diff --git a/advisories/unreviewed/2022/10/GHSA-2gqc-hf8q-hvqq/GHSA-2gqc-hf8q-hvqq.json b/advisories/unreviewed/2022/10/GHSA-2gqc-hf8q-hvqq/GHSA-2gqc-hf8q-hvqq.json index 01be0a1d70f..3f826b8712f 100644 --- a/advisories/unreviewed/2022/10/GHSA-2gqc-hf8q-hvqq/GHSA-2gqc-hf8q-hvqq.json +++ b/advisories/unreviewed/2022/10/GHSA-2gqc-hf8q-hvqq/GHSA-2gqc-hf8q-hvqq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2gqc-hf8q-hvqq", - "modified": "2022-10-18T19:00:34Z", + "modified": "2025-05-15T15:31:11Z", "published": "2022-10-14T19:00:39Z", "aliases": [ "CVE-2022-38986" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-4f2h-772x-5h66/GHSA-4f2h-772x-5h66.json b/advisories/unreviewed/2022/10/GHSA-4f2h-772x-5h66/GHSA-4f2h-772x-5h66.json index c65d04fa3e3..c385c3a50d0 100644 --- a/advisories/unreviewed/2022/10/GHSA-4f2h-772x-5h66/GHSA-4f2h-772x-5h66.json +++ b/advisories/unreviewed/2022/10/GHSA-4f2h-772x-5h66/GHSA-4f2h-772x-5h66.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-787" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/10/GHSA-5v6v-qhhf-hv9g/GHSA-5v6v-qhhf-hv9g.json b/advisories/unreviewed/2022/10/GHSA-5v6v-qhhf-hv9g/GHSA-5v6v-qhhf-hv9g.json index c05da0de447..c6226a60718 100644 --- a/advisories/unreviewed/2022/10/GHSA-5v6v-qhhf-hv9g/GHSA-5v6v-qhhf-hv9g.json +++ b/advisories/unreviewed/2022/10/GHSA-5v6v-qhhf-hv9g/GHSA-5v6v-qhhf-hv9g.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/10/GHSA-6mrc-mhh5-mvx5/GHSA-6mrc-mhh5-mvx5.json b/advisories/unreviewed/2022/10/GHSA-6mrc-mhh5-mvx5/GHSA-6mrc-mhh5-mvx5.json index 27007faeb2a..801646fcc81 100644 --- a/advisories/unreviewed/2022/10/GHSA-6mrc-mhh5-mvx5/GHSA-6mrc-mhh5-mvx5.json +++ b/advisories/unreviewed/2022/10/GHSA-6mrc-mhh5-mvx5/GHSA-6mrc-mhh5-mvx5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6mrc-mhh5-mvx5", - "modified": "2022-10-18T19:00:34Z", + "modified": "2025-05-15T15:31:09Z", "published": "2022-10-14T12:00:23Z", "aliases": [ "CVE-2022-41674" @@ -35,6 +35,18 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2022/11/msg00001.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GGHENNMLCWIQV2LLA56BJNFIUZ7WB4IY" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/S2KTU5LFZNQS7YNGE56MT46VHMXL3DD2" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VNN3VFQPECS6D4PS6ZWD7AFXTOSJDSSR" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GGHENNMLCWIQV2LLA56BJNFIUZ7WB4IY" diff --git a/advisories/unreviewed/2022/10/GHSA-6q82-84qc-99r9/GHSA-6q82-84qc-99r9.json b/advisories/unreviewed/2022/10/GHSA-6q82-84qc-99r9/GHSA-6q82-84qc-99r9.json index 3bafa21e1a5..a909322d7ed 100644 --- a/advisories/unreviewed/2022/10/GHSA-6q82-84qc-99r9/GHSA-6q82-84qc-99r9.json +++ b/advisories/unreviewed/2022/10/GHSA-6q82-84qc-99r9/GHSA-6q82-84qc-99r9.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-190", "CWE-787" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/10/GHSA-77r6-fvw7-mprq/GHSA-77r6-fvw7-mprq.json b/advisories/unreviewed/2022/10/GHSA-77r6-fvw7-mprq/GHSA-77r6-fvw7-mprq.json index 50f836e7332..1fdee05952d 100644 --- a/advisories/unreviewed/2022/10/GHSA-77r6-fvw7-mprq/GHSA-77r6-fvw7-mprq.json +++ b/advisories/unreviewed/2022/10/GHSA-77r6-fvw7-mprq/GHSA-77r6-fvw7-mprq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-77r6-fvw7-mprq", - "modified": "2022-10-18T19:00:31Z", + "modified": "2025-05-15T15:31:11Z", "published": "2022-10-14T19:00:39Z", "aliases": [ "CVE-2022-39011" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-693" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-7q22-vf3p-qvwp/GHSA-7q22-vf3p-qvwp.json b/advisories/unreviewed/2022/10/GHSA-7q22-vf3p-qvwp/GHSA-7q22-vf3p-qvwp.json index e1dc5f344f4..3d1343a93d5 100644 --- a/advisories/unreviewed/2022/10/GHSA-7q22-vf3p-qvwp/GHSA-7q22-vf3p-qvwp.json +++ b/advisories/unreviewed/2022/10/GHSA-7q22-vf3p-qvwp/GHSA-7q22-vf3p-qvwp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7q22-vf3p-qvwp", - "modified": "2022-10-15T12:01:07Z", + "modified": "2025-05-15T15:31:08Z", "published": "2022-10-13T12:00:26Z", "aliases": [ "CVE-2022-40187" diff --git a/advisories/unreviewed/2022/10/GHSA-7rf6-xmxm-mxrr/GHSA-7rf6-xmxm-mxrr.json b/advisories/unreviewed/2022/10/GHSA-7rf6-xmxm-mxrr/GHSA-7rf6-xmxm-mxrr.json index 976e482e204..875a2453a05 100644 --- a/advisories/unreviewed/2022/10/GHSA-7rf6-xmxm-mxrr/GHSA-7rf6-xmxm-mxrr.json +++ b/advisories/unreviewed/2022/10/GHSA-7rf6-xmxm-mxrr/GHSA-7rf6-xmxm-mxrr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7rf6-xmxm-mxrr", - "modified": "2022-10-18T19:00:35Z", + "modified": "2025-05-15T15:31:08Z", "published": "2022-10-14T12:00:25Z", "aliases": [ "CVE-2022-42156" diff --git a/advisories/unreviewed/2022/10/GHSA-7xh6-c3pp-j98r/GHSA-7xh6-c3pp-j98r.json b/advisories/unreviewed/2022/10/GHSA-7xh6-c3pp-j98r/GHSA-7xh6-c3pp-j98r.json index a4239b9fcd7..7410dbc9aa3 100644 --- a/advisories/unreviewed/2022/10/GHSA-7xh6-c3pp-j98r/GHSA-7xh6-c3pp-j98r.json +++ b/advisories/unreviewed/2022/10/GHSA-7xh6-c3pp-j98r/GHSA-7xh6-c3pp-j98r.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-434" + "CWE-434", + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/10/GHSA-c5hv-rh39-2jjj/GHSA-c5hv-rh39-2jjj.json b/advisories/unreviewed/2022/10/GHSA-c5hv-rh39-2jjj/GHSA-c5hv-rh39-2jjj.json index d30e9cf1007..23b816ef6fe 100644 --- a/advisories/unreviewed/2022/10/GHSA-c5hv-rh39-2jjj/GHSA-c5hv-rh39-2jjj.json +++ b/advisories/unreviewed/2022/10/GHSA-c5hv-rh39-2jjj/GHSA-c5hv-rh39-2jjj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c5hv-rh39-2jjj", - "modified": "2022-10-19T19:00:24Z", + "modified": "2025-05-15T15:31:09Z", "published": "2022-10-14T12:00:18Z", "aliases": [ "CVE-2022-2780" diff --git a/advisories/unreviewed/2022/10/GHSA-fh5c-qmvh-m75j/GHSA-fh5c-qmvh-m75j.json b/advisories/unreviewed/2022/10/GHSA-fh5c-qmvh-m75j/GHSA-fh5c-qmvh-m75j.json index 57d7c317061..5abe0d184a0 100644 --- a/advisories/unreviewed/2022/10/GHSA-fh5c-qmvh-m75j/GHSA-fh5c-qmvh-m75j.json +++ b/advisories/unreviewed/2022/10/GHSA-fh5c-qmvh-m75j/GHSA-fh5c-qmvh-m75j.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-763" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/10/GHSA-g2xr-62jm-9q24/GHSA-g2xr-62jm-9q24.json b/advisories/unreviewed/2022/10/GHSA-g2xr-62jm-9q24/GHSA-g2xr-62jm-9q24.json index d1c0d67b9ae..2c505504afe 100644 --- a/advisories/unreviewed/2022/10/GHSA-g2xr-62jm-9q24/GHSA-g2xr-62jm-9q24.json +++ b/advisories/unreviewed/2022/10/GHSA-g2xr-62jm-9q24/GHSA-g2xr-62jm-9q24.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-126", "CWE-787" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/10/GHSA-g583-v3h6-j432/GHSA-g583-v3h6-j432.json b/advisories/unreviewed/2022/10/GHSA-g583-v3h6-j432/GHSA-g583-v3h6-j432.json index 62c52677d63..91d67e42164 100644 --- a/advisories/unreviewed/2022/10/GHSA-g583-v3h6-j432/GHSA-g583-v3h6-j432.json +++ b/advisories/unreviewed/2022/10/GHSA-g583-v3h6-j432/GHSA-g583-v3h6-j432.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g583-v3h6-j432", - "modified": "2022-10-18T19:00:33Z", + "modified": "2025-05-15T15:31:11Z", "published": "2022-10-14T19:00:39Z", "aliases": [ "CVE-2022-38998" diff --git a/advisories/unreviewed/2022/10/GHSA-gmj5-fw2w-2qxq/GHSA-gmj5-fw2w-2qxq.json b/advisories/unreviewed/2022/10/GHSA-gmj5-fw2w-2qxq/GHSA-gmj5-fw2w-2qxq.json index 72e53f423d2..5eb20b5a527 100644 --- a/advisories/unreviewed/2022/10/GHSA-gmj5-fw2w-2qxq/GHSA-gmj5-fw2w-2qxq.json +++ b/advisories/unreviewed/2022/10/GHSA-gmj5-fw2w-2qxq/GHSA-gmj5-fw2w-2qxq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gmj5-fw2w-2qxq", - "modified": "2022-10-18T19:00:34Z", + "modified": "2025-05-15T15:31:11Z", "published": "2022-10-14T19:00:38Z", "aliases": [ "CVE-2022-38985" diff --git a/advisories/unreviewed/2022/10/GHSA-jcg7-m437-6g35/GHSA-jcg7-m437-6g35.json b/advisories/unreviewed/2022/10/GHSA-jcg7-m437-6g35/GHSA-jcg7-m437-6g35.json index b02d3086bbc..9748ee5429c 100644 --- a/advisories/unreviewed/2022/10/GHSA-jcg7-m437-6g35/GHSA-jcg7-m437-6g35.json +++ b/advisories/unreviewed/2022/10/GHSA-jcg7-m437-6g35/GHSA-jcg7-m437-6g35.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-121", "CWE-787" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/10/GHSA-jpcv-6q9f-58c6/GHSA-jpcv-6q9f-58c6.json b/advisories/unreviewed/2022/10/GHSA-jpcv-6q9f-58c6/GHSA-jpcv-6q9f-58c6.json index 59e1b5ed1c0..84cb78aedb6 100644 --- a/advisories/unreviewed/2022/10/GHSA-jpcv-6q9f-58c6/GHSA-jpcv-6q9f-58c6.json +++ b/advisories/unreviewed/2022/10/GHSA-jpcv-6q9f-58c6/GHSA-jpcv-6q9f-58c6.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-400", "CWE-862" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/10/GHSA-p994-97w6-6qr3/GHSA-p994-97w6-6qr3.json b/advisories/unreviewed/2022/10/GHSA-p994-97w6-6qr3/GHSA-p994-97w6-6qr3.json index bfaef21d9de..16e0d61ed7c 100644 --- a/advisories/unreviewed/2022/10/GHSA-p994-97w6-6qr3/GHSA-p994-97w6-6qr3.json +++ b/advisories/unreviewed/2022/10/GHSA-p994-97w6-6qr3/GHSA-p994-97w6-6qr3.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-79", "CWE-89" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2022/10/GHSA-px7v-2mmh-wrwf/GHSA-px7v-2mmh-wrwf.json b/advisories/unreviewed/2022/10/GHSA-px7v-2mmh-wrwf/GHSA-px7v-2mmh-wrwf.json index 3c4ef678e92..39411d86993 100644 --- a/advisories/unreviewed/2022/10/GHSA-px7v-2mmh-wrwf/GHSA-px7v-2mmh-wrwf.json +++ b/advisories/unreviewed/2022/10/GHSA-px7v-2mmh-wrwf/GHSA-px7v-2mmh-wrwf.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-400", "CWE-862" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/10/GHSA-q36q-v436-3mgq/GHSA-q36q-v436-3mgq.json b/advisories/unreviewed/2022/10/GHSA-q36q-v436-3mgq/GHSA-q36q-v436-3mgq.json index d55a9e2cb67..75105d83035 100644 --- a/advisories/unreviewed/2022/10/GHSA-q36q-v436-3mgq/GHSA-q36q-v436-3mgq.json +++ b/advisories/unreviewed/2022/10/GHSA-q36q-v436-3mgq/GHSA-q36q-v436-3mgq.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-200", "CWE-862" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/10/GHSA-q83g-rwc4-phpc/GHSA-q83g-rwc4-phpc.json b/advisories/unreviewed/2022/10/GHSA-q83g-rwc4-phpc/GHSA-q83g-rwc4-phpc.json index cbf261ee542..d0853f1f1a5 100644 --- a/advisories/unreviewed/2022/10/GHSA-q83g-rwc4-phpc/GHSA-q83g-rwc4-phpc.json +++ b/advisories/unreviewed/2022/10/GHSA-q83g-rwc4-phpc/GHSA-q83g-rwc4-phpc.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-200", "CWE-862" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/10/GHSA-qrg6-f4g9-6p3f/GHSA-qrg6-f4g9-6p3f.json b/advisories/unreviewed/2022/10/GHSA-qrg6-f4g9-6p3f/GHSA-qrg6-f4g9-6p3f.json index 3923718501e..da62a3605c8 100644 --- a/advisories/unreviewed/2022/10/GHSA-qrg6-f4g9-6p3f/GHSA-qrg6-f4g9-6p3f.json +++ b/advisories/unreviewed/2022/10/GHSA-qrg6-f4g9-6p3f/GHSA-qrg6-f4g9-6p3f.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-400", "CWE-862" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/10/GHSA-qrpw-2c8v-5x85/GHSA-qrpw-2c8v-5x85.json b/advisories/unreviewed/2022/10/GHSA-qrpw-2c8v-5x85/GHSA-qrpw-2c8v-5x85.json index 1b5047e1187..1e8d4f67b10 100644 --- a/advisories/unreviewed/2022/10/GHSA-qrpw-2c8v-5x85/GHSA-qrpw-2c8v-5x85.json +++ b/advisories/unreviewed/2022/10/GHSA-qrpw-2c8v-5x85/GHSA-qrpw-2c8v-5x85.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qrpw-2c8v-5x85", - "modified": "2022-10-18T19:00:34Z", + "modified": "2025-05-15T15:31:11Z", "published": "2022-10-14T19:00:38Z", "aliases": [ "CVE-2022-38983" diff --git a/advisories/unreviewed/2022/10/GHSA-v6hc-f6w3-8v26/GHSA-v6hc-f6w3-8v26.json b/advisories/unreviewed/2022/10/GHSA-v6hc-f6w3-8v26/GHSA-v6hc-f6w3-8v26.json index 17773f83b81..aa18a05633c 100644 --- a/advisories/unreviewed/2022/10/GHSA-v6hc-f6w3-8v26/GHSA-v6hc-f6w3-8v26.json +++ b/advisories/unreviewed/2022/10/GHSA-v6hc-f6w3-8v26/GHSA-v6hc-f6w3-8v26.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v6hc-f6w3-8v26", - "modified": "2022-10-18T19:00:34Z", + "modified": "2025-05-15T15:31:11Z", "published": "2022-10-14T19:00:38Z", "aliases": [ "CVE-2022-38984" diff --git a/advisories/unreviewed/2022/10/GHSA-wx3h-mcq4-xc2r/GHSA-wx3h-mcq4-xc2r.json b/advisories/unreviewed/2022/10/GHSA-wx3h-mcq4-xc2r/GHSA-wx3h-mcq4-xc2r.json index c01ac7df68c..1d703232259 100644 --- a/advisories/unreviewed/2022/10/GHSA-wx3h-mcq4-xc2r/GHSA-wx3h-mcq4-xc2r.json +++ b/advisories/unreviewed/2022/10/GHSA-wx3h-mcq4-xc2r/GHSA-wx3h-mcq4-xc2r.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-287" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-xj53-rhqx-x9x6/GHSA-xj53-rhqx-x9x6.json b/advisories/unreviewed/2022/10/GHSA-xj53-rhqx-x9x6/GHSA-xj53-rhqx-x9x6.json index 348bbcdeece..e84bb67ecfd 100644 --- a/advisories/unreviewed/2022/10/GHSA-xj53-rhqx-x9x6/GHSA-xj53-rhqx-x9x6.json +++ b/advisories/unreviewed/2022/10/GHSA-xj53-rhqx-x9x6/GHSA-xj53-rhqx-x9x6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xj53-rhqx-x9x6", - "modified": "2022-10-14T19:00:39Z", + "modified": "2025-05-15T15:31:07Z", "published": "2022-10-13T12:00:26Z", "aliases": [ "CVE-2022-2828" diff --git a/advisories/unreviewed/2024/01/GHSA-73m5-j333-fcwc/GHSA-73m5-j333-fcwc.json b/advisories/unreviewed/2024/01/GHSA-73m5-j333-fcwc/GHSA-73m5-j333-fcwc.json index f1001f81296..57209c0f799 100644 --- a/advisories/unreviewed/2024/01/GHSA-73m5-j333-fcwc/GHSA-73m5-j333-fcwc.json +++ b/advisories/unreviewed/2024/01/GHSA-73m5-j333-fcwc/GHSA-73m5-j333-fcwc.json @@ -105,7 +105,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/01/GHSA-8g27-wpjg-5vv9/GHSA-8g27-wpjg-5vv9.json b/advisories/unreviewed/2024/01/GHSA-8g27-wpjg-5vv9/GHSA-8g27-wpjg-5vv9.json index 70141cac072..15a240b602d 100644 --- a/advisories/unreviewed/2024/01/GHSA-8g27-wpjg-5vv9/GHSA-8g27-wpjg-5vv9.json +++ b/advisories/unreviewed/2024/01/GHSA-8g27-wpjg-5vv9/GHSA-8g27-wpjg-5vv9.json @@ -53,7 +53,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-922" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/01/GHSA-h5f8-8ppp-6wxq/GHSA-h5f8-8ppp-6wxq.json b/advisories/unreviewed/2024/01/GHSA-h5f8-8ppp-6wxq/GHSA-h5f8-8ppp-6wxq.json index 7b2c4b2392b..8ca359c3a4b 100644 --- a/advisories/unreviewed/2024/01/GHSA-h5f8-8ppp-6wxq/GHSA-h5f8-8ppp-6wxq.json +++ b/advisories/unreviewed/2024/01/GHSA-h5f8-8ppp-6wxq/GHSA-h5f8-8ppp-6wxq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h5f8-8ppp-6wxq", - "modified": "2024-01-29T15:30:24Z", + "modified": "2025-05-15T15:31:18Z", "published": "2024-01-24T00:30:32Z", "aliases": [ "CVE-2024-0809" @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-693" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/01/GHSA-vm83-g92c-f35p/GHSA-vm83-g92c-f35p.json b/advisories/unreviewed/2024/01/GHSA-vm83-g92c-f35p/GHSA-vm83-g92c-f35p.json index d84e9b437d9..5fd3b6d27c6 100644 --- a/advisories/unreviewed/2024/01/GHSA-vm83-g92c-f35p/GHSA-vm83-g92c-f35p.json +++ b/advisories/unreviewed/2024/01/GHSA-vm83-g92c-f35p/GHSA-vm83-g92c-f35p.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-396g-3mmq-29wc/GHSA-396g-3mmq-29wc.json b/advisories/unreviewed/2024/05/GHSA-396g-3mmq-29wc/GHSA-396g-3mmq-29wc.json index 2bbe5b44395..403d7f59b29 100644 --- a/advisories/unreviewed/2024/05/GHSA-396g-3mmq-29wc/GHSA-396g-3mmq-29wc.json +++ b/advisories/unreviewed/2024/05/GHSA-396g-3mmq-29wc/GHSA-396g-3mmq-29wc.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-54h8-92cq-9gxw/GHSA-54h8-92cq-9gxw.json b/advisories/unreviewed/2024/05/GHSA-54h8-92cq-9gxw/GHSA-54h8-92cq-9gxw.json index e9f3fc4db4b..5e8d6718dad 100644 --- a/advisories/unreviewed/2024/05/GHSA-54h8-92cq-9gxw/GHSA-54h8-92cq-9gxw.json +++ b/advisories/unreviewed/2024/05/GHSA-54h8-92cq-9gxw/GHSA-54h8-92cq-9gxw.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-5683-vqrc-j724/GHSA-5683-vqrc-j724.json b/advisories/unreviewed/2024/05/GHSA-5683-vqrc-j724/GHSA-5683-vqrc-j724.json index ebb9d676b30..2b97b1eb5cb 100644 --- a/advisories/unreviewed/2024/05/GHSA-5683-vqrc-j724/GHSA-5683-vqrc-j724.json +++ b/advisories/unreviewed/2024/05/GHSA-5683-vqrc-j724/GHSA-5683-vqrc-j724.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-56m5-6v25-whgm/GHSA-56m5-6v25-whgm.json b/advisories/unreviewed/2024/05/GHSA-56m5-6v25-whgm/GHSA-56m5-6v25-whgm.json index d25f96812b9..ba004fb2cd7 100644 --- a/advisories/unreviewed/2024/05/GHSA-56m5-6v25-whgm/GHSA-56m5-6v25-whgm.json +++ b/advisories/unreviewed/2024/05/GHSA-56m5-6v25-whgm/GHSA-56m5-6v25-whgm.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-5wq8-45w5-cxgr/GHSA-5wq8-45w5-cxgr.json b/advisories/unreviewed/2024/05/GHSA-5wq8-45w5-cxgr/GHSA-5wq8-45w5-cxgr.json index 9017ff2924f..efde1e3411a 100644 --- a/advisories/unreviewed/2024/05/GHSA-5wq8-45w5-cxgr/GHSA-5wq8-45w5-cxgr.json +++ b/advisories/unreviewed/2024/05/GHSA-5wq8-45w5-cxgr/GHSA-5wq8-45w5-cxgr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-6qj8-69gc-hqf2/GHSA-6qj8-69gc-hqf2.json b/advisories/unreviewed/2024/05/GHSA-6qj8-69gc-hqf2/GHSA-6qj8-69gc-hqf2.json index 14e879842f1..1ed2f51e6d5 100644 --- a/advisories/unreviewed/2024/05/GHSA-6qj8-69gc-hqf2/GHSA-6qj8-69gc-hqf2.json +++ b/advisories/unreviewed/2024/05/GHSA-6qj8-69gc-hqf2/GHSA-6qj8-69gc-hqf2.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-7fh8-jfq5-3gc5/GHSA-7fh8-jfq5-3gc5.json b/advisories/unreviewed/2024/05/GHSA-7fh8-jfq5-3gc5/GHSA-7fh8-jfq5-3gc5.json index 8cc3b03c32a..6473246fa85 100644 --- a/advisories/unreviewed/2024/05/GHSA-7fh8-jfq5-3gc5/GHSA-7fh8-jfq5-3gc5.json +++ b/advisories/unreviewed/2024/05/GHSA-7fh8-jfq5-3gc5/GHSA-7fh8-jfq5-3gc5.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-7gh2-59h4-gcm3/GHSA-7gh2-59h4-gcm3.json b/advisories/unreviewed/2024/05/GHSA-7gh2-59h4-gcm3/GHSA-7gh2-59h4-gcm3.json index f00be133718..65dcbb705db 100644 --- a/advisories/unreviewed/2024/05/GHSA-7gh2-59h4-gcm3/GHSA-7gh2-59h4-gcm3.json +++ b/advisories/unreviewed/2024/05/GHSA-7gh2-59h4-gcm3/GHSA-7gh2-59h4-gcm3.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-84g3-f88g-74fq/GHSA-84g3-f88g-74fq.json b/advisories/unreviewed/2024/05/GHSA-84g3-f88g-74fq/GHSA-84g3-f88g-74fq.json index 3bbcaa3d1d8..45e621cf6a1 100644 --- a/advisories/unreviewed/2024/05/GHSA-84g3-f88g-74fq/GHSA-84g3-f88g-74fq.json +++ b/advisories/unreviewed/2024/05/GHSA-84g3-f88g-74fq/GHSA-84g3-f88g-74fq.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-9997-w8mf-jp86/GHSA-9997-w8mf-jp86.json b/advisories/unreviewed/2024/05/GHSA-9997-w8mf-jp86/GHSA-9997-w8mf-jp86.json index fdbcef3280c..2f1bc7ae09c 100644 --- a/advisories/unreviewed/2024/05/GHSA-9997-w8mf-jp86/GHSA-9997-w8mf-jp86.json +++ b/advisories/unreviewed/2024/05/GHSA-9997-w8mf-jp86/GHSA-9997-w8mf-jp86.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-cm6j-82c5-ggcj/GHSA-cm6j-82c5-ggcj.json b/advisories/unreviewed/2024/05/GHSA-cm6j-82c5-ggcj/GHSA-cm6j-82c5-ggcj.json index 79535939594..242b94351c3 100644 --- a/advisories/unreviewed/2024/05/GHSA-cm6j-82c5-ggcj/GHSA-cm6j-82c5-ggcj.json +++ b/advisories/unreviewed/2024/05/GHSA-cm6j-82c5-ggcj/GHSA-cm6j-82c5-ggcj.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-cxm9-9r6p-3785/GHSA-cxm9-9r6p-3785.json b/advisories/unreviewed/2024/05/GHSA-cxm9-9r6p-3785/GHSA-cxm9-9r6p-3785.json index 42165741885..cf280a87a2d 100644 --- a/advisories/unreviewed/2024/05/GHSA-cxm9-9r6p-3785/GHSA-cxm9-9r6p-3785.json +++ b/advisories/unreviewed/2024/05/GHSA-cxm9-9r6p-3785/GHSA-cxm9-9r6p-3785.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-f7vw-6h99-wmxg/GHSA-f7vw-6h99-wmxg.json b/advisories/unreviewed/2024/05/GHSA-f7vw-6h99-wmxg/GHSA-f7vw-6h99-wmxg.json index 36685cbad33..6776fc50587 100644 --- a/advisories/unreviewed/2024/05/GHSA-f7vw-6h99-wmxg/GHSA-f7vw-6h99-wmxg.json +++ b/advisories/unreviewed/2024/05/GHSA-f7vw-6h99-wmxg/GHSA-f7vw-6h99-wmxg.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-hphp-8vrw-jr5x/GHSA-hphp-8vrw-jr5x.json b/advisories/unreviewed/2024/05/GHSA-hphp-8vrw-jr5x/GHSA-hphp-8vrw-jr5x.json index 4e4a43d15b9..9fcf3d199fb 100644 --- a/advisories/unreviewed/2024/05/GHSA-hphp-8vrw-jr5x/GHSA-hphp-8vrw-jr5x.json +++ b/advisories/unreviewed/2024/05/GHSA-hphp-8vrw-jr5x/GHSA-hphp-8vrw-jr5x.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-j46m-35mg-whvf/GHSA-j46m-35mg-whvf.json b/advisories/unreviewed/2024/05/GHSA-j46m-35mg-whvf/GHSA-j46m-35mg-whvf.json index 9e8b5b257cf..8b963e9b23c 100644 --- a/advisories/unreviewed/2024/05/GHSA-j46m-35mg-whvf/GHSA-j46m-35mg-whvf.json +++ b/advisories/unreviewed/2024/05/GHSA-j46m-35mg-whvf/GHSA-j46m-35mg-whvf.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-p3vp-jg8v-gfmh/GHSA-p3vp-jg8v-gfmh.json b/advisories/unreviewed/2024/05/GHSA-p3vp-jg8v-gfmh/GHSA-p3vp-jg8v-gfmh.json index a67375f0c52..8a421ea5717 100644 --- a/advisories/unreviewed/2024/05/GHSA-p3vp-jg8v-gfmh/GHSA-p3vp-jg8v-gfmh.json +++ b/advisories/unreviewed/2024/05/GHSA-p3vp-jg8v-gfmh/GHSA-p3vp-jg8v-gfmh.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-pc4x-j8x7-66jg/GHSA-pc4x-j8x7-66jg.json b/advisories/unreviewed/2024/05/GHSA-pc4x-j8x7-66jg/GHSA-pc4x-j8x7-66jg.json index 2629296011a..dbc761cb2fd 100644 --- a/advisories/unreviewed/2024/05/GHSA-pc4x-j8x7-66jg/GHSA-pc4x-j8x7-66jg.json +++ b/advisories/unreviewed/2024/05/GHSA-pc4x-j8x7-66jg/GHSA-pc4x-j8x7-66jg.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-q2jj-h86w-hpw2/GHSA-q2jj-h86w-hpw2.json b/advisories/unreviewed/2024/05/GHSA-q2jj-h86w-hpw2/GHSA-q2jj-h86w-hpw2.json index 57ce3d5d961..4c72135f4e6 100644 --- a/advisories/unreviewed/2024/05/GHSA-q2jj-h86w-hpw2/GHSA-q2jj-h86w-hpw2.json +++ b/advisories/unreviewed/2024/05/GHSA-q2jj-h86w-hpw2/GHSA-q2jj-h86w-hpw2.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-rm3h-m7rx-3jrq/GHSA-rm3h-m7rx-3jrq.json b/advisories/unreviewed/2024/05/GHSA-rm3h-m7rx-3jrq/GHSA-rm3h-m7rx-3jrq.json index a353d194f57..175b363fd44 100644 --- a/advisories/unreviewed/2024/05/GHSA-rm3h-m7rx-3jrq/GHSA-rm3h-m7rx-3jrq.json +++ b/advisories/unreviewed/2024/05/GHSA-rm3h-m7rx-3jrq/GHSA-rm3h-m7rx-3jrq.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-vvgm-85j8-2648/GHSA-vvgm-85j8-2648.json b/advisories/unreviewed/2024/05/GHSA-vvgm-85j8-2648/GHSA-vvgm-85j8-2648.json index c27051d183d..ac011158469 100644 --- a/advisories/unreviewed/2024/05/GHSA-vvgm-85j8-2648/GHSA-vvgm-85j8-2648.json +++ b/advisories/unreviewed/2024/05/GHSA-vvgm-85j8-2648/GHSA-vvgm-85j8-2648.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-w682-79hv-gcr8/GHSA-w682-79hv-gcr8.json b/advisories/unreviewed/2024/05/GHSA-w682-79hv-gcr8/GHSA-w682-79hv-gcr8.json index 3bbd5d03eea..81b70dc26ea 100644 --- a/advisories/unreviewed/2024/05/GHSA-w682-79hv-gcr8/GHSA-w682-79hv-gcr8.json +++ b/advisories/unreviewed/2024/05/GHSA-w682-79hv-gcr8/GHSA-w682-79hv-gcr8.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-wx9p-r67p-8cjf/GHSA-wx9p-r67p-8cjf.json b/advisories/unreviewed/2024/05/GHSA-wx9p-r67p-8cjf/GHSA-wx9p-r67p-8cjf.json index 877885f26da..8525f6d6643 100644 --- a/advisories/unreviewed/2024/05/GHSA-wx9p-r67p-8cjf/GHSA-wx9p-r67p-8cjf.json +++ b/advisories/unreviewed/2024/05/GHSA-wx9p-r67p-8cjf/GHSA-wx9p-r67p-8cjf.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-x989-xh8p-mqvh/GHSA-x989-xh8p-mqvh.json b/advisories/unreviewed/2024/05/GHSA-x989-xh8p-mqvh/GHSA-x989-xh8p-mqvh.json index 6f1c0bcece3..85245a2df62 100644 --- a/advisories/unreviewed/2024/05/GHSA-x989-xh8p-mqvh/GHSA-x989-xh8p-mqvh.json +++ b/advisories/unreviewed/2024/05/GHSA-x989-xh8p-mqvh/GHSA-x989-xh8p-mqvh.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-xm4h-65xf-x594/GHSA-xm4h-65xf-x594.json b/advisories/unreviewed/2024/05/GHSA-xm4h-65xf-x594/GHSA-xm4h-65xf-x594.json index 8fde6110b5c..6fb0e794189 100644 --- a/advisories/unreviewed/2024/05/GHSA-xm4h-65xf-x594/GHSA-xm4h-65xf-x594.json +++ b/advisories/unreviewed/2024/05/GHSA-xm4h-65xf-x594/GHSA-xm4h-65xf-x594.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-8pvr-h3wm-pfpm/GHSA-8pvr-h3wm-pfpm.json b/advisories/unreviewed/2024/11/GHSA-8pvr-h3wm-pfpm/GHSA-8pvr-h3wm-pfpm.json index a261454277f..9f66adb54d7 100644 --- a/advisories/unreviewed/2024/11/GHSA-8pvr-h3wm-pfpm/GHSA-8pvr-h3wm-pfpm.json +++ b/advisories/unreviewed/2024/11/GHSA-8pvr-h3wm-pfpm/GHSA-8pvr-h3wm-pfpm.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-cpgg-w28j-jvph/GHSA-cpgg-w28j-jvph.json b/advisories/unreviewed/2024/11/GHSA-cpgg-w28j-jvph/GHSA-cpgg-w28j-jvph.json index 5c0ea608d17..92524669f58 100644 --- a/advisories/unreviewed/2024/11/GHSA-cpgg-w28j-jvph/GHSA-cpgg-w28j-jvph.json +++ b/advisories/unreviewed/2024/11/GHSA-cpgg-w28j-jvph/GHSA-cpgg-w28j-jvph.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-jcwm-grfm-4xmh/GHSA-jcwm-grfm-4xmh.json b/advisories/unreviewed/2025/03/GHSA-jcwm-grfm-4xmh/GHSA-jcwm-grfm-4xmh.json index 57e6be89a91..b50e1ddfe93 100644 --- a/advisories/unreviewed/2025/03/GHSA-jcwm-grfm-4xmh/GHSA-jcwm-grfm-4xmh.json +++ b/advisories/unreviewed/2025/03/GHSA-jcwm-grfm-4xmh/GHSA-jcwm-grfm-4xmh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jcwm-grfm-4xmh", - "modified": "2025-03-13T12:30:32Z", + "modified": "2025-05-15T15:31:22Z", "published": "2025-03-12T18:32:52Z", "aliases": [ "CVE-2025-1683" @@ -34,6 +34,10 @@ { "type": "WEB", "url": "https://www.1e.com/trust-security-compliance/cve-info" + }, + { + "type": "WEB", + "url": "https://www.teamviewer.com/en/resources/trust-center/security-bulletins/1e-2025-2001" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/05/GHSA-25wx-48p7-wfpx/GHSA-25wx-48p7-wfpx.json b/advisories/unreviewed/2025/05/GHSA-25wx-48p7-wfpx/GHSA-25wx-48p7-wfpx.json index bdbc4b479c2..44232267a0b 100644 --- a/advisories/unreviewed/2025/05/GHSA-25wx-48p7-wfpx/GHSA-25wx-48p7-wfpx.json +++ b/advisories/unreviewed/2025/05/GHSA-25wx-48p7-wfpx/GHSA-25wx-48p7-wfpx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-25wx-48p7-wfpx", - "modified": "2025-05-15T00:30:26Z", + "modified": "2025-05-15T15:31:26Z", "published": "2025-05-15T00:30:26Z", "aliases": [ "CVE-2025-29691" ], "details": "A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the userName parameter at /login/LoginsController.java.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-14T22:15:17Z" diff --git a/advisories/unreviewed/2025/05/GHSA-2fmh-chfc-392c/GHSA-2fmh-chfc-392c.json b/advisories/unreviewed/2025/05/GHSA-2fmh-chfc-392c/GHSA-2fmh-chfc-392c.json index 7f9301833db..10dc91e8253 100644 --- a/advisories/unreviewed/2025/05/GHSA-2fmh-chfc-392c/GHSA-2fmh-chfc-392c.json +++ b/advisories/unreviewed/2025/05/GHSA-2fmh-chfc-392c/GHSA-2fmh-chfc-392c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2fmh-chfc-392c", - "modified": "2025-05-14T21:31:19Z", + "modified": "2025-05-15T15:31:24Z", "published": "2025-05-14T21:31:19Z", "aliases": [ "CVE-2025-32363" ], "details": "mediDOK before 2.5.18.43 allows remote attackers to achieve remote code execution on a target system via deserialization of untrusted data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-14T20:15:22Z" diff --git a/advisories/unreviewed/2025/05/GHSA-357g-hmp7-jxcf/GHSA-357g-hmp7-jxcf.json b/advisories/unreviewed/2025/05/GHSA-357g-hmp7-jxcf/GHSA-357g-hmp7-jxcf.json new file mode 100644 index 00000000000..bdcc9757716 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-357g-hmp7-jxcf/GHSA-357g-hmp7-jxcf.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-357g-hmp7-jxcf", + "modified": "2025-05-15T15:31:27Z", + "published": "2025-05-15T15:31:27Z", + "aliases": [ + "CVE-2025-44185" + ], + "details": "SourceCodester Best Employee Management System V1.0 is vulnerable to Cross Site Request Forgery (CSRF) in /admin/change_pass.php via the password parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44185" + }, + { + "type": "WEB", + "url": "https://github.com/cumakurt/CVE-SourceCodester-Best-Employee-Management-System-1.0/blob/main/CVE-2025-44185-SourceCodester-Best-Employee-Management-System-1.0-CSRF-in-Password-Change.md" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com/php/17689/best-employee-management-system-php.html" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com/sites/default/files/download/mayuri_k/_hr_soft_updated.zip" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T15:16:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3c5g-ff4p-m2gx/GHSA-3c5g-ff4p-m2gx.json b/advisories/unreviewed/2025/05/GHSA-3c5g-ff4p-m2gx/GHSA-3c5g-ff4p-m2gx.json index c48517a1a91..e18199c707c 100644 --- a/advisories/unreviewed/2025/05/GHSA-3c5g-ff4p-m2gx/GHSA-3c5g-ff4p-m2gx.json +++ b/advisories/unreviewed/2025/05/GHSA-3c5g-ff4p-m2gx/GHSA-3c5g-ff4p-m2gx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3c5g-ff4p-m2gx", - "modified": "2025-05-14T21:31:20Z", + "modified": "2025-05-15T15:31:24Z", "published": "2025-05-14T21:31:20Z", "aliases": [ "CVE-2025-44024" ], "details": "Cross-Site Scripting (XSS) vulnerability was discovered in the Pichome system v2.1.0 and before. The vulnerability exists due to insufficient sanitization of user input in the login form. An attacker can inject malicious JavaScript code into the username or password fields during the login process", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-14T21:15:59Z" diff --git a/advisories/unreviewed/2025/05/GHSA-3jpv-h4fh-v8h9/GHSA-3jpv-h4fh-v8h9.json b/advisories/unreviewed/2025/05/GHSA-3jpv-h4fh-v8h9/GHSA-3jpv-h4fh-v8h9.json index a3e3f538ff8..995bea74126 100644 --- a/advisories/unreviewed/2025/05/GHSA-3jpv-h4fh-v8h9/GHSA-3jpv-h4fh-v8h9.json +++ b/advisories/unreviewed/2025/05/GHSA-3jpv-h4fh-v8h9/GHSA-3jpv-h4fh-v8h9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3jpv-h4fh-v8h9", - "modified": "2025-05-13T00:31:14Z", + "modified": "2025-05-15T15:31:22Z", "published": "2025-05-13T00:31:14Z", "aliases": [ "CVE-2025-31215" ], "details": "The issue was addressed with improved checks. This issue is fixed in watchOS 11.5, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, Safari 18.5. Processing maliciously crafted web content may lead to an unexpected process crash.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:22Z" diff --git a/advisories/unreviewed/2025/05/GHSA-45cr-hmqj-f6p9/GHSA-45cr-hmqj-f6p9.json b/advisories/unreviewed/2025/05/GHSA-45cr-hmqj-f6p9/GHSA-45cr-hmqj-f6p9.json new file mode 100644 index 00000000000..c02e0946e83 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-45cr-hmqj-f6p9/GHSA-45cr-hmqj-f6p9.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-45cr-hmqj-f6p9", + "modified": "2025-05-15T15:31:26Z", + "published": "2025-05-15T15:31:26Z", + "aliases": [ + "CVE-2025-4695" + ], + "details": "A vulnerability was found in PHPGurukul Cyber Cafe Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /add-users.php. The manipulation of the argument uadd leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4695" + }, + { + "type": "WEB", + "url": "https://github.com/Iandweb/CVE/issues/14" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.308994" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.308994" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.567673" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T13:16:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-67qh-xgqw-xxw5/GHSA-67qh-xgqw-xxw5.json b/advisories/unreviewed/2025/05/GHSA-67qh-xgqw-xxw5/GHSA-67qh-xgqw-xxw5.json new file mode 100644 index 00000000000..a3933aee695 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-67qh-xgqw-xxw5/GHSA-67qh-xgqw-xxw5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67qh-xgqw-xxw5", + "modified": "2025-05-15T15:31:26Z", + "published": "2025-05-15T15:31:26Z", + "aliases": [ + "CVE-2025-44182" + ], + "details": "Phpgurukul Vehicle Record Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via the vehiclename, modelnumber, regnumber, vehiclesubtype, chasisnum, enginenumber' in the /admin/edit-vehicle.php component. This allows attackers to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44182" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com/vehicle-record-system-using-php-and-mysql" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T14:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-68gh-935w-wv3c/GHSA-68gh-935w-wv3c.json b/advisories/unreviewed/2025/05/GHSA-68gh-935w-wv3c/GHSA-68gh-935w-wv3c.json index de2d23b61b1..b0d3d6e9936 100644 --- a/advisories/unreviewed/2025/05/GHSA-68gh-935w-wv3c/GHSA-68gh-935w-wv3c.json +++ b/advisories/unreviewed/2025/05/GHSA-68gh-935w-wv3c/GHSA-68gh-935w-wv3c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-68gh-935w-wv3c", - "modified": "2025-05-14T21:31:19Z", + "modified": "2025-05-15T15:31:24Z", "published": "2025-05-14T21:31:19Z", "aliases": [ "CVE-2024-55569" ], "details": "An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. The lack of a length check leads to out-of-bounds writes.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-14T21:15:57Z" diff --git a/advisories/unreviewed/2025/05/GHSA-69gm-vfv3-578x/GHSA-69gm-vfv3-578x.json b/advisories/unreviewed/2025/05/GHSA-69gm-vfv3-578x/GHSA-69gm-vfv3-578x.json index 7008aa77e3a..14a8fa3438e 100644 --- a/advisories/unreviewed/2025/05/GHSA-69gm-vfv3-578x/GHSA-69gm-vfv3-578x.json +++ b/advisories/unreviewed/2025/05/GHSA-69gm-vfv3-578x/GHSA-69gm-vfv3-578x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-69gm-vfv3-578x", - "modified": "2025-05-14T15:31:38Z", + "modified": "2025-05-15T15:31:23Z", "published": "2025-05-14T15:31:38Z", "aliases": [ "CVE-2024-10864" diff --git a/advisories/unreviewed/2025/05/GHSA-69m9-2g5j-9m4h/GHSA-69m9-2g5j-9m4h.json b/advisories/unreviewed/2025/05/GHSA-69m9-2g5j-9m4h/GHSA-69m9-2g5j-9m4h.json index 7d9444d43fe..3d6e29dfebf 100644 --- a/advisories/unreviewed/2025/05/GHSA-69m9-2g5j-9m4h/GHSA-69m9-2g5j-9m4h.json +++ b/advisories/unreviewed/2025/05/GHSA-69m9-2g5j-9m4h/GHSA-69m9-2g5j-9m4h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-69m9-2g5j-9m4h", - "modified": "2025-05-14T18:30:47Z", + "modified": "2025-05-15T15:31:23Z", "published": "2025-05-14T18:30:47Z", "aliases": [ "CVE-2025-3877" ], "details": "A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's desktop or home directory without prompting, even if auto-saving is disabled. This behavior can be abused to fill the disk with garbage data (e.g. using /dev/urandom on Linux) or to leak Windows credentials via SMB links when the email is viewed in HTML mode. While user interaction is required to download the .pdf file, visual obfuscation can conceal the download trigger. Viewing the email in HTML mode is enough to load external content. This vulnerability affects Thunderbird < 128.10.1 and Thunderbird < 138.0.1.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-14T17:15:48Z" diff --git a/advisories/unreviewed/2025/05/GHSA-6v8w-jmjm-w8cq/GHSA-6v8w-jmjm-w8cq.json b/advisories/unreviewed/2025/05/GHSA-6v8w-jmjm-w8cq/GHSA-6v8w-jmjm-w8cq.json index a00a9630128..a6d2e0ba0f4 100644 --- a/advisories/unreviewed/2025/05/GHSA-6v8w-jmjm-w8cq/GHSA-6v8w-jmjm-w8cq.json +++ b/advisories/unreviewed/2025/05/GHSA-6v8w-jmjm-w8cq/GHSA-6v8w-jmjm-w8cq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6v8w-jmjm-w8cq", - "modified": "2025-05-14T15:31:38Z", + "modified": "2025-05-15T15:31:23Z", "published": "2025-05-14T15:31:38Z", "aliases": [ "CVE-2024-10865" diff --git a/advisories/unreviewed/2025/05/GHSA-775f-97x4-x974/GHSA-775f-97x4-x974.json b/advisories/unreviewed/2025/05/GHSA-775f-97x4-x974/GHSA-775f-97x4-x974.json new file mode 100644 index 00000000000..0a35740b2ac --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-775f-97x4-x974/GHSA-775f-97x4-x974.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-775f-97x4-x974", + "modified": "2025-05-15T15:31:27Z", + "published": "2025-05-15T15:31:27Z", + "aliases": [ + "CVE-2025-46053" + ], + "details": "A SQL Injection vulnerability in WebERP v4.15.2 allows attackers to execute arbitrary SQL commands and extract sensitive data by injecting a crafted payload into the ReportID and ReplaceReportID parameters within a POST request to /reportwriter/admin/ReportCreator.php", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46053" + }, + { + "type": "WEB", + "url": "https://github.com/johnchd/CVEs/blob/main/WebERP/CVE-2025-46053%20-%20SQLi.md" + }, + { + "type": "WEB", + "url": "https://www.weberp.org" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T15:16:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9c4g-4r76-5rq7/GHSA-9c4g-4r76-5rq7.json b/advisories/unreviewed/2025/05/GHSA-9c4g-4r76-5rq7/GHSA-9c4g-4r76-5rq7.json new file mode 100644 index 00000000000..d2f6d4292f4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9c4g-4r76-5rq7/GHSA-9c4g-4r76-5rq7.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9c4g-4r76-5rq7", + "modified": "2025-05-15T15:31:26Z", + "published": "2025-05-15T15:31:26Z", + "aliases": [ + "CVE-2025-4696" + ], + "details": "A vulnerability was found in PHPGurukul Cyber Cafe Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /search.php. The manipulation of the argument searchdata leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4696" + }, + { + "type": "WEB", + "url": "https://github.com/Iandweb/CVE/issues/15" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.308995" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.308995" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.567683" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T13:16:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9ppr-22gc-5w96/GHSA-9ppr-22gc-5w96.json b/advisories/unreviewed/2025/05/GHSA-9ppr-22gc-5w96/GHSA-9ppr-22gc-5w96.json index aadfcef8b0d..dbb4c43d978 100644 --- a/advisories/unreviewed/2025/05/GHSA-9ppr-22gc-5w96/GHSA-9ppr-22gc-5w96.json +++ b/advisories/unreviewed/2025/05/GHSA-9ppr-22gc-5w96/GHSA-9ppr-22gc-5w96.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9ppr-22gc-5w96", - "modified": "2025-05-15T00:30:26Z", + "modified": "2025-05-15T15:31:25Z", "published": "2025-05-15T00:30:26Z", "aliases": [ "CVE-2025-29688" ], "details": "A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the title parameter at /daymanager/daymanageabilitycontroller.java.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-14T22:15:17Z" diff --git a/advisories/unreviewed/2025/05/GHSA-cp9r-g575-xc5f/GHSA-cp9r-g575-xc5f.json b/advisories/unreviewed/2025/05/GHSA-cp9r-g575-xc5f/GHSA-cp9r-g575-xc5f.json index 95125026f65..778296d1d8d 100644 --- a/advisories/unreviewed/2025/05/GHSA-cp9r-g575-xc5f/GHSA-cp9r-g575-xc5f.json +++ b/advisories/unreviewed/2025/05/GHSA-cp9r-g575-xc5f/GHSA-cp9r-g575-xc5f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cp9r-g575-xc5f", - "modified": "2025-05-14T21:31:20Z", + "modified": "2025-05-15T15:31:25Z", "published": "2025-05-14T21:31:20Z", "aliases": [ "CVE-2025-47888" ], "details": "Jenkins DingTalk Plugin 2.7.3 and earlier unconditionally disables SSL/TLS certificate and hostname validation for connections to the configured DingTalk webhooks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-14T21:15:59Z" diff --git a/advisories/unreviewed/2025/05/GHSA-fvmq-5x7q-w2cc/GHSA-fvmq-5x7q-w2cc.json b/advisories/unreviewed/2025/05/GHSA-fvmq-5x7q-w2cc/GHSA-fvmq-5x7q-w2cc.json index a61b89d3a5a..37bb3868dfe 100644 --- a/advisories/unreviewed/2025/05/GHSA-fvmq-5x7q-w2cc/GHSA-fvmq-5x7q-w2cc.json +++ b/advisories/unreviewed/2025/05/GHSA-fvmq-5x7q-w2cc/GHSA-fvmq-5x7q-w2cc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fvmq-5x7q-w2cc", - "modified": "2025-05-14T18:30:48Z", + "modified": "2025-05-15T15:31:23Z", "published": "2025-05-14T18:30:48Z", "aliases": [ "CVE-2025-44184" ], "details": "SourceCodester Best Employee Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/profile.php via the website_image, fname, lname, contact, username, and address parameters.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-14T17:15:49Z" diff --git a/advisories/unreviewed/2025/05/GHSA-gh72-rxwr-vvrq/GHSA-gh72-rxwr-vvrq.json b/advisories/unreviewed/2025/05/GHSA-gh72-rxwr-vvrq/GHSA-gh72-rxwr-vvrq.json new file mode 100644 index 00000000000..de8849bf0d7 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gh72-rxwr-vvrq/GHSA-gh72-rxwr-vvrq.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gh72-rxwr-vvrq", + "modified": "2025-05-15T15:31:26Z", + "published": "2025-05-15T15:31:26Z", + "aliases": [ + "CVE-2025-44180" + ], + "details": "Phpgurukul Vehicle Record Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /edit-brand.php?bid={brandId}.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44180" + }, + { + "type": "WEB", + "url": "https://github.com/nscerol/Vehicle-Record-Management-System/blob/main/CVE-2025-44180-Vehicle-Record-Management-System-1.0-Stored-Cross-Site-Scripting-Vulnerability.md" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com/vehicle-record-system-using-php-and-mysql" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T14:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-ghrr-gjmc-qq88/GHSA-ghrr-gjmc-qq88.json b/advisories/unreviewed/2025/05/GHSA-ghrr-gjmc-qq88/GHSA-ghrr-gjmc-qq88.json index ffa83752864..711e3f93221 100644 --- a/advisories/unreviewed/2025/05/GHSA-ghrr-gjmc-qq88/GHSA-ghrr-gjmc-qq88.json +++ b/advisories/unreviewed/2025/05/GHSA-ghrr-gjmc-qq88/GHSA-ghrr-gjmc-qq88.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-ghrr-gjmc-qq88", - "modified": "2025-05-14T21:31:20Z", + "modified": "2025-05-15T15:31:24Z", "published": "2025-05-14T21:31:20Z", "aliases": [ "CVE-2025-26783" ], "details": "An issue was discovered in RRC in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 2100, 1280, 2200, 1330, 1380, 1480, 2400, W1000, Modem 5300, and Modem 5400. Incorrect handling of undefined values leads to a Denial of Service.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-14T21:15:58Z" diff --git a/advisories/unreviewed/2025/05/GHSA-gwqp-vrqv-c9q6/GHSA-gwqp-vrqv-c9q6.json b/advisories/unreviewed/2025/05/GHSA-gwqp-vrqv-c9q6/GHSA-gwqp-vrqv-c9q6.json index 255e17e1203..8ed13a11e24 100644 --- a/advisories/unreviewed/2025/05/GHSA-gwqp-vrqv-c9q6/GHSA-gwqp-vrqv-c9q6.json +++ b/advisories/unreviewed/2025/05/GHSA-gwqp-vrqv-c9q6/GHSA-gwqp-vrqv-c9q6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gwqp-vrqv-c9q6", - "modified": "2025-05-14T21:31:19Z", + "modified": "2025-05-15T15:31:24Z", "published": "2025-05-14T21:31:19Z", "aliases": [ "CVE-2024-58101" ], "details": "Samsung Galaxy Buds and Galaxy Buds 2 audio devices are Bluetooth pairable by default without user input nor a way to stop this mode. As a consequence, audio playback takeover or even microphone recording without user consent or notification is achieved. Note: This is considered a low severity vulnerability by the vendor.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-14T20:15:21Z" diff --git a/advisories/unreviewed/2025/05/GHSA-h6cg-6m9j-xj9g/GHSA-h6cg-6m9j-xj9g.json b/advisories/unreviewed/2025/05/GHSA-h6cg-6m9j-xj9g/GHSA-h6cg-6m9j-xj9g.json index 2d7063bdfa2..70655ee0c58 100644 --- a/advisories/unreviewed/2025/05/GHSA-h6cg-6m9j-xj9g/GHSA-h6cg-6m9j-xj9g.json +++ b/advisories/unreviewed/2025/05/GHSA-h6cg-6m9j-xj9g/GHSA-h6cg-6m9j-xj9g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h6cg-6m9j-xj9g", - "modified": "2025-05-14T18:30:48Z", + "modified": "2025-05-15T15:31:23Z", "published": "2025-05-14T18:30:47Z", "aliases": [ "CVE-2025-3909" ], "details": "Thunderbird's handling of the X-Mozilla-External-Attachment-URL header can be exploited to execute JavaScript in the file:/// context. By crafting a nested email attachment (message/rfc822) and setting its content type to application/pdf, Thunderbird may incorrectly render it as HTML when opened, allowing the embedded JavaScript to run without requiring a file download. This behavior relies on Thunderbird auto-saving the attachment to /tmp and linking to it via the file:/// protocol, potentially enabling JavaScript execution as part of the HTML. This vulnerability affects Thunderbird < 128.10.1 and Thunderbird < 138.0.1.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-290" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-14T17:15:48Z" diff --git a/advisories/unreviewed/2025/05/GHSA-h8j4-8q54-qmm9/GHSA-h8j4-8q54-qmm9.json b/advisories/unreviewed/2025/05/GHSA-h8j4-8q54-qmm9/GHSA-h8j4-8q54-qmm9.json index 27690ef9353..d41cc1285d6 100644 --- a/advisories/unreviewed/2025/05/GHSA-h8j4-8q54-qmm9/GHSA-h8j4-8q54-qmm9.json +++ b/advisories/unreviewed/2025/05/GHSA-h8j4-8q54-qmm9/GHSA-h8j4-8q54-qmm9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h8j4-8q54-qmm9", - "modified": "2025-05-13T00:31:12Z", + "modified": "2025-05-15T15:31:22Z", "published": "2025-05-13T00:31:12Z", "aliases": [ "CVE-2025-24144" ], "details": "An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.6, visionOS 2.3, iPadOS 17.7.7, watchOS 11.3, macOS Ventura 13.7.6, iOS 18.3 and iPadOS 18.3, tvOS 18.3. An app may be able to leak sensitive kernel state.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:19Z" diff --git a/advisories/unreviewed/2025/05/GHSA-hg9g-m8wg-jv2x/GHSA-hg9g-m8wg-jv2x.json b/advisories/unreviewed/2025/05/GHSA-hg9g-m8wg-jv2x/GHSA-hg9g-m8wg-jv2x.json index 28f692f7170..f29410bc0cf 100644 --- a/advisories/unreviewed/2025/05/GHSA-hg9g-m8wg-jv2x/GHSA-hg9g-m8wg-jv2x.json +++ b/advisories/unreviewed/2025/05/GHSA-hg9g-m8wg-jv2x/GHSA-hg9g-m8wg-jv2x.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-119" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-hm4p-7q9f-fx6q/GHSA-hm4p-7q9f-fx6q.json b/advisories/unreviewed/2025/05/GHSA-hm4p-7q9f-fx6q/GHSA-hm4p-7q9f-fx6q.json new file mode 100644 index 00000000000..d04dbe7d2e7 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hm4p-7q9f-fx6q/GHSA-hm4p-7q9f-fx6q.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hm4p-7q9f-fx6q", + "modified": "2025-05-15T15:31:26Z", + "published": "2025-05-15T15:31:26Z", + "aliases": [ + "CVE-2025-46052" + ], + "details": "An error-based SQL Injection (SQLi) vulnerability in WebERP v4.15.2 allows attackers to execute arbitrary SQL command and extract sensitive data by injecting a crafted payload into the DEL form field in a POST request to /StockCounts.php", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46052" + }, + { + "type": "WEB", + "url": "https://github.com/johnchd/CVEs/blob/main/WebERP/CVE-2025-46052%20-%20SQLi.md" + }, + { + "type": "WEB", + "url": "https://www.weberp.org" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T14:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hp48-2c8c-rm54/GHSA-hp48-2c8c-rm54.json b/advisories/unreviewed/2025/05/GHSA-hp48-2c8c-rm54/GHSA-hp48-2c8c-rm54.json new file mode 100644 index 00000000000..192f17ffa6e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hp48-2c8c-rm54/GHSA-hp48-2c8c-rm54.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hp48-2c8c-rm54", + "modified": "2025-05-15T15:31:27Z", + "published": "2025-05-15T15:31:27Z", + "aliases": [ + "CVE-2025-4701" + ], + "details": "A vulnerability, which was classified as problematic, has been found in VITA-MLLM Freeze-Omni up to 20250421. This issue affects the function torch.load of the file models/utils.py. The manipulation of the argument path leads to deserialization. It is possible to launch the attack on the local host.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4701" + }, + { + "type": "WEB", + "url": "https://github.com/VITA-MLLM/Freeze-Omni/issues/29" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.308999" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.308999" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.567796" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T15:16:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-j6wh-9fq4-rcrh/GHSA-j6wh-9fq4-rcrh.json b/advisories/unreviewed/2025/05/GHSA-j6wh-9fq4-rcrh/GHSA-j6wh-9fq4-rcrh.json index 15d95458d8d..f797d0e01bc 100644 --- a/advisories/unreviewed/2025/05/GHSA-j6wh-9fq4-rcrh/GHSA-j6wh-9fq4-rcrh.json +++ b/advisories/unreviewed/2025/05/GHSA-j6wh-9fq4-rcrh/GHSA-j6wh-9fq4-rcrh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j6wh-9fq4-rcrh", - "modified": "2025-05-13T00:31:15Z", + "modified": "2025-05-15T15:31:23Z", "published": "2025-05-13T00:31:15Z", "aliases": [ "CVE-2025-31234" ], "details": "The issue was addressed with improved input sanitization. This issue is fixed in visionOS 2.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5. An attacker may be able to cause unexpected system termination or corrupt kernel memory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:23Z" diff --git a/advisories/unreviewed/2025/05/GHSA-j8r3-cghj-9jhg/GHSA-j8r3-cghj-9jhg.json b/advisories/unreviewed/2025/05/GHSA-j8r3-cghj-9jhg/GHSA-j8r3-cghj-9jhg.json new file mode 100644 index 00000000000..c6c679a5ced --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-j8r3-cghj-9jhg/GHSA-j8r3-cghj-9jhg.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j8r3-cghj-9jhg", + "modified": "2025-05-15T15:31:27Z", + "published": "2025-05-15T15:31:27Z", + "aliases": [ + "CVE-2025-4516" + ], + "details": "There is an issue in CPython when using `bytes.decode(\"unicode_escape\", error=\"ignore|replace\")`. If you are not using the \"unicode_escape\" encoding or an error handler your usage is not affected. To work-around this issue you may stop using the error= handler and instead wrap the bytes.decode() call in a try-except catching the DecodeError.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4516" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/issues/133767" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/pull/129648" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/69b4387f78f413e8c47572a85b3478c47eba8142" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/9f69a58623bd01349a18ba0c7a9cb1dad6a51e8e" + }, + { + "type": "WEB", + "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/L75IPBBTSCYEF56I2M4KIW353BB3AY74" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T14:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-j92j-6p6g-x235/GHSA-j92j-6p6g-x235.json b/advisories/unreviewed/2025/05/GHSA-j92j-6p6g-x235/GHSA-j92j-6p6g-x235.json index 97af81065f3..b169d2927cf 100644 --- a/advisories/unreviewed/2025/05/GHSA-j92j-6p6g-x235/GHSA-j92j-6p6g-x235.json +++ b/advisories/unreviewed/2025/05/GHSA-j92j-6p6g-x235/GHSA-j92j-6p6g-x235.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j92j-6p6g-x235", - "modified": "2025-05-14T21:31:19Z", + "modified": "2025-05-15T15:31:24Z", "published": "2025-05-14T21:31:19Z", "aliases": [ "CVE-2024-57096" ], "details": "An issue in wps office before v.19302 allows a local attacker to obtain sensitive information via a crafted file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-14T20:15:21Z" diff --git a/advisories/unreviewed/2025/05/GHSA-jfxg-6gv4-f2gh/GHSA-jfxg-6gv4-f2gh.json b/advisories/unreviewed/2025/05/GHSA-jfxg-6gv4-f2gh/GHSA-jfxg-6gv4-f2gh.json index 40aa377903e..cbcb7b834a7 100644 --- a/advisories/unreviewed/2025/05/GHSA-jfxg-6gv4-f2gh/GHSA-jfxg-6gv4-f2gh.json +++ b/advisories/unreviewed/2025/05/GHSA-jfxg-6gv4-f2gh/GHSA-jfxg-6gv4-f2gh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jfxg-6gv4-f2gh", - "modified": "2025-05-14T18:30:48Z", + "modified": "2025-05-15T15:31:23Z", "published": "2025-05-14T18:30:48Z", "aliases": [ "CVE-2025-3932" ], "details": "It was possible to craft an email that showed a tracking link as an attachment. If the user attempted to open the attachment, Thunderbird automatically accessed the link. The configuration to block remote content did not prevent that. Thunderbird has been fixed to no longer allow access to web pages listed in the X-Mozilla-External-Attachment-URL header of an email. This vulnerability affects Thunderbird < 128.10.1 and Thunderbird < 138.0.1.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-288" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-14T17:15:48Z" diff --git a/advisories/unreviewed/2025/05/GHSA-jqh7-h346-vm4j/GHSA-jqh7-h346-vm4j.json b/advisories/unreviewed/2025/05/GHSA-jqh7-h346-vm4j/GHSA-jqh7-h346-vm4j.json new file mode 100644 index 00000000000..ca492152dbf --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jqh7-h346-vm4j/GHSA-jqh7-h346-vm4j.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jqh7-h346-vm4j", + "modified": "2025-05-15T15:31:26Z", + "published": "2025-05-15T15:31:26Z", + "aliases": [ + "CVE-2025-4697" + ], + "details": "A vulnerability was found in PHPGurukul Directory Management System 2.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/edit-directory.php. The manipulation of the argument editid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4697" + }, + { + "type": "WEB", + "url": "https://github.com/lwecho/myCVE/issues/2" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.308996" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.308996" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.567694" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T13:16:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-m7cj-8qx5-j738/GHSA-m7cj-8qx5-j738.json b/advisories/unreviewed/2025/05/GHSA-m7cj-8qx5-j738/GHSA-m7cj-8qx5-j738.json index 672f8fe7714..ed766454404 100644 --- a/advisories/unreviewed/2025/05/GHSA-m7cj-8qx5-j738/GHSA-m7cj-8qx5-j738.json +++ b/advisories/unreviewed/2025/05/GHSA-m7cj-8qx5-j738/GHSA-m7cj-8qx5-j738.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m7cj-8qx5-j738", - "modified": "2025-05-14T21:31:19Z", + "modified": "2025-05-15T15:31:24Z", "published": "2025-05-14T21:31:19Z", "aliases": [ "CVE-2025-25370" ], "details": "An issue in realme GT 2 (RMX3311) running Android 14 with realme UI 5.0 allows a physically proximate attacker to obtain sensitive information via the show app only setting function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-14T20:15:21Z" diff --git a/advisories/unreviewed/2025/05/GHSA-m9rv-9j45-vx77/GHSA-m9rv-9j45-vx77.json b/advisories/unreviewed/2025/05/GHSA-m9rv-9j45-vx77/GHSA-m9rv-9j45-vx77.json new file mode 100644 index 00000000000..c979c762baf --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-m9rv-9j45-vx77/GHSA-m9rv-9j45-vx77.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m9rv-9j45-vx77", + "modified": "2025-05-15T15:31:26Z", + "published": "2025-05-15T15:31:26Z", + "aliases": [ + "CVE-2025-44183" + ], + "details": "Phpgurukul Vehicle Record Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/profile.php via the name, email, and mobile parameters.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44183" + }, + { + "type": "WEB", + "url": "https://github.com/nscerol/Vehicle-Record-Management-System/blob/main/CVE-2025-44183-Vehicle-Record-Management-System-1.0-Stored-Cross-Site-Scripting-Vulnerability.md" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com/vehicle-record-system-using-php-and-mysql" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T14:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mrg2-jr6m-xfj9/GHSA-mrg2-jr6m-xfj9.json b/advisories/unreviewed/2025/05/GHSA-mrg2-jr6m-xfj9/GHSA-mrg2-jr6m-xfj9.json index ecc036c9d8f..3fb48656c4d 100644 --- a/advisories/unreviewed/2025/05/GHSA-mrg2-jr6m-xfj9/GHSA-mrg2-jr6m-xfj9.json +++ b/advisories/unreviewed/2025/05/GHSA-mrg2-jr6m-xfj9/GHSA-mrg2-jr6m-xfj9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mrg2-jr6m-xfj9", - "modified": "2025-05-15T00:30:26Z", + "modified": "2025-05-15T15:31:25Z", "published": "2025-05-15T00:30:26Z", "aliases": [ "CVE-2025-29689" ], "details": "A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the password parameter at /mail/MailController.java.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-14T22:15:17Z" diff --git a/advisories/unreviewed/2025/05/GHSA-p24g-cj72-gpfv/GHSA-p24g-cj72-gpfv.json b/advisories/unreviewed/2025/05/GHSA-p24g-cj72-gpfv/GHSA-p24g-cj72-gpfv.json index fa78a181dd8..04f863b722e 100644 --- a/advisories/unreviewed/2025/05/GHSA-p24g-cj72-gpfv/GHSA-p24g-cj72-gpfv.json +++ b/advisories/unreviewed/2025/05/GHSA-p24g-cj72-gpfv/GHSA-p24g-cj72-gpfv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p24g-cj72-gpfv", - "modified": "2025-05-14T18:30:50Z", + "modified": "2025-05-15T15:31:24Z", "published": "2025-05-14T18:30:50Z", "aliases": [ "CVE-2025-47707" ], "details": "Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Authentication Bypass.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-288" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-14T17:15:49Z" diff --git a/advisories/unreviewed/2025/05/GHSA-p2h7-5rp6-x3fx/GHSA-p2h7-5rp6-x3fx.json b/advisories/unreviewed/2025/05/GHSA-p2h7-5rp6-x3fx/GHSA-p2h7-5rp6-x3fx.json index 049f0feab10..6eebec2cb35 100644 --- a/advisories/unreviewed/2025/05/GHSA-p2h7-5rp6-x3fx/GHSA-p2h7-5rp6-x3fx.json +++ b/advisories/unreviewed/2025/05/GHSA-p2h7-5rp6-x3fx/GHSA-p2h7-5rp6-x3fx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p2h7-5rp6-x3fx", - "modified": "2025-05-14T21:31:20Z", + "modified": "2025-05-15T15:31:24Z", "published": "2025-05-14T21:31:20Z", "aliases": [ "CVE-2025-27891" ], "details": "An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. The lack of a length check leads to out-of-bounds reads via malformed NAS packets.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-14T21:15:58Z" diff --git a/advisories/unreviewed/2025/05/GHSA-r2m3-qfw3-6wmj/GHSA-r2m3-qfw3-6wmj.json b/advisories/unreviewed/2025/05/GHSA-r2m3-qfw3-6wmj/GHSA-r2m3-qfw3-6wmj.json new file mode 100644 index 00000000000..a11d08d1698 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-r2m3-qfw3-6wmj/GHSA-r2m3-qfw3-6wmj.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r2m3-qfw3-6wmj", + "modified": "2025-05-15T15:31:27Z", + "published": "2025-05-15T15:31:26Z", + "aliases": [ + "CVE-2025-4698" + ], + "details": "A vulnerability classified as critical has been found in PHPGurukul Directory Management System 2.0. This affects an unknown part of the file /admin/forget-password.php. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4698" + }, + { + "type": "WEB", + "url": "https://github.com/lwecho/myCVE/issues/3" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.308997" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.308997" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.567695" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T14:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rc6v-fxv5-mfxg/GHSA-rc6v-fxv5-mfxg.json b/advisories/unreviewed/2025/05/GHSA-rc6v-fxv5-mfxg/GHSA-rc6v-fxv5-mfxg.json new file mode 100644 index 00000000000..537b26f877f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rc6v-fxv5-mfxg/GHSA-rc6v-fxv5-mfxg.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rc6v-fxv5-mfxg", + "modified": "2025-05-15T15:31:26Z", + "published": "2025-05-15T15:31:26Z", + "aliases": [ + "CVE-2025-44181" + ], + "details": "Phpgurukul Vehicle Record Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/add-brand.php via the brandname parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44181" + }, + { + "type": "WEB", + "url": "https://github.com/nscerol/Vehicle-Record-Management-System/blob/main/CVE-2025-44181-Vehicle-Record-Management-System-1.0-Stored-Cross-Site-Scripting-Vulnerability.md" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com/vehicle-record-system-using-php-and-mysql" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T14:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rg69-33g2-mp48/GHSA-rg69-33g2-mp48.json b/advisories/unreviewed/2025/05/GHSA-rg69-33g2-mp48/GHSA-rg69-33g2-mp48.json index 203590f5cc6..5a38cc27389 100644 --- a/advisories/unreviewed/2025/05/GHSA-rg69-33g2-mp48/GHSA-rg69-33g2-mp48.json +++ b/advisories/unreviewed/2025/05/GHSA-rg69-33g2-mp48/GHSA-rg69-33g2-mp48.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rg69-33g2-mp48", - "modified": "2025-05-14T18:30:47Z", + "modified": "2025-05-15T15:31:23Z", "published": "2025-05-14T18:30:47Z", "aliases": [ "CVE-2025-3875" ], "details": "Thunderbird parses addresses in a way that can allow sender spoofing in case the server allows an invalid From address to be used. For example, if the From header contains an (invalid) value \"Spoofed Name \", Thunderbird treats spoofed@example.com as the actual address. This vulnerability affects Thunderbird < 128.10.1 and Thunderbird < 138.0.1.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-290" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-14T17:15:48Z" diff --git a/advisories/unreviewed/2025/05/GHSA-rjrm-h7wx-7c3m/GHSA-rjrm-h7wx-7c3m.json b/advisories/unreviewed/2025/05/GHSA-rjrm-h7wx-7c3m/GHSA-rjrm-h7wx-7c3m.json index 5163a49ff4a..147a99f0933 100644 --- a/advisories/unreviewed/2025/05/GHSA-rjrm-h7wx-7c3m/GHSA-rjrm-h7wx-7c3m.json +++ b/advisories/unreviewed/2025/05/GHSA-rjrm-h7wx-7c3m/GHSA-rjrm-h7wx-7c3m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rjrm-h7wx-7c3m", - "modified": "2025-05-14T18:30:48Z", + "modified": "2025-05-15T15:31:23Z", "published": "2025-05-14T18:30:48Z", "aliases": [ "CVE-2025-47702" ], "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal oEmbed Providers allows Cross-Site Scripting (XSS).This issue affects oEmbed Providers: from 0.0.0 before 2.2.2.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-14T17:15:49Z" diff --git a/advisories/unreviewed/2025/05/GHSA-v265-mq78-w999/GHSA-v265-mq78-w999.json b/advisories/unreviewed/2025/05/GHSA-v265-mq78-w999/GHSA-v265-mq78-w999.json index c1a6a9916d0..f3c01f80381 100644 --- a/advisories/unreviewed/2025/05/GHSA-v265-mq78-w999/GHSA-v265-mq78-w999.json +++ b/advisories/unreviewed/2025/05/GHSA-v265-mq78-w999/GHSA-v265-mq78-w999.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v265-mq78-w999", - "modified": "2025-05-14T18:30:49Z", + "modified": "2025-05-15T15:31:23Z", "published": "2025-05-14T18:30:49Z", "aliases": [ "CVE-2025-47705" ], "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal IFrame Remove Filter allows Cross-Site Scripting (XSS).This issue affects IFrame Remove Filter: from 0.0.0 before 2.0.5.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-14T17:15:49Z" diff --git a/advisories/unreviewed/2025/05/GHSA-v69c-p4g4-vw22/GHSA-v69c-p4g4-vw22.json b/advisories/unreviewed/2025/05/GHSA-v69c-p4g4-vw22/GHSA-v69c-p4g4-vw22.json new file mode 100644 index 00000000000..3cf73e3cf49 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v69c-p4g4-vw22/GHSA-v69c-p4g4-vw22.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v69c-p4g4-vw22", + "modified": "2025-05-15T15:31:28Z", + "published": "2025-05-15T15:31:28Z", + "aliases": [ + "CVE-2025-4702" + ], + "details": "A vulnerability, which was classified as critical, was found in PHPGurukul Vehicle Parking Management System 1.13. Affected is an unknown function of the file /admin/add-category.php. The manipulation of the argument catename leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4702" + }, + { + "type": "WEB", + "url": "https://github.com/baixiaobai001/myCVE/issues/1" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309000" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309000" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.567805" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T15:16:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w899-x298-m75w/GHSA-w899-x298-m75w.json b/advisories/unreviewed/2025/05/GHSA-w899-x298-m75w/GHSA-w899-x298-m75w.json index 3b36095b2b0..1fa1ee7d338 100644 --- a/advisories/unreviewed/2025/05/GHSA-w899-x298-m75w/GHSA-w899-x298-m75w.json +++ b/advisories/unreviewed/2025/05/GHSA-w899-x298-m75w/GHSA-w899-x298-m75w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w899-x298-m75w", - "modified": "2025-05-14T21:31:20Z", + "modified": "2025-05-15T15:31:25Z", "published": "2025-05-14T21:31:20Z", "aliases": [ "CVE-2025-44879" ], "details": "WS-WN572HP3 V230525 was discovered to contain a buffer overflow in the component /www/cgi-bin/upload.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-14T21:15:59Z" diff --git a/advisories/unreviewed/2025/05/GHSA-wcp5-vgqm-h42v/GHSA-wcp5-vgqm-h42v.json b/advisories/unreviewed/2025/05/GHSA-wcp5-vgqm-h42v/GHSA-wcp5-vgqm-h42v.json new file mode 100644 index 00000000000..220665a118b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wcp5-vgqm-h42v/GHSA-wcp5-vgqm-h42v.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wcp5-vgqm-h42v", + "modified": "2025-05-15T15:31:27Z", + "published": "2025-05-15T15:31:27Z", + "aliases": [ + "CVE-2025-4699" + ], + "details": "A vulnerability classified as critical was found in PHPGurukul Apartment Visitors Management System 1.0. This vulnerability affects unknown code of the file /admin/visitors-form.php. The manipulation of the argument Category leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4699" + }, + { + "type": "WEB", + "url": "https://github.com/y77-88/myCVE/issues/10" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.308998" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.308998" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.567738" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T14:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-x696-h3x7-xxjp/GHSA-x696-h3x7-xxjp.json b/advisories/unreviewed/2025/05/GHSA-x696-h3x7-xxjp/GHSA-x696-h3x7-xxjp.json index f46f0346626..7e27a00acd7 100644 --- a/advisories/unreviewed/2025/05/GHSA-x696-h3x7-xxjp/GHSA-x696-h3x7-xxjp.json +++ b/advisories/unreviewed/2025/05/GHSA-x696-h3x7-xxjp/GHSA-x696-h3x7-xxjp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x696-h3x7-xxjp", - "modified": "2025-05-13T00:31:13Z", + "modified": "2025-05-15T15:31:22Z", "published": "2025-05-13T00:31:13Z", "aliases": [ "CVE-2025-31214" ], "details": "This issue was addressed through improved state management. This issue is fixed in iOS 18.5 and iPadOS 18.5. An attacker in a privileged network position may be able to intercept network traffic.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-300" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:22Z" diff --git a/advisories/unreviewed/2025/05/GHSA-x6c2-8j4w-4vxx/GHSA-x6c2-8j4w-4vxx.json b/advisories/unreviewed/2025/05/GHSA-x6c2-8j4w-4vxx/GHSA-x6c2-8j4w-4vxx.json index 9ad07b32868..0e1e8d9ffde 100644 --- a/advisories/unreviewed/2025/05/GHSA-x6c2-8j4w-4vxx/GHSA-x6c2-8j4w-4vxx.json +++ b/advisories/unreviewed/2025/05/GHSA-x6c2-8j4w-4vxx/GHSA-x6c2-8j4w-4vxx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x6c2-8j4w-4vxx", - "modified": "2025-05-15T00:30:26Z", + "modified": "2025-05-15T15:31:26Z", "published": "2025-05-15T00:30:26Z", "aliases": [ "CVE-2025-29690" ], "details": "A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the outtype parameter at /address/AddrController.java.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-14T22:15:17Z"