/unreviewed/2022/09/GHSA-955x-77q4-5vqw/GHSA-955x-77q4-5vqw.json index 41648bcadea..3fc539df882 100644 --- a/advisories/unreviewed/2022/09/GHSA-955x-77q4-5vqw/GHSA-955x-77q4-5vqw.json +++ b/advisories/unreviewed/2022/09/GHSA-955x-77q4-5vqw/GHSA-955x-77q4-5vqw.json @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-98r4-4f3j-q239/GHSA-98r4-4f3j-q239.json b/advisories/unreviewed/2022/09/GHSA-98r4-4f3j-q239/GHSA-98r4-4f3j-q239.json index 412078569cd..a50879398aa 100644 --- a/advisories/unreviewed/2022/09/GHSA-98r4-4f3j-q239/GHSA-98r4-4f3j-q239.json +++ b/advisories/unreviewed/2022/09/GHSA-98r4-4f3j-q239/GHSA-98r4-4f3j-q239.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-98r4-4f3j-q239", - "modified": "2022-09-25T00:00:18Z", + "modified": "2025-05-22T21:30:35Z", "published": "2022-09-25T00:00:18Z", "aliases": [ "CVE-2022-27492" diff --git a/advisories/unreviewed/2022/09/GHSA-c7hp-7v7r-r7v9/GHSA-c7hp-7v7r-r7v9.json b/advisories/unreviewed/2022/09/GHSA-c7hp-7v7r-r7v9/GHSA-c7hp-7v7r-r7v9.json index 66904970831..594fb5a012b 100644 --- a/advisories/unreviewed/2022/09/GHSA-c7hp-7v7r-r7v9/GHSA-c7hp-7v7r-r7v9.json +++ b/advisories/unreviewed/2022/09/GHSA-c7hp-7v7r-r7v9/GHSA-c7hp-7v7r-r7v9.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-cc8c-93xf-8jgq/GHSA-cc8c-93xf-8jgq.json b/advisories/unreviewed/2022/09/GHSA-cc8c-93xf-8jgq/GHSA-cc8c-93xf-8jgq.json index c97ac214f53..e849ee56f66 100644 --- a/advisories/unreviewed/2022/09/GHSA-cc8c-93xf-8jgq/GHSA-cc8c-93xf-8jgq.json +++ b/advisories/unreviewed/2022/09/GHSA-cc8c-93xf-8jgq/GHSA-cc8c-93xf-8jgq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cc8c-93xf-8jgq", - "modified": "2022-09-27T00:00:14Z", + "modified": "2025-05-22T21:30:37Z", "published": "2022-09-25T00:00:19Z", "aliases": [ "CVE-2022-40358" diff --git a/advisories/unreviewed/2022/09/GHSA-gmgf-76vr-x3ch/GHSA-gmgf-76vr-x3ch.json b/advisories/unreviewed/2022/09/GHSA-gmgf-76vr-x3ch/GHSA-gmgf-76vr-x3ch.json index 7d8d83bb6d7..a5256a2f4e9 100644 --- a/advisories/unreviewed/2022/09/GHSA-gmgf-76vr-x3ch/GHSA-gmgf-76vr-x3ch.json +++ b/advisories/unreviewed/2022/09/GHSA-gmgf-76vr-x3ch/GHSA-gmgf-76vr-x3ch.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-jjrw-xpw9-v3qh/GHSA-jjrw-xpw9-v3qh.json b/advisories/unreviewed/2022/09/GHSA-jjrw-xpw9-v3qh/GHSA-jjrw-xpw9-v3qh.json index a77dab9c451..10bf4944dff 100644 --- a/advisories/unreviewed/2022/09/GHSA-jjrw-xpw9-v3qh/GHSA-jjrw-xpw9-v3qh.json +++ b/advisories/unreviewed/2022/09/GHSA-jjrw-xpw9-v3qh/GHSA-jjrw-xpw9-v3qh.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-451" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-jx87-887q-554q/GHSA-jx87-887q-554q.json b/advisories/unreviewed/2022/09/GHSA-jx87-887q-554q/GHSA-jx87-887q-554q.json index cdc34c58453..08d54dae141 100644 --- a/advisories/unreviewed/2022/09/GHSA-jx87-887q-554q/GHSA-jx87-887q-554q.json +++ b/advisories/unreviewed/2022/09/GHSA-jx87-887q-554q/GHSA-jx87-887q-554q.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-284" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/09/GHSA-q3cp-h2hv-r3mf/GHSA-q3cp-h2hv-r3mf.json b/advisories/unreviewed/2022/09/GHSA-q3cp-h2hv-r3mf/GHSA-q3cp-h2hv-r3mf.json index 6c581e9ac35..4e385b88935 100644 --- a/advisories/unreviewed/2022/09/GHSA-q3cp-h2hv-r3mf/GHSA-q3cp-h2hv-r3mf.json +++ b/advisories/unreviewed/2022/09/GHSA-q3cp-h2hv-r3mf/GHSA-q3cp-h2hv-r3mf.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-qf6h-wr49-rv76/GHSA-qf6h-wr49-rv76.json b/advisories/unreviewed/2022/09/GHSA-qf6h-wr49-rv76/GHSA-qf6h-wr49-rv76.json index e10bc5e8e11..c2a3fd5884d 100644 --- a/advisories/unreviewed/2022/09/GHSA-qf6h-wr49-rv76/GHSA-qf6h-wr49-rv76.json +++ b/advisories/unreviewed/2022/09/GHSA-qf6h-wr49-rv76/GHSA-qf6h-wr49-rv76.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-312", "CWE-532" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/09/GHSA-v9wp-86gv-6c8f/GHSA-v9wp-86gv-6c8f.json b/advisories/unreviewed/2022/09/GHSA-v9wp-86gv-6c8f/GHSA-v9wp-86gv-6c8f.json index ff2dcb3f849..8d382fcba24 100644 --- a/advisories/unreviewed/2022/09/GHSA-v9wp-86gv-6c8f/GHSA-v9wp-86gv-6c8f.json +++ b/advisories/unreviewed/2022/09/GHSA-v9wp-86gv-6c8f/GHSA-v9wp-86gv-6c8f.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-v9xf-qq9q-332r/GHSA-v9xf-qq9q-332r.json b/advisories/unreviewed/2022/09/GHSA-v9xf-qq9q-332r/GHSA-v9xf-qq9q-332r.json index d2d771fc4cf..6d03a6bc5ff 100644 --- a/advisories/unreviewed/2022/09/GHSA-v9xf-qq9q-332r/GHSA-v9xf-qq9q-332r.json +++ b/advisories/unreviewed/2022/09/GHSA-v9xf-qq9q-332r/GHSA-v9xf-qq9q-332r.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-vcqh-2q2g-pgc3/GHSA-vcqh-2q2g-pgc3.json b/advisories/unreviewed/2022/09/GHSA-vcqh-2q2g-pgc3/GHSA-vcqh-2q2g-pgc3.json index 213189aae8e..fe3b9338b3b 100644 --- a/advisories/unreviewed/2022/09/GHSA-vcqh-2q2g-pgc3/GHSA-vcqh-2q2g-pgc3.json +++ b/advisories/unreviewed/2022/09/GHSA-vcqh-2q2g-pgc3/GHSA-vcqh-2q2g-pgc3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vcqh-2q2g-pgc3", - "modified": "2022-10-02T00:00:32Z", + "modified": "2025-05-22T21:30:35Z", "published": "2022-09-25T00:00:26Z", "aliases": [ "CVE-2022-30121" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-xhq5-7429-4hrv/GHSA-xhq5-7429-4hrv.json b/advisories/unreviewed/2022/09/GHSA-xhq5-7429-4hrv/GHSA-xhq5-7429-4hrv.json index 61f42a646fb..0542a52ec46 100644 --- a/advisories/unreviewed/2022/09/GHSA-xhq5-7429-4hrv/GHSA-xhq5-7429-4hrv.json +++ b/advisories/unreviewed/2022/09/GHSA-xhq5-7429-4hrv/GHSA-xhq5-7429-4hrv.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-20" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/12/GHSA-gvp5-cq52-6qx5/GHSA-gvp5-cq52-6qx5.json b/advisories/unreviewed/2023/12/GHSA-gvp5-cq52-6qx5/GHSA-gvp5-cq52-6qx5.json index e3b6c395448..12e40898b08 100644 --- a/advisories/unreviewed/2023/12/GHSA-gvp5-cq52-6qx5/GHSA-gvp5-cq52-6qx5.json +++ b/advisories/unreviewed/2023/12/GHSA-gvp5-cq52-6qx5/GHSA-gvp5-cq52-6qx5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gvp5-cq52-6qx5", - "modified": "2023-12-13T03:31:55Z", + "modified": "2025-05-22T21:30:41Z", "published": "2023-12-13T03:31:55Z", "aliases": [ "CVE-2023-45864" diff --git a/advisories/unreviewed/2023/12/GHSA-h4pp-j4x6-f6f6/GHSA-h4pp-j4x6-f6f6.json b/advisories/unreviewed/2023/12/GHSA-h4pp-j4x6-f6f6/GHSA-h4pp-j4x6-f6f6.json index 92dea0378de..ced0a679138 100644 --- a/advisories/unreviewed/2023/12/GHSA-h4pp-j4x6-f6f6/GHSA-h4pp-j4x6-f6f6.json +++ b/advisories/unreviewed/2023/12/GHSA-h4pp-j4x6-f6f6/GHSA-h4pp-j4x6-f6f6.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-290" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/01/GHSA-9r3v-3w88-2hh3/GHSA-9r3v-3w88-2hh3.json b/advisories/unreviewed/2024/01/GHSA-9r3v-3w88-2hh3/GHSA-9r3v-3w88-2hh3.json index c4ef2522379..73e592e56cc 100644 --- a/advisories/unreviewed/2024/01/GHSA-9r3v-3w88-2hh3/GHSA-9r3v-3w88-2hh3.json +++ b/advisories/unreviewed/2024/01/GHSA-9r3v-3w88-2hh3/GHSA-9r3v-3w88-2hh3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9r3v-3w88-2hh3", - "modified": "2024-01-24T18:31:00Z", + "modified": "2025-05-22T21:30:41Z", "published": "2024-01-16T18:31:09Z", "aliases": [ "CVE-2022-2413" diff --git a/advisories/unreviewed/2025/02/GHSA-255m-x7w5-9w65/GHSA-255m-x7w5-9w65.json b/advisories/unreviewed/2025/02/GHSA-255m-x7w5-9w65/GHSA-255m-x7w5-9w65.json index 4d53c24b4c2..0e91aadf4ef 100644 --- a/advisories/unreviewed/2025/02/GHSA-255m-x7w5-9w65/GHSA-255m-x7w5-9w65.json +++ b/advisories/unreviewed/2025/02/GHSA-255m-x7w5-9w65/GHSA-255m-x7w5-9w65.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-255m-x7w5-9w65", - "modified": "2025-02-06T06:31:26Z", + "modified": "2025-05-22T21:30:42Z", "published": "2025-02-06T06:31:26Z", "aliases": [ "CVE-2024-51547" @@ -26,10 +26,15 @@ { "type": "WEB", "url": "https://search.abb.com/library/Download.aspx?DocumentID=9AKK108470A6775&LanguageCode=en&DocumentPartId=pdf%20-%20Public%20Advisory&Action=Launch" + }, + { + "type": "WEB", + "url": "https://search.abb.com/library/Download.aspx?DocumentID=9AKK108471A0021&LanguageCode=en&DocumentPartId=pdf&Action=Launch" } ], "database_specific": { "cwe_ids": [ + "CWE-312", "CWE-798" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2025/05/GHSA-28c7-hwc8-phgm/GHSA-28c7-hwc8-phgm.json b/advisories/unreviewed/2025/05/GHSA-28c7-hwc8-phgm/GHSA-28c7-hwc8-phgm.json index acd3d232cd8..f325204b900 100644 --- a/advisories/unreviewed/2025/05/GHSA-28c7-hwc8-phgm/GHSA-28c7-hwc8-phgm.json +++ b/advisories/unreviewed/2025/05/GHSA-28c7-hwc8-phgm/GHSA-28c7-hwc8-phgm.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-2rg9-797v-v3pv/GHSA-2rg9-797v-v3pv.json b/advisories/unreviewed/2025/05/GHSA-2rg9-797v-v3pv/GHSA-2rg9-797v-v3pv.json new file mode 100644 index 00000000000..a3ff705d676 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2rg9-797v-v3pv/GHSA-2rg9-797v-v3pv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2rg9-797v-v3pv", + "modified": "2025-05-22T21:30:47Z", + "published": "2025-05-22T21:30:47Z", + "aliases": [ + "CVE-2024-7103" + ], + "details": "A reflected cross-site scripting (XSS) vulnerability exists in the sub-organization login flow of WSO2 Identity Server 7.0.0 due to improper input validation. A malicious actor can exploit this vulnerability to inject arbitrary JavaScript into the login flow, potentially leading to UI modifications, redirections to malicious websites, or data exfiltration from the browser.\n\nWhile this issue could allow an attacker to manipulate the user’s browser, session-related sensitive cookies remain protected with the httpOnly flag, preventing session hijacking.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7103" + }, + { + "type": "WEB", + "url": "https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2024-3425" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T19:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3262-4hm9-mq8q/GHSA-3262-4hm9-mq8q.json b/advisories/unreviewed/2025/05/GHSA-3262-4hm9-mq8q/GHSA-3262-4hm9-mq8q.json index d3b9e340391..3e965cd9a06 100644 --- a/advisories/unreviewed/2025/05/GHSA-3262-4hm9-mq8q/GHSA-3262-4hm9-mq8q.json +++ b/advisories/unreviewed/2025/05/GHSA-3262-4hm9-mq8q/GHSA-3262-4hm9-mq8q.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-3h6w-hjgc-hx7q/GHSA-3h6w-hjgc-hx7q.json b/advisories/unreviewed/2025/05/GHSA-3h6w-hjgc-hx7q/GHSA-3h6w-hjgc-hx7q.json new file mode 100644 index 00000000000..50c614c23d4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3h6w-hjgc-hx7q/GHSA-3h6w-hjgc-hx7q.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3h6w-hjgc-hx7q", + "modified": "2025-05-22T21:30:47Z", + "published": "2025-05-22T21:30:47Z", + "aliases": [ + "CVE-2024-13948" + ], + "details": "Windows permissions for ASPECT configuration toolsets are not fully secured allow-ing exposure of configuration informationThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13948" + }, + { + "type": "WEB", + "url": "https://search.abb.com/library/Download.aspx?DocumentID=9AKK108471A0021&LanguageCode=en&DocumentPartId=pdf&Action=Launch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T19:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4g4f-j7gv-ph46/GHSA-4g4f-j7gv-ph46.json b/advisories/unreviewed/2025/05/GHSA-4g4f-j7gv-ph46/GHSA-4g4f-j7gv-ph46.json index 46e5a328662..c7e654c9263 100644 --- a/advisories/unreviewed/2025/05/GHSA-4g4f-j7gv-ph46/GHSA-4g4f-j7gv-ph46.json +++ b/advisories/unreviewed/2025/05/GHSA-4g4f-j7gv-ph46/GHSA-4g4f-j7gv-ph46.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-59h9-45h4-4xj9/GHSA-59h9-45h4-4xj9.json b/advisories/unreviewed/2025/05/GHSA-59h9-45h4-4xj9/GHSA-59h9-45h4-4xj9.json new file mode 100644 index 00000000000..9eb414f22a6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-59h9-45h4-4xj9/GHSA-59h9-45h4-4xj9.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-59h9-45h4-4xj9", + "modified": "2025-05-22T21:30:47Z", + "published": "2025-05-22T21:30:47Z", + "aliases": [ + "CVE-2024-40461" + ], + "details": "An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the STOCKORDERENTRY.EXE component", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40461" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1DyiyLQRvTRAZD8gn2BT7oDzX1NQ7wmFT/view?usp=drive_link" + }, + { + "type": "WEB", + "url": "https://gist.githubusercontent.com/john0x186/1d9cc7fcc8386480d2bdaa9fdcfa914b/raw/d2d3d74ccaa939127ee2b03139061509a7dd238c/full-disclosure.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T19:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6g64-v8cr-g3f9/GHSA-6g64-v8cr-g3f9.json b/advisories/unreviewed/2025/05/GHSA-6g64-v8cr-g3f9/GHSA-6g64-v8cr-g3f9.json new file mode 100644 index 00000000000..09815de6f87 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6g64-v8cr-g3f9/GHSA-6g64-v8cr-g3f9.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6g64-v8cr-g3f9", + "modified": "2025-05-22T21:30:47Z", + "published": "2025-05-22T21:30:47Z", + "aliases": [ + "CVE-2024-13953" + ], + "details": "Sensitive device logger information in ASPECT may be exposed if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13953" + }, + { + "type": "WEB", + "url": "https://search.abb.com/library/Download.aspx?DocumentID=9AKK108471A0021&LanguageCode=en&DocumentPartId=pdf&Action=Launch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-359" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T19:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-77wx-cf44-5rxx/GHSA-77wx-cf44-5rxx.json b/advisories/unreviewed/2025/05/GHSA-77wx-cf44-5rxx/GHSA-77wx-cf44-5rxx.json new file mode 100644 index 00000000000..40e4b9ae850 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-77wx-cf44-5rxx/GHSA-77wx-cf44-5rxx.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-77wx-cf44-5rxx", + "modified": "2025-05-22T21:30:47Z", + "published": "2025-05-22T21:30:47Z", + "aliases": [ + "CVE-2024-13952" + ], + "details": "Predictable filename vulnerabilities in ASPECT may expose sensitive information to a potential attacker if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13952" + }, + { + "type": "WEB", + "url": "https://search.abb.com/library/Download.aspx?DocumentID=9AKK108471A0021&LanguageCode=en&DocumentPartId=pdf&Action=Launch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T19:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7r8r-45g3-pmf8/GHSA-7r8r-45g3-pmf8.json b/advisories/unreviewed/2025/05/GHSA-7r8r-45g3-pmf8/GHSA-7r8r-45g3-pmf8.json new file mode 100644 index 00000000000..a4cb49602a5 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7r8r-45g3-pmf8/GHSA-7r8r-45g3-pmf8.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7r8r-45g3-pmf8", + "modified": "2025-05-22T21:30:47Z", + "published": "2025-05-22T21:30:47Z", + "aliases": [ + "CVE-2024-13954" + ], + "details": "Serialized configuration information may be disclosed during device commissioning while using ASPECT's configuration toolsetThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13954" + }, + { + "type": "WEB", + "url": "https://search.abb.com/library/Download.aspx?DocumentID=9AKK108471A0021&LanguageCode=en&DocumentPartId=pdf&Action=Launch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-922" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T19:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7xfj-j894-qgcq/GHSA-7xfj-j894-qgcq.json b/advisories/unreviewed/2025/05/GHSA-7xfj-j894-qgcq/GHSA-7xfj-j894-qgcq.json index b287442df4a..006269a54f1 100644 --- a/advisories/unreviewed/2025/05/GHSA-7xfj-j894-qgcq/GHSA-7xfj-j894-qgcq.json +++ b/advisories/unreviewed/2025/05/GHSA-7xfj-j894-qgcq/GHSA-7xfj-j894-qgcq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7xfj-j894-qgcq", - "modified": "2025-05-22T18:31:15Z", + "modified": "2025-05-22T21:30:46Z", "published": "2025-05-22T18:31:15Z", "aliases": [ "CVE-2025-45468" ], "details": "Insecure permissions in fc-stable-diffusion-plus v1.0.18 allows attackers to escalate privileges and compromise the customer cloud account.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-732" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-22T16:15:54Z" diff --git a/advisories/unreviewed/2025/05/GHSA-8jcq-cgc3-57jm/GHSA-8jcq-cgc3-57jm.json b/advisories/unreviewed/2025/05/GHSA-8jcq-cgc3-57jm/GHSA-8jcq-cgc3-57jm.json index 0fbbe0fbb7e..a968418db37 100644 --- a/advisories/unreviewed/2025/05/GHSA-8jcq-cgc3-57jm/GHSA-8jcq-cgc3-57jm.json +++ b/advisories/unreviewed/2025/05/GHSA-8jcq-cgc3-57jm/GHSA-8jcq-cgc3-57jm.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-8vvc-hmjh-w8jg/GHSA-8vvc-hmjh-w8jg.json b/advisories/unreviewed/2025/05/GHSA-8vvc-hmjh-w8jg/GHSA-8vvc-hmjh-w8jg.json new file mode 100644 index 00000000000..fafa834123b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8vvc-hmjh-w8jg/GHSA-8vvc-hmjh-w8jg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8vvc-hmjh-w8jg", + "modified": "2025-05-22T21:30:47Z", + "published": "2025-05-22T21:30:47Z", + "aliases": [ + "CVE-2024-7487" + ], + "details": "An improper authentication vulnerability exists in WSO2 Identity Server 7.0.0 due to an implementation flaw that allows app-native authentication to be bypassed when an invalid object is passed.\n\nExploitation of this vulnerability could enable malicious actors to circumvent the client verification mechanism, compromising the integrity of the authentication process.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7487" + }, + { + "type": "WEB", + "url": "https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2024-3348" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T19:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9495-7c48-4348/GHSA-9495-7c48-4348.json b/advisories/unreviewed/2025/05/GHSA-9495-7c48-4348/GHSA-9495-7c48-4348.json index 8ff306dc701..43d707a7e0d 100644 --- a/advisories/unreviewed/2025/05/GHSA-9495-7c48-4348/GHSA-9495-7c48-4348.json +++ b/advisories/unreviewed/2025/05/GHSA-9495-7c48-4348/GHSA-9495-7c48-4348.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-94c7-f7jq-xgj6/GHSA-94c7-f7jq-xgj6.json b/advisories/unreviewed/2025/05/GHSA-94c7-f7jq-xgj6/GHSA-94c7-f7jq-xgj6.json index f352838a5c9..763c909f58b 100644 --- a/advisories/unreviewed/2025/05/GHSA-94c7-f7jq-xgj6/GHSA-94c7-f7jq-xgj6.json +++ b/advisories/unreviewed/2025/05/GHSA-94c7-f7jq-xgj6/GHSA-94c7-f7jq-xgj6.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-9g48-983j-g56m/GHSA-9g48-983j-g56m.json b/advisories/unreviewed/2025/05/GHSA-9g48-983j-g56m/GHSA-9g48-983j-g56m.json new file mode 100644 index 00000000000..8dfe09bb851 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9g48-983j-g56m/GHSA-9g48-983j-g56m.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9g48-983j-g56m", + "modified": "2025-05-22T21:30:47Z", + "published": "2025-05-22T21:30:47Z", + "aliases": [ + "CVE-2024-13946" + ], + "details": "DLL's are not digitally signed when loaded in ASPECT's configuration toolset exposing the application to binary planting during device commissioning.This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:L/VA:L/SC:H/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13946" + }, + { + "type": "WEB", + "url": "https://search.abb.com/library/Download.aspx?DocumentID=9AKK108471A0021&LanguageCode=en&DocumentPartId=pdf&Action=Launch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T19:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9gx6-8hww-xm54/GHSA-9gx6-8hww-xm54.json b/advisories/unreviewed/2025/05/GHSA-9gx6-8hww-xm54/GHSA-9gx6-8hww-xm54.json new file mode 100644 index 00000000000..b473c5d1e28 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9gx6-8hww-xm54/GHSA-9gx6-8hww-xm54.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9gx6-8hww-xm54", + "modified": "2025-05-22T21:30:47Z", + "published": "2025-05-22T21:30:47Z", + "aliases": [ + "CVE-2024-40458" + ], + "details": "An issue in Ocuco Innovation Tracking.exe v.2.10.24.51 allows a local attacker to escalate privileges via the modification of TCP packets.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40458" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1E8dxLt2LnvmLcCEUyp6qtnG-yZjyvMji/view?usp=drive_link" + }, + { + "type": "WEB", + "url": "https://gist.githubusercontent.com/john0x186/1d9cc7fcc8386480d2bdaa9fdcfa914b/raw/d2d3d74ccaa939127ee2b03139061509a7dd238c/full-disclosure.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T19:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9h69-wwg8-442f/GHSA-9h69-wwg8-442f.json b/advisories/unreviewed/2025/05/GHSA-9h69-wwg8-442f/GHSA-9h69-wwg8-442f.json new file mode 100644 index 00000000000..b88991b42aa --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9h69-wwg8-442f/GHSA-9h69-wwg8-442f.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9h69-wwg8-442f", + "modified": "2025-05-22T21:30:47Z", + "published": "2025-05-22T21:30:47Z", + "aliases": [ + "CVE-2024-13958" + ], + "details": "Stored Cross Site Scripting vulnerabilities exist in ASPECT if administrator creden-tials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13958" + }, + { + "type": "WEB", + "url": "https://search.abb.com/library/Download.aspx?DocumentID=9AKK108471A0021&LanguageCode=en&DocumentPartId=pdf&Action=Launch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T19:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9x45-8qmx-683p/GHSA-9x45-8qmx-683p.json b/advisories/unreviewed/2025/05/GHSA-9x45-8qmx-683p/GHSA-9x45-8qmx-683p.json new file mode 100644 index 00000000000..7b1b65a1c7e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9x45-8qmx-683p/GHSA-9x45-8qmx-683p.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9x45-8qmx-683p", + "modified": "2025-05-22T21:30:47Z", + "published": "2025-05-22T21:30:47Z", + "aliases": [ + "CVE-2024-40460" + ], + "details": "An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the JOBENTRY.EXE", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40460" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/10M4x2jL_l-kPSZOOE_tUmBzCTCr0tMiF/view?usp=drive_link" + }, + { + "type": "WEB", + "url": "https://gist.githubusercontent.com/john0x186/1d9cc7fcc8386480d2bdaa9fdcfa914b/raw/d2d3d74ccaa939127ee2b03139061509a7dd238c/full-disclosure.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T19:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-cgq3-4xq4-v94r/GHSA-cgq3-4xq4-v94r.json b/advisories/unreviewed/2025/05/GHSA-cgq3-4xq4-v94r/GHSA-cgq3-4xq4-v94r.json new file mode 100644 index 00000000000..0ad14722417 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-cgq3-4xq4-v94r/GHSA-cgq3-4xq4-v94r.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cgq3-4xq4-v94r", + "modified": "2025-05-22T21:30:47Z", + "published": "2025-05-22T21:30:47Z", + "aliases": [ + "CVE-2024-51553" + ], + "details": "Predictable filename vulnerabilities in ASPECT may expose sensitive information to a potential attacker if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51553" + }, + { + "type": "WEB", + "url": "https://search.abb.com/library/Download.aspx?DocumentID=9AKK108471A0021&LanguageCode=en&DocumentPartId=pdf&Action=Launch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-73" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T19:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g6rf-7www-ggmp/GHSA-g6rf-7www-ggmp.json b/advisories/unreviewed/2025/05/GHSA-g6rf-7www-ggmp/GHSA-g6rf-7www-ggmp.json index 178baecd86f..bcc72b36467 100644 --- a/advisories/unreviewed/2025/05/GHSA-g6rf-7www-ggmp/GHSA-g6rf-7www-ggmp.json +++ b/advisories/unreviewed/2025/05/GHSA-g6rf-7www-ggmp/GHSA-g6rf-7www-ggmp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g6rf-7www-ggmp", - "modified": "2025-05-22T15:34:51Z", + "modified": "2025-05-22T21:30:46Z", "published": "2025-05-22T15:34:51Z", "aliases": [ "CVE-2025-45471" ], "details": "Insecure permissions in measure-cold-start v1.4.1 allows attackers to escalate privileges and compromise the customer cloud account.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-732" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-22T15:16:05Z" diff --git a/advisories/unreviewed/2025/05/GHSA-g7cj-ccj4-m3wq/GHSA-g7cj-ccj4-m3wq.json b/advisories/unreviewed/2025/05/GHSA-g7cj-ccj4-m3wq/GHSA-g7cj-ccj4-m3wq.json new file mode 100644 index 00000000000..f775edc042b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g7cj-ccj4-m3wq/GHSA-g7cj-ccj4-m3wq.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g7cj-ccj4-m3wq", + "modified": "2025-05-22T21:30:47Z", + "published": "2025-05-22T21:30:47Z", + "aliases": [ + "CVE-2024-13947" + ], + "details": "Device commissioning parameters in ASPECT may be modified by an external source if administrative credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:L/VA:L/SC:H/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13947" + }, + { + "type": "WEB", + "url": "https://search.abb.com/library/Download.aspx?DocumentID=9AKK108471A0021&LanguageCode=en&DocumentPartId=pdf&Action=Launch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T19:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gfm6-h4jq-qp9r/GHSA-gfm6-h4jq-qp9r.json b/advisories/unreviewed/2025/05/GHSA-gfm6-h4jq-qp9r/GHSA-gfm6-h4jq-qp9r.json index fda6dc10feb..4d295b26cc8 100644 --- a/advisories/unreviewed/2025/05/GHSA-gfm6-h4jq-qp9r/GHSA-gfm6-h4jq-qp9r.json +++ b/advisories/unreviewed/2025/05/GHSA-gfm6-h4jq-qp9r/GHSA-gfm6-h4jq-qp9r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gfm6-h4jq-qp9r", - "modified": "2025-05-22T15:34:51Z", + "modified": "2025-05-22T21:30:46Z", "published": "2025-05-22T15:34:51Z", "aliases": [ "CVE-2025-32814" ], "details": "An issue was discovered in Infoblox NETMRI before 7.6.1. Unauthenticated SQL Injection can occur.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-22T15:16:04Z" diff --git a/advisories/unreviewed/2025/05/GHSA-hchj-55px-fgw7/GHSA-hchj-55px-fgw7.json b/advisories/unreviewed/2025/05/GHSA-hchj-55px-fgw7/GHSA-hchj-55px-fgw7.json index ce73ea12585..ec4050d9dde 100644 --- a/advisories/unreviewed/2025/05/GHSA-hchj-55px-fgw7/GHSA-hchj-55px-fgw7.json +++ b/advisories/unreviewed/2025/05/GHSA-hchj-55px-fgw7/GHSA-hchj-55px-fgw7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hchj-55px-fgw7", - "modified": "2025-05-21T21:31:40Z", + "modified": "2025-05-22T21:30:45Z", "published": "2025-05-21T21:31:40Z", "aliases": [ "CVE-2025-27558" ], "details": "IEEE P802.11-REVme D1.1 through D7.0 allows FragAttacks against mesh networks. In mesh networks using Wi-Fi Protected Access (WPA, WPA2, or WPA3) or Wired Equivalent Privacy (WEP), an adversary can exploit this vulnerability to inject arbitrary frames towards devices that support receiving non-SSP A-MSDU frames. NOTE: this issue exists because of an incorrect fix for CVE-2020-24588. P802.11-REVme, as of early 2025, is a planned release of the 802.11 standard.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-345" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-21T19:16:08Z" diff --git a/advisories/unreviewed/2025/05/GHSA-hqgr-xf2j-75r5/GHSA-hqgr-xf2j-75r5.json b/advisories/unreviewed/2025/05/GHSA-hqgr-xf2j-75r5/GHSA-hqgr-xf2j-75r5.json new file mode 100644 index 00000000000..93bd48a5c9f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hqgr-xf2j-75r5/GHSA-hqgr-xf2j-75r5.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hqgr-xf2j-75r5", + "modified": "2025-05-22T21:30:47Z", + "published": "2025-05-22T21:30:47Z", + "aliases": [ + "CVE-2024-6914" + ], + "details": "An incorrect authorization vulnerability exists in multiple WSO2 products due to a business logic flaw in the account recovery-related SOAP admin service. A malicious actor can exploit this vulnerability to reset the password of any user account, leading to a complete account takeover, including accounts with elevated privileges.\n\nThis vulnerability is exploitable only through the account recovery SOAP admin services exposed via the \"/services\" context path in affected products. The impact may be reduced if access to these endpoints has been restricted based on the \"Security Guidelines for Production Deployment\" by disabling exposure to untrusted networks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6914" + }, + { + "type": "WEB", + "url": "https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2024-3561" + }, + { + "type": "WEB", + "url": "https://security.docs.wso2.com/en/latest/security-guidelines/security-guidelines-for-production-deployment" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T19:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hrcg-68ff-5vg7/GHSA-hrcg-68ff-5vg7.json b/advisories/unreviewed/2025/05/GHSA-hrcg-68ff-5vg7/GHSA-hrcg-68ff-5vg7.json new file mode 100644 index 00000000000..50180b2d0fd --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hrcg-68ff-5vg7/GHSA-hrcg-68ff-5vg7.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hrcg-68ff-5vg7", + "modified": "2025-05-22T21:30:47Z", + "published": "2025-05-22T21:30:47Z", + "aliases": [ + "CVE-2024-13955" + ], + "details": "2nd Order SQL injection vulnerabilities in ASPECT allow unintended access and manipulation of database repositories if administrator credentials become compromised.This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13955" + }, + { + "type": "WEB", + "url": "https://search.abb.com/library/Download.aspx?DocumentID=9AKK108471A0021&LanguageCode=en&DocumentPartId=pdf&Action=Launch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T19:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-j55x-w58q-g339/GHSA-j55x-w58q-g339.json b/advisories/unreviewed/2025/05/GHSA-j55x-w58q-g339/GHSA-j55x-w58q-g339.json new file mode 100644 index 00000000000..88e0fde6e9a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-j55x-w58q-g339/GHSA-j55x-w58q-g339.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j55x-w58q-g339", + "modified": "2025-05-22T21:30:47Z", + "published": "2025-05-22T21:30:47Z", + "aliases": [ + "CVE-2024-40462" + ], + "details": "An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the SETTINGSVATIGATOR.EXE component", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40462" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1MDU9FGo36U83yQy55nnVj1syWVy9WLm5/view?usp=drive_link" + }, + { + "type": "WEB", + "url": "https://gist.githubusercontent.com/john0x186/1d9cc7fcc8386480d2bdaa9fdcfa914b/raw/d2d3d74ccaa939127ee2b03139061509a7dd238c/full-disclosure.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T19:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jrxx-3w86-jfqf/GHSA-jrxx-3w86-jfqf.json b/advisories/unreviewed/2025/05/GHSA-jrxx-3w86-jfqf/GHSA-jrxx-3w86-jfqf.json new file mode 100644 index 00000000000..d5181671fd3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jrxx-3w86-jfqf/GHSA-jrxx-3w86-jfqf.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jrxx-3w86-jfqf", + "modified": "2025-05-22T21:30:48Z", + "published": "2025-05-22T21:30:48Z", + "aliases": [ + "CVE-2024-51552" + ], + "details": "Weak password storage vulnerabilities exist in ASPECT if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:L/VA:L/SC:H/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51552" + }, + { + "type": "WEB", + "url": "https://search.abb.com/library/Download.aspx?DocumentID=9AKK108471A0021&LanguageCode=en&DocumentPartId=pdf&Action=Launch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-257" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T19:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jw4h-4rg7-p2p2/GHSA-jw4h-4rg7-p2p2.json b/advisories/unreviewed/2025/05/GHSA-jw4h-4rg7-p2p2/GHSA-jw4h-4rg7-p2p2.json new file mode 100644 index 00000000000..5ad84388d54 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jw4h-4rg7-p2p2/GHSA-jw4h-4rg7-p2p2.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jw4h-4rg7-p2p2", + "modified": "2025-05-22T21:30:47Z", + "published": "2025-05-22T21:30:47Z", + "aliases": [ + "CVE-2024-41197" + ], + "details": "An issue in Ocuco Innovation - INVCLIENT.EXE v2.10.24.5 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41197" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1XgbcJqYIHxAROcCACdgdD8V_97Hcwdze/view?usp=drive_link" + }, + { + "type": "WEB", + "url": "https://gist.githubusercontent.com/john0x186/1d9cc7fcc8386480d2bdaa9fdcfa914b/raw/d2d3d74ccaa939127ee2b03139061509a7dd238c/full-disclosure.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T19:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mcq5-86cv-w2rc/GHSA-mcq5-86cv-w2rc.json b/advisories/unreviewed/2025/05/GHSA-mcq5-86cv-w2rc/GHSA-mcq5-86cv-w2rc.json new file mode 100644 index 00000000000..fbfe3614f2e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mcq5-86cv-w2rc/GHSA-mcq5-86cv-w2rc.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mcq5-86cv-w2rc", + "modified": "2025-05-22T21:30:47Z", + "published": "2025-05-22T21:30:47Z", + "aliases": [ + "CVE-2024-13951" + ], + "details": "One way hash with predictable salt vulnerabilities in ASPECT may expose sensitive information to a potential attackerThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13951" + }, + { + "type": "WEB", + "url": "https://search.abb.com/library/Download.aspx?DocumentID=9AKK108471A0021&LanguageCode=en&DocumentPartId=pdf&Action=Launch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-760" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T19:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mgj6-95h9-vg3g/GHSA-mgj6-95h9-vg3g.json b/advisories/unreviewed/2025/05/GHSA-mgj6-95h9-vg3g/GHSA-mgj6-95h9-vg3g.json new file mode 100644 index 00000000000..984a9f70718 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mgj6-95h9-vg3g/GHSA-mgj6-95h9-vg3g.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mgj6-95h9-vg3g", + "modified": "2025-05-22T21:30:47Z", + "published": "2025-05-22T21:30:47Z", + "aliases": [ + "CVE-2024-40459" + ], + "details": "An issue in Ocuco Innovation APPMANAGER.EXE v.2.10.24.51 allows a local attacker to escalate privileges via the application manager function", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40459" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1J2PsjRc6u2q4Teo3eVnBVmTEFjOgaPzX/view?usp=drive_link" + }, + { + "type": "WEB", + "url": "https://gist.githubusercontent.com/john0x186/1d9cc7fcc8386480d2bdaa9fdcfa914b/raw/d2d3d74ccaa939127ee2b03139061509a7dd238c/full-disclosure.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T19:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mhfp-2wg5-h75r/GHSA-mhfp-2wg5-h75r.json b/advisories/unreviewed/2025/05/GHSA-mhfp-2wg5-h75r/GHSA-mhfp-2wg5-h75r.json new file mode 100644 index 00000000000..1e2a106c923 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mhfp-2wg5-h75r/GHSA-mhfp-2wg5-h75r.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mhfp-2wg5-h75r", + "modified": "2025-05-22T21:30:48Z", + "published": "2025-05-22T21:30:47Z", + "aliases": [ + "CVE-2024-41196" + ], + "details": "An issue in Ocuco Innovation - REPORTSERVER.EXE v2.10.24.13 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41196" + }, + { + "type": "WEB", + "url": "https://cwe.mitre.org/data/definitions/285.html" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1UqJAQiwhHZCHtgac4-YiJHElBYhqUu3M/view?usp=drive_link" + }, + { + "type": "WEB", + "url": "https://gist.githubusercontent.com/john0x186/1d9cc7fcc8386480d2bdaa9fdcfa914b/raw/d2d3d74ccaa939127ee2b03139061509a7dd238c/full-disclosure.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T19:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mv2f-363v-qmfc/GHSA-mv2f-363v-qmfc.json b/advisories/unreviewed/2025/05/GHSA-mv2f-363v-qmfc/GHSA-mv2f-363v-qmfc.json new file mode 100644 index 00000000000..5215291d49e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mv2f-363v-qmfc/GHSA-mv2f-363v-qmfc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mv2f-363v-qmfc", + "modified": "2025-05-22T21:30:48Z", + "published": "2025-05-22T21:30:48Z", + "aliases": [ + "CVE-2024-5962" + ], + "details": "A reflected cross-site scripting (XSS) vulnerability exists in the authentication endpoint of multiple WSO2 products due to missing output encoding of user-supplied input. A malicious actor can exploit this vulnerability to inject arbitrary JavaScript into the authentication flow, potentially leading to UI modifications, redirections to malicious websites, or data exfiltration from the browser.\n\nWhile this issue could allow an attacker to manipulate the user’s browser, session-related sensitive cookies remain protected with the httpOnly flag, preventing session hijacking.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5962" + }, + { + "type": "WEB", + "url": "https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2024-3443" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T20:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-pjg9-5v2q-9fpf/GHSA-pjg9-5v2q-9fpf.json b/advisories/unreviewed/2025/05/GHSA-pjg9-5v2q-9fpf/GHSA-pjg9-5v2q-9fpf.json new file mode 100644 index 00000000000..5f26cfc8954 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pjg9-5v2q-9fpf/GHSA-pjg9-5v2q-9fpf.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pjg9-5v2q-9fpf", + "modified": "2025-05-22T21:30:47Z", + "published": "2025-05-22T21:30:47Z", + "aliases": [ + "CVE-2024-48848" + ], + "details": "Large content vulnerabilities are present in ASPECT exposing a device to disk overutilization on a system if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48848" + }, + { + "type": "WEB", + "url": "https://search.abb.com/library/Download.aspx?DocumentID=9AKK108471A0021&LanguageCode=en&DocumentPartId=pdf&Action=Launch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-774" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T19:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qf5x-7jf5-56qp/GHSA-qf5x-7jf5-56qp.json b/advisories/unreviewed/2025/05/GHSA-qf5x-7jf5-56qp/GHSA-qf5x-7jf5-56qp.json index 554da6093de..7ef88e59909 100644 --- a/advisories/unreviewed/2025/05/GHSA-qf5x-7jf5-56qp/GHSA-qf5x-7jf5-56qp.json +++ b/advisories/unreviewed/2025/05/GHSA-qf5x-7jf5-56qp/GHSA-qf5x-7jf5-56qp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qf5x-7jf5-56qp", - "modified": "2025-05-21T21:31:40Z", + "modified": "2025-05-22T21:30:45Z", "published": "2025-05-21T21:31:40Z", "aliases": [ "CVE-2024-57529" ], "details": "Cross Site Scripting vulnerability in Jeppesen JetPlanner Pro v.1.6.2.20 allows a remote attacker to execute arbitrary code.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-21T19:16:07Z" diff --git a/advisories/unreviewed/2025/05/GHSA-qqrc-c2h6-m823/GHSA-qqrc-c2h6-m823.json b/advisories/unreviewed/2025/05/GHSA-qqrc-c2h6-m823/GHSA-qqrc-c2h6-m823.json index 38b57b22447..54631de154e 100644 --- a/advisories/unreviewed/2025/05/GHSA-qqrc-c2h6-m823/GHSA-qqrc-c2h6-m823.json +++ b/advisories/unreviewed/2025/05/GHSA-qqrc-c2h6-m823/GHSA-qqrc-c2h6-m823.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qqrc-c2h6-m823", - "modified": "2025-05-09T18:30:36Z", + "modified": "2025-05-22T21:30:42Z", "published": "2025-05-02T09:30:35Z", "aliases": [ "CVE-2024-13858" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://www.buddyboss.com/resources/buddyboss-platform-releases/2-8-51" }, + { + "type": "WEB", + "url": "https://www.buddyboss.com/resources/buddyboss-theme-releases/2-8-50" + }, { "type": "WEB", "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5f50e293-aebd-44dd-a692-64dea8f6622f?source=cve" diff --git a/advisories/unreviewed/2025/05/GHSA-r532-jjq9-737h/GHSA-r532-jjq9-737h.json b/advisories/unreviewed/2025/05/GHSA-r532-jjq9-737h/GHSA-r532-jjq9-737h.json new file mode 100644 index 00000000000..5e02bf215cd --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-r532-jjq9-737h/GHSA-r532-jjq9-737h.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r532-jjq9-737h", + "modified": "2025-05-22T21:30:47Z", + "published": "2025-05-22T21:30:47Z", + "aliases": [ + "CVE-2024-13956" + ], + "details": "SSL Verification Bypass vulnerabilities exist in ASPECT if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13956" + }, + { + "type": "WEB", + "url": "https://search.abb.com/library/Download.aspx?DocumentID=9AKK108471A0021&LanguageCode=en&DocumentPartId=pdf&Action=Launch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T19:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rx9g-4vxh-vcv6/GHSA-rx9g-4vxh-vcv6.json b/advisories/unreviewed/2025/05/GHSA-rx9g-4vxh-vcv6/GHSA-rx9g-4vxh-vcv6.json new file mode 100644 index 00000000000..dbf9bdbf8cf --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rx9g-4vxh-vcv6/GHSA-rx9g-4vxh-vcv6.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rx9g-4vxh-vcv6", + "modified": "2025-05-22T21:30:47Z", + "published": "2025-05-22T21:30:47Z", + "aliases": [ + "CVE-2024-41198" + ], + "details": "An issue in Ocuco Innovation - REPORTS.EXE v2.10.24.13 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41198" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1k7P36ygRjQE6XfcT-FJgsN2yrtQy2yhH/view?usp=drive_link" + }, + { + "type": "WEB", + "url": "https://gist.githubusercontent.com/john0x186/1d9cc7fcc8386480d2bdaa9fdcfa914b/raw/d2d3d74ccaa939127ee2b03139061509a7dd238c/full-disclosure.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T19:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v28g-wcvm-jvfw/GHSA-v28g-wcvm-jvfw.json b/advisories/unreviewed/2025/05/GHSA-v28g-wcvm-jvfw/GHSA-v28g-wcvm-jvfw.json new file mode 100644 index 00000000000..0e460438986 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v28g-wcvm-jvfw/GHSA-v28g-wcvm-jvfw.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v28g-wcvm-jvfw", + "modified": "2025-05-22T21:30:47Z", + "published": "2025-05-22T21:30:47Z", + "aliases": [ + "CVE-2024-41199" + ], + "details": "An issue in Ocuco Innovation - JOBMANAGER.EXE v2.10.24.16 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41199" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1dVvH9l0gKRK0OPcF6_8yTLPsARKFqWqB/view?usp=drive_link" + }, + { + "type": "WEB", + "url": "https://gist.githubusercontent.com/john0x186/1d9cc7fcc8386480d2bdaa9fdcfa914b/raw/d2d3d74ccaa939127ee2b03139061509a7dd238c/full-disclosure.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T19:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w34f-x9rj-jg28/GHSA-w34f-x9rj-jg28.json b/advisories/unreviewed/2025/05/GHSA-w34f-x9rj-jg28/GHSA-w34f-x9rj-jg28.json index 6b6c54e06f2..9dbbdf63caf 100644 --- a/advisories/unreviewed/2025/05/GHSA-w34f-x9rj-jg28/GHSA-w34f-x9rj-jg28.json +++ b/advisories/unreviewed/2025/05/GHSA-w34f-x9rj-jg28/GHSA-w34f-x9rj-jg28.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w34f-x9rj-jg28", - "modified": "2025-05-21T21:31:40Z", + "modified": "2025-05-22T21:30:45Z", "published": "2025-05-21T21:31:40Z", "aliases": [ "CVE-2025-45752" ], "details": "A vulnerability in SeedDMS 6.0.32 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting the zip import functionality in the Extension Manager.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-21T19:16:08Z" diff --git a/advisories/unreviewed/2025/05/GHSA-wc69-3q88-j8fp/GHSA-wc69-3q88-j8fp.json b/advisories/unreviewed/2025/05/GHSA-wc69-3q88-j8fp/GHSA-wc69-3q88-j8fp.json new file mode 100644 index 00000000000..888698af424 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wc69-3q88-j8fp/GHSA-wc69-3q88-j8fp.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wc69-3q88-j8fp", + "modified": "2025-05-22T21:30:47Z", + "published": "2025-05-22T21:30:47Z", + "aliases": [ + "CVE-2024-13950" + ], + "details": "Log injection vulnerabilities in ASPECT provide attacker access to inject malicious browser scripts if administrator credentials become compromised.This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13950" + }, + { + "type": "WEB", + "url": "https://search.abb.com/library/Download.aspx?DocumentID=9AKK108471A0021&LanguageCode=en&DocumentPartId=pdf&Action=Launch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T19:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wcmm-3mhw-34w9/GHSA-wcmm-3mhw-34w9.json b/advisories/unreviewed/2025/05/GHSA-wcmm-3mhw-34w9/GHSA-wcmm-3mhw-34w9.json new file mode 100644 index 00000000000..3fbc8ad3102 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wcmm-3mhw-34w9/GHSA-wcmm-3mhw-34w9.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wcmm-3mhw-34w9", + "modified": "2025-05-22T21:30:47Z", + "published": "2025-05-22T21:30:47Z", + "aliases": [ + "CVE-2024-13949" + ], + "details": "Large content vulnerabilities are present in ASPECT exposing a device to disk overutilization on a system if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13949" + }, + { + "type": "WEB", + "url": "https://search.abb.com/library/Download.aspx?DocumentID=9AKK108471A0021&LanguageCode=en&DocumentPartId=pdf&Action=Launch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-117" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T19:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wfm4-cvqx-m7rj/GHSA-wfm4-cvqx-m7rj.json b/advisories/unreviewed/2025/05/GHSA-wfm4-cvqx-m7rj/GHSA-wfm4-cvqx-m7rj.json new file mode 100644 index 00000000000..a9a6e055ce8 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wfm4-cvqx-m7rj/GHSA-wfm4-cvqx-m7rj.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wfm4-cvqx-m7rj", + "modified": "2025-05-22T21:30:47Z", + "published": "2025-05-22T21:30:47Z", + "aliases": [ + "CVE-2024-41195" + ], + "details": "An issue in Ocuco Innovation - INNOVASERVICEINTF.EXE v2.10.24.17 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41195" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1U50ZsLo7VXWKQ1_6FxWy70F_75jzVUwi/view?usp=drive_link" + }, + { + "type": "WEB", + "url": "https://gist.githubusercontent.com/john0x186/1d9cc7fcc8386480d2bdaa9fdcfa914b/raw/d2d3d74ccaa939127ee2b03139061509a7dd238c/full-disclosure.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T19:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wr74-f9qr-g5xw/GHSA-wr74-f9qr-g5xw.json b/advisories/unreviewed/2025/05/GHSA-wr74-f9qr-g5xw/GHSA-wr74-f9qr-g5xw.json new file mode 100644 index 00000000000..0ff6819b90e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wr74-f9qr-g5xw/GHSA-wr74-f9qr-g5xw.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wr74-f9qr-g5xw", + "modified": "2025-05-22T21:30:47Z", + "published": "2025-05-22T21:30:47Z", + "aliases": [ + "CVE-2024-13957" + ], + "details": "SSRF Server Side Request Forgery vulnerabilities exist in ASPECT if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13957" + }, + { + "type": "WEB", + "url": "https://search.abb.com/library/Download.aspx?DocumentID=9AKK108471A0021&LanguageCode=en&DocumentPartId=pdf&Action=Launch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T19:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xwcp-6g2q-65gm/GHSA-xwcp-6g2q-65gm.json b/advisories/unreviewed/2025/05/GHSA-xwcp-6g2q-65gm/GHSA-xwcp-6g2q-65gm.json index 0d0a2b15f17..69af9707784 100644 --- a/advisories/unreviewed/2025/05/GHSA-xwcp-6g2q-65gm/GHSA-xwcp-6g2q-65gm.json +++ b/advisories/unreviewed/2025/05/GHSA-xwcp-6g2q-65gm/GHSA-xwcp-6g2q-65gm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xwcp-6g2q-65gm", - "modified": "2025-05-21T21:31:40Z", + "modified": "2025-05-22T21:30:45Z", "published": "2025-05-21T21:31:40Z", "aliases": [ "CVE-2025-44083" ], "details": "An issue in D-Link DI-8100 16.07.26A1 allows a remote attacker to bypass administrator login authentication", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-287" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-21T19:16:08Z"