From a0ac5a7b5c5e44d526868297a556826da32f858e Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 22 May 2025 18:32:48 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-3vcw-xhqc-97mh.json | 13 ++++- .../GHSA-474q-vp74-243q.json | 7 ++- .../GHSA-4g99-xhm8-2rwc.json | 11 +++- .../GHSA-7gxh-p4c9-cq3r.json | 11 +++- .../GHSA-cv4q-4xgp-cr7m.json | 9 ++- .../GHSA-fxw8-j27m-3752.json | 6 +- .../GHSA-gf7p-63p6-4m97.json | 6 +- .../GHSA-h42x-qcjr-3ww7.json | 7 ++- .../GHSA-h435-fgp5-q25r.json | 13 ++++- .../GHSA-22jw-r3jv-5f4f.json | 4 +- .../GHSA-255p-hfwr-9qm4.json | 4 +- .../GHSA-4jx6-c96p-4mcx.json | 4 +- .../GHSA-4m4c-mm78-3pcw.json | 4 +- .../GHSA-5qv2-q3p3-26r4.json | 4 +- .../GHSA-5rj5-5628-7w5m.json | 4 +- .../GHSA-74v5-x8gw-q8f8.json | 1 + .../GHSA-j8gh-qgf7-j54p.json | 1 + .../GHSA-p38h-v883-px7v.json | 4 +- .../GHSA-v8x2-pmhm-gqcj.json | 6 +- .../GHSA-wchp-7c65-4hqg.json | 1 + .../GHSA-3568-h36m-7jmf.json | 2 +- .../GHSA-9m8r-h264-rvx5.json | 2 +- .../GHSA-c352-2vg8-m9gr.json | 6 +- .../GHSA-h6xq-j8xx-3fv4.json | 6 +- .../GHSA-hpcp-jfj7-rjww.json | 2 +- .../GHSA-jx5w-px6r-88w4.json | 6 +- .../GHSA-m2r6-996j-pvf6.json | 6 +- .../GHSA-v39r-662x-j524.json | 6 +- .../GHSA-4pr9-2v9c-fmpv.json | 4 +- .../GHSA-rcjh-j3cc-cq79.json | 4 +- .../GHSA-48wm-4cr2-qrfh.json | 15 +++-- .../GHSA-26fm-jh3j-2ww5.json | 36 ++++++++++++ .../GHSA-3f53-v88v-m2r8.json | 40 +++++++++++++ .../GHSA-3wc3-w43j-x6wh.json | 36 ++++++++++++ .../GHSA-5548-25gc-qcxx.json | 56 +++++++++++++++++++ .../GHSA-5fcg-gph2-wcvg.json | 40 +++++++++++++ .../GHSA-662m-3r43-rvw4.json | 15 +++-- .../GHSA-6jv2-q76w-6w5g.json | 40 +++++++++++++ .../GHSA-7893-2vg2-2738.json | 36 ++++++++++++ .../GHSA-7xfj-j894-qgcq.json | 29 ++++++++++ .../GHSA-9mcw-h59j-pwj3.json | 40 +++++++++++++ .../GHSA-9r52-rcmc-x62w.json | 52 +++++++++++++++++ .../GHSA-9vwh-wfrg-2h6f.json | 40 +++++++++++++ .../GHSA-c9x9-qgxx-cj62.json | 40 +++++++++++++ .../GHSA-cp2f-vm9g-5gqr.json | 36 ++++++++++++ .../GHSA-cq8v-wvwh-vcpg.json | 40 +++++++++++++ .../GHSA-ffqf-972q-qhhv.json | 29 ++++++++++ .../GHSA-gjwx-g2ph-472r.json | 10 +++- .../GHSA-pf9f-fx8v-xgx8.json | 3 +- .../GHSA-qg6w-c843-2xjm.json | 40 +++++++++++++ .../GHSA-r29h-8w9g-r68q.json | 40 +++++++++++++ .../GHSA-rhjh-wqrx-9374.json | 40 +++++++++++++ .../GHSA-v8qh-5c5w-48pp.json | 6 +- .../GHSA-vvcp-wcvc-hv6h.json | 40 +++++++++++++ .../GHSA-w6gx-hfp5-rmhr.json | 36 ++++++++++++ .../GHSA-x4jw-p584-84v2.json | 4 +- .../GHSA-x5rp-3mjc-5m63.json | 40 +++++++++++++ .../GHSA-x9g7-j8rx-fcjc.json | 29 ++++++++++ .../GHSA-xfj4-w5m6-x8f6.json | 4 +- .../GHSA-xm8g-3cm4-4x8x.json | 40 +++++++++++++ .../GHSA-xpm6-qgmg-747p.json | 40 +++++++++++++ 61 files changed, 1108 insertions(+), 48 deletions(-) create mode 100644 advisories/unreviewed/2025/05/GHSA-26fm-jh3j-2ww5/GHSA-26fm-jh3j-2ww5.json create mode 100644 advisories/unreviewed/2025/05/GHSA-3f53-v88v-m2r8/GHSA-3f53-v88v-m2r8.json create mode 100644 advisories/unreviewed/2025/05/GHSA-3wc3-w43j-x6wh/GHSA-3wc3-w43j-x6wh.json create mode 100644 advisories/unreviewed/2025/05/GHSA-5548-25gc-qcxx/GHSA-5548-25gc-qcxx.json create mode 100644 advisories/unreviewed/2025/05/GHSA-5fcg-gph2-wcvg/GHSA-5fcg-gph2-wcvg.json create mode 100644 advisories/unreviewed/2025/05/GHSA-6jv2-q76w-6w5g/GHSA-6jv2-q76w-6w5g.json create mode 100644 advisories/unreviewed/2025/05/GHSA-7893-2vg2-2738/GHSA-7893-2vg2-2738.json create mode 100644 advisories/unreviewed/2025/05/GHSA-7xfj-j894-qgcq/GHSA-7xfj-j894-qgcq.json create mode 100644 advisories/unreviewed/2025/05/GHSA-9mcw-h59j-pwj3/GHSA-9mcw-h59j-pwj3.json create mode 100644 advisories/unreviewed/2025/05/GHSA-9r52-rcmc-x62w/GHSA-9r52-rcmc-x62w.json create mode 100644 advisories/unreviewed/2025/05/GHSA-9vwh-wfrg-2h6f/GHSA-9vwh-wfrg-2h6f.json create mode 100644 advisories/unreviewed/2025/05/GHSA-c9x9-qgxx-cj62/GHSA-c9x9-qgxx-cj62.json create mode 100644 advisories/unreviewed/2025/05/GHSA-cp2f-vm9g-5gqr/GHSA-cp2f-vm9g-5gqr.json create mode 100644 advisories/unreviewed/2025/05/GHSA-cq8v-wvwh-vcpg/GHSA-cq8v-wvwh-vcpg.json create mode 100644 advisories/unreviewed/2025/05/GHSA-ffqf-972q-qhhv/GHSA-ffqf-972q-qhhv.json create mode 100644 advisories/unreviewed/2025/05/GHSA-qg6w-c843-2xjm/GHSA-qg6w-c843-2xjm.json create mode 100644 advisories/unreviewed/2025/05/GHSA-r29h-8w9g-r68q/GHSA-r29h-8w9g-r68q.json create mode 100644 advisories/unreviewed/2025/05/GHSA-rhjh-wqrx-9374/GHSA-rhjh-wqrx-9374.json create mode 100644 advisories/unreviewed/2025/05/GHSA-vvcp-wcvc-hv6h/GHSA-vvcp-wcvc-hv6h.json create mode 100644 advisories/unreviewed/2025/05/GHSA-w6gx-hfp5-rmhr/GHSA-w6gx-hfp5-rmhr.json create mode 100644 advisories/unreviewed/2025/05/GHSA-x5rp-3mjc-5m63/GHSA-x5rp-3mjc-5m63.json create mode 100644 advisories/unreviewed/2025/05/GHSA-x9g7-j8rx-fcjc/GHSA-x9g7-j8rx-fcjc.json create mode 100644 advisories/unreviewed/2025/05/GHSA-xm8g-3cm4-4x8x/GHSA-xm8g-3cm4-4x8x.json create mode 100644 advisories/unreviewed/2025/05/GHSA-xpm6-qgmg-747p/GHSA-xpm6-qgmg-747p.json diff --git a/advisories/unreviewed/2022/05/GHSA-3vcw-xhqc-97mh/GHSA-3vcw-xhqc-97mh.json b/advisories/unreviewed/2022/05/GHSA-3vcw-xhqc-97mh/GHSA-3vcw-xhqc-97mh.json index 701af3ab28c..98ae35da7e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-3vcw-xhqc-97mh/GHSA-3vcw-xhqc-97mh.json +++ b/advisories/unreviewed/2022/05/GHSA-3vcw-xhqc-97mh/GHSA-3vcw-xhqc-97mh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3vcw-xhqc-97mh", - "modified": "2022-05-13T01:35:00Z", + "modified": "2025-05-22T18:31:08Z", "published": "2022-05-13T01:35:00Z", "aliases": [ "CVE-2018-10596" @@ -19,14 +19,23 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-10596" }, + { + "type": "WEB", + "url": "https://global.medtronic.com/xg-en/product-security/security-bulletins/carelink-2090-29901.html" + }, { "type": "WEB", "url": "https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-01" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-18-058-01" } ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-923" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-474q-vp74-243q/GHSA-474q-vp74-243q.json b/advisories/unreviewed/2022/05/GHSA-474q-vp74-243q/GHSA-474q-vp74-243q.json index 5f8ebf7330a..885f89de2db 100644 --- a/advisories/unreviewed/2022/05/GHSA-474q-vp74-243q/GHSA-474q-vp74-243q.json +++ b/advisories/unreviewed/2022/05/GHSA-474q-vp74-243q/GHSA-474q-vp74-243q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-474q-vp74-243q", - "modified": "2022-05-13T01:16:10Z", + "modified": "2025-05-22T18:31:09Z", "published": "2022-05-13T01:16:10Z", "aliases": [ "CVE-2018-18984" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-18984" }, + { + "type": "WEB", + "url": "https://global.medtronic.com/xg-en/product-security/security-bulletins/carelink-9790-2090-29901.html" + }, { "type": "WEB", "url": "https://ics-cert.us-cert.gov/advisories/ICSMA-18-347-01" @@ -30,6 +34,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-311", "CWE-312" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/05/GHSA-4g99-xhm8-2rwc/GHSA-4g99-xhm8-2rwc.json b/advisories/unreviewed/2022/05/GHSA-4g99-xhm8-2rwc/GHSA-4g99-xhm8-2rwc.json index fa08f565f57..736e942efc4 100644 --- a/advisories/unreviewed/2022/05/GHSA-4g99-xhm8-2rwc/GHSA-4g99-xhm8-2rwc.json +++ b/advisories/unreviewed/2022/05/GHSA-4g99-xhm8-2rwc/GHSA-4g99-xhm8-2rwc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4g99-xhm8-2rwc", - "modified": "2022-05-13T01:34:58Z", + "modified": "2025-05-22T18:31:08Z", "published": "2022-05-13T01:34:58Z", "aliases": [ "CVE-2018-10631" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-10631" }, + { + "type": "WEB", + "url": "https://global.medtronic.com/xg-en/product-security/security-bulletins/nvision.html" + }, { "type": "WEB", "url": "https://ics-cert.us-cert.gov/advisories/ICSMA-18-137-01" @@ -26,11 +30,16 @@ { "type": "WEB", "url": "https://www.medtronic.com/security" + }, + { + "type": "WEB", + "url": "http://www.securityfocus.com/bid/104213" } ], "database_specific": { "cwe_ids": [ "CWE-284", + "CWE-311", "CWE-693" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/05/GHSA-7gxh-p4c9-cq3r/GHSA-7gxh-p4c9-cq3r.json b/advisories/unreviewed/2022/05/GHSA-7gxh-p4c9-cq3r/GHSA-7gxh-p4c9-cq3r.json index d47e8095bc3..a1f83b25966 100644 --- a/advisories/unreviewed/2022/05/GHSA-7gxh-p4c9-cq3r/GHSA-7gxh-p4c9-cq3r.json +++ b/advisories/unreviewed/2022/05/GHSA-7gxh-p4c9-cq3r/GHSA-7gxh-p4c9-cq3r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7gxh-p4c9-cq3r", - "modified": "2022-05-13T01:32:08Z", + "modified": "2025-05-22T18:31:07Z", "published": "2022-05-13T01:32:08Z", "aliases": [ "CVE-2018-5446" @@ -19,13 +19,22 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-5446" }, + { + "type": "WEB", + "url": "https://global.medtronic.com/xg-en/product-security/security-bulletins/carelink-2090-29901.html" + }, { "type": "WEB", "url": "https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-01" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-18-058-01" } ], "database_specific": { "cwe_ids": [ + "CWE-257", "CWE-522" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/05/GHSA-cv4q-4xgp-cr7m/GHSA-cv4q-4xgp-cr7m.json b/advisories/unreviewed/2022/05/GHSA-cv4q-4xgp-cr7m/GHSA-cv4q-4xgp-cr7m.json index f26e2a066ee..266d9bfaee8 100644 --- a/advisories/unreviewed/2022/05/GHSA-cv4q-4xgp-cr7m/GHSA-cv4q-4xgp-cr7m.json +++ b/advisories/unreviewed/2022/05/GHSA-cv4q-4xgp-cr7m/GHSA-cv4q-4xgp-cr7m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cv4q-4xgp-cr7m", - "modified": "2022-05-13T01:34:29Z", + "modified": "2025-05-22T18:31:09Z", "published": "2022-05-13T01:34:29Z", "aliases": [ "CVE-2018-14781" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-14781" }, + { + "type": "WEB", + "url": "https://global.medtronic.com/xg-en/product-security/security-bulletins/minimed.html" + }, { "type": "WEB", "url": "https://ics-cert.us-cert.gov/advisories/ICSMA-18-219-02" @@ -30,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-294" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-fxw8-j27m-3752/GHSA-fxw8-j27m-3752.json b/advisories/unreviewed/2022/05/GHSA-fxw8-j27m-3752/GHSA-fxw8-j27m-3752.json index 08658ca5a4a..77c7ff13beb 100644 --- a/advisories/unreviewed/2022/05/GHSA-fxw8-j27m-3752/GHSA-fxw8-j27m-3752.json +++ b/advisories/unreviewed/2022/05/GHSA-fxw8-j27m-3752/GHSA-fxw8-j27m-3752.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fxw8-j27m-3752", - "modified": "2022-05-13T01:34:58Z", + "modified": "2025-05-22T18:31:09Z", "published": "2022-05-13T01:34:58Z", "aliases": [ "CVE-2018-10634" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-10634" }, + { + "type": "WEB", + "url": "https://global.medtronic.com/xg-en/product-security/security-bulletins/minimed.html" + }, { "type": "WEB", "url": "https://ics-cert.us-cert.gov/advisories/ICSMA-18-219-02" diff --git a/advisories/unreviewed/2022/05/GHSA-gf7p-63p6-4m97/GHSA-gf7p-63p6-4m97.json b/advisories/unreviewed/2022/05/GHSA-gf7p-63p6-4m97/GHSA-gf7p-63p6-4m97.json index 608003c7f04..92f9e27a913 100644 --- a/advisories/unreviewed/2022/05/GHSA-gf7p-63p6-4m97/GHSA-gf7p-63p6-4m97.json +++ b/advisories/unreviewed/2022/05/GHSA-gf7p-63p6-4m97/GHSA-gf7p-63p6-4m97.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gf7p-63p6-4m97", - "modified": "2022-05-13T01:34:58Z", + "modified": "2025-05-22T18:31:09Z", "published": "2022-05-13T01:34:58Z", "aliases": [ "CVE-2018-10626" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-10626" }, + { + "type": "WEB", + "url": "https://global.medtronic.com/xg-en/product-security/security-bulletins/mycarelink-8-7-18.html" + }, { "type": "WEB", "url": "https://ics-cert.us-cert.gov/advisories/ICSMA-18-219-01" diff --git a/advisories/unreviewed/2022/05/GHSA-h42x-qcjr-3ww7/GHSA-h42x-qcjr-3ww7.json b/advisories/unreviewed/2022/05/GHSA-h42x-qcjr-3ww7/GHSA-h42x-qcjr-3ww7.json index ede996ff6ff..ca53f8ab9d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-h42x-qcjr-3ww7/GHSA-h42x-qcjr-3ww7.json +++ b/advisories/unreviewed/2022/05/GHSA-h42x-qcjr-3ww7/GHSA-h42x-qcjr-3ww7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h42x-qcjr-3ww7", - "modified": "2022-05-13T01:34:59Z", + "modified": "2025-05-22T18:31:08Z", "published": "2022-05-13T01:34:59Z", "aliases": [ "CVE-2018-10622" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-10622" }, + { + "type": "WEB", + "url": "https://global.medtronic.com/xg-en/product-security/security-bulletins/mycarelink-8-7-18.html" + }, { "type": "WEB", "url": "https://ics-cert.us-cert.gov/advisories/ICSMA-18-219-01" @@ -30,6 +34,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-257", "CWE-522" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/05/GHSA-h435-fgp5-q25r/GHSA-h435-fgp5-q25r.json b/advisories/unreviewed/2022/05/GHSA-h435-fgp5-q25r/GHSA-h435-fgp5-q25r.json index 63b37aa620c..d7d7e233603 100644 --- a/advisories/unreviewed/2022/05/GHSA-h435-fgp5-q25r/GHSA-h435-fgp5-q25r.json +++ b/advisories/unreviewed/2022/05/GHSA-h435-fgp5-q25r/GHSA-h435-fgp5-q25r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h435-fgp5-q25r", - "modified": "2022-05-13T01:32:09Z", + "modified": "2025-05-22T18:31:07Z", "published": "2022-05-13T01:32:09Z", "aliases": [ "CVE-2018-5448" @@ -19,14 +19,23 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-5448" }, + { + "type": "WEB", + "url": "https://global.medtronic.com/xg-en/product-security/security-bulletins/carelink-2090-29901.html" + }, { "type": "WEB", "url": "https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-01" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-18-058-01" } ], "database_specific": { "cwe_ids": [ - "CWE-22" + "CWE-22", + "CWE-23" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/09/GHSA-22jw-r3jv-5f4f/GHSA-22jw-r3jv-5f4f.json b/advisories/unreviewed/2022/09/GHSA-22jw-r3jv-5f4f/GHSA-22jw-r3jv-5f4f.json index ea06f6e342d..5b6dc2ed758 100644 --- a/advisories/unreviewed/2022/09/GHSA-22jw-r3jv-5f4f/GHSA-22jw-r3jv-5f4f.json +++ b/advisories/unreviewed/2022/09/GHSA-22jw-r3jv-5f4f/GHSA-22jw-r3jv-5f4f.json @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-255p-hfwr-9qm4/GHSA-255p-hfwr-9qm4.json b/advisories/unreviewed/2022/09/GHSA-255p-hfwr-9qm4/GHSA-255p-hfwr-9qm4.json index 3879bb0ca95..129cd4364fe 100644 --- a/advisories/unreviewed/2022/09/GHSA-255p-hfwr-9qm4/GHSA-255p-hfwr-9qm4.json +++ b/advisories/unreviewed/2022/09/GHSA-255p-hfwr-9qm4/GHSA-255p-hfwr-9qm4.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-4jx6-c96p-4mcx/GHSA-4jx6-c96p-4mcx.json b/advisories/unreviewed/2022/09/GHSA-4jx6-c96p-4mcx/GHSA-4jx6-c96p-4mcx.json index 50b8bf97d0a..087a733e8df 100644 --- a/advisories/unreviewed/2022/09/GHSA-4jx6-c96p-4mcx/GHSA-4jx6-c96p-4mcx.json +++ b/advisories/unreviewed/2022/09/GHSA-4jx6-c96p-4mcx/GHSA-4jx6-c96p-4mcx.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-4m4c-mm78-3pcw/GHSA-4m4c-mm78-3pcw.json b/advisories/unreviewed/2022/09/GHSA-4m4c-mm78-3pcw/GHSA-4m4c-mm78-3pcw.json index 0a96528a4c8..5b2d2ed96e7 100644 --- a/advisories/unreviewed/2022/09/GHSA-4m4c-mm78-3pcw/GHSA-4m4c-mm78-3pcw.json +++ b/advisories/unreviewed/2022/09/GHSA-4m4c-mm78-3pcw/GHSA-4m4c-mm78-3pcw.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-5qv2-q3p3-26r4/GHSA-5qv2-q3p3-26r4.json b/advisories/unreviewed/2022/09/GHSA-5qv2-q3p3-26r4/GHSA-5qv2-q3p3-26r4.json index b2a0e118830..fb4eca3bd55 100644 --- a/advisories/unreviewed/2022/09/GHSA-5qv2-q3p3-26r4/GHSA-5qv2-q3p3-26r4.json +++ b/advisories/unreviewed/2022/09/GHSA-5qv2-q3p3-26r4/GHSA-5qv2-q3p3-26r4.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-5rj5-5628-7w5m/GHSA-5rj5-5628-7w5m.json b/advisories/unreviewed/2022/09/GHSA-5rj5-5628-7w5m/GHSA-5rj5-5628-7w5m.json index da9cf9097cd..7b0a2da7f63 100644 --- a/advisories/unreviewed/2022/09/GHSA-5rj5-5628-7w5m/GHSA-5rj5-5628-7w5m.json +++ b/advisories/unreviewed/2022/09/GHSA-5rj5-5628-7w5m/GHSA-5rj5-5628-7w5m.json @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-74v5-x8gw-q8f8/GHSA-74v5-x8gw-q8f8.json b/advisories/unreviewed/2022/09/GHSA-74v5-x8gw-q8f8/GHSA-74v5-x8gw-q8f8.json index de357640b91..d70ecc85b1e 100644 --- a/advisories/unreviewed/2022/09/GHSA-74v5-x8gw-q8f8/GHSA-74v5-x8gw-q8f8.json +++ b/advisories/unreviewed/2022/09/GHSA-74v5-x8gw-q8f8/GHSA-74v5-x8gw-q8f8.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-20", "CWE-668" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/09/GHSA-j8gh-qgf7-j54p/GHSA-j8gh-qgf7-j54p.json b/advisories/unreviewed/2022/09/GHSA-j8gh-qgf7-j54p/GHSA-j8gh-qgf7-j54p.json index bece67457a3..de720aabde3 100644 --- a/advisories/unreviewed/2022/09/GHSA-j8gh-qgf7-j54p/GHSA-j8gh-qgf7-j54p.json +++ b/advisories/unreviewed/2022/09/GHSA-j8gh-qgf7-j54p/GHSA-j8gh-qgf7-j54p.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-200", "CWE-862" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/09/GHSA-p38h-v883-px7v/GHSA-p38h-v883-px7v.json b/advisories/unreviewed/2022/09/GHSA-p38h-v883-px7v/GHSA-p38h-v883-px7v.json index df01246c894..b3ea8532ff5 100644 --- a/advisories/unreviewed/2022/09/GHSA-p38h-v883-px7v/GHSA-p38h-v883-px7v.json +++ b/advisories/unreviewed/2022/09/GHSA-p38h-v883-px7v/GHSA-p38h-v883-px7v.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-346" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/12/GHSA-v8x2-pmhm-gqcj/GHSA-v8x2-pmhm-gqcj.json b/advisories/unreviewed/2023/12/GHSA-v8x2-pmhm-gqcj/GHSA-v8x2-pmhm-gqcj.json index 1034138f5c5..73a532ff6e7 100644 --- a/advisories/unreviewed/2023/12/GHSA-v8x2-pmhm-gqcj/GHSA-v8x2-pmhm-gqcj.json +++ b/advisories/unreviewed/2023/12/GHSA-v8x2-pmhm-gqcj/GHSA-v8x2-pmhm-gqcj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v8x2-pmhm-gqcj", - "modified": "2023-12-19T21:32:19Z", + "modified": "2025-05-22T18:31:10Z", "published": "2023-12-14T09:30:19Z", "aliases": [ "CVE-2023-48085" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/12/GHSA-wchp-7c65-4hqg/GHSA-wchp-7c65-4hqg.json b/advisories/unreviewed/2023/12/GHSA-wchp-7c65-4hqg/GHSA-wchp-7c65-4hqg.json index 44cfe4e7e30..f8db1f6a371 100644 --- a/advisories/unreviewed/2023/12/GHSA-wchp-7c65-4hqg/GHSA-wchp-7c65-4hqg.json +++ b/advisories/unreviewed/2023/12/GHSA-wchp-7c65-4hqg/GHSA-wchp-7c65-4hqg.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-400", "CWE-755" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/01/GHSA-3568-h36m-7jmf/GHSA-3568-h36m-7jmf.json b/advisories/unreviewed/2024/01/GHSA-3568-h36m-7jmf/GHSA-3568-h36m-7jmf.json index 86c78b7b358..6044530ce9d 100644 --- a/advisories/unreviewed/2024/01/GHSA-3568-h36m-7jmf/GHSA-3568-h36m-7jmf.json +++ b/advisories/unreviewed/2024/01/GHSA-3568-h36m-7jmf/GHSA-3568-h36m-7jmf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3568-h36m-7jmf", - "modified": "2024-01-30T18:30:19Z", + "modified": "2025-05-22T18:31:12Z", "published": "2024-01-23T15:30:58Z", "aliases": [ "CVE-2024-0749" diff --git a/advisories/unreviewed/2024/01/GHSA-9m8r-h264-rvx5/GHSA-9m8r-h264-rvx5.json b/advisories/unreviewed/2024/01/GHSA-9m8r-h264-rvx5/GHSA-9m8r-h264-rvx5.json index 254c03910fc..849666d6ad0 100644 --- a/advisories/unreviewed/2024/01/GHSA-9m8r-h264-rvx5/GHSA-9m8r-h264-rvx5.json +++ b/advisories/unreviewed/2024/01/GHSA-9m8r-h264-rvx5/GHSA-9m8r-h264-rvx5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9m8r-h264-rvx5", - "modified": "2024-01-23T18:31:11Z", + "modified": "2025-05-22T18:31:11Z", "published": "2024-01-16T18:31:10Z", "aliases": [ "CVE-2024-0187" diff --git a/advisories/unreviewed/2024/01/GHSA-c352-2vg8-m9gr/GHSA-c352-2vg8-m9gr.json b/advisories/unreviewed/2024/01/GHSA-c352-2vg8-m9gr/GHSA-c352-2vg8-m9gr.json index 1befd8d01f6..6b5aa587c99 100644 --- a/advisories/unreviewed/2024/01/GHSA-c352-2vg8-m9gr/GHSA-c352-2vg8-m9gr.json +++ b/advisories/unreviewed/2024/01/GHSA-c352-2vg8-m9gr/GHSA-c352-2vg8-m9gr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c352-2vg8-m9gr", - "modified": "2024-01-29T15:30:24Z", + "modified": "2025-05-22T18:31:13Z", "published": "2024-01-24T00:30:32Z", "aliases": [ "CVE-2024-0810" @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/01/GHSA-h6xq-j8xx-3fv4/GHSA-h6xq-j8xx-3fv4.json b/advisories/unreviewed/2024/01/GHSA-h6xq-j8xx-3fv4/GHSA-h6xq-j8xx-3fv4.json index 9b67ffbec03..bbf2c9c65de 100644 --- a/advisories/unreviewed/2024/01/GHSA-h6xq-j8xx-3fv4/GHSA-h6xq-j8xx-3fv4.json +++ b/advisories/unreviewed/2024/01/GHSA-h6xq-j8xx-3fv4/GHSA-h6xq-j8xx-3fv4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h6xq-j8xx-3fv4", - "modified": "2024-01-30T18:30:19Z", + "modified": "2025-05-22T18:31:12Z", "published": "2024-01-23T15:30:58Z", "aliases": [ "CVE-2024-0754" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-248" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/01/GHSA-hpcp-jfj7-rjww/GHSA-hpcp-jfj7-rjww.json b/advisories/unreviewed/2024/01/GHSA-hpcp-jfj7-rjww/GHSA-hpcp-jfj7-rjww.json index 4d14bfdd7e9..74ea41aa26a 100644 --- a/advisories/unreviewed/2024/01/GHSA-hpcp-jfj7-rjww/GHSA-hpcp-jfj7-rjww.json +++ b/advisories/unreviewed/2024/01/GHSA-hpcp-jfj7-rjww/GHSA-hpcp-jfj7-rjww.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hpcp-jfj7-rjww", - "modified": "2024-02-05T18:31:36Z", + "modified": "2025-05-22T18:31:13Z", "published": "2024-01-29T15:30:29Z", "aliases": [ "CVE-2023-5124" diff --git a/advisories/unreviewed/2024/01/GHSA-jx5w-px6r-88w4/GHSA-jx5w-px6r-88w4.json b/advisories/unreviewed/2024/01/GHSA-jx5w-px6r-88w4/GHSA-jx5w-px6r-88w4.json index 5994418e19a..82cfffd5ab9 100644 --- a/advisories/unreviewed/2024/01/GHSA-jx5w-px6r-88w4/GHSA-jx5w-px6r-88w4.json +++ b/advisories/unreviewed/2024/01/GHSA-jx5w-px6r-88w4/GHSA-jx5w-px6r-88w4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jx5w-px6r-88w4", - "modified": "2024-01-30T18:30:19Z", + "modified": "2025-05-22T18:31:11Z", "published": "2024-01-23T15:30:58Z", "aliases": [ "CVE-2024-0747" @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-693" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/01/GHSA-m2r6-996j-pvf6/GHSA-m2r6-996j-pvf6.json b/advisories/unreviewed/2024/01/GHSA-m2r6-996j-pvf6/GHSA-m2r6-996j-pvf6.json index 4e34b938181..4d5116f3380 100644 --- a/advisories/unreviewed/2024/01/GHSA-m2r6-996j-pvf6/GHSA-m2r6-996j-pvf6.json +++ b/advisories/unreviewed/2024/01/GHSA-m2r6-996j-pvf6/GHSA-m2r6-996j-pvf6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m2r6-996j-pvf6", - "modified": "2024-01-29T15:30:24Z", + "modified": "2025-05-22T18:31:12Z", "published": "2024-01-24T00:30:32Z", "aliases": [ "CVE-2024-0804" @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-693" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/01/GHSA-v39r-662x-j524/GHSA-v39r-662x-j524.json b/advisories/unreviewed/2024/01/GHSA-v39r-662x-j524/GHSA-v39r-662x-j524.json index 347bca7367f..d9e16644d8d 100644 --- a/advisories/unreviewed/2024/01/GHSA-v39r-662x-j524/GHSA-v39r-662x-j524.json +++ b/advisories/unreviewed/2024/01/GHSA-v39r-662x-j524/GHSA-v39r-662x-j524.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v39r-662x-j524", - "modified": "2024-01-22T21:31:07Z", + "modified": "2025-05-22T18:31:11Z", "published": "2024-01-17T00:30:19Z", "aliases": [ "CVE-2024-0517" @@ -34,6 +34,10 @@ { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TNN4SO5UI3U3Q6ASTVT6WMZ4723FYDLH" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/out-of-bound-write-in-v8-javascript-engine-cve-2024-0517" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/04/GHSA-4pr9-2v9c-fmpv/GHSA-4pr9-2v9c-fmpv.json b/advisories/unreviewed/2024/04/GHSA-4pr9-2v9c-fmpv/GHSA-4pr9-2v9c-fmpv.json index df59babf81c..7824c5e87d6 100644 --- a/advisories/unreviewed/2024/04/GHSA-4pr9-2v9c-fmpv/GHSA-4pr9-2v9c-fmpv.json +++ b/advisories/unreviewed/2024/04/GHSA-4pr9-2v9c-fmpv/GHSA-4pr9-2v9c-fmpv.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-rcjh-j3cc-cq79/GHSA-rcjh-j3cc-cq79.json b/advisories/unreviewed/2024/05/GHSA-rcjh-j3cc-cq79/GHSA-rcjh-j3cc-cq79.json index b69c8c65d0a..8160b625a24 100644 --- a/advisories/unreviewed/2024/05/GHSA-rcjh-j3cc-cq79/GHSA-rcjh-j3cc-cq79.json +++ b/advisories/unreviewed/2024/05/GHSA-rcjh-j3cc-cq79/GHSA-rcjh-j3cc-cq79.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-502" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-48wm-4cr2-qrfh/GHSA-48wm-4cr2-qrfh.json b/advisories/unreviewed/2024/11/GHSA-48wm-4cr2-qrfh/GHSA-48wm-4cr2-qrfh.json index 9fdfc301928..98ad6625909 100644 --- a/advisories/unreviewed/2024/11/GHSA-48wm-4cr2-qrfh/GHSA-48wm-4cr2-qrfh.json +++ b/advisories/unreviewed/2024/11/GHSA-48wm-4cr2-qrfh/GHSA-48wm-4cr2-qrfh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-48wm-4cr2-qrfh", - "modified": "2024-11-20T21:30:50Z", + "modified": "2025-05-22T18:31:14Z", "published": "2024-11-20T21:30:50Z", "aliases": [ "CVE-2024-52701" ], "details": "A stored cross-site scripting (XSS) vulnerability in the Configuration page of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Page banner parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-20T21:15:08Z" diff --git a/advisories/unreviewed/2025/05/GHSA-26fm-jh3j-2ww5/GHSA-26fm-jh3j-2ww5.json b/advisories/unreviewed/2025/05/GHSA-26fm-jh3j-2ww5/GHSA-26fm-jh3j-2ww5.json new file mode 100644 index 00000000000..ece0f0d853d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-26fm-jh3j-2ww5/GHSA-26fm-jh3j-2ww5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-26fm-jh3j-2ww5", + "modified": "2025-05-22T18:31:15Z", + "published": "2025-05-22T18:31:15Z", + "aliases": [ + "CVE-2025-33138" + ], + "details": "IBM Aspera Faspex 5.0.0 through 5.0.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33138" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7234114" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-80" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T17:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3f53-v88v-m2r8/GHSA-3f53-v88v-m2r8.json b/advisories/unreviewed/2025/05/GHSA-3f53-v88v-m2r8/GHSA-3f53-v88v-m2r8.json new file mode 100644 index 00000000000..390b7312ce4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3f53-v88v-m2r8/GHSA-3f53-v88v-m2r8.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3f53-v88v-m2r8", + "modified": "2025-05-22T18:31:16Z", + "published": "2025-05-22T18:31:16Z", + "aliases": [ + "CVE-2025-30169" + ], + "details": "File upload and execute vulnerabilities in ASPECT allow PHP script injection if session administrator credentials become compromised.\nThis issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:C/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30169" + }, + { + "type": "WEB", + "url": "https://search.abb.com/library/Download.aspx?DocumentID=9AKK108471A0021&LanguageCode=en&DocumentPartId=pdf&Action=Launch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T18:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3wc3-w43j-x6wh/GHSA-3wc3-w43j-x6wh.json b/advisories/unreviewed/2025/05/GHSA-3wc3-w43j-x6wh/GHSA-3wc3-w43j-x6wh.json new file mode 100644 index 00000000000..de41450b8f4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3wc3-w43j-x6wh/GHSA-3wc3-w43j-x6wh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3wc3-w43j-x6wh", + "modified": "2025-05-22T18:31:15Z", + "published": "2025-05-22T18:31:15Z", + "aliases": [ + "CVE-2025-33136" + ], + "details": "IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due to improper protection of assumed immutable data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33136" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7234114" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-471" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T17:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5548-25gc-qcxx/GHSA-5548-25gc-qcxx.json b/advisories/unreviewed/2025/05/GHSA-5548-25gc-qcxx/GHSA-5548-25gc-qcxx.json new file mode 100644 index 00000000000..c50167bba90 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5548-25gc-qcxx/GHSA-5548-25gc-qcxx.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5548-25gc-qcxx", + "modified": "2025-05-22T18:31:15Z", + "published": "2025-05-22T18:31:15Z", + "aliases": [ + "CVE-2025-5081" + ], + "details": "A vulnerability classified as critical was found in Campcodes Cybercafe Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /adminprofile.php. The manipulation of the argument mobilenumber leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5081" + }, + { + "type": "WEB", + "url": "https://github.com/wzylky/CVE/issues/1" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309961" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309961" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.582065" + }, + { + "type": "WEB", + "url": "https://www.campcodes.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T16:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5fcg-gph2-wcvg/GHSA-5fcg-gph2-wcvg.json b/advisories/unreviewed/2025/05/GHSA-5fcg-gph2-wcvg/GHSA-5fcg-gph2-wcvg.json new file mode 100644 index 00000000000..cca210f28a8 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5fcg-gph2-wcvg/GHSA-5fcg-gph2-wcvg.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5fcg-gph2-wcvg", + "modified": "2025-05-22T18:31:16Z", + "published": "2025-05-22T18:31:16Z", + "aliases": [ + "CVE-2024-13930" + ], + "details": "An Unchecked Loop Condition in ASPECT provides an attacker the ability to maliciously consume system resources if session administrator credentials become compromised\nThis issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:C/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13930" + }, + { + "type": "WEB", + "url": "https://search.abb.com/library/Download.aspx?DocumentID=9AKK108471A0021&LanguageCode=en&DocumentPartId=pdf&Action=Launch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-606" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T18:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-662m-3r43-rvw4/GHSA-662m-3r43-rvw4.json b/advisories/unreviewed/2025/05/GHSA-662m-3r43-rvw4/GHSA-662m-3r43-rvw4.json index df928e83ecd..1ef79dae4b4 100644 --- a/advisories/unreviewed/2025/05/GHSA-662m-3r43-rvw4/GHSA-662m-3r43-rvw4.json +++ b/advisories/unreviewed/2025/05/GHSA-662m-3r43-rvw4/GHSA-662m-3r43-rvw4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-662m-3r43-rvw4", - "modified": "2025-05-22T15:34:51Z", + "modified": "2025-05-22T18:31:15Z", "published": "2025-05-22T15:34:51Z", "aliases": [ "CVE-2025-32815" ], "details": "An issue was discovered in Infoblox NETMRI before 7.6.1. Authentication Bypass via a Hardcoded credential can occur.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-22T15:16:04Z" diff --git a/advisories/unreviewed/2025/05/GHSA-6jv2-q76w-6w5g/GHSA-6jv2-q76w-6w5g.json b/advisories/unreviewed/2025/05/GHSA-6jv2-q76w-6w5g/GHSA-6jv2-q76w-6w5g.json new file mode 100644 index 00000000000..96fc3d1e673 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6jv2-q76w-6w5g/GHSA-6jv2-q76w-6w5g.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6jv2-q76w-6w5g", + "modified": "2025-05-22T18:31:16Z", + "published": "2025-05-22T18:31:16Z", + "aliases": [ + "CVE-2025-2409" + ], + "details": "File corruption vulnerabilities in ASPECT provide attackers access to overwrite sys-tem files if session administrator credentials become compromised\nThis issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:C/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2409" + }, + { + "type": "WEB", + "url": "https://search.abb.com/library/Download.aspx?DocumentID=9AKK108471A0021&LanguageCode=en&DocumentPartId=pdf&Action=Launch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-73" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T18:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7893-2vg2-2738/GHSA-7893-2vg2-2738.json b/advisories/unreviewed/2025/05/GHSA-7893-2vg2-2738/GHSA-7893-2vg2-2738.json new file mode 100644 index 00000000000..225e5f2627a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7893-2vg2-2738/GHSA-7893-2vg2-2738.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7893-2vg2-2738", + "modified": "2025-05-22T18:31:15Z", + "published": "2025-05-22T18:31:15Z", + "aliases": [ + "CVE-2025-23183" + ], + "details": "CWE-601: URL Redirection to Untrusted Site ('Open Redirect')", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23183" + }, + { + "type": "WEB", + "url": "https://www.gov.il/en/departments/dynamiccollectors/cve_advisories_listing?skip=0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T16:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7xfj-j894-qgcq/GHSA-7xfj-j894-qgcq.json b/advisories/unreviewed/2025/05/GHSA-7xfj-j894-qgcq/GHSA-7xfj-j894-qgcq.json new file mode 100644 index 00000000000..b287442df4a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7xfj-j894-qgcq/GHSA-7xfj-j894-qgcq.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7xfj-j894-qgcq", + "modified": "2025-05-22T18:31:15Z", + "published": "2025-05-22T18:31:15Z", + "aliases": [ + "CVE-2025-45468" + ], + "details": "Insecure permissions in fc-stable-diffusion-plus v1.0.18 allows attackers to escalate privileges and compromise the customer cloud account.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45468" + }, + { + "type": "WEB", + "url": "https://gist.github.com/zolaer9527/fda954ea6ab9a34b3d3de35e7131e3e1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T16:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9mcw-h59j-pwj3/GHSA-9mcw-h59j-pwj3.json b/advisories/unreviewed/2025/05/GHSA-9mcw-h59j-pwj3/GHSA-9mcw-h59j-pwj3.json new file mode 100644 index 00000000000..4a6ac15b928 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9mcw-h59j-pwj3/GHSA-9mcw-h59j-pwj3.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9mcw-h59j-pwj3", + "modified": "2025-05-22T18:31:16Z", + "published": "2025-05-22T18:31:16Z", + "aliases": [ + "CVE-2024-13929" + ], + "details": "Servlet injection vulnerabilities in ASPECT allow remote code execution if session administrator credentials become compromised.\nThis issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:C/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13929" + }, + { + "type": "WEB", + "url": "https://search.abb.com/library/Download.aspx?DocumentID=9AKK108471A0021&LanguageCode=en&DocumentPartId=pdf&Action=Launch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T18:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9r52-rcmc-x62w/GHSA-9r52-rcmc-x62w.json b/advisories/unreviewed/2025/05/GHSA-9r52-rcmc-x62w/GHSA-9r52-rcmc-x62w.json new file mode 100644 index 00000000000..ce57e2c03f1 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9r52-rcmc-x62w/GHSA-9r52-rcmc-x62w.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9r52-rcmc-x62w", + "modified": "2025-05-22T18:31:16Z", + "published": "2025-05-22T18:31:16Z", + "aliases": [ + "CVE-2025-43596" + ], + "details": "An insecure file system permissions vulnerability in MSP360 Backup 8.0 allows a low privileged user to execute commands with SYSTEM level privileges using a specially crafted file with an arbitrary file backup target. Upgrade to MSP360 Backup 8.1.1.19 (released on 2025-05-15).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43596" + }, + { + "type": "WEB", + "url": "https://help.msp360.com/cloudberry-backup/security/admin-privileges" + }, + { + "type": "WEB", + "url": "https://help.msp360.com/cloudberry-backup/whats-new" + }, + { + "type": "WEB", + "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-119-01.json" + }, + { + "type": "WEB", + "url": "https://www.cve.org/CVERecord?id=CVE-2025-43596" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T17:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9vwh-wfrg-2h6f/GHSA-9vwh-wfrg-2h6f.json b/advisories/unreviewed/2025/05/GHSA-9vwh-wfrg-2h6f/GHSA-9vwh-wfrg-2h6f.json new file mode 100644 index 00000000000..d93a7c105d6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9vwh-wfrg-2h6f/GHSA-9vwh-wfrg-2h6f.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9vwh-wfrg-2h6f", + "modified": "2025-05-22T18:31:16Z", + "published": "2025-05-22T18:31:16Z", + "aliases": [ + "CVE-2025-30171" + ], + "details": "System File Deletion vulnerabilities in ASPECT provide attackers access to delete system files if session administrator credentials become compromised.\nThis issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:C/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30171" + }, + { + "type": "WEB", + "url": "https://search.abb.com/library/Download.aspx?DocumentID=9AKK108471A0021&LanguageCode=en&DocumentPartId=pdf&Action=Launch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T18:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c9x9-qgxx-cj62/GHSA-c9x9-qgxx-cj62.json b/advisories/unreviewed/2025/05/GHSA-c9x9-qgxx-cj62/GHSA-c9x9-qgxx-cj62.json new file mode 100644 index 00000000000..2f99c631101 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c9x9-qgxx-cj62/GHSA-c9x9-qgxx-cj62.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c9x9-qgxx-cj62", + "modified": "2025-05-22T18:31:15Z", + "published": "2025-05-22T18:31:15Z", + "aliases": [ + "CVE-2024-48853" + ], + "details": "An escalation of privilege vulnerability in ASPECT could provide an attacker root access to a server when logged in as a \"non\" root ASPECT user. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:U/V:C/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48853" + }, + { + "type": "WEB", + "url": "https://search.abb.com/library/Download.aspx?DocumentID=9AKK108471A0021&LanguageCode=en&DocumentPartId=pdf&Action=Launch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-286" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T17:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-cp2f-vm9g-5gqr/GHSA-cp2f-vm9g-5gqr.json b/advisories/unreviewed/2025/05/GHSA-cp2f-vm9g-5gqr/GHSA-cp2f-vm9g-5gqr.json new file mode 100644 index 00000000000..91e843c013e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-cp2f-vm9g-5gqr/GHSA-cp2f-vm9g-5gqr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cp2f-vm9g-5gqr", + "modified": "2025-05-22T18:31:15Z", + "published": "2025-05-22T18:31:15Z", + "aliases": [ + "CVE-2025-23182" + ], + "details": "CWE-203: Observable Discrepancy", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23182" + }, + { + "type": "WEB", + "url": "https://www.gov.il/en/departments/dynamiccollectors/cve_advisories_listing?skip=0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-203" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T16:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-cq8v-wvwh-vcpg/GHSA-cq8v-wvwh-vcpg.json b/advisories/unreviewed/2025/05/GHSA-cq8v-wvwh-vcpg/GHSA-cq8v-wvwh-vcpg.json new file mode 100644 index 00000000000..776c9986ada --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-cq8v-wvwh-vcpg/GHSA-cq8v-wvwh-vcpg.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cq8v-wvwh-vcpg", + "modified": "2025-05-22T18:31:16Z", + "published": "2025-05-22T18:31:16Z", + "aliases": [ + "CVE-2024-13928" + ], + "details": "SQL injection vulnerabilities in ASPECT allow unintended access and manipulation of database repositories if session administrator credentials become compromised.\nThis issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:C/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13928" + }, + { + "type": "WEB", + "url": "https://search.abb.com/library/Download.aspx?DocumentID=9AKK108471A0021&LanguageCode=en&DocumentPartId=pdf&Action=Launch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T18:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-ffqf-972q-qhhv/GHSA-ffqf-972q-qhhv.json b/advisories/unreviewed/2025/05/GHSA-ffqf-972q-qhhv/GHSA-ffqf-972q-qhhv.json new file mode 100644 index 00000000000..a949fcd12dd --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-ffqf-972q-qhhv/GHSA-ffqf-972q-qhhv.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ffqf-972q-qhhv", + "modified": "2025-05-22T18:31:16Z", + "published": "2025-05-22T18:31:16Z", + "aliases": [ + "CVE-2024-52874" + ], + "details": "In Infoblox NETMRI before 7.6.1, authenticated users can perform SQL injection attacks.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52874" + }, + { + "type": "WEB", + "url": "https://support.infoblox.com/s/article/Infoblox-NetMRI-is-vulnerable-to-CVE-2024-52874" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T18:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gjwx-g2ph-472r/GHSA-gjwx-g2ph-472r.json b/advisories/unreviewed/2025/05/GHSA-gjwx-g2ph-472r/GHSA-gjwx-g2ph-472r.json index 635cea9cbda..a53b724fc30 100644 --- a/advisories/unreviewed/2025/05/GHSA-gjwx-g2ph-472r/GHSA-gjwx-g2ph-472r.json +++ b/advisories/unreviewed/2025/05/GHSA-gjwx-g2ph-472r/GHSA-gjwx-g2ph-472r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gjwx-g2ph-472r", - "modified": "2025-05-02T00:32:15Z", + "modified": "2025-05-22T18:31:14Z", "published": "2025-05-02T00:32:15Z", "aliases": [ "CVE-2025-43595" @@ -26,6 +26,14 @@ { "type": "WEB", "url": "https://help.msp360.com/cloudberry-backup-mac-linux/whats-new" + }, + { + "type": "WEB", + "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-119-01.json" + }, + { + "type": "WEB", + "url": "https://www.cve.org/CVERecord?id=CVE-2025-43595" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/05/GHSA-pf9f-fx8v-xgx8/GHSA-pf9f-fx8v-xgx8.json b/advisories/unreviewed/2025/05/GHSA-pf9f-fx8v-xgx8/GHSA-pf9f-fx8v-xgx8.json index d8d26eb57c5..f54cca754a5 100644 --- a/advisories/unreviewed/2025/05/GHSA-pf9f-fx8v-xgx8/GHSA-pf9f-fx8v-xgx8.json +++ b/advisories/unreviewed/2025/05/GHSA-pf9f-fx8v-xgx8/GHSA-pf9f-fx8v-xgx8.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-qg6w-c843-2xjm/GHSA-qg6w-c843-2xjm.json b/advisories/unreviewed/2025/05/GHSA-qg6w-c843-2xjm/GHSA-qg6w-c843-2xjm.json new file mode 100644 index 00000000000..1d6da87db41 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qg6w-c843-2xjm/GHSA-qg6w-c843-2xjm.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qg6w-c843-2xjm", + "modified": "2025-05-22T18:31:17Z", + "published": "2025-05-22T18:31:16Z", + "aliases": [ + "CVE-2025-30173" + ], + "details": "File upload vulnerabilities are present in ASPECT if session administrator credentials become compromised\nThis issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:C/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30173" + }, + { + "type": "WEB", + "url": "https://search.abb.com/library/Download.aspx?DocumentID=9AKK108471A0021&LanguageCode=en&DocumentPartId=pdf&Action=Launch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T18:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-r29h-8w9g-r68q/GHSA-r29h-8w9g-r68q.json b/advisories/unreviewed/2025/05/GHSA-r29h-8w9g-r68q/GHSA-r29h-8w9g-r68q.json new file mode 100644 index 00000000000..44120731423 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-r29h-8w9g-r68q/GHSA-r29h-8w9g-r68q.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r29h-8w9g-r68q", + "modified": "2025-05-22T18:31:16Z", + "published": "2025-05-22T18:31:16Z", + "aliases": [ + "CVE-2024-9639" + ], + "details": "Remote Code Execution vulnerabilities are present in ASPECT if session administra-tor credentials become compromised.\nThis issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:U/V:C/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9639" + }, + { + "type": "WEB", + "url": "https://search.abb.com/library/Download.aspx?DocumentID=9AKK108471A0021&LanguageCode=en&DocumentPartId=pdf&Action=Launch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T18:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rhjh-wqrx-9374/GHSA-rhjh-wqrx-9374.json b/advisories/unreviewed/2025/05/GHSA-rhjh-wqrx-9374/GHSA-rhjh-wqrx-9374.json new file mode 100644 index 00000000000..ea92471ed4a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rhjh-wqrx-9374/GHSA-rhjh-wqrx-9374.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rhjh-wqrx-9374", + "modified": "2025-05-22T18:31:16Z", + "published": "2025-05-22T18:31:16Z", + "aliases": [ + "CVE-2024-13931" + ], + "details": "Relative Path Traversal vulnerabilities in ASPECT allow access to file resources if session administrator credentials become compromised.\nThis issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:C/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13931" + }, + { + "type": "WEB", + "url": "https://search.abb.com/library/Download.aspx?DocumentID=9AKK108471A0021&LanguageCode=en&DocumentPartId=pdf&Action=Launch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-606" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T18:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v8qh-5c5w-48pp/GHSA-v8qh-5c5w-48pp.json b/advisories/unreviewed/2025/05/GHSA-v8qh-5c5w-48pp/GHSA-v8qh-5c5w-48pp.json index e9e65666152..99ee13f4fbb 100644 --- a/advisories/unreviewed/2025/05/GHSA-v8qh-5c5w-48pp/GHSA-v8qh-5c5w-48pp.json +++ b/advisories/unreviewed/2025/05/GHSA-v8qh-5c5w-48pp/GHSA-v8qh-5c5w-48pp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v8qh-5c5w-48pp", - "modified": "2025-05-22T15:34:50Z", + "modified": "2025-05-22T18:31:15Z", "published": "2025-05-22T15:34:50Z", "aliases": [ "CVE-2025-4575" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://openssl-library.org/news/secadv/20250522.txt" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/05/22/1" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/05/GHSA-vvcp-wcvc-hv6h/GHSA-vvcp-wcvc-hv6h.json b/advisories/unreviewed/2025/05/GHSA-vvcp-wcvc-hv6h/GHSA-vvcp-wcvc-hv6h.json new file mode 100644 index 00000000000..d22ab6d4106 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vvcp-wcvc-hv6h/GHSA-vvcp-wcvc-hv6h.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vvcp-wcvc-hv6h", + "modified": "2025-05-22T18:31:15Z", + "published": "2025-05-22T18:31:15Z", + "aliases": [ + "CVE-2024-48850" + ], + "details": "Absolute File Traversal vulnerabilities in ASPECT allows access and modification of unintended resources.\nThis issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:U/V:C/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48850" + }, + { + "type": "WEB", + "url": "https://search.abb.com/library/Download.aspx?DocumentID=9AKK108471A0021&LanguageCode=en&DocumentPartId=pdf&Action=Launch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-36" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T17:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w6gx-hfp5-rmhr/GHSA-w6gx-hfp5-rmhr.json b/advisories/unreviewed/2025/05/GHSA-w6gx-hfp5-rmhr/GHSA-w6gx-hfp5-rmhr.json new file mode 100644 index 00000000000..6317715a8d9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w6gx-hfp5-rmhr/GHSA-w6gx-hfp5-rmhr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w6gx-hfp5-rmhr", + "modified": "2025-05-22T18:31:15Z", + "published": "2025-05-22T18:31:15Z", + "aliases": [ + "CVE-2025-33137" + ], + "details": "IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due to client-side enforcement of server-side security.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33137" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7234114" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-602" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T17:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-x4jw-p584-84v2/GHSA-x4jw-p584-84v2.json b/advisories/unreviewed/2025/05/GHSA-x4jw-p584-84v2/GHSA-x4jw-p584-84v2.json index bd18ee170a8..d26f180f901 100644 --- a/advisories/unreviewed/2025/05/GHSA-x4jw-p584-84v2/GHSA-x4jw-p584-84v2.json +++ b/advisories/unreviewed/2025/05/GHSA-x4jw-p584-84v2/GHSA-x4jw-p584-84v2.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-x5rp-3mjc-5m63/GHSA-x5rp-3mjc-5m63.json b/advisories/unreviewed/2025/05/GHSA-x5rp-3mjc-5m63/GHSA-x5rp-3mjc-5m63.json new file mode 100644 index 00000000000..a2e55319472 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-x5rp-3mjc-5m63/GHSA-x5rp-3mjc-5m63.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x5rp-3mjc-5m63", + "modified": "2025-05-22T18:31:16Z", + "published": "2025-05-22T18:31:16Z", + "aliases": [ + "CVE-2025-30172" + ], + "details": "Remote Code Execution vulnerabilities are present in ASPECT if session administrator credentials become compromised\nThis issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:C/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30172" + }, + { + "type": "WEB", + "url": "https://search.abb.com/library/Download.aspx?DocumentID=9AKK108471A0021&LanguageCode=en&DocumentPartId=pdf&Action=Launch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T18:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-x9g7-j8rx-fcjc/GHSA-x9g7-j8rx-fcjc.json b/advisories/unreviewed/2025/05/GHSA-x9g7-j8rx-fcjc/GHSA-x9g7-j8rx-fcjc.json new file mode 100644 index 00000000000..8d860518ed2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-x9g7-j8rx-fcjc/GHSA-x9g7-j8rx-fcjc.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x9g7-j8rx-fcjc", + "modified": "2025-05-22T18:31:16Z", + "published": "2025-05-22T18:31:16Z", + "aliases": [ + "CVE-2025-45472" + ], + "details": "Insecure permissions in autodeploy-layer v1.2.0 allows attackers to escalate privileges and compromise the customer cloud account.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45472" + }, + { + "type": "WEB", + "url": "https://gist.github.com/zolaer9527/9a703e9dc575bf1889b275caf7121578" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T17:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xfj4-w5m6-x8f6/GHSA-xfj4-w5m6-x8f6.json b/advisories/unreviewed/2025/05/GHSA-xfj4-w5m6-x8f6/GHSA-xfj4-w5m6-x8f6.json index 8692a5a60b2..fddd8ed1c31 100644 --- a/advisories/unreviewed/2025/05/GHSA-xfj4-w5m6-x8f6/GHSA-xfj4-w5m6-x8f6.json +++ b/advisories/unreviewed/2025/05/GHSA-xfj4-w5m6-x8f6/GHSA-xfj4-w5m6-x8f6.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-121" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-xm8g-3cm4-4x8x/GHSA-xm8g-3cm4-4x8x.json b/advisories/unreviewed/2025/05/GHSA-xm8g-3cm4-4x8x/GHSA-xm8g-3cm4-4x8x.json new file mode 100644 index 00000000000..b449d8a6007 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xm8g-3cm4-4x8x/GHSA-xm8g-3cm4-4x8x.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xm8g-3cm4-4x8x", + "modified": "2025-05-22T18:31:16Z", + "published": "2025-05-22T18:31:16Z", + "aliases": [ + "CVE-2025-2410" + ], + "details": "Port manipulation vulnerabilities in ASPECT provide attackers with the ability to con-trol TCP/IP port access if session administrator credentials become compromised.\nThis issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:C/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2410" + }, + { + "type": "WEB", + "url": "https://search.abb.com/library/Download.aspx?DocumentID=9AKK108471A0021&LanguageCode=en&DocumentPartId=pdf&Action=Launch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-36" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T18:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xpm6-qgmg-747p/GHSA-xpm6-qgmg-747p.json b/advisories/unreviewed/2025/05/GHSA-xpm6-qgmg-747p/GHSA-xpm6-qgmg-747p.json new file mode 100644 index 00000000000..08a1e78d9e2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xpm6-qgmg-747p/GHSA-xpm6-qgmg-747p.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xpm6-qgmg-747p", + "modified": "2025-05-22T18:31:16Z", + "published": "2025-05-22T18:31:16Z", + "aliases": [ + "CVE-2025-30170" + ], + "details": "Exposure of file path, file size or file existence vulnerabilities in ASPECT provide attackers access to file system information if session administrator credentials become compromised.\nThis issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:C/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30170" + }, + { + "type": "WEB", + "url": "https://search.abb.com/library/Download.aspx?DocumentID=9AKK108471A0021&LanguageCode=en&DocumentPartId=pdf&Action=Launch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T18:15:41Z" + } +} \ No newline at end of file