From a254210027c5ae8cce78be8df2893279aa28de98 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 23 May 2025 15:32:51 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-gmg8-593g-7mv3.json | 6 +- .../GHSA-8f4m-xpm2-5rxj.json | 4 +- .../GHSA-jw74-jmpx-mj4j.json | 4 +- .../GHSA-v7pq-vg76-qwqx.json | 6 +- .../GHSA-22xf-532v-3xqg.json | 3 +- .../GHSA-6484-jh3g-q998.json | 3 +- .../GHSA-fph8-w359-q9x9.json | 3 +- .../GHSA-vg86-8433-4hr2.json | 2 +- .../GHSA-65rj-829h-6g8x.json | 6 +- .../GHSA-cqj4-fp95-jqxq.json | 6 +- .../GHSA-j3qr-8f3v-fgjj.json | 6 +- .../GHSA-25wq-m5r4-rrm3.json | 36 ++++++++++++ .../GHSA-2659-8m74-4v6x.json | 36 ++++++++++++ .../GHSA-2963-8wvc-3fv3.json | 36 ++++++++++++ .../GHSA-2g6j-8hm3-67hp.json | 36 ++++++++++++ .../GHSA-2gf3-v8px-49h6.json | 36 ++++++++++++ .../GHSA-2m9r-8wqr-rccv.json | 3 +- .../GHSA-2rcx-2829-7fg5.json | 36 ++++++++++++ .../GHSA-2rgj-5hr4-v9vp.json | 36 ++++++++++++ .../GHSA-2v3m-6ccx-2995.json | 36 ++++++++++++ .../GHSA-3268-x73x-v8rp.json | 36 ++++++++++++ .../GHSA-33j7-6p7h-f87g.json | 40 +++++++++++++ .../GHSA-36xm-ch76-gv9j.json | 36 ++++++++++++ .../GHSA-39hr-qmg2-rcg4.json | 36 ++++++++++++ .../GHSA-3c52-m5xj-c7ff.json | 40 +++++++++++++ .../GHSA-3f9c-xxj6-82v8.json | 36 ++++++++++++ .../GHSA-3grc-cj2m-fpc6.json | 36 ++++++++++++ .../GHSA-3hmp-hq97-xvfh.json | 36 ++++++++++++ .../GHSA-3hv9-p65c-7g5r.json | 36 ++++++++++++ .../GHSA-43mx-35xv-4r2v.json | 36 ++++++++++++ .../GHSA-46xm-5ggp-p743.json | 36 ++++++++++++ .../GHSA-4c59-wg4x-f787.json | 3 +- .../GHSA-4hrj-7997-8qf3.json | 36 ++++++++++++ .../GHSA-4v9q-9v9j-rwrc.json | 36 ++++++++++++ .../GHSA-4w7m-m9xf-94pc.json | 3 +- .../GHSA-4wjv-q2ww-cm43.json | 36 ++++++++++++ .../GHSA-4x22-29pf-hh57.json | 36 ++++++++++++ .../GHSA-4xfx-qcgh-g3x4.json | 52 +++++++++++++++++ .../GHSA-528m-5r46-h6pj.json | 36 ++++++++++++ .../GHSA-5445-5pxc-8pcc.json | 36 ++++++++++++ .../GHSA-5556-32h3-7q94.json | 36 ++++++++++++ .../GHSA-5857-r24c-jg46.json | 36 ++++++++++++ .../GHSA-58mp-vjj5-c38v.json | 36 ++++++++++++ .../GHSA-5h4m-f9x8-8ffh.json | 52 +++++++++++++++++ .../GHSA-5j6j-9vjj-6r3v.json | 36 ++++++++++++ .../GHSA-5jpm-x79x-x3cf.json | 36 ++++++++++++ .../GHSA-5mg8-4p8m-7w4r.json | 36 ++++++++++++ .../GHSA-5whm-4gc4-rw65.json | 36 ++++++++++++ .../GHSA-5xgx-vjx4-mfwv.json | 36 ++++++++++++ .../GHSA-6356-52fq-7vxx.json | 36 ++++++++++++ .../GHSA-6599-4gf3-q8fm.json | 36 ++++++++++++ .../GHSA-6cfw-fhp6-2m5g.json | 36 ++++++++++++ .../GHSA-6g94-c7r6-364g.json | 36 ++++++++++++ .../GHSA-6jj3-5xxj-9xx4.json | 36 ++++++++++++ .../GHSA-6rph-38r5-8hhp.json | 36 ++++++++++++ .../GHSA-6v5q-hw53-jvh9.json | 36 ++++++++++++ .../GHSA-735c-m362-rv89.json | 36 ++++++++++++ .../GHSA-73r7-6qf7-8658.json | 36 ++++++++++++ .../GHSA-746h-9hhm-mgv6.json | 36 ++++++++++++ .../GHSA-7893-p2h2-24qf.json | 36 ++++++++++++ .../GHSA-7wvq-x6j3-ggcp.json | 36 ++++++++++++ .../GHSA-7x5x-m772-p63v.json | 36 ++++++++++++ .../GHSA-87qj-crf6-m933.json | 36 ++++++++++++ .../GHSA-8jx5-64fv-87qh.json | 40 +++++++++++++ .../GHSA-8qv9-rg87-qg9x.json | 36 ++++++++++++ .../GHSA-8rwf-97vc-4rh3.json | 36 ++++++++++++ .../GHSA-963m-hgv5-33vg.json | 52 +++++++++++++++++ .../GHSA-97jw-vj6m-r4jm.json | 36 ++++++++++++ .../GHSA-98mr-vfww-x4x2.json | 36 ++++++++++++ .../GHSA-9g7r-jg3m-m6wm.json | 36 ++++++++++++ .../GHSA-9grh-5gv9-xf63.json | 36 ++++++++++++ .../GHSA-9h8v-w795-r85q.json | 36 ++++++++++++ .../GHSA-9hpw-wrhw-6g76.json | 36 ++++++++++++ .../GHSA-9v6c-p69r-jc8x.json | 36 ++++++++++++ .../GHSA-9w2j-w59m-592g.json | 36 ++++++++++++ .../GHSA-9wr9-p53c-hqrq.json | 36 ++++++++++++ .../GHSA-9x45-8qmx-683p.json | 15 +++-- .../GHSA-c33v-v5r9-774j.json | 36 ++++++++++++ .../GHSA-c4jq-c26m-8vfh.json | 36 ++++++++++++ .../GHSA-cf8h-x8xq-r3cr.json | 36 ++++++++++++ .../GHSA-cjvp-vp4r-jppc.json | 3 +- .../GHSA-cqh9-2fgp-cxw2.json | 36 ++++++++++++ .../GHSA-f3vf-9cvm-w329.json | 36 ++++++++++++ .../GHSA-f9xv-95hg-pxgf.json | 36 ++++++++++++ .../GHSA-ffpp-564x-w86f.json | 36 ++++++++++++ .../GHSA-fh7c-x2jh-rc4w.json | 36 ++++++++++++ .../GHSA-fhfv-mjv5-35hp.json | 36 ++++++++++++ .../GHSA-fjqw-wgr4-3jjp.json | 36 ++++++++++++ .../GHSA-fqj7-rj6h-ppvp.json | 29 ++++++++++ .../GHSA-fqmr-g5hc-mhmq.json | 52 +++++++++++++++++ .../GHSA-fv46-529r-fc72.json | 36 ++++++++++++ .../GHSA-fvcg-g6jq-f58x.json | 36 ++++++++++++ .../GHSA-fwfc-62f3-6h7j.json | 36 ++++++++++++ .../GHSA-g4f5-x2r2-hg23.json | 52 +++++++++++++++++ .../GHSA-g78q-vwc9-9f65.json | 3 +- .../GHSA-g83r-7cwr-h2jw.json | 36 ++++++++++++ .../GHSA-gcjf-8x3p-64v2.json | 36 ++++++++++++ .../GHSA-gj3c-w556-7qwm.json | 36 ++++++++++++ .../GHSA-gpxg-v5x4-r25g.json | 36 ++++++++++++ .../GHSA-gpxh-j79m-whcj.json | 36 ++++++++++++ .../GHSA-gqgx-hgvf-f75f.json | 6 +- .../GHSA-gvwq-4r92-cj5h.json | 56 +++++++++++++++++++ .../GHSA-h2pj-2gpr-72vh.json | 36 ++++++++++++ .../GHSA-h3r6-f23f-fjw6.json | 36 ++++++++++++ .../GHSA-h3w6-hg9p-c6c4.json | 36 ++++++++++++ .../GHSA-h3xr-5jg5-xwr6.json | 36 ++++++++++++ .../GHSA-hjh6-jj5p-wf3x.json | 36 ++++++++++++ .../GHSA-hqgp-gmgc-jhhm.json | 36 ++++++++++++ .../GHSA-hx67-26rf-cg4v.json | 36 ++++++++++++ .../GHSA-j646-j4cf-jj5h.json | 36 ++++++++++++ .../GHSA-jcv7-4rpc-rwj8.json | 36 ++++++++++++ .../GHSA-jgcc-pm4w-jp8q.json | 36 ++++++++++++ .../GHSA-jgv5-6946-fjqx.json | 29 ++++++++++ .../GHSA-jp9f-x59g-67pq.json | 36 ++++++++++++ .../GHSA-jv73-vqgv-2mch.json | 36 ++++++++++++ .../GHSA-m4g8-47g2-j394.json | 52 +++++++++++++++++ .../GHSA-m537-88r7-p568.json | 29 ++++++++++ .../GHSA-m6x2-v3jc-m2m7.json | 36 ++++++++++++ .../GHSA-m9vv-g4wc-gc4q.json | 36 ++++++++++++ .../GHSA-mchr-xvw2-q64f.json | 36 ++++++++++++ .../GHSA-mgj6-95h9-vg3g.json | 15 +++-- .../GHSA-mjw8-4r4w-cj9r.json | 36 ++++++++++++ .../GHSA-mpm6-wggf-97xv.json | 36 ++++++++++++ .../GHSA-mqcw-437p-q69q.json | 40 +++++++++++++ .../GHSA-mqvg-gc79-6rxx.json | 36 ++++++++++++ .../GHSA-mvfc-pmj6-8j77.json | 3 +- .../GHSA-p2p2-vfxx-r5rp.json | 36 ++++++++++++ .../GHSA-p39x-3wqr-ggff.json | 36 ++++++++++++ .../GHSA-p97h-v2qf-9878.json | 36 ++++++++++++ .../GHSA-p9wx-2529-fp83.json | 48 ++++++++++++++++ .../GHSA-pqgc-vw44-8qm5.json | 36 ++++++++++++ .../GHSA-pr3p-9qh5-qp2f.json | 36 ++++++++++++ .../GHSA-q52p-775j-hjv8.json | 36 ++++++++++++ .../GHSA-q749-5rmc-5pxm.json | 36 ++++++++++++ .../GHSA-qjr4-ppfx-2vc4.json | 36 ++++++++++++ .../GHSA-qw6m-wwcp-hjpw.json | 36 ++++++++++++ .../GHSA-qwmp-5m8m-pjvf.json | 36 ++++++++++++ .../GHSA-r9pj-264x-c5c5.json | 36 ++++++++++++ .../GHSA-rhqf-r6rm-3j54.json | 36 ++++++++++++ .../GHSA-rmxc-5894-fxhq.json | 36 ++++++++++++ .../GHSA-rqwp-p4f7-h975.json | 36 ++++++++++++ .../GHSA-rvm6-q5vv-cfhx.json | 36 ++++++++++++ .../GHSA-v4pp-gcmm-cv95.json | 36 ++++++++++++ .../GHSA-v5wj-4vcq-v5gw.json | 36 ++++++++++++ .../GHSA-v6m7-qh5v-q2j5.json | 36 ++++++++++++ .../GHSA-v7cm-mpcm-37f9.json | 36 ++++++++++++ .../GHSA-v7m3-xg38-3qfq.json | 36 ++++++++++++ .../GHSA-v8q7-jm3p-3j3q.json | 36 ++++++++++++ .../GHSA-vcf3-77pf-w4hq.json | 36 ++++++++++++ .../GHSA-vphc-878c-44gv.json | 36 ++++++++++++ .../GHSA-vrwv-78gw-c2wc.json | 36 ++++++++++++ .../GHSA-w3mv-rjr4-wpcg.json | 36 ++++++++++++ .../GHSA-w4q4-qqj7-r6q8.json | 36 ++++++++++++ .../GHSA-wfv4-fr2r-9jgv.json | 36 ++++++++++++ .../GHSA-wg2m-xw57-fqc9.json | 3 +- .../GHSA-wjqw-p7j2-5gx2.json | 36 ++++++++++++ .../GHSA-wm4r-97wr-6vw2.json | 36 ++++++++++++ .../GHSA-wqj4-2vw3-c5jw.json | 36 ++++++++++++ .../GHSA-wqrq-vwwp-qpvv.json | 3 +- .../GHSA-wx7w-g52q-jg5g.json | 36 ++++++++++++ .../GHSA-x6xg-9w9q-643p.json | 29 ++++++++++ .../GHSA-xgcx-978m-c62h.json | 29 ++++++++++ .../GHSA-xp23-94cq-8m5g.json | 40 +++++++++++++ 163 files changed, 5269 insertions(+), 29 deletions(-) create mode 100644 advisories/unreviewed/2025/05/GHSA-25wq-m5r4-rrm3/GHSA-25wq-m5r4-rrm3.json create mode 100644 advisories/unreviewed/2025/05/GHSA-2659-8m74-4v6x/GHSA-2659-8m74-4v6x.json create mode 100644 advisories/unreviewed/2025/05/GHSA-2963-8wvc-3fv3/GHSA-2963-8wvc-3fv3.json create mode 100644 advisories/unreviewed/2025/05/GHSA-2g6j-8hm3-67hp/GHSA-2g6j-8hm3-67hp.json create mode 100644 advisories/unreviewed/2025/05/GHSA-2gf3-v8px-49h6/GHSA-2gf3-v8px-49h6.json create mode 100644 advisories/unreviewed/2025/05/GHSA-2rcx-2829-7fg5/GHSA-2rcx-2829-7fg5.json create mode 100644 advisories/unreviewed/2025/05/GHSA-2rgj-5hr4-v9vp/GHSA-2rgj-5hr4-v9vp.json create mode 100644 advisories/unreviewed/2025/05/GHSA-2v3m-6ccx-2995/GHSA-2v3m-6ccx-2995.json create mode 100644 advisories/unreviewed/2025/05/GHSA-3268-x73x-v8rp/GHSA-3268-x73x-v8rp.json create mode 100644 advisories/unreviewed/2025/05/GHSA-33j7-6p7h-f87g/GHSA-33j7-6p7h-f87g.json create mode 100644 advisories/unreviewed/2025/05/GHSA-36xm-ch76-gv9j/GHSA-36xm-ch76-gv9j.json create mode 100644 advisories/unreviewed/2025/05/GHSA-39hr-qmg2-rcg4/GHSA-39hr-qmg2-rcg4.json create mode 100644 advisories/unreviewed/2025/05/GHSA-3c52-m5xj-c7ff/GHSA-3c52-m5xj-c7ff.json create mode 100644 advisories/unreviewed/2025/05/GHSA-3f9c-xxj6-82v8/GHSA-3f9c-xxj6-82v8.json create mode 100644 advisories/unreviewed/2025/05/GHSA-3grc-cj2m-fpc6/GHSA-3grc-cj2m-fpc6.json create mode 100644 advisories/unreviewed/2025/05/GHSA-3hmp-hq97-xvfh/GHSA-3hmp-hq97-xvfh.json create mode 100644 advisories/unreviewed/2025/05/GHSA-3hv9-p65c-7g5r/GHSA-3hv9-p65c-7g5r.json create mode 100644 advisories/unreviewed/2025/05/GHSA-43mx-35xv-4r2v/GHSA-43mx-35xv-4r2v.json create mode 100644 advisories/unreviewed/2025/05/GHSA-46xm-5ggp-p743/GHSA-46xm-5ggp-p743.json create mode 100644 advisories/unreviewed/2025/05/GHSA-4hrj-7997-8qf3/GHSA-4hrj-7997-8qf3.json create mode 100644 advisories/unreviewed/2025/05/GHSA-4v9q-9v9j-rwrc/GHSA-4v9q-9v9j-rwrc.json create mode 100644 advisories/unreviewed/2025/05/GHSA-4wjv-q2ww-cm43/GHSA-4wjv-q2ww-cm43.json create mode 100644 advisories/unreviewed/2025/05/GHSA-4x22-29pf-hh57/GHSA-4x22-29pf-hh57.json create mode 100644 advisories/unreviewed/2025/05/GHSA-4xfx-qcgh-g3x4/GHSA-4xfx-qcgh-g3x4.json create mode 100644 advisories/unreviewed/2025/05/GHSA-528m-5r46-h6pj/GHSA-528m-5r46-h6pj.json create mode 100644 advisories/unreviewed/2025/05/GHSA-5445-5pxc-8pcc/GHSA-5445-5pxc-8pcc.json create mode 100644 advisories/unreviewed/2025/05/GHSA-5556-32h3-7q94/GHSA-5556-32h3-7q94.json create mode 100644 advisories/unreviewed/2025/05/GHSA-5857-r24c-jg46/GHSA-5857-r24c-jg46.json create mode 100644 advisories/unreviewed/2025/05/GHSA-58mp-vjj5-c38v/GHSA-58mp-vjj5-c38v.json create mode 100644 advisories/unreviewed/2025/05/GHSA-5h4m-f9x8-8ffh/GHSA-5h4m-f9x8-8ffh.json create mode 100644 advisories/unreviewed/2025/05/GHSA-5j6j-9vjj-6r3v/GHSA-5j6j-9vjj-6r3v.json create mode 100644 advisories/unreviewed/2025/05/GHSA-5jpm-x79x-x3cf/GHSA-5jpm-x79x-x3cf.json create mode 100644 advisories/unreviewed/2025/05/GHSA-5mg8-4p8m-7w4r/GHSA-5mg8-4p8m-7w4r.json create mode 100644 advisories/unreviewed/2025/05/GHSA-5whm-4gc4-rw65/GHSA-5whm-4gc4-rw65.json create mode 100644 advisories/unreviewed/2025/05/GHSA-5xgx-vjx4-mfwv/GHSA-5xgx-vjx4-mfwv.json create mode 100644 advisories/unreviewed/2025/05/GHSA-6356-52fq-7vxx/GHSA-6356-52fq-7vxx.json create mode 100644 advisories/unreviewed/2025/05/GHSA-6599-4gf3-q8fm/GHSA-6599-4gf3-q8fm.json create mode 100644 advisories/unreviewed/2025/05/GHSA-6cfw-fhp6-2m5g/GHSA-6cfw-fhp6-2m5g.json create mode 100644 advisories/unreviewed/2025/05/GHSA-6g94-c7r6-364g/GHSA-6g94-c7r6-364g.json create mode 100644 advisories/unreviewed/2025/05/GHSA-6jj3-5xxj-9xx4/GHSA-6jj3-5xxj-9xx4.json create mode 100644 advisories/unreviewed/2025/05/GHSA-6rph-38r5-8hhp/GHSA-6rph-38r5-8hhp.json create mode 100644 advisories/unreviewed/2025/05/GHSA-6v5q-hw53-jvh9/GHSA-6v5q-hw53-jvh9.json create mode 100644 advisories/unreviewed/2025/05/GHSA-735c-m362-rv89/GHSA-735c-m362-rv89.json create mode 100644 advisories/unreviewed/2025/05/GHSA-73r7-6qf7-8658/GHSA-73r7-6qf7-8658.json create mode 100644 advisories/unreviewed/2025/05/GHSA-746h-9hhm-mgv6/GHSA-746h-9hhm-mgv6.json create mode 100644 advisories/unreviewed/2025/05/GHSA-7893-p2h2-24qf/GHSA-7893-p2h2-24qf.json create mode 100644 advisories/unreviewed/2025/05/GHSA-7wvq-x6j3-ggcp/GHSA-7wvq-x6j3-ggcp.json create mode 100644 advisories/unreviewed/2025/05/GHSA-7x5x-m772-p63v/GHSA-7x5x-m772-p63v.json create mode 100644 advisories/unreviewed/2025/05/GHSA-87qj-crf6-m933/GHSA-87qj-crf6-m933.json create mode 100644 advisories/unreviewed/2025/05/GHSA-8jx5-64fv-87qh/GHSA-8jx5-64fv-87qh.json create mode 100644 advisories/unreviewed/2025/05/GHSA-8qv9-rg87-qg9x/GHSA-8qv9-rg87-qg9x.json create mode 100644 advisories/unreviewed/2025/05/GHSA-8rwf-97vc-4rh3/GHSA-8rwf-97vc-4rh3.json create mode 100644 advisories/unreviewed/2025/05/GHSA-963m-hgv5-33vg/GHSA-963m-hgv5-33vg.json create mode 100644 advisories/unreviewed/2025/05/GHSA-97jw-vj6m-r4jm/GHSA-97jw-vj6m-r4jm.json create mode 100644 advisories/unreviewed/2025/05/GHSA-98mr-vfww-x4x2/GHSA-98mr-vfww-x4x2.json create mode 100644 advisories/unreviewed/2025/05/GHSA-9g7r-jg3m-m6wm/GHSA-9g7r-jg3m-m6wm.json create mode 100644 advisories/unreviewed/2025/05/GHSA-9grh-5gv9-xf63/GHSA-9grh-5gv9-xf63.json create mode 100644 advisories/unreviewed/2025/05/GHSA-9h8v-w795-r85q/GHSA-9h8v-w795-r85q.json create mode 100644 advisories/unreviewed/2025/05/GHSA-9hpw-wrhw-6g76/GHSA-9hpw-wrhw-6g76.json create mode 100644 advisories/unreviewed/2025/05/GHSA-9v6c-p69r-jc8x/GHSA-9v6c-p69r-jc8x.json create mode 100644 advisories/unreviewed/2025/05/GHSA-9w2j-w59m-592g/GHSA-9w2j-w59m-592g.json create mode 100644 advisories/unreviewed/2025/05/GHSA-9wr9-p53c-hqrq/GHSA-9wr9-p53c-hqrq.json create mode 100644 advisories/unreviewed/2025/05/GHSA-c33v-v5r9-774j/GHSA-c33v-v5r9-774j.json create mode 100644 advisories/unreviewed/2025/05/GHSA-c4jq-c26m-8vfh/GHSA-c4jq-c26m-8vfh.json create mode 100644 advisories/unreviewed/2025/05/GHSA-cf8h-x8xq-r3cr/GHSA-cf8h-x8xq-r3cr.json create mode 100644 advisories/unreviewed/2025/05/GHSA-cqh9-2fgp-cxw2/GHSA-cqh9-2fgp-cxw2.json create mode 100644 advisories/unreviewed/2025/05/GHSA-f3vf-9cvm-w329/GHSA-f3vf-9cvm-w329.json create mode 100644 advisories/unreviewed/2025/05/GHSA-f9xv-95hg-pxgf/GHSA-f9xv-95hg-pxgf.json create mode 100644 advisories/unreviewed/2025/05/GHSA-ffpp-564x-w86f/GHSA-ffpp-564x-w86f.json create mode 100644 advisories/unreviewed/2025/05/GHSA-fh7c-x2jh-rc4w/GHSA-fh7c-x2jh-rc4w.json create mode 100644 advisories/unreviewed/2025/05/GHSA-fhfv-mjv5-35hp/GHSA-fhfv-mjv5-35hp.json create mode 100644 advisories/unreviewed/2025/05/GHSA-fjqw-wgr4-3jjp/GHSA-fjqw-wgr4-3jjp.json create mode 100644 advisories/unreviewed/2025/05/GHSA-fqj7-rj6h-ppvp/GHSA-fqj7-rj6h-ppvp.json create mode 100644 advisories/unreviewed/2025/05/GHSA-fqmr-g5hc-mhmq/GHSA-fqmr-g5hc-mhmq.json create mode 100644 advisories/unreviewed/2025/05/GHSA-fv46-529r-fc72/GHSA-fv46-529r-fc72.json create mode 100644 advisories/unreviewed/2025/05/GHSA-fvcg-g6jq-f58x/GHSA-fvcg-g6jq-f58x.json create mode 100644 advisories/unreviewed/2025/05/GHSA-fwfc-62f3-6h7j/GHSA-fwfc-62f3-6h7j.json create mode 100644 advisories/unreviewed/2025/05/GHSA-g4f5-x2r2-hg23/GHSA-g4f5-x2r2-hg23.json create mode 100644 advisories/unreviewed/2025/05/GHSA-g83r-7cwr-h2jw/GHSA-g83r-7cwr-h2jw.json create mode 100644 advisories/unreviewed/2025/05/GHSA-gcjf-8x3p-64v2/GHSA-gcjf-8x3p-64v2.json create mode 100644 advisories/unreviewed/2025/05/GHSA-gj3c-w556-7qwm/GHSA-gj3c-w556-7qwm.json create mode 100644 advisories/unreviewed/2025/05/GHSA-gpxg-v5x4-r25g/GHSA-gpxg-v5x4-r25g.json create mode 100644 advisories/unreviewed/2025/05/GHSA-gpxh-j79m-whcj/GHSA-gpxh-j79m-whcj.json create mode 100644 advisories/unreviewed/2025/05/GHSA-gvwq-4r92-cj5h/GHSA-gvwq-4r92-cj5h.json create mode 100644 advisories/unreviewed/2025/05/GHSA-h2pj-2gpr-72vh/GHSA-h2pj-2gpr-72vh.json create mode 100644 advisories/unreviewed/2025/05/GHSA-h3r6-f23f-fjw6/GHSA-h3r6-f23f-fjw6.json create mode 100644 advisories/unreviewed/2025/05/GHSA-h3w6-hg9p-c6c4/GHSA-h3w6-hg9p-c6c4.json create mode 100644 advisories/unreviewed/2025/05/GHSA-h3xr-5jg5-xwr6/GHSA-h3xr-5jg5-xwr6.json create mode 100644 advisories/unreviewed/2025/05/GHSA-hjh6-jj5p-wf3x/GHSA-hjh6-jj5p-wf3x.json create mode 100644 advisories/unreviewed/2025/05/GHSA-hqgp-gmgc-jhhm/GHSA-hqgp-gmgc-jhhm.json create mode 100644 advisories/unreviewed/2025/05/GHSA-hx67-26rf-cg4v/GHSA-hx67-26rf-cg4v.json create mode 100644 advisories/unreviewed/2025/05/GHSA-j646-j4cf-jj5h/GHSA-j646-j4cf-jj5h.json create mode 100644 advisories/unreviewed/2025/05/GHSA-jcv7-4rpc-rwj8/GHSA-jcv7-4rpc-rwj8.json create mode 100644 advisories/unreviewed/2025/05/GHSA-jgcc-pm4w-jp8q/GHSA-jgcc-pm4w-jp8q.json create mode 100644 advisories/unreviewed/2025/05/GHSA-jgv5-6946-fjqx/GHSA-jgv5-6946-fjqx.json create mode 100644 advisories/unreviewed/2025/05/GHSA-jp9f-x59g-67pq/GHSA-jp9f-x59g-67pq.json create mode 100644 advisories/unreviewed/2025/05/GHSA-jv73-vqgv-2mch/GHSA-jv73-vqgv-2mch.json create mode 100644 advisories/unreviewed/2025/05/GHSA-m4g8-47g2-j394/GHSA-m4g8-47g2-j394.json create mode 100644 advisories/unreviewed/2025/05/GHSA-m537-88r7-p568/GHSA-m537-88r7-p568.json create mode 100644 advisories/unreviewed/2025/05/GHSA-m6x2-v3jc-m2m7/GHSA-m6x2-v3jc-m2m7.json create mode 100644 advisories/unreviewed/2025/05/GHSA-m9vv-g4wc-gc4q/GHSA-m9vv-g4wc-gc4q.json create mode 100644 advisories/unreviewed/2025/05/GHSA-mchr-xvw2-q64f/GHSA-mchr-xvw2-q64f.json create mode 100644 advisories/unreviewed/2025/05/GHSA-mjw8-4r4w-cj9r/GHSA-mjw8-4r4w-cj9r.json create mode 100644 advisories/unreviewed/2025/05/GHSA-mpm6-wggf-97xv/GHSA-mpm6-wggf-97xv.json create mode 100644 advisories/unreviewed/2025/05/GHSA-mqcw-437p-q69q/GHSA-mqcw-437p-q69q.json create mode 100644 advisories/unreviewed/2025/05/GHSA-mqvg-gc79-6rxx/GHSA-mqvg-gc79-6rxx.json create mode 100644 advisories/unreviewed/2025/05/GHSA-p2p2-vfxx-r5rp/GHSA-p2p2-vfxx-r5rp.json create mode 100644 advisories/unreviewed/2025/05/GHSA-p39x-3wqr-ggff/GHSA-p39x-3wqr-ggff.json create mode 100644 advisories/unreviewed/2025/05/GHSA-p97h-v2qf-9878/GHSA-p97h-v2qf-9878.json create mode 100644 advisories/unreviewed/2025/05/GHSA-p9wx-2529-fp83/GHSA-p9wx-2529-fp83.json create mode 100644 advisories/unreviewed/2025/05/GHSA-pqgc-vw44-8qm5/GHSA-pqgc-vw44-8qm5.json create mode 100644 advisories/unreviewed/2025/05/GHSA-pr3p-9qh5-qp2f/GHSA-pr3p-9qh5-qp2f.json create mode 100644 advisories/unreviewed/2025/05/GHSA-q52p-775j-hjv8/GHSA-q52p-775j-hjv8.json create mode 100644 advisories/unreviewed/2025/05/GHSA-q749-5rmc-5pxm/GHSA-q749-5rmc-5pxm.json create mode 100644 advisories/unreviewed/2025/05/GHSA-qjr4-ppfx-2vc4/GHSA-qjr4-ppfx-2vc4.json create mode 100644 advisories/unreviewed/2025/05/GHSA-qw6m-wwcp-hjpw/GHSA-qw6m-wwcp-hjpw.json create mode 100644 advisories/unreviewed/2025/05/GHSA-qwmp-5m8m-pjvf/GHSA-qwmp-5m8m-pjvf.json create mode 100644 advisories/unreviewed/2025/05/GHSA-r9pj-264x-c5c5/GHSA-r9pj-264x-c5c5.json create mode 100644 advisories/unreviewed/2025/05/GHSA-rhqf-r6rm-3j54/GHSA-rhqf-r6rm-3j54.json create mode 100644 advisories/unreviewed/2025/05/GHSA-rmxc-5894-fxhq/GHSA-rmxc-5894-fxhq.json create mode 100644 advisories/unreviewed/2025/05/GHSA-rqwp-p4f7-h975/GHSA-rqwp-p4f7-h975.json create mode 100644 advisories/unreviewed/2025/05/GHSA-rvm6-q5vv-cfhx/GHSA-rvm6-q5vv-cfhx.json create mode 100644 advisories/unreviewed/2025/05/GHSA-v4pp-gcmm-cv95/GHSA-v4pp-gcmm-cv95.json create mode 100644 advisories/unreviewed/2025/05/GHSA-v5wj-4vcq-v5gw/GHSA-v5wj-4vcq-v5gw.json create mode 100644 advisories/unreviewed/2025/05/GHSA-v6m7-qh5v-q2j5/GHSA-v6m7-qh5v-q2j5.json create mode 100644 advisories/unreviewed/2025/05/GHSA-v7cm-mpcm-37f9/GHSA-v7cm-mpcm-37f9.json create mode 100644 advisories/unreviewed/2025/05/GHSA-v7m3-xg38-3qfq/GHSA-v7m3-xg38-3qfq.json create mode 100644 advisories/unreviewed/2025/05/GHSA-v8q7-jm3p-3j3q/GHSA-v8q7-jm3p-3j3q.json create mode 100644 advisories/unreviewed/2025/05/GHSA-vcf3-77pf-w4hq/GHSA-vcf3-77pf-w4hq.json create mode 100644 advisories/unreviewed/2025/05/GHSA-vphc-878c-44gv/GHSA-vphc-878c-44gv.json create mode 100644 advisories/unreviewed/2025/05/GHSA-vrwv-78gw-c2wc/GHSA-vrwv-78gw-c2wc.json create mode 100644 advisories/unreviewed/2025/05/GHSA-w3mv-rjr4-wpcg/GHSA-w3mv-rjr4-wpcg.json create mode 100644 advisories/unreviewed/2025/05/GHSA-w4q4-qqj7-r6q8/GHSA-w4q4-qqj7-r6q8.json create mode 100644 advisories/unreviewed/2025/05/GHSA-wfv4-fr2r-9jgv/GHSA-wfv4-fr2r-9jgv.json create mode 100644 advisories/unreviewed/2025/05/GHSA-wjqw-p7j2-5gx2/GHSA-wjqw-p7j2-5gx2.json create mode 100644 advisories/unreviewed/2025/05/GHSA-wm4r-97wr-6vw2/GHSA-wm4r-97wr-6vw2.json create mode 100644 advisories/unreviewed/2025/05/GHSA-wqj4-2vw3-c5jw/GHSA-wqj4-2vw3-c5jw.json create mode 100644 advisories/unreviewed/2025/05/GHSA-wx7w-g52q-jg5g/GHSA-wx7w-g52q-jg5g.json create mode 100644 advisories/unreviewed/2025/05/GHSA-x6xg-9w9q-643p/GHSA-x6xg-9w9q-643p.json create mode 100644 advisories/unreviewed/2025/05/GHSA-xgcx-978m-c62h/GHSA-xgcx-978m-c62h.json create mode 100644 advisories/unreviewed/2025/05/GHSA-xp23-94cq-8m5g/GHSA-xp23-94cq-8m5g.json diff --git a/advisories/github-reviewed/2025/04/GHSA-gmg8-593g-7mv3/GHSA-gmg8-593g-7mv3.json b/advisories/github-reviewed/2025/04/GHSA-gmg8-593g-7mv3/GHSA-gmg8-593g-7mv3.json index 31e8b5252c4..d93735d4f21 100644 --- a/advisories/github-reviewed/2025/04/GHSA-gmg8-593g-7mv3/GHSA-gmg8-593g-7mv3.json +++ b/advisories/github-reviewed/2025/04/GHSA-gmg8-593g-7mv3/GHSA-gmg8-593g-7mv3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gmg8-593g-7mv3", - "modified": "2025-04-18T18:34:17Z", + "modified": "2025-05-23T15:31:06Z", "published": "2025-04-09T12:30:24Z", "aliases": [ "CVE-2025-31672" @@ -56,6 +56,10 @@ "type": "WEB", "url": "https://lists.apache.org/thread/k14w8vcjqy4h34hh5kzldko78kpylkq5" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250523-0004" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2025/04/08/2" diff --git a/advisories/unreviewed/2024/03/GHSA-8f4m-xpm2-5rxj/GHSA-8f4m-xpm2-5rxj.json b/advisories/unreviewed/2024/03/GHSA-8f4m-xpm2-5rxj/GHSA-8f4m-xpm2-5rxj.json index 8bf3347bea8..371b573bc3a 100644 --- a/advisories/unreviewed/2024/03/GHSA-8f4m-xpm2-5rxj/GHSA-8f4m-xpm2-5rxj.json +++ b/advisories/unreviewed/2024/03/GHSA-8f4m-xpm2-5rxj/GHSA-8f4m-xpm2-5rxj.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-jw74-jmpx-mj4j/GHSA-jw74-jmpx-mj4j.json b/advisories/unreviewed/2024/03/GHSA-jw74-jmpx-mj4j/GHSA-jw74-jmpx-mj4j.json index 07797306f85..126b66afccc 100644 --- a/advisories/unreviewed/2024/03/GHSA-jw74-jmpx-mj4j/GHSA-jw74-jmpx-mj4j.json +++ b/advisories/unreviewed/2024/03/GHSA-jw74-jmpx-mj4j/GHSA-jw74-jmpx-mj4j.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-jw74-jmpx-mj4j", - "modified": "2024-03-15T15:30:43Z", + "modified": "2025-05-23T15:31:03Z", "published": "2024-03-15T15:30:43Z", "aliases": [ "CVE-2024-25934" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FormFacade allows Stored XSS.This issue affects FormFacade: from n/a through 1.0.0.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FormFacade allows Stored XSS.This issue affects FormFacade: from n/a through 1.0.0.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/10/GHSA-v7pq-vg76-qwqx/GHSA-v7pq-vg76-qwqx.json b/advisories/unreviewed/2024/10/GHSA-v7pq-vg76-qwqx/GHSA-v7pq-vg76-qwqx.json index a884d921052..4b403e540f5 100644 --- a/advisories/unreviewed/2024/10/GHSA-v7pq-vg76-qwqx/GHSA-v7pq-vg76-qwqx.json +++ b/advisories/unreviewed/2024/10/GHSA-v7pq-vg76-qwqx/GHSA-v7pq-vg76-qwqx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v7pq-vg76-qwqx", - "modified": "2024-10-30T15:30:46Z", + "modified": "2025-05-23T15:31:04Z", "published": "2024-10-29T03:31:06Z", "aliases": [ "CVE-2024-50083" @@ -42,6 +42,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/db04d1848777ae52a7ab93c4591e7c0bf8f55fb4" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250523-0010" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-22xf-532v-3xqg/GHSA-22xf-532v-3xqg.json b/advisories/unreviewed/2025/01/GHSA-22xf-532v-3xqg/GHSA-22xf-532v-3xqg.json index 7386a5eff07..dca0584f4c6 100644 --- a/advisories/unreviewed/2025/01/GHSA-22xf-532v-3xqg/GHSA-22xf-532v-3xqg.json +++ b/advisories/unreviewed/2025/01/GHSA-22xf-532v-3xqg/GHSA-22xf-532v-3xqg.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-6484-jh3g-q998/GHSA-6484-jh3g-q998.json b/advisories/unreviewed/2025/01/GHSA-6484-jh3g-q998/GHSA-6484-jh3g-q998.json index deb226595dd..c7506b6669a 100644 --- a/advisories/unreviewed/2025/01/GHSA-6484-jh3g-q998/GHSA-6484-jh3g-q998.json +++ b/advisories/unreviewed/2025/01/GHSA-6484-jh3g-q998/GHSA-6484-jh3g-q998.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-fph8-w359-q9x9/GHSA-fph8-w359-q9x9.json b/advisories/unreviewed/2025/01/GHSA-fph8-w359-q9x9/GHSA-fph8-w359-q9x9.json index d360437ee82..bf3dd3b9785 100644 --- a/advisories/unreviewed/2025/01/GHSA-fph8-w359-q9x9/GHSA-fph8-w359-q9x9.json +++ b/advisories/unreviewed/2025/01/GHSA-fph8-w359-q9x9/GHSA-fph8-w359-q9x9.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-vg86-8433-4hr2/GHSA-vg86-8433-4hr2.json b/advisories/unreviewed/2025/01/GHSA-vg86-8433-4hr2/GHSA-vg86-8433-4hr2.json index f0205395a84..bc44930e02d 100644 --- a/advisories/unreviewed/2025/01/GHSA-vg86-8433-4hr2/GHSA-vg86-8433-4hr2.json +++ b/advisories/unreviewed/2025/01/GHSA-vg86-8433-4hr2/GHSA-vg86-8433-4hr2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vg86-8433-4hr2", - "modified": "2025-01-29T06:31:50Z", + "modified": "2025-05-23T15:31:05Z", "published": "2025-01-29T06:31:50Z", "aliases": [ "CVE-2025-0804" diff --git a/advisories/unreviewed/2025/02/GHSA-65rj-829h-6g8x/GHSA-65rj-829h-6g8x.json b/advisories/unreviewed/2025/02/GHSA-65rj-829h-6g8x/GHSA-65rj-829h-6g8x.json index 6a8b9cacb5a..4ff0c13ac39 100644 --- a/advisories/unreviewed/2025/02/GHSA-65rj-829h-6g8x/GHSA-65rj-829h-6g8x.json +++ b/advisories/unreviewed/2025/02/GHSA-65rj-829h-6g8x/GHSA-65rj-829h-6g8x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-65rj-829h-6g8x", - "modified": "2025-02-04T15:31:37Z", + "modified": "2025-05-23T15:31:05Z", "published": "2025-02-04T15:31:37Z", "aliases": [ "CVE-2025-0825" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://github.com/yhirose/cpp-httplib/commit/9c36aae4b73e2b6e493f4133e4173103c9266289" + }, + { + "type": "WEB", + "url": "https://advisory.checkmarx.net/advisory/CVE-2025-0825" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/02/GHSA-cqj4-fp95-jqxq/GHSA-cqj4-fp95-jqxq.json b/advisories/unreviewed/2025/02/GHSA-cqj4-fp95-jqxq/GHSA-cqj4-fp95-jqxq.json index 85ce8242510..88a00737856 100644 --- a/advisories/unreviewed/2025/02/GHSA-cqj4-fp95-jqxq/GHSA-cqj4-fp95-jqxq.json +++ b/advisories/unreviewed/2025/02/GHSA-cqj4-fp95-jqxq/GHSA-cqj4-fp95-jqxq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cqj4-fp95-jqxq", - "modified": "2025-05-21T00:30:23Z", + "modified": "2025-05-23T15:31:05Z", "published": "2025-02-10T18:30:46Z", "aliases": [ "CVE-2024-12243" @@ -46,6 +46,10 @@ { "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2025/02/msg00027.html" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250523-0002" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/02/GHSA-j3qr-8f3v-fgjj/GHSA-j3qr-8f3v-fgjj.json b/advisories/unreviewed/2025/02/GHSA-j3qr-8f3v-fgjj/GHSA-j3qr-8f3v-fgjj.json index 09f8e641f4e..5f31447463f 100644 --- a/advisories/unreviewed/2025/02/GHSA-j3qr-8f3v-fgjj/GHSA-j3qr-8f3v-fgjj.json +++ b/advisories/unreviewed/2025/02/GHSA-j3qr-8f3v-fgjj/GHSA-j3qr-8f3v-fgjj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j3qr-8f3v-fgjj", - "modified": "2025-05-21T00:30:22Z", + "modified": "2025-05-23T15:31:05Z", "published": "2025-02-10T18:30:47Z", "aliases": [ "CVE-2024-12133" @@ -47,6 +47,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2025/02/msg00025.html" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250523-0003" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2025/02/06/6" diff --git a/advisories/unreviewed/2025/05/GHSA-25wq-m5r4-rrm3/GHSA-25wq-m5r4-rrm3.json b/advisories/unreviewed/2025/05/GHSA-25wq-m5r4-rrm3/GHSA-25wq-m5r4-rrm3.json new file mode 100644 index 00000000000..8bc697a53e1 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-25wq-m5r4-rrm3/GHSA-25wq-m5r4-rrm3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-25wq-m5r4-rrm3", + "modified": "2025-05-23T15:31:09Z", + "published": "2025-05-23T15:31:09Z", + "aliases": [ + "CVE-2025-31049" + ], + "details": "Deserialization of Untrusted Data vulnerability in themeton Dash allows Object Injection. This issue affects Dash: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31049" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/dash/vulnerability/wordpress-dash-1-3-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2659-8m74-4v6x/GHSA-2659-8m74-4v6x.json b/advisories/unreviewed/2025/05/GHSA-2659-8m74-4v6x/GHSA-2659-8m74-4v6x.json new file mode 100644 index 00000000000..ce814995aaf --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2659-8m74-4v6x/GHSA-2659-8m74-4v6x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2659-8m74-4v6x", + "modified": "2025-05-23T15:31:10Z", + "published": "2025-05-23T15:31:10Z", + "aliases": [ + "CVE-2025-32289" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme Yozi allows PHP Local File Inclusion. This issue affects Yozi: from n/a through 2.0.52.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32289" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/yozi/vulnerability/wordpress-yozi-2-0-52-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2963-8wvc-3fv3/GHSA-2963-8wvc-3fv3.json b/advisories/unreviewed/2025/05/GHSA-2963-8wvc-3fv3/GHSA-2963-8wvc-3fv3.json new file mode 100644 index 00000000000..4e388f419e4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2963-8wvc-3fv3/GHSA-2963-8wvc-3fv3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2963-8wvc-3fv3", + "modified": "2025-05-23T15:31:15Z", + "published": "2025-05-23T15:31:15Z", + "aliases": [ + "CVE-2025-47673" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tychesoftwares Arconix Shortcodes allows Reflected XSS. This issue affects Arconix Shortcodes: from n/a through 2.1.16.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47673" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/arconix-shortcodes/vulnerability/wordpress-arconix-shortcodes-plugin-2-1-16-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2g6j-8hm3-67hp/GHSA-2g6j-8hm3-67hp.json b/advisories/unreviewed/2025/05/GHSA-2g6j-8hm3-67hp/GHSA-2g6j-8hm3-67hp.json new file mode 100644 index 00000000000..7be26487706 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2g6j-8hm3-67hp/GHSA-2g6j-8hm3-67hp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2g6j-8hm3-67hp", + "modified": "2025-05-23T15:31:10Z", + "published": "2025-05-23T15:31:10Z", + "aliases": [ + "CVE-2025-39485" + ], + "details": "Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Tour | Travel Agency WordPress allows Object Injection. This issue affects Grand Tour | Travel Agency WordPress: from n/a through 5.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39485" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/grandtour/vulnerability/wordpress-grandtour-theme-5-5-1-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2gf3-v8px-49h6/GHSA-2gf3-v8px-49h6.json b/advisories/unreviewed/2025/05/GHSA-2gf3-v8px-49h6/GHSA-2gf3-v8px-49h6.json new file mode 100644 index 00000000000..e1c66543ebc --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2gf3-v8px-49h6/GHSA-2gf3-v8px-49h6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2gf3-v8px-49h6", + "modified": "2025-05-23T15:31:11Z", + "published": "2025-05-23T15:31:11Z", + "aliases": [ + "CVE-2025-39506" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NasaTheme Nasa Core allows PHP Local File Inclusion. This issue affects Nasa Core: from n/a through 6.3.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39506" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/nasa-core/vulnerability/wordpress-nasa-core-plugin-6-3-2-local-file-inclusion-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2m9r-8wqr-rccv/GHSA-2m9r-8wqr-rccv.json b/advisories/unreviewed/2025/05/GHSA-2m9r-8wqr-rccv/GHSA-2m9r-8wqr-rccv.json index 3b3da7e8d65..831f85317d7 100644 --- a/advisories/unreviewed/2025/05/GHSA-2m9r-8wqr-rccv/GHSA-2m9r-8wqr-rccv.json +++ b/advisories/unreviewed/2025/05/GHSA-2m9r-8wqr-rccv/GHSA-2m9r-8wqr-rccv.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-2rcx-2829-7fg5/GHSA-2rcx-2829-7fg5.json b/advisories/unreviewed/2025/05/GHSA-2rcx-2829-7fg5/GHSA-2rcx-2829-7fg5.json new file mode 100644 index 00000000000..eef196ab4b1 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2rcx-2829-7fg5/GHSA-2rcx-2829-7fg5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2rcx-2829-7fg5", + "modified": "2025-05-23T15:31:09Z", + "published": "2025-05-23T15:31:09Z", + "aliases": [ + "CVE-2025-31069" + ], + "details": "Deserialization of Untrusted Data vulnerability in themeton HotStar – Multi-Purpose Business Theme allows Object Injection. This issue affects HotStar – Multi-Purpose Business Theme: from n/a through 1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31069" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/hotstar/vulnerability/wordpress-hotstar-multi-purpose-business-theme-1-4-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2rgj-5hr4-v9vp/GHSA-2rgj-5hr4-v9vp.json b/advisories/unreviewed/2025/05/GHSA-2rgj-5hr4-v9vp/GHSA-2rgj-5hr4-v9vp.json new file mode 100644 index 00000000000..86cd83b04de --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2rgj-5hr4-v9vp/GHSA-2rgj-5hr4-v9vp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2rgj-5hr4-v9vp", + "modified": "2025-05-23T15:31:14Z", + "published": "2025-05-23T15:31:14Z", + "aliases": [ + "CVE-2025-47619" + ], + "details": "Missing Authorization vulnerability in 6Storage 6Storage Rentals allows Path Traversal. This issue affects 6Storage Rentals: from n/a through 2.19.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47619" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/6storage-rentals/vulnerability/wordpress-6storage-rentals-2-19-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2v3m-6ccx-2995/GHSA-2v3m-6ccx-2995.json b/advisories/unreviewed/2025/05/GHSA-2v3m-6ccx-2995/GHSA-2v3m-6ccx-2995.json new file mode 100644 index 00000000000..9544904f322 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2v3m-6ccx-2995/GHSA-2v3m-6ccx-2995.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2v3m-6ccx-2995", + "modified": "2025-05-23T15:31:14Z", + "published": "2025-05-23T15:31:14Z", + "aliases": [ + "CVE-2025-47575" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla School Management allows SQL Injection. This issue affects School Management: from n/a through 92.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47575" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/school-management/vulnerability/wordpress-school-management-plugin-92-0-0-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3268-x73x-v8rp/GHSA-3268-x73x-v8rp.json b/advisories/unreviewed/2025/05/GHSA-3268-x73x-v8rp/GHSA-3268-x73x-v8rp.json new file mode 100644 index 00000000000..c373a84846a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3268-x73x-v8rp/GHSA-3268-x73x-v8rp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3268-x73x-v8rp", + "modified": "2025-05-23T15:31:09Z", + "published": "2025-05-23T15:31:09Z", + "aliases": [ + "CVE-2025-31633" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Kiamo - Responsive Business Service WordPress Theme allows PHP Local File Inclusion. This issue affects Kiamo - Responsive Business Service WordPress Theme: from n/a through 1.3.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31633" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/kiamo/vulnerability/wordpress-kiamo-responsive-business-service-wordpress-theme-1-3-3-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-33j7-6p7h-f87g/GHSA-33j7-6p7h-f87g.json b/advisories/unreviewed/2025/05/GHSA-33j7-6p7h-f87g/GHSA-33j7-6p7h-f87g.json new file mode 100644 index 00000000000..8435b300a9b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-33j7-6p7h-f87g/GHSA-33j7-6p7h-f87g.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-33j7-6p7h-f87g", + "modified": "2025-05-23T15:31:16Z", + "published": "2025-05-23T15:31:16Z", + "aliases": [ + "CVE-2022-31807" + ], + "details": "A vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions), SiPass integrated ACC-AP (All versions). Affected devices do not properly check the integrity of firmware updates. This could allow a local attacker to upload a maliciously modified firmware onto the device. In a second scenario, a remote attacker who is able to intercept the transfer of a valid firmware from the server to the device could modify the firmware \"on the fly\".", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-31807" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-367714.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-347" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T15:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-36xm-ch76-gv9j/GHSA-36xm-ch76-gv9j.json b/advisories/unreviewed/2025/05/GHSA-36xm-ch76-gv9j/GHSA-36xm-ch76-gv9j.json new file mode 100644 index 00000000000..a53af81bfaa --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-36xm-ch76-gv9j/GHSA-36xm-ch76-gv9j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-36xm-ch76-gv9j", + "modified": "2025-05-23T15:31:10Z", + "published": "2025-05-23T15:31:09Z", + "aliases": [ + "CVE-2025-31636" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SaurabhSharma WP Post Modules for Elementor allows Reflected XSS. This issue affects WP Post Modules for Elementor: from n/a through 2.5.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31636" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-post-modules-el/vulnerability/wordpress-wp-post-modules-for-elementor-plugin-2-5-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-39hr-qmg2-rcg4/GHSA-39hr-qmg2-rcg4.json b/advisories/unreviewed/2025/05/GHSA-39hr-qmg2-rcg4/GHSA-39hr-qmg2-rcg4.json new file mode 100644 index 00000000000..b5093aee102 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-39hr-qmg2-rcg4/GHSA-39hr-qmg2-rcg4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-39hr-qmg2-rcg4", + "modified": "2025-05-23T15:31:11Z", + "published": "2025-05-23T15:31:11Z", + "aliases": [ + "CVE-2025-39504" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GoodLayers Goodlayers Hotel allows Blind SQL Injection. This issue affects Goodlayers Hotel: from n/a through 3.1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39504" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gdlr-hotel/vulnerability/wordpress-goodlayers-hotel-plugin-3-1-4-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3c52-m5xj-c7ff/GHSA-3c52-m5xj-c7ff.json b/advisories/unreviewed/2025/05/GHSA-3c52-m5xj-c7ff/GHSA-3c52-m5xj-c7ff.json new file mode 100644 index 00000000000..f054d1b671f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3c52-m5xj-c7ff/GHSA-3c52-m5xj-c7ff.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3c52-m5xj-c7ff", + "modified": "2025-05-23T15:31:09Z", + "published": "2025-05-23T15:31:09Z", + "aliases": [ + "CVE-2025-1123" + ], + "details": "The Solid Mail – SMTP email and logging made by SolidWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email Name, Subject, and Body in all versions up to, and including, 2.1.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1123" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3283671/wp-smtp" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f99a918d-53c1-46bd-8e55-9ba77a92efe8?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3f9c-xxj6-82v8/GHSA-3f9c-xxj6-82v8.json b/advisories/unreviewed/2025/05/GHSA-3f9c-xxj6-82v8/GHSA-3f9c-xxj6-82v8.json new file mode 100644 index 00000000000..6e74f97b873 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3f9c-xxj6-82v8/GHSA-3f9c-xxj6-82v8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3f9c-xxj6-82v8", + "modified": "2025-05-23T15:31:14Z", + "published": "2025-05-23T15:31:14Z", + "aliases": [ + "CVE-2025-47530" + ], + "details": "Deserialization of Untrusted Data vulnerability in WPFunnels WPFunnels allows Object Injection. This issue affects WPFunnels: from n/a through 3.5.18.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47530" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpfunnels/vulnerability/wordpress-wpfunnels-3-5-18-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3grc-cj2m-fpc6/GHSA-3grc-cj2m-fpc6.json b/advisories/unreviewed/2025/05/GHSA-3grc-cj2m-fpc6/GHSA-3grc-cj2m-fpc6.json new file mode 100644 index 00000000000..acc3cbac00e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3grc-cj2m-fpc6/GHSA-3grc-cj2m-fpc6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3grc-cj2m-fpc6", + "modified": "2025-05-23T15:31:10Z", + "published": "2025-05-23T15:31:10Z", + "aliases": [ + "CVE-2025-31927" + ], + "details": "Deserialization of Untrusted Data vulnerability in themeton Acerola allows Object Injection. This issue affects Acerola: from n/a through 1.6.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31927" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/acerola/vulnerability/wordpress-acerola-1-6-5-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3hmp-hq97-xvfh/GHSA-3hmp-hq97-xvfh.json b/advisories/unreviewed/2025/05/GHSA-3hmp-hq97-xvfh/GHSA-3hmp-hq97-xvfh.json new file mode 100644 index 00000000000..aaa8696e43c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3hmp-hq97-xvfh/GHSA-3hmp-hq97-xvfh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3hmp-hq97-xvfh", + "modified": "2025-05-23T15:31:10Z", + "published": "2025-05-23T15:31:10Z", + "aliases": [ + "CVE-2025-31924" + ], + "details": "Deserialization of Untrusted Data vulnerability in designthemes Crafts & Arts allows Object Injection. This issue affects Crafts & Arts: from n/a through 2.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31924" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/crafts-and-arts/vulnerability/wordpress-crafts-arts-2-5-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3hv9-p65c-7g5r/GHSA-3hv9-p65c-7g5r.json b/advisories/unreviewed/2025/05/GHSA-3hv9-p65c-7g5r/GHSA-3hv9-p65c-7g5r.json new file mode 100644 index 00000000000..f12f2cba42a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3hv9-p65c-7g5r/GHSA-3hv9-p65c-7g5r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3hv9-p65c-7g5r", + "modified": "2025-05-23T15:31:14Z", + "published": "2025-05-23T15:31:14Z", + "aliases": [ + "CVE-2025-47599" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in facturante Facturante allows SQL Injection. This issue affects Facturante: from n/a through 1.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47599" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/facturante/vulnerability/wordpress-facturante-1-11-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-43mx-35xv-4r2v/GHSA-43mx-35xv-4r2v.json b/advisories/unreviewed/2025/05/GHSA-43mx-35xv-4r2v/GHSA-43mx-35xv-4r2v.json new file mode 100644 index 00000000000..e0b706ece71 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-43mx-35xv-4r2v/GHSA-43mx-35xv-4r2v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-43mx-35xv-4r2v", + "modified": "2025-05-23T15:31:16Z", + "published": "2025-05-23T15:31:16Z", + "aliases": [ + "CVE-2025-48286" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in catkin ReDi Restaurant Reservation allows Reflected XSS. This issue affects ReDi Restaurant Reservation: from n/a through 24.1209.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48286" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/redi-restaurant-reservation/vulnerability/wordpress-redi-restaurant-reservation-plugin-24-1209-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-46xm-5ggp-p743/GHSA-46xm-5ggp-p743.json b/advisories/unreviewed/2025/05/GHSA-46xm-5ggp-p743/GHSA-46xm-5ggp-p743.json new file mode 100644 index 00000000000..11b5b89fbc0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-46xm-5ggp-p743/GHSA-46xm-5ggp-p743.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-46xm-5ggp-p743", + "modified": "2025-05-23T15:31:12Z", + "published": "2025-05-23T15:31:12Z", + "aliases": [ + "CVE-2025-46463" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yamna Khawaja Mailing Group Listserv allows SQL Injection. This issue affects Mailing Group Listserv: from n/a through 3.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46463" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-mailing-group/vulnerability/wordpress-mailing-group-listserv-3-0-4-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4c59-wg4x-f787/GHSA-4c59-wg4x-f787.json b/advisories/unreviewed/2025/05/GHSA-4c59-wg4x-f787/GHSA-4c59-wg4x-f787.json index ed006e09676..72c56ea158f 100644 --- a/advisories/unreviewed/2025/05/GHSA-4c59-wg4x-f787/GHSA-4c59-wg4x-f787.json +++ b/advisories/unreviewed/2025/05/GHSA-4c59-wg4x-f787/GHSA-4c59-wg4x-f787.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-4hrj-7997-8qf3/GHSA-4hrj-7997-8qf3.json b/advisories/unreviewed/2025/05/GHSA-4hrj-7997-8qf3/GHSA-4hrj-7997-8qf3.json new file mode 100644 index 00000000000..d5243cd45c6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4hrj-7997-8qf3/GHSA-4hrj-7997-8qf3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4hrj-7997-8qf3", + "modified": "2025-05-23T15:31:12Z", + "published": "2025-05-23T15:31:12Z", + "aliases": [ + "CVE-2025-46474" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SEUR OFICIAL SEUR Oficial allows PHP Local File Inclusion. This issue affects SEUR Oficial: from n/a through 2.2.23.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46474" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/seur/vulnerability/wordpress-seur-oficial-2-2-23-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4v9q-9v9j-rwrc/GHSA-4v9q-9v9j-rwrc.json b/advisories/unreviewed/2025/05/GHSA-4v9q-9v9j-rwrc/GHSA-4v9q-9v9j-rwrc.json new file mode 100644 index 00000000000..0febc9c3882 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4v9q-9v9j-rwrc/GHSA-4v9q-9v9j-rwrc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4v9q-9v9j-rwrc", + "modified": "2025-05-23T15:31:13Z", + "published": "2025-05-23T15:31:13Z", + "aliases": [ + "CVE-2025-46518" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in phpaddicted IGIT Related Posts With Thumb Image After Posts allows Stored XSS. This issue affects IGIT Related Posts With Thumb Image After Posts: from n/a through 4.5.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46518" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/igit-related-posts-with-thumb-images-after-posts/vulnerability/wordpress-igit-related-posts-with-thumb-image-after-posts-4-5-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4w7m-m9xf-94pc/GHSA-4w7m-m9xf-94pc.json b/advisories/unreviewed/2025/05/GHSA-4w7m-m9xf-94pc/GHSA-4w7m-m9xf-94pc.json index 894d930c72f..bdaeb2c81e7 100644 --- a/advisories/unreviewed/2025/05/GHSA-4w7m-m9xf-94pc/GHSA-4w7m-m9xf-94pc.json +++ b/advisories/unreviewed/2025/05/GHSA-4w7m-m9xf-94pc/GHSA-4w7m-m9xf-94pc.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-4wjv-q2ww-cm43/GHSA-4wjv-q2ww-cm43.json b/advisories/unreviewed/2025/05/GHSA-4wjv-q2ww-cm43/GHSA-4wjv-q2ww-cm43.json new file mode 100644 index 00000000000..f96344da6c1 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4wjv-q2ww-cm43/GHSA-4wjv-q2ww-cm43.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4wjv-q2ww-cm43", + "modified": "2025-05-23T15:31:11Z", + "published": "2025-05-23T15:31:11Z", + "aliases": [ + "CVE-2025-41380" + ], + "details": "Iridium Certus 700 version 1.0.1 has an embedded credentials vulnerability in the code. This vulnerability allows a local user to retrieve the SSH hash string.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-41380" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-intellian-technologies-iridium-certus" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-798" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4x22-29pf-hh57/GHSA-4x22-29pf-hh57.json b/advisories/unreviewed/2025/05/GHSA-4x22-29pf-hh57/GHSA-4x22-29pf-hh57.json new file mode 100644 index 00000000000..062cead0fb0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4x22-29pf-hh57/GHSA-4x22-29pf-hh57.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4x22-29pf-hh57", + "modified": "2025-05-23T15:31:15Z", + "published": "2025-05-23T15:31:15Z", + "aliases": [ + "CVE-2025-47690" + ], + "details": "Missing Authorization vulnerability in smackcoders Lead Form Data Collection to CRM allows Privilege Escalation. This issue affects Lead Form Data Collection to CRM: from n/a through 3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47690" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-leads-builder-any-crm/vulnerability/wordpress-lead-form-data-collection-to-crm-plugin-3-1-arbitrary-option-update-to-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4xfx-qcgh-g3x4/GHSA-4xfx-qcgh-g3x4.json b/advisories/unreviewed/2025/05/GHSA-4xfx-qcgh-g3x4/GHSA-4xfx-qcgh-g3x4.json new file mode 100644 index 00000000000..0129cffed79 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4xfx-qcgh-g3x4/GHSA-4xfx-qcgh-g3x4.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4xfx-qcgh-g3x4", + "modified": "2025-05-23T15:31:16Z", + "published": "2025-05-23T15:31:16Z", + "aliases": [ + "CVE-2025-5111" + ], + "details": "A vulnerability, which was classified as critical, has been found in FreeFloat FTP Server 1.0. Affected by this issue is some unknown functionality of the component TYPE Command Handler. The manipulation leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5111" + }, + { + "type": "WEB", + "url": "https://fitoxs.com/exploit/exploit-b08607fc683b518b37423881e5ee902fdb2a7c04ac57f7ff725df240e171f5e3.txt" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310088" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310088" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.582958" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T14:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-528m-5r46-h6pj/GHSA-528m-5r46-h6pj.json b/advisories/unreviewed/2025/05/GHSA-528m-5r46-h6pj/GHSA-528m-5r46-h6pj.json new file mode 100644 index 00000000000..ed0c9c51a43 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-528m-5r46-h6pj/GHSA-528m-5r46-h6pj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-528m-5r46-h6pj", + "modified": "2025-05-23T15:31:09Z", + "published": "2025-05-23T15:31:09Z", + "aliases": [ + "CVE-2025-31916" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in joy2012bd JP Students Result Management System Premium allows Upload a Web Shell to a Web Server. This issue affects JP Students Result Management System Premium: from 1.1.7 through n/a.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31916" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/jp-students-result-system-premium/vulnerability/wordpress-jp-students-result-management-system-premium-plugin-1-1-7-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5445-5pxc-8pcc/GHSA-5445-5pxc-8pcc.json b/advisories/unreviewed/2025/05/GHSA-5445-5pxc-8pcc/GHSA-5445-5pxc-8pcc.json new file mode 100644 index 00000000000..d85fbb6ea68 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5445-5pxc-8pcc/GHSA-5445-5pxc-8pcc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5445-5pxc-8pcc", + "modified": "2025-05-23T15:31:15Z", + "published": "2025-05-23T15:31:15Z", + "aliases": [ + "CVE-2025-47670" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in miniOrange WordPress Social Login and Register allows PHP Local File Inclusion. This issue affects WordPress Social Login and Register: from n/a through 7.6.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47670" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/miniorange-login-openid/vulnerability/wordpress-wordpress-social-login-and-register-7-6-9-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5556-32h3-7q94/GHSA-5556-32h3-7q94.json b/advisories/unreviewed/2025/05/GHSA-5556-32h3-7q94/GHSA-5556-32h3-7q94.json new file mode 100644 index 00000000000..25aac2b40b2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5556-32h3-7q94/GHSA-5556-32h3-7q94.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5556-32h3-7q94", + "modified": "2025-05-23T15:31:11Z", + "published": "2025-05-23T15:31:11Z", + "aliases": [ + "CVE-2025-41377" + ], + "details": "Cryptographic vulnerability in Iridium Certus 700. This vulnerability allows a user to retrieve the encryption key, resulting in the loading of malicious firmware.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-41377" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-intellian-technologies-iridium-certus" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5857-r24c-jg46/GHSA-5857-r24c-jg46.json b/advisories/unreviewed/2025/05/GHSA-5857-r24c-jg46/GHSA-5857-r24c-jg46.json new file mode 100644 index 00000000000..3d792ba8ab9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5857-r24c-jg46/GHSA-5857-r24c-jg46.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5857-r24c-jg46", + "modified": "2025-05-23T15:31:12Z", + "published": "2025-05-23T15:31:12Z", + "aliases": [ + "CVE-2025-46490" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in wordwebsoftware Crossword Compiler Puzzles allows Upload a Web Shell to a Web Server. This issue affects Crossword Compiler Puzzles: from n/a through 5.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46490" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/crossword-compiler-puzzles/vulnerability/wordpress-crossword-compiler-puzzles-5-2-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-58mp-vjj5-c38v/GHSA-58mp-vjj5-c38v.json b/advisories/unreviewed/2025/05/GHSA-58mp-vjj5-c38v/GHSA-58mp-vjj5-c38v.json new file mode 100644 index 00000000000..c5e246b6635 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-58mp-vjj5-c38v/GHSA-58mp-vjj5-c38v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-58mp-vjj5-c38v", + "modified": "2025-05-23T15:31:12Z", + "published": "2025-05-23T15:31:12Z", + "aliases": [ + "CVE-2025-46468" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WPFable Fable Extra allows PHP Local File Inclusion. This issue affects Fable Extra: from n/a through 1.0.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46468" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/fable-extra/vulnerability/wordpress-fable-extra-1-0-5-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5h4m-f9x8-8ffh/GHSA-5h4m-f9x8-8ffh.json b/advisories/unreviewed/2025/05/GHSA-5h4m-f9x8-8ffh/GHSA-5h4m-f9x8-8ffh.json new file mode 100644 index 00000000000..54313403a90 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5h4m-f9x8-8ffh/GHSA-5h4m-f9x8-8ffh.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5h4m-f9x8-8ffh", + "modified": "2025-05-23T15:31:16Z", + "published": "2025-05-23T15:31:16Z", + "aliases": [ + "CVE-2025-5107" + ], + "details": "A vulnerability was found in Fujian Kelixun 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /app/xml_cdr/xml_cdr_details.php. The manipulation of the argument uuid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5107" + }, + { + "type": "WEB", + "url": "https://github.com/Qi-gy/cve/issues/1" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310084" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310084" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.569448" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5j6j-9vjj-6r3v/GHSA-5j6j-9vjj-6r3v.json b/advisories/unreviewed/2025/05/GHSA-5j6j-9vjj-6r3v/GHSA-5j6j-9vjj-6r3v.json new file mode 100644 index 00000000000..2369e8afefa --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5j6j-9vjj-6r3v/GHSA-5j6j-9vjj-6r3v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5j6j-9vjj-6r3v", + "modified": "2025-05-23T15:31:10Z", + "published": "2025-05-23T15:31:10Z", + "aliases": [ + "CVE-2025-32285" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ApusTheme Butcher allows Reflected XSS. This issue affects Butcher: from n/a through 2.40.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32285" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/butcher/vulnerability/wordpress-butcher-theme-2-40-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5jpm-x79x-x3cf/GHSA-5jpm-x79x-x3cf.json b/advisories/unreviewed/2025/05/GHSA-5jpm-x79x-x3cf/GHSA-5jpm-x79x-x3cf.json new file mode 100644 index 00000000000..88dae86f9d1 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5jpm-x79x-x3cf/GHSA-5jpm-x79x-x3cf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5jpm-x79x-x3cf", + "modified": "2025-05-23T15:31:13Z", + "published": "2025-05-23T15:31:13Z", + "aliases": [ + "CVE-2025-47458" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in B2itech B2i Investor Tools allows Reflected XSS. This issue affects B2i Investor Tools: from n/a through 1.0.7.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47458" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/b2i-investor-tools/vulnerability/wordpress-b2i-investor-tools-plugin-1-0-7-9-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5mg8-4p8m-7w4r/GHSA-5mg8-4p8m-7w4r.json b/advisories/unreviewed/2025/05/GHSA-5mg8-4p8m-7w4r/GHSA-5mg8-4p8m-7w4r.json new file mode 100644 index 00000000000..8ced3e7d7b7 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5mg8-4p8m-7w4r/GHSA-5mg8-4p8m-7w4r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5mg8-4p8m-7w4r", + "modified": "2025-05-23T15:31:13Z", + "published": "2025-05-23T15:31:13Z", + "aliases": [ + "CVE-2025-47438" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpjobportal WP Job Portal allows PHP Local File Inclusion. This issue affects WP Job Portal: from n/a through 2.3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47438" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-job-portal/vulnerability/wordpress-wp-job-portal-plugin-2-3-1-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5whm-4gc4-rw65/GHSA-5whm-4gc4-rw65.json b/advisories/unreviewed/2025/05/GHSA-5whm-4gc4-rw65/GHSA-5whm-4gc4-rw65.json new file mode 100644 index 00000000000..3524928be26 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5whm-4gc4-rw65/GHSA-5whm-4gc4-rw65.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5whm-4gc4-rw65", + "modified": "2025-05-23T15:31:15Z", + "published": "2025-05-23T15:31:15Z", + "aliases": [ + "CVE-2025-47678" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FunnelCockpit FunnelCockpit allows Reflected XSS. This issue affects FunnelCockpit: from n/a through 1.4.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47678" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/funnelcockpit/vulnerability/wordpress-funnelcockpit-plugin-1-4-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5xgx-vjx4-mfwv/GHSA-5xgx-vjx4-mfwv.json b/advisories/unreviewed/2025/05/GHSA-5xgx-vjx4-mfwv/GHSA-5xgx-vjx4-mfwv.json new file mode 100644 index 00000000000..9fb2db02136 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5xgx-vjx4-mfwv/GHSA-5xgx-vjx4-mfwv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5xgx-vjx4-mfwv", + "modified": "2025-05-23T15:31:15Z", + "published": "2025-05-23T15:31:15Z", + "aliases": [ + "CVE-2025-47672" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in miniOrange miniOrange Discord Integration allows PHP Local File Inclusion. This issue affects miniOrange Discord Integration: from n/a through 2.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47672" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/miniorange-discord-integration/vulnerability/wordpress-miniorange-discord-integration-2-2-1-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6356-52fq-7vxx/GHSA-6356-52fq-7vxx.json b/advisories/unreviewed/2025/05/GHSA-6356-52fq-7vxx/GHSA-6356-52fq-7vxx.json new file mode 100644 index 00000000000..ca5030b972a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6356-52fq-7vxx/GHSA-6356-52fq-7vxx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6356-52fq-7vxx", + "modified": "2025-05-23T15:31:16Z", + "published": "2025-05-23T15:31:16Z", + "aliases": [ + "CVE-2025-48271" + ], + "details": "Missing Authorization vulnerability in Leadinfo Leadinfo allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Leadinfo: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48271" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/leadinfo/vulnerability/wordpress-leadinfo-1-1-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6599-4gf3-q8fm/GHSA-6599-4gf3-q8fm.json b/advisories/unreviewed/2025/05/GHSA-6599-4gf3-q8fm/GHSA-6599-4gf3-q8fm.json new file mode 100644 index 00000000000..b77d3b4a871 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6599-4gf3-q8fm/GHSA-6599-4gf3-q8fm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6599-4gf3-q8fm", + "modified": "2025-05-23T15:31:10Z", + "published": "2025-05-23T15:31:10Z", + "aliases": [ + "CVE-2025-32294" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Oxpitan allows PHP Local File Inclusion. This issue affects Oxpitan: from n/a through 1.3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32294" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/oxpitan/vulnerability/wordpress-oxpitan-1-3-1-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6cfw-fhp6-2m5g/GHSA-6cfw-fhp6-2m5g.json b/advisories/unreviewed/2025/05/GHSA-6cfw-fhp6-2m5g/GHSA-6cfw-fhp6-2m5g.json new file mode 100644 index 00000000000..06f2986c9fb --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6cfw-fhp6-2m5g/GHSA-6cfw-fhp6-2m5g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6cfw-fhp6-2m5g", + "modified": "2025-05-23T15:31:10Z", + "published": "2025-05-23T15:31:10Z", + "aliases": [ + "CVE-2025-39495" + ], + "details": "Deserialization of Untrusted Data vulnerability in BoldThemes Avantage allows Object Injection. This issue affects Avantage: from n/a through 2.4.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39495" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/avantage/vulnerability/wordpress-avantage-theme-2-4-6-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6g94-c7r6-364g/GHSA-6g94-c7r6-364g.json b/advisories/unreviewed/2025/05/GHSA-6g94-c7r6-364g/GHSA-6g94-c7r6-364g.json new file mode 100644 index 00000000000..d4f5bcfc6a6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6g94-c7r6-364g/GHSA-6g94-c7r6-364g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6g94-c7r6-364g", + "modified": "2025-05-23T15:31:16Z", + "published": "2025-05-23T15:31:16Z", + "aliases": [ + "CVE-2025-48245" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fullworks Quick Contact Form allows Reflected XSS. This issue affects Quick Contact Form : from n/a through 8.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48245" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/quick-contact-form/vulnerability/wordpress-quick-contact-form-plugin-8-2-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6jj3-5xxj-9xx4/GHSA-6jj3-5xxj-9xx4.json b/advisories/unreviewed/2025/05/GHSA-6jj3-5xxj-9xx4/GHSA-6jj3-5xxj-9xx4.json new file mode 100644 index 00000000000..1dea79f4b3b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6jj3-5xxj-9xx4/GHSA-6jj3-5xxj-9xx4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6jj3-5xxj-9xx4", + "modified": "2025-05-23T15:31:13Z", + "published": "2025-05-23T15:31:13Z", + "aliases": [ + "CVE-2025-46527" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in LikeCoin Web3Press allows Path Traversal. This issue affects Web3Press: from n/a through 3.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46527" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/likecoin/vulnerability/wordpress-web3press-decentralize-publishing-with-writing-nft-plugin-3-2-0-arbitrary-file-read-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6rph-38r5-8hhp/GHSA-6rph-38r5-8hhp.json b/advisories/unreviewed/2025/05/GHSA-6rph-38r5-8hhp/GHSA-6rph-38r5-8hhp.json new file mode 100644 index 00000000000..cc207df4cde --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6rph-38r5-8hhp/GHSA-6rph-38r5-8hhp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6rph-38r5-8hhp", + "modified": "2025-05-23T15:31:14Z", + "published": "2025-05-23T15:31:14Z", + "aliases": [ + "CVE-2025-47529" + ], + "details": "Missing Authorization vulnerability in UX Design Experts Experto CTA Widget – Call To Action, Sticky CTA, Floating Button Plugin allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Experto CTA Widget – Call To Action, Sticky CTA, Floating Button Plugin: from n/a through 1.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47529" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/experto-cta-widget/vulnerability/wordpress-experto-cta-widget-call-to-action-sticky-cta-floating-button-plugin-1-1-1-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6v5q-hw53-jvh9/GHSA-6v5q-hw53-jvh9.json b/advisories/unreviewed/2025/05/GHSA-6v5q-hw53-jvh9/GHSA-6v5q-hw53-jvh9.json new file mode 100644 index 00000000000..fd7a684f616 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6v5q-hw53-jvh9/GHSA-6v5q-hw53-jvh9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6v5q-hw53-jvh9", + "modified": "2025-05-23T15:31:16Z", + "published": "2025-05-23T15:31:16Z", + "aliases": [ + "CVE-2025-48273" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpjobportal WP Job Portal allows Path Traversal. This issue affects WP Job Portal: from n/a through 2.3.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48273" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-job-portal/vulnerability/wordpress-wp-job-portal-2-3-2-arbitrary-file-download-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-735c-m362-rv89/GHSA-735c-m362-rv89.json b/advisories/unreviewed/2025/05/GHSA-735c-m362-rv89/GHSA-735c-m362-rv89.json new file mode 100644 index 00000000000..9def8f4270c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-735c-m362-rv89/GHSA-735c-m362-rv89.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-735c-m362-rv89", + "modified": "2025-05-23T15:31:13Z", + "published": "2025-05-23T15:31:13Z", + "aliases": [ + "CVE-2025-46539" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFable Fable Extra allows Blind SQL Injection. This issue affects Fable Extra: from n/a through 1.0.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46539" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/fable-extra/vulnerability/wordpress-fable-extra-1-0-6-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-73r7-6qf7-8658/GHSA-73r7-6qf7-8658.json b/advisories/unreviewed/2025/05/GHSA-73r7-6qf7-8658/GHSA-73r7-6qf7-8658.json new file mode 100644 index 00000000000..f8a9bf56148 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-73r7-6qf7-8658/GHSA-73r7-6qf7-8658.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-73r7-6qf7-8658", + "modified": "2025-05-23T15:31:11Z", + "published": "2025-05-23T15:31:11Z", + "aliases": [ + "CVE-2025-39505" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GoodLayers Goodlayers Hotel allows Reflected XSS. This issue affects Goodlayers Hotel: from n/a through 3.1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39505" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gdlr-hotel/vulnerability/wordpress-goodlayers-hotel-plugin-3-1-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-746h-9hhm-mgv6/GHSA-746h-9hhm-mgv6.json b/advisories/unreviewed/2025/05/GHSA-746h-9hhm-mgv6/GHSA-746h-9hhm-mgv6.json new file mode 100644 index 00000000000..7e49c70ccb0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-746h-9hhm-mgv6/GHSA-746h-9hhm-mgv6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-746h-9hhm-mgv6", + "modified": "2025-05-23T15:31:13Z", + "published": "2025-05-23T15:31:13Z", + "aliases": [ + "CVE-2025-47512" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in tainacan Tainacan allows Path Traversal. This issue affects Tainacan: from n/a through 0.21.14.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47512" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/tainacan/vulnerability/wordpress-tainacan-plugin-0-21-14-arbitrary-file-deletion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7893-p2h2-24qf/GHSA-7893-p2h2-24qf.json b/advisories/unreviewed/2025/05/GHSA-7893-p2h2-24qf/GHSA-7893-p2h2-24qf.json new file mode 100644 index 00000000000..181cdcbcac5 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7893-p2h2-24qf/GHSA-7893-p2h2-24qf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7893-p2h2-24qf", + "modified": "2025-05-23T15:31:16Z", + "published": "2025-05-23T15:31:16Z", + "aliases": [ + "CVE-2025-48283" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Majestic Support Majestic Support allows SQL Injection. This issue affects Majestic Support: from n/a through 1.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48283" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/majestic-support/vulnerability/wordpress-majestic-support-1-1-0-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7wvq-x6j3-ggcp/GHSA-7wvq-x6j3-ggcp.json b/advisories/unreviewed/2025/05/GHSA-7wvq-x6j3-ggcp/GHSA-7wvq-x6j3-ggcp.json new file mode 100644 index 00000000000..3ae72fff17b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7wvq-x6j3-ggcp/GHSA-7wvq-x6j3-ggcp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7wvq-x6j3-ggcp", + "modified": "2025-05-23T15:31:16Z", + "published": "2025-05-23T15:31:16Z", + "aliases": [ + "CVE-2025-48289" + ], + "details": "Deserialization of Untrusted Data vulnerability in AncoraThemes Kids Planet allows Object Injection. This issue affects Kids Planet: from n/a through 2.2.14.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48289" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/kidsplanet/vulnerability/wordpress-kids-planet-2-2-14-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7x5x-m772-p63v/GHSA-7x5x-m772-p63v.json b/advisories/unreviewed/2025/05/GHSA-7x5x-m772-p63v/GHSA-7x5x-m772-p63v.json new file mode 100644 index 00000000000..f8e57421a74 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7x5x-m772-p63v/GHSA-7x5x-m772-p63v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7x5x-m772-p63v", + "modified": "2025-05-23T15:31:09Z", + "published": "2025-05-23T15:31:09Z", + "aliases": [ + "CVE-2025-31914" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav Pixel WordPress Form BuilderPlugin & Autoresponder allows Blind SQL Injection. This issue affects Pixel WordPress Form BuilderPlugin & Autoresponder: from n/a through 1.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31914" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/pixel-formbuilder/vulnerability/wordpress-pixel-wordpress-form-builderplugin-autoresponder-1-0-2-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-87qj-crf6-m933/GHSA-87qj-crf6-m933.json b/advisories/unreviewed/2025/05/GHSA-87qj-crf6-m933/GHSA-87qj-crf6-m933.json new file mode 100644 index 00000000000..123e3fce1b0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-87qj-crf6-m933/GHSA-87qj-crf6-m933.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-87qj-crf6-m933", + "modified": "2025-05-23T15:31:09Z", + "published": "2025-05-23T15:31:09Z", + "aliases": [ + "CVE-2025-31912" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Enzio - Responsive Business WordPress Theme allows PHP Local File Inclusion. This issue affects Enzio - Responsive Business WordPress Theme: from n/a through 1.1.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31912" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/enzio/vulnerability/wordpress-enzio-responsive-business-wordpress-theme-1-1-8-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8jx5-64fv-87qh/GHSA-8jx5-64fv-87qh.json b/advisories/unreviewed/2025/05/GHSA-8jx5-64fv-87qh/GHSA-8jx5-64fv-87qh.json new file mode 100644 index 00000000000..3a0ed69f04f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8jx5-64fv-87qh/GHSA-8jx5-64fv-87qh.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8jx5-64fv-87qh", + "modified": "2025-05-23T15:31:09Z", + "published": "2025-05-23T15:31:09Z", + "aliases": [ + "CVE-2024-7803" + ], + "details": "An issue has been discovered in GitLab CE/EE affecting all versions from 11.6 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A Discord webhook integration may cause DoS.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7803" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2648631" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/479168" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8qv9-rg87-qg9x/GHSA-8qv9-rg87-qg9x.json b/advisories/unreviewed/2025/05/GHSA-8qv9-rg87-qg9x/GHSA-8qv9-rg87-qg9x.json new file mode 100644 index 00000000000..aeadc67e93a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8qv9-rg87-qg9x/GHSA-8qv9-rg87-qg9x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8qv9-rg87-qg9x", + "modified": "2025-05-23T15:31:10Z", + "published": "2025-05-23T15:31:10Z", + "aliases": [ + "CVE-2025-32293" + ], + "details": "Deserialization of Untrusted Data vulnerability in designthemes Finance Consultant allows Object Injection. This issue affects Finance Consultant: from n/a through 2.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32293" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/finance/vulnerability/wordpress-finance-consultant-2-8-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8rwf-97vc-4rh3/GHSA-8rwf-97vc-4rh3.json b/advisories/unreviewed/2025/05/GHSA-8rwf-97vc-4rh3/GHSA-8rwf-97vc-4rh3.json new file mode 100644 index 00000000000..c28cdd18fe3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8rwf-97vc-4rh3/GHSA-8rwf-97vc-4rh3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8rwf-97vc-4rh3", + "modified": "2025-05-23T15:31:09Z", + "published": "2025-05-23T15:31:09Z", + "aliases": [ + "CVE-2025-31631" + ], + "details": "Deserialization of Untrusted Data vulnerability in AncoraThemes Fish House allows Object Injection. This issue affects Fish House: from n/a through 1.2.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31631" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/fish-house/vulnerability/wordpress-fish-house-1-2-7-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-963m-hgv5-33vg/GHSA-963m-hgv5-33vg.json b/advisories/unreviewed/2025/05/GHSA-963m-hgv5-33vg/GHSA-963m-hgv5-33vg.json new file mode 100644 index 00000000000..d5f2d8a0fbd --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-963m-hgv5-33vg/GHSA-963m-hgv5-33vg.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-963m-hgv5-33vg", + "modified": "2025-05-23T15:31:16Z", + "published": "2025-05-23T15:31:16Z", + "aliases": [ + "CVE-2025-5108" + ], + "details": "A vulnerability was found in zongzhige ShopXO 6.5.0. It has been rated as critical. This issue affects the function Upload of the file app/admin/controller/Payment.php of the component ZIP File Handler. The manipulation of the argument params leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5108" + }, + { + "type": "WEB", + "url": "https://github.com/147536951/Qiany1/blob/main/shopxo6.5.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310085" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310085" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.569827" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-97jw-vj6m-r4jm/GHSA-97jw-vj6m-r4jm.json b/advisories/unreviewed/2025/05/GHSA-97jw-vj6m-r4jm/GHSA-97jw-vj6m-r4jm.json new file mode 100644 index 00000000000..846c4ea3f35 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-97jw-vj6m-r4jm/GHSA-97jw-vj6m-r4jm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-97jw-vj6m-r4jm", + "modified": "2025-05-23T15:31:14Z", + "published": "2025-05-23T15:31:14Z", + "aliases": [ + "CVE-2025-47603" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Belingo belingoGeo allows Path Traversal. This issue affects belingoGeo: from n/a through 1.12.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47603" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/belingogeo/vulnerability/wordpress-belingogeo-1-12-0-arbitrary-file-download-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-98mr-vfww-x4x2/GHSA-98mr-vfww-x4x2.json b/advisories/unreviewed/2025/05/GHSA-98mr-vfww-x4x2/GHSA-98mr-vfww-x4x2.json new file mode 100644 index 00000000000..a5ed45f2204 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-98mr-vfww-x4x2/GHSA-98mr-vfww-x4x2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-98mr-vfww-x4x2", + "modified": "2025-05-23T15:31:14Z", + "published": "2025-05-23T15:31:14Z", + "aliases": [ + "CVE-2025-47618" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mortgage Calculator BMI Adult & Kid Calculator allows Reflected XSS. This issue affects BMI Adult & Kid Calculator: from n/a through 1.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47618" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bmi-adultkid-calculator/vulnerability/wordpress-bmi-adult-kid-calculator-plugin-1-2-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9g7r-jg3m-m6wm/GHSA-9g7r-jg3m-m6wm.json b/advisories/unreviewed/2025/05/GHSA-9g7r-jg3m-m6wm/GHSA-9g7r-jg3m-m6wm.json new file mode 100644 index 00000000000..9c4775e00e1 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9g7r-jg3m-m6wm/GHSA-9g7r-jg3m-m6wm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9g7r-jg3m-m6wm", + "modified": "2025-05-23T15:31:09Z", + "published": "2025-05-23T15:31:09Z", + "aliases": [ + "CVE-2025-31397" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartcms Bus Ticket Booking with Seat Reservation for WooCommerce allows SQL Injection. This issue affects Bus Ticket Booking with Seat Reservation for WooCommerce: from n/a through 1.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31397" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/scw-bus-seat-reservation/vulnerability/wordpress-bus-ticket-booking-with-seat-reservation-for-woocommerce-plugin-1-7-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9grh-5gv9-xf63/GHSA-9grh-5gv9-xf63.json b/advisories/unreviewed/2025/05/GHSA-9grh-5gv9-xf63/GHSA-9grh-5gv9-xf63.json new file mode 100644 index 00000000000..43bc6c53199 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9grh-5gv9-xf63/GHSA-9grh-5gv9-xf63.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9grh-5gv9-xf63", + "modified": "2025-05-23T15:31:11Z", + "published": "2025-05-23T15:31:11Z", + "aliases": [ + "CVE-2025-46446" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ivanrojas Libro de Reclamaciones allows Stored XSS. This issue affects Libro de Reclamaciones: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46446" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/libro-de-reclamaciones/vulnerability/wordpress-libro-de-reclamaciones-1-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9h8v-w795-r85q/GHSA-9h8v-w795-r85q.json b/advisories/unreviewed/2025/05/GHSA-9h8v-w795-r85q/GHSA-9h8v-w795-r85q.json new file mode 100644 index 00000000000..dead100b85c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9h8v-w795-r85q/GHSA-9h8v-w795-r85q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9h8v-w795-r85q", + "modified": "2025-05-23T15:31:13Z", + "published": "2025-05-23T15:31:13Z", + "aliases": [ + "CVE-2025-46537" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ctltwp Section Widget allows Reflected XSS. This issue affects Section Widget: from n/a through 3.3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46537" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/section-widget/vulnerability/wordpress-section-widget-plugin-3-2-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9hpw-wrhw-6g76/GHSA-9hpw-wrhw-6g76.json b/advisories/unreviewed/2025/05/GHSA-9hpw-wrhw-6g76/GHSA-9hpw-wrhw-6g76.json new file mode 100644 index 00000000000..8312cc12b74 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9hpw-wrhw-6g76/GHSA-9hpw-wrhw-6g76.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9hpw-wrhw-6g76", + "modified": "2025-05-23T15:31:11Z", + "published": "2025-05-23T15:31:11Z", + "aliases": [ + "CVE-2025-41378" + ], + "details": "The SSID field is not parsed correctly and can be used to inject commands into the hostpad.conf file. This can be exploited by an attacker to extend his knowledge of the system and compromise other devices. The information is filtered by the logs function of the web panel.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-41378" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-intellian-technologies-iridium-certus" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9v6c-p69r-jc8x/GHSA-9v6c-p69r-jc8x.json b/advisories/unreviewed/2025/05/GHSA-9v6c-p69r-jc8x/GHSA-9v6c-p69r-jc8x.json new file mode 100644 index 00000000000..3ad2567be35 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9v6c-p69r-jc8x/GHSA-9v6c-p69r-jc8x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9v6c-p69r-jc8x", + "modified": "2025-05-23T15:31:10Z", + "published": "2025-05-23T15:31:10Z", + "aliases": [ + "CVE-2025-32309" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Healsoul allows PHP Local File Inclusion. This issue affects Healsoul: from n/a through 2.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32309" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/healsoul/vulnerability/wordpress-healsoul-2-0-2-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9w2j-w59m-592g/GHSA-9w2j-w59m-592g.json b/advisories/unreviewed/2025/05/GHSA-9w2j-w59m-592g/GHSA-9w2j-w59m-592g.json new file mode 100644 index 00000000000..9be39679ef0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9w2j-w59m-592g/GHSA-9w2j-w59m-592g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9w2j-w59m-592g", + "modified": "2025-05-23T15:31:11Z", + "published": "2025-05-23T15:31:11Z", + "aliases": [ + "CVE-2025-39536" + ], + "details": "Missing Authorization vulnerability in Chimpstudio JobHunt Job Alerts allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JobHunt Job Alerts: from n/a through 3.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39536" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/jobhunt-notifications/vulnerability/wordpress-jobhunt-job-alerts-3-6-arbitrary-content-deletion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9wr9-p53c-hqrq/GHSA-9wr9-p53c-hqrq.json b/advisories/unreviewed/2025/05/GHSA-9wr9-p53c-hqrq/GHSA-9wr9-p53c-hqrq.json new file mode 100644 index 00000000000..b74629611da --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9wr9-p53c-hqrq/GHSA-9wr9-p53c-hqrq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9wr9-p53c-hqrq", + "modified": "2025-05-23T15:31:09Z", + "published": "2025-05-23T15:31:09Z", + "aliases": [ + "CVE-2025-31053" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in quantumcloud KBx Pro Ultimate allows Path Traversal. This issue affects KBx Pro Ultimate: from n/a through 7.9.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31053" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/knowledgebase-helpdesk-pro/vulnerability/wordpress-kbx-pro-ultimate-7-9-8-arbitrary-file-deletion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9x45-8qmx-683p/GHSA-9x45-8qmx-683p.json b/advisories/unreviewed/2025/05/GHSA-9x45-8qmx-683p/GHSA-9x45-8qmx-683p.json index 7b1b65a1c7e..26408b3e3d9 100644 --- a/advisories/unreviewed/2025/05/GHSA-9x45-8qmx-683p/GHSA-9x45-8qmx-683p.json +++ b/advisories/unreviewed/2025/05/GHSA-9x45-8qmx-683p/GHSA-9x45-8qmx-683p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9x45-8qmx-683p", - "modified": "2025-05-22T21:30:47Z", + "modified": "2025-05-23T15:31:09Z", "published": "2025-05-22T21:30:47Z", "aliases": [ "CVE-2024-40460" ], "details": "An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the JOBENTRY.EXE", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-22T19:15:40Z" diff --git a/advisories/unreviewed/2025/05/GHSA-c33v-v5r9-774j/GHSA-c33v-v5r9-774j.json b/advisories/unreviewed/2025/05/GHSA-c33v-v5r9-774j/GHSA-c33v-v5r9-774j.json new file mode 100644 index 00000000000..f3eb80d4ef7 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c33v-v5r9-774j/GHSA-c33v-v5r9-774j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c33v-v5r9-774j", + "modified": "2025-05-23T15:31:12Z", + "published": "2025-05-23T15:31:12Z", + "aliases": [ + "CVE-2025-46487" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sftranna EC Authorize.net allows Reflected XSS. This issue affects EC Authorize.net: from n/a through 0.3.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46487" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ec-authorizenet/vulnerability/wordpress-ec-authorize-net-plugin-0-3-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c4jq-c26m-8vfh/GHSA-c4jq-c26m-8vfh.json b/advisories/unreviewed/2025/05/GHSA-c4jq-c26m-8vfh/GHSA-c4jq-c26m-8vfh.json new file mode 100644 index 00000000000..cad78434aa6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c4jq-c26m-8vfh/GHSA-c4jq-c26m-8vfh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c4jq-c26m-8vfh", + "modified": "2025-05-23T15:31:09Z", + "published": "2025-05-23T15:31:09Z", + "aliases": [ + "CVE-2025-31056" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Techspawn WhatsCart - Whatsapp Abandoned Cart Recovery, Order Notifications, Chat Box, OTP for WooCommerce allows SQL Injection. This issue affects WhatsCart - Whatsapp Abandoned Cart Recovery, Order Notifications, Chat Box, OTP for WooCommerce: from n/a through 1.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31056" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/whatscart-for-woocommerce/vulnerability/wordpress-whatscart-plugin-1-1-0-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-cf8h-x8xq-r3cr/GHSA-cf8h-x8xq-r3cr.json b/advisories/unreviewed/2025/05/GHSA-cf8h-x8xq-r3cr/GHSA-cf8h-x8xq-r3cr.json new file mode 100644 index 00000000000..0f620ac73ac --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-cf8h-x8xq-r3cr/GHSA-cf8h-x8xq-r3cr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cf8h-x8xq-r3cr", + "modified": "2025-05-23T15:31:14Z", + "published": "2025-05-23T15:31:14Z", + "aliases": [ + "CVE-2025-47642" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Ajar Productions Ajar in5 Embed allows Upload a Web Shell to a Web Server. This issue affects Ajar in5 Embed: from n/a through 3.1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47642" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ajar-productions-in5-embed/vulnerability/wordpress-ajar-in5-embed-3-1-5-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-cjvp-vp4r-jppc/GHSA-cjvp-vp4r-jppc.json b/advisories/unreviewed/2025/05/GHSA-cjvp-vp4r-jppc/GHSA-cjvp-vp4r-jppc.json index d9189f44f4d..905dc4ba10f 100644 --- a/advisories/unreviewed/2025/05/GHSA-cjvp-vp4r-jppc/GHSA-cjvp-vp4r-jppc.json +++ b/advisories/unreviewed/2025/05/GHSA-cjvp-vp4r-jppc/GHSA-cjvp-vp4r-jppc.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-cqh9-2fgp-cxw2/GHSA-cqh9-2fgp-cxw2.json b/advisories/unreviewed/2025/05/GHSA-cqh9-2fgp-cxw2/GHSA-cqh9-2fgp-cxw2.json new file mode 100644 index 00000000000..b26b956ae67 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-cqh9-2fgp-cxw2/GHSA-cqh9-2fgp-cxw2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cqh9-2fgp-cxw2", + "modified": "2025-05-23T15:31:14Z", + "published": "2025-05-23T15:31:14Z", + "aliases": [ + "CVE-2025-47641" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in printcart Printcart Web to Print Product Designer for WooCommerce allows Upload a Web Shell to a Web Server. This issue affects Printcart Web to Print Product Designer for WooCommerce: from n/a through 2.3.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47641" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/printcart-integration/vulnerability/wordpress-printcart-web-to-print-product-designer-for-woocommerce-2-3-6-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-f3vf-9cvm-w329/GHSA-f3vf-9cvm-w329.json b/advisories/unreviewed/2025/05/GHSA-f3vf-9cvm-w329/GHSA-f3vf-9cvm-w329.json new file mode 100644 index 00000000000..2c0063b65d2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-f3vf-9cvm-w329/GHSA-f3vf-9cvm-w329.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f3vf-9cvm-w329", + "modified": "2025-05-23T15:31:10Z", + "published": "2025-05-23T15:31:10Z", + "aliases": [ + "CVE-2025-32284" + ], + "details": "Deserialization of Untrusted Data vulnerability in designthemes Pet World allows Object Injection. This issue affects Pet World: from n/a through 2.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32284" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/petsworld/vulnerability/wordpress-pet-world-2-8-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-f9xv-95hg-pxgf/GHSA-f9xv-95hg-pxgf.json b/advisories/unreviewed/2025/05/GHSA-f9xv-95hg-pxgf/GHSA-f9xv-95hg-pxgf.json new file mode 100644 index 00000000000..ed3eb85a86f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-f9xv-95hg-pxgf/GHSA-f9xv-95hg-pxgf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f9xv-95hg-pxgf", + "modified": "2025-05-23T15:31:15Z", + "published": "2025-05-23T15:31:15Z", + "aliases": [ + "CVE-2025-47663" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla Hospital Management System allows Upload a Web Shell to a Web Server. This issue affects Hospital Management System: from 47.0(20 through 11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47663" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/hospital-management/vulnerability/wordpress-hospital-management-system-plugin-47-0-20-11-2023-arbitrary-file-upload-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-ffpp-564x-w86f/GHSA-ffpp-564x-w86f.json b/advisories/unreviewed/2025/05/GHSA-ffpp-564x-w86f/GHSA-ffpp-564x-w86f.json new file mode 100644 index 00000000000..ca6ac618322 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-ffpp-564x-w86f/GHSA-ffpp-564x-w86f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ffpp-564x-w86f", + "modified": "2025-05-23T15:31:14Z", + "published": "2025-05-23T15:31:14Z", + "aliases": [ + "CVE-2025-47568" + ], + "details": "Deserialization of Untrusted Data vulnerability in ZoomIt ZoomSounds allows Object Injection. This issue affects ZoomSounds: from n/a through 6.91.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47568" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/dzs-zoomsounds/vulnerability/wordpress-zoomsounds-plugin-6-91-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fh7c-x2jh-rc4w/GHSA-fh7c-x2jh-rc4w.json b/advisories/unreviewed/2025/05/GHSA-fh7c-x2jh-rc4w/GHSA-fh7c-x2jh-rc4w.json new file mode 100644 index 00000000000..09b3ff032bc --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fh7c-x2jh-rc4w/GHSA-fh7c-x2jh-rc4w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fh7c-x2jh-rc4w", + "modified": "2025-05-23T15:31:10Z", + "published": "2025-05-23T15:31:10Z", + "aliases": [ + "CVE-2025-39494" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Wilmër allows PHP Local File Inclusion. This issue affects Wilmër: from n/a through n/a.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39494" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/wilmer/vulnerability/wordpress-wilmer-theme-3-4-2-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fhfv-mjv5-35hp/GHSA-fhfv-mjv5-35hp.json b/advisories/unreviewed/2025/05/GHSA-fhfv-mjv5-35hp/GHSA-fhfv-mjv5-35hp.json new file mode 100644 index 00000000000..1034e8eb3b2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fhfv-mjv5-35hp/GHSA-fhfv-mjv5-35hp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fhfv-mjv5-35hp", + "modified": "2025-05-23T15:31:10Z", + "published": "2025-05-23T15:31:10Z", + "aliases": [ + "CVE-2025-32286" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme Butcher allows PHP Local File Inclusion. This issue affects Butcher: from n/a through 2.40.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32286" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/butcher/vulnerability/wordpress-butcher-2-40-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fjqw-wgr4-3jjp/GHSA-fjqw-wgr4-3jjp.json b/advisories/unreviewed/2025/05/GHSA-fjqw-wgr4-3jjp/GHSA-fjqw-wgr4-3jjp.json new file mode 100644 index 00000000000..1085bd3f0a2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fjqw-wgr4-3jjp/GHSA-fjqw-wgr4-3jjp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fjqw-wgr4-3jjp", + "modified": "2025-05-23T15:31:09Z", + "published": "2025-05-23T15:31:09Z", + "aliases": [ + "CVE-2025-31918" + ], + "details": "Incorrect Privilege Assignment vulnerability in quantumcloud Simple Business Directory Pro allows Privilege Escalation. This issue affects Simple Business Directory Pro: from n/a through 15.4.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31918" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simple-business-directory-pro/vulnerability/wordpress-simple-business-directory-pro-15-4-8-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fqj7-rj6h-ppvp/GHSA-fqj7-rj6h-ppvp.json b/advisories/unreviewed/2025/05/GHSA-fqj7-rj6h-ppvp/GHSA-fqj7-rj6h-ppvp.json new file mode 100644 index 00000000000..17262450bd1 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fqj7-rj6h-ppvp/GHSA-fqj7-rj6h-ppvp.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fqj7-rj6h-ppvp", + "modified": "2025-05-23T15:31:17Z", + "published": "2025-05-23T15:31:17Z", + "aliases": [ + "CVE-2024-51101" + ], + "details": "PHPGURUKUL Restaurant Table Booking System using PHP and MySQL v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter at /rtbs/check-status.php.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51101" + }, + { + "type": "WEB", + "url": "https://github.com/0xBhushan/Writeups/blob/main/CVE/phpGurukul/Restaurant%20Table%20Booking%20System%20using%20PHP%20and%20MySQL/SQL%20Injection-Search.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fqmr-g5hc-mhmq/GHSA-fqmr-g5hc-mhmq.json b/advisories/unreviewed/2025/05/GHSA-fqmr-g5hc-mhmq/GHSA-fqmr-g5hc-mhmq.json new file mode 100644 index 00000000000..9a9e892bd8d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fqmr-g5hc-mhmq/GHSA-fqmr-g5hc-mhmq.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fqmr-g5hc-mhmq", + "modified": "2025-05-23T15:31:16Z", + "published": "2025-05-23T15:31:16Z", + "aliases": [ + "CVE-2025-5110" + ], + "details": "A vulnerability classified as critical was found in FreeFloat FTP Server 1.0. Affected by this vulnerability is an unknown functionality of the component VERBOSE Command Handler. The manipulation leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5110" + }, + { + "type": "WEB", + "url": "https://fitoxs.com/exploit/exploit-325e5cf47259d3b511d301c84b53946fd1b78226df7291d441103ef5295f216e.txt" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310087" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310087" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.582957" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T14:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fv46-529r-fc72/GHSA-fv46-529r-fc72.json b/advisories/unreviewed/2025/05/GHSA-fv46-529r-fc72/GHSA-fv46-529r-fc72.json new file mode 100644 index 00000000000..3227553cd76 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fv46-529r-fc72/GHSA-fv46-529r-fc72.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fv46-529r-fc72", + "modified": "2025-05-23T15:31:13Z", + "published": "2025-05-23T15:31:13Z", + "aliases": [ + "CVE-2025-46526" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in janekniefeldt My Custom Widgets allows Reflected XSS. This issue affects My Custom Widgets: from n/a through 2.0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46526" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mycustomwidget/vulnerability/wordpress-my-custom-widgets-plugin-2-0-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fvcg-g6jq-f58x/GHSA-fvcg-g6jq-f58x.json b/advisories/unreviewed/2025/05/GHSA-fvcg-g6jq-f58x/GHSA-fvcg-g6jq-f58x.json new file mode 100644 index 00000000000..4b610d81bb4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fvcg-g6jq-f58x/GHSA-fvcg-g6jq-f58x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fvcg-g6jq-f58x", + "modified": "2025-05-23T15:31:15Z", + "published": "2025-05-23T15:31:15Z", + "aliases": [ + "CVE-2025-47687" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in StoreKeeper B.V. StoreKeeper for WooCommerce allows Upload a Web Shell to a Web Server. This issue affects StoreKeeper for WooCommerce: from n/a through 14.4.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47687" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/storekeeper-for-woocommerce/vulnerability/wordpress-storekeeper-for-woocommerce-14-4-4-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fwfc-62f3-6h7j/GHSA-fwfc-62f3-6h7j.json b/advisories/unreviewed/2025/05/GHSA-fwfc-62f3-6h7j/GHSA-fwfc-62f3-6h7j.json new file mode 100644 index 00000000000..94fc573af60 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fwfc-62f3-6h7j/GHSA-fwfc-62f3-6h7j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fwfc-62f3-6h7j", + "modified": "2025-05-23T15:31:14Z", + "published": "2025-05-23T15:31:14Z", + "aliases": [ + "CVE-2025-47532" + ], + "details": "Deserialization of Untrusted Data vulnerability in CoinPayments CoinPayments.net Payment Gateway for WooCommerce allows Object Injection. This issue affects CoinPayments.net Payment Gateway for WooCommerce: from n/a through 1.0.17.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47532" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/coinpayments-payment-gateway-for-woocommerce/vulnerability/wordpress-coinpayments-net-payment-gateway-for-woocommerce-1-0-17-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g4f5-x2r2-hg23/GHSA-g4f5-x2r2-hg23.json b/advisories/unreviewed/2025/05/GHSA-g4f5-x2r2-hg23/GHSA-g4f5-x2r2-hg23.json new file mode 100644 index 00000000000..5d11ac37290 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g4f5-x2r2-hg23/GHSA-g4f5-x2r2-hg23.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g4f5-x2r2-hg23", + "modified": "2025-05-23T15:31:16Z", + "published": "2025-05-23T15:31:16Z", + "aliases": [ + "CVE-2025-5112" + ], + "details": "A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. This affects an unknown part of the component MGET Command Handler. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5112" + }, + { + "type": "WEB", + "url": "https://fitoxs.com/exploit/exploit-47929b46e253abc8390610b6ad91d5dc9f2d64a755e6fdb51d5f8f92e37947e2.txt" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310089" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310089" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.582962" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T14:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g78q-vwc9-9f65/GHSA-g78q-vwc9-9f65.json b/advisories/unreviewed/2025/05/GHSA-g78q-vwc9-9f65/GHSA-g78q-vwc9-9f65.json index 82a07ce2124..253d2bd5349 100644 --- a/advisories/unreviewed/2025/05/GHSA-g78q-vwc9-9f65/GHSA-g78q-vwc9-9f65.json +++ b/advisories/unreviewed/2025/05/GHSA-g78q-vwc9-9f65/GHSA-g78q-vwc9-9f65.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-g83r-7cwr-h2jw/GHSA-g83r-7cwr-h2jw.json b/advisories/unreviewed/2025/05/GHSA-g83r-7cwr-h2jw/GHSA-g83r-7cwr-h2jw.json new file mode 100644 index 00000000000..dae16b81c4c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g83r-7cwr-h2jw/GHSA-g83r-7cwr-h2jw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g83r-7cwr-h2jw", + "modified": "2025-05-23T15:31:15Z", + "published": "2025-05-23T15:31:15Z", + "aliases": [ + "CVE-2025-47646" + ], + "details": "Weak Password Recovery Mechanism for Forgotten Password vulnerability in Gilblas Ngunte Possi PSW Front-end Login & Registration allows Password Recovery Exploitation. This issue affects PSW Front-end Login & Registration: from n/a through 1.13.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47646" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/psw-login-and-registration/vulnerability/wordpress-psw-front-end-login-registration-1-12-broken-authentication-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-640" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gcjf-8x3p-64v2/GHSA-gcjf-8x3p-64v2.json b/advisories/unreviewed/2025/05/GHSA-gcjf-8x3p-64v2/GHSA-gcjf-8x3p-64v2.json new file mode 100644 index 00000000000..1293f4f1e54 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gcjf-8x3p-64v2/GHSA-gcjf-8x3p-64v2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gcjf-8x3p-64v2", + "modified": "2025-05-23T15:31:16Z", + "published": "2025-05-23T15:31:16Z", + "aliases": [ + "CVE-2025-3580" + ], + "details": "An access control vulnerability was discovered in Grafana OSS where an Organization administrator could permanently delete the Server administrator account. This vulnerability exists in the DELETE /api/org/users/ endpoint.\n\nThe vulnerability can be exploited when:\n\n1. An Organization administrator exists\n\n2. The Server administrator is either:\n\n - Not part of any organization, or\n - Part of the same organization as the Organization administrator\nImpact:\n\n- Organization administrators can permanently delete Server administrator accounts\n\n- If the only Server administrator is deleted, the Grafana instance becomes unmanageable\n\n- No super-user permissions remain in the system\n\n- Affects all users, organizations, and teams managed in the instance\n\nThe vulnerability is particularly serious as it can lead to a complete loss of administrative control over the Grafana instance.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3580" + }, + { + "type": "WEB", + "url": "https://grafana.com/security/security-advisories/cve-2025-3580" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T14:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gj3c-w556-7qwm/GHSA-gj3c-w556-7qwm.json b/advisories/unreviewed/2025/05/GHSA-gj3c-w556-7qwm/GHSA-gj3c-w556-7qwm.json new file mode 100644 index 00000000000..b210805215b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gj3c-w556-7qwm/GHSA-gj3c-w556-7qwm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gj3c-w556-7qwm", + "modified": "2025-05-23T15:31:12Z", + "published": "2025-05-23T15:31:12Z", + "aliases": [ + "CVE-2025-46458" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in x000x occupancyplan allows SQL Injection. This issue affects occupancyplan: from n/a through 1.0.3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46458" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/occupancyplan/vulnerability/wordpress-occupancyplan-plugin-1-0-3-0-csrf-to-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gpxg-v5x4-r25g/GHSA-gpxg-v5x4-r25g.json b/advisories/unreviewed/2025/05/GHSA-gpxg-v5x4-r25g/GHSA-gpxg-v5x4-r25g.json new file mode 100644 index 00000000000..715ac81863a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gpxg-v5x4-r25g/GHSA-gpxg-v5x4-r25g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gpxg-v5x4-r25g", + "modified": "2025-05-23T15:31:12Z", + "published": "2025-05-23T15:31:12Z", + "aliases": [ + "CVE-2025-46454" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in svil4ok Meta Keywords & Description allows PHP Local File Inclusion. This issue affects Meta Keywords & Description: from n/a through 0.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46454" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-meta-keywords-meta-description/vulnerability/wordpress-meta-keywords-description-0-8-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gpxh-j79m-whcj/GHSA-gpxh-j79m-whcj.json b/advisories/unreviewed/2025/05/GHSA-gpxh-j79m-whcj/GHSA-gpxh-j79m-whcj.json new file mode 100644 index 00000000000..785b3a5de36 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gpxh-j79m-whcj/GHSA-gpxh-j79m-whcj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gpxh-j79m-whcj", + "modified": "2025-05-23T15:31:14Z", + "published": "2025-05-23T15:31:14Z", + "aliases": [ + "CVE-2025-47637" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in STAGGS STAGGS allows Upload a Web Shell to a Web Server. This issue affects STAGGS: from n/a through 2.11.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47637" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/staggs/vulnerability/wordpress-staggs-2-10-1-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gqgx-hgvf-f75f/GHSA-gqgx-hgvf-f75f.json b/advisories/unreviewed/2025/05/GHSA-gqgx-hgvf-f75f/GHSA-gqgx-hgvf-f75f.json index 7d0f3139f20..62d77902bb0 100644 --- a/advisories/unreviewed/2025/05/GHSA-gqgx-hgvf-f75f/GHSA-gqgx-hgvf-f75f.json +++ b/advisories/unreviewed/2025/05/GHSA-gqgx-hgvf-f75f/GHSA-gqgx-hgvf-f75f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gqgx-hgvf-f75f", - "modified": "2025-05-21T15:30:33Z", + "modified": "2025-05-23T15:31:08Z", "published": "2025-05-21T15:30:33Z", "aliases": [ "CVE-2025-40775" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://kb.isc.org/docs/cve-2025-40775" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250523-0001" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2025/05/21/1" diff --git a/advisories/unreviewed/2025/05/GHSA-gvwq-4r92-cj5h/GHSA-gvwq-4r92-cj5h.json b/advisories/unreviewed/2025/05/GHSA-gvwq-4r92-cj5h/GHSA-gvwq-4r92-cj5h.json new file mode 100644 index 00000000000..2324bea131c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gvwq-4r92-cj5h/GHSA-gvwq-4r92-cj5h.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gvwq-4r92-cj5h", + "modified": "2025-05-23T15:31:17Z", + "published": "2025-05-23T15:31:17Z", + "aliases": [ + "CVE-2025-5114" + ], + "details": "A vulnerability has been found in easysoft zentaopms 21.5_20250307 and classified as critical. This vulnerability affects the function Edit of the file /index.php?m=editor&f=edit&filePath=cGhhcjovLy9ldGMvcGFzc3dk&action=edit of the component Committer. The manipulation of the argument filePath leads to deserialization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5114" + }, + { + "type": "WEB", + "url": "https://github.com/3em0/cve_repo/blob/main/zentaopms/Phar%20Bypass%20Vulnerability%20in%20ZenTao.md" + }, + { + "type": "WEB", + "url": "https://github.com/3em0/cve_repo/blob/main/zentaopms/Phar%20Bypass%20Vulnerability%20in%20ZenTao.md#exploitation" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310090" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310090" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.570727" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T15:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h2pj-2gpr-72vh/GHSA-h2pj-2gpr-72vh.json b/advisories/unreviewed/2025/05/GHSA-h2pj-2gpr-72vh/GHSA-h2pj-2gpr-72vh.json new file mode 100644 index 00000000000..8e08891b20f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h2pj-2gpr-72vh/GHSA-h2pj-2gpr-72vh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h2pj-2gpr-72vh", + "modified": "2025-05-23T15:31:11Z", + "published": "2025-05-23T15:31:10Z", + "aliases": [ + "CVE-2025-39503" + ], + "details": "Deserialization of Untrusted Data vulnerability in GoodLayers Goodlayers Hotel allows Object Injection. This issue affects Goodlayers Hotel: from n/a through 3.1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39503" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gdlr-hotel/vulnerability/wordpress-goodlayers-hotel-plugin-3-1-4-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h3r6-f23f-fjw6/GHSA-h3r6-f23f-fjw6.json b/advisories/unreviewed/2025/05/GHSA-h3r6-f23f-fjw6/GHSA-h3r6-f23f-fjw6.json new file mode 100644 index 00000000000..f1585da87d5 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h3r6-f23f-fjw6/GHSA-h3r6-f23f-fjw6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h3r6-f23f-fjw6", + "modified": "2025-05-23T15:31:15Z", + "published": "2025-05-23T15:31:15Z", + "aliases": [ + "CVE-2025-47680" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michel - xiligroup dev xili-tidy-tags allows Reflected XSS. This issue affects xili-tidy-tags: from n/a through 1.12.06.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47680" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/xili-tidy-tags/vulnerability/wordpress-xili-tidy-tags-plugin-1-12-06-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h3w6-hg9p-c6c4/GHSA-h3w6-hg9p-c6c4.json b/advisories/unreviewed/2025/05/GHSA-h3w6-hg9p-c6c4/GHSA-h3w6-hg9p-c6c4.json new file mode 100644 index 00000000000..4145c6dbfea --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h3w6-hg9p-c6c4/GHSA-h3w6-hg9p-c6c4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h3w6-hg9p-c6c4", + "modified": "2025-05-23T15:31:11Z", + "published": "2025-05-23T15:31:11Z", + "aliases": [ + "CVE-2025-39502" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GoodLayers Goodlayers Hostel allows Reflected XSS. This issue affects Goodlayers Hostel: from n/a through 3.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39502" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gdlr-hostel/vulnerability/wordpress-goodlayers-hostel-plugin-3-1-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h3xr-5jg5-xwr6/GHSA-h3xr-5jg5-xwr6.json b/advisories/unreviewed/2025/05/GHSA-h3xr-5jg5-xwr6/GHSA-h3xr-5jg5-xwr6.json new file mode 100644 index 00000000000..333ff60c1df --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h3xr-5jg5-xwr6/GHSA-h3xr-5jg5-xwr6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h3xr-5jg5-xwr6", + "modified": "2025-05-23T15:31:14Z", + "published": "2025-05-23T15:31:14Z", + "aliases": [ + "CVE-2025-47611" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Khaled User Meta allows Reflected XSS. This issue affects User Meta: from n/a through 3.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47611" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/user-meta/vulnerability/wordpress-user-meta-plugin-3-1-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hjh6-jj5p-wf3x/GHSA-hjh6-jj5p-wf3x.json b/advisories/unreviewed/2025/05/GHSA-hjh6-jj5p-wf3x/GHSA-hjh6-jj5p-wf3x.json new file mode 100644 index 00000000000..5d8c9238633 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hjh6-jj5p-wf3x/GHSA-hjh6-jj5p-wf3x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hjh6-jj5p-wf3x", + "modified": "2025-05-23T15:31:14Z", + "published": "2025-05-23T15:31:14Z", + "aliases": [ + "CVE-2025-47640" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in printcart Printcart Web to Print Product Designer for WooCommerce allows SQL Injection. This issue affects Printcart Web to Print Product Designer for WooCommerce: from n/a through 2.3.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47640" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/printcart-integration/vulnerability/wordpress-printcart-web-to-print-product-designer-for-woocommerce-2-3-6-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hqgp-gmgc-jhhm/GHSA-hqgp-gmgc-jhhm.json b/advisories/unreviewed/2025/05/GHSA-hqgp-gmgc-jhhm/GHSA-hqgp-gmgc-jhhm.json new file mode 100644 index 00000000000..66837bc54ad --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hqgp-gmgc-jhhm/GHSA-hqgp-gmgc-jhhm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hqgp-gmgc-jhhm", + "modified": "2025-05-23T15:31:12Z", + "published": "2025-05-23T15:31:12Z", + "aliases": [ + "CVE-2025-46486" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in totalprocessing Nomupay Payment Processing Gateway allows Path Traversal. This issue affects Nomupay Payment Processing Gateway: from n/a through 7.1.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46486" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/totalprocessing-card-payments/vulnerability/wordpress-nomupay-payment-processing-gateway-7-1-7-arbitrary-file-download-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hx67-26rf-cg4v/GHSA-hx67-26rf-cg4v.json b/advisories/unreviewed/2025/05/GHSA-hx67-26rf-cg4v/GHSA-hx67-26rf-cg4v.json new file mode 100644 index 00000000000..17c7e4fb716 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hx67-26rf-cg4v/GHSA-hx67-26rf-cg4v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hx67-26rf-cg4v", + "modified": "2025-05-23T15:31:11Z", + "published": "2025-05-23T15:31:11Z", + "aliases": [ + "CVE-2025-46444" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in scripteo Ads Pro Plugin allows PHP Local File Inclusion. This issue affects Ads Pro Plugin: from n/a through 4.88.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46444" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ap-plugin-scripteo/vulnerability/wordpress-ads-pro-plugin-4-88-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-j646-j4cf-jj5h/GHSA-j646-j4cf-jj5h.json b/advisories/unreviewed/2025/05/GHSA-j646-j4cf-jj5h/GHSA-j646-j4cf-jj5h.json new file mode 100644 index 00000000000..0c2c5ad3221 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-j646-j4cf-jj5h/GHSA-j646-j4cf-jj5h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j646-j4cf-jj5h", + "modified": "2025-05-23T15:31:10Z", + "published": "2025-05-23T15:31:10Z", + "aliases": [ + "CVE-2025-39489" + ], + "details": "Incorrect Privilege Assignment vulnerability in pebas CouponXL allows Privilege Escalation. This issue affects CouponXL: from n/a through 4.5.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39489" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/couponxl/vulnerability/wordpress-couponxl-4-5-0-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jcv7-4rpc-rwj8/GHSA-jcv7-4rpc-rwj8.json b/advisories/unreviewed/2025/05/GHSA-jcv7-4rpc-rwj8/GHSA-jcv7-4rpc-rwj8.json new file mode 100644 index 00000000000..94c38d41b32 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jcv7-4rpc-rwj8/GHSA-jcv7-4rpc-rwj8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jcv7-4rpc-rwj8", + "modified": "2025-05-23T15:31:16Z", + "published": "2025-05-23T15:31:16Z", + "aliases": [ + "CVE-2025-48287" + ], + "details": "Deserialization of Untrusted Data vulnerability in Pagaleve Pix 4x sem juros - Pagaleve allows Object Injection.This issue affects Pix 4x sem juros - Pagaleve: from n/a through 1.6.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48287" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wc-pagaleve/vulnerability/wordpress-pix-4x-sem-juros-pagaleve-1-6-9-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jgcc-pm4w-jp8q/GHSA-jgcc-pm4w-jp8q.json b/advisories/unreviewed/2025/05/GHSA-jgcc-pm4w-jp8q/GHSA-jgcc-pm4w-jp8q.json new file mode 100644 index 00000000000..7c557e41d3b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jgcc-pm4w-jp8q/GHSA-jgcc-pm4w-jp8q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jgcc-pm4w-jp8q", + "modified": "2025-05-23T15:31:12Z", + "published": "2025-05-23T15:31:12Z", + "aliases": [ + "CVE-2025-46460" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Detheme Easy Guide allows SQL Injection. This issue affects Easy Guide: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46460" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-easy-guide/vulnerability/wordpress-easy-guide-1-0-0-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jgv5-6946-fjqx/GHSA-jgv5-6946-fjqx.json b/advisories/unreviewed/2025/05/GHSA-jgv5-6946-fjqx/GHSA-jgv5-6946-fjqx.json new file mode 100644 index 00000000000..60bada96851 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jgv5-6946-fjqx/GHSA-jgv5-6946-fjqx.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jgv5-6946-fjqx", + "modified": "2025-05-23T15:31:17Z", + "published": "2025-05-23T15:31:16Z", + "aliases": [ + "CVE-2024-48702" + ], + "details": "PHPGurukul Old Age Home Management System v1.0 is vulnerable to HTML Injection via the searchdata parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48702" + }, + { + "type": "WEB", + "url": "https://github.com/0xBhushan/Writeups/blob/main/CVE/phpGurukul/Medical%20Card%20Generation%20System/HTML%20Injection%28pagedes%29.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jp9f-x59g-67pq/GHSA-jp9f-x59g-67pq.json b/advisories/unreviewed/2025/05/GHSA-jp9f-x59g-67pq/GHSA-jp9f-x59g-67pq.json new file mode 100644 index 00000000000..9cf2fb5cd67 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jp9f-x59g-67pq/GHSA-jp9f-x59g-67pq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jp9f-x59g-67pq", + "modified": "2025-05-23T15:31:16Z", + "published": "2025-05-23T15:31:16Z", + "aliases": [ + "CVE-2025-48292" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in GoodLayers Tourmaster allows PHP Local File Inclusion. This issue affects Tourmaster: from n/a through 5.3.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48292" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/tourmaster/vulnerability/wordpress-tourmaster-plugin-5-3-8-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jv73-vqgv-2mch/GHSA-jv73-vqgv-2mch.json b/advisories/unreviewed/2025/05/GHSA-jv73-vqgv-2mch/GHSA-jv73-vqgv-2mch.json new file mode 100644 index 00000000000..700f9726ac4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jv73-vqgv-2mch/GHSA-jv73-vqgv-2mch.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jv73-vqgv-2mch", + "modified": "2025-05-23T15:31:10Z", + "published": "2025-05-23T15:31:10Z", + "aliases": [ + "CVE-2025-39499" + ], + "details": "Deserialization of Untrusted Data vulnerability in BoldThemes Medicare allows Object Injection. This issue affects Medicare: from n/a through 2.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39499" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/medicare/vulnerability/wordpress-medicare-theme-2-1-0-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-m4g8-47g2-j394/GHSA-m4g8-47g2-j394.json b/advisories/unreviewed/2025/05/GHSA-m4g8-47g2-j394/GHSA-m4g8-47g2-j394.json new file mode 100644 index 00000000000..47ac811d0fd --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-m4g8-47g2-j394/GHSA-m4g8-47g2-j394.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m4g8-47g2-j394", + "modified": "2025-05-23T15:31:16Z", + "published": "2025-05-23T15:31:16Z", + "aliases": [ + "CVE-2025-5109" + ], + "details": "A vulnerability classified as critical has been found in FreeFloat FTP Server 1.0. Affected is an unknown function of the component STATUS Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5109" + }, + { + "type": "WEB", + "url": "https://fitoxs.com/exploit/exploit-0420d1a7d4e6b45cf1f0b87c2d580c4df77281242d0e9d1b77d7e2fd08f3a41d.txt" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310086" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310086" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.581298" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-m537-88r7-p568/GHSA-m537-88r7-p568.json b/advisories/unreviewed/2025/05/GHSA-m537-88r7-p568/GHSA-m537-88r7-p568.json new file mode 100644 index 00000000000..3a8f3d28028 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-m537-88r7-p568/GHSA-m537-88r7-p568.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m537-88r7-p568", + "modified": "2025-05-23T15:31:17Z", + "published": "2025-05-23T15:31:17Z", + "aliases": [ + "CVE-2024-51360" + ], + "details": "An issue in Hospital Management System In PHP V4.0 allows a remote attacker to execute arbitrary code via the hms/doctor/edit-profile.php file", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51360" + }, + { + "type": "WEB", + "url": "https://github.com/Anil0x/CVE/blob/main/Session%20Hijacking.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-m6x2-v3jc-m2m7/GHSA-m6x2-v3jc-m2m7.json b/advisories/unreviewed/2025/05/GHSA-m6x2-v3jc-m2m7/GHSA-m6x2-v3jc-m2m7.json new file mode 100644 index 00000000000..13404e51f0d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-m6x2-v3jc-m2m7/GHSA-m6x2-v3jc-m2m7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m6x2-v3jc-m2m7", + "modified": "2025-05-23T15:31:14Z", + "published": "2025-05-23T15:31:14Z", + "aliases": [ + "CVE-2025-47613" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mojoomla School Management allows Reflected XSS. This issue affects School Management: from n/a through 92.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47613" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/school-management/vulnerability/wordpress-school-management-system-for-wordpress-plugin-92-0-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-m9vv-g4wc-gc4q/GHSA-m9vv-g4wc-gc4q.json b/advisories/unreviewed/2025/05/GHSA-m9vv-g4wc-gc4q/GHSA-m9vv-g4wc-gc4q.json new file mode 100644 index 00000000000..79b56b1752d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-m9vv-g4wc-gc4q/GHSA-m9vv-g4wc-gc4q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m9vv-g4wc-gc4q", + "modified": "2025-05-23T15:31:12Z", + "published": "2025-05-23T15:31:12Z", + "aliases": [ + "CVE-2025-46455" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in IndigoThemes WP HRM LITE allows SQL Injection. This issue affects WP HRM LITE: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46455" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-hrm-lite-human-resource-management-system/vulnerability/wordpress-wp-hrm-lite-1-1-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mchr-xvw2-q64f/GHSA-mchr-xvw2-q64f.json b/advisories/unreviewed/2025/05/GHSA-mchr-xvw2-q64f/GHSA-mchr-xvw2-q64f.json new file mode 100644 index 00000000000..b318397a8c9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mchr-xvw2-q64f/GHSA-mchr-xvw2-q64f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mchr-xvw2-q64f", + "modified": "2025-05-23T15:31:14Z", + "published": "2025-05-23T15:31:14Z", + "aliases": [ + "CVE-2025-47558" + ], + "details": "Missing Authorization vulnerability in RomanCode MapSVG allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects MapSVG: from n/a through 8.5.31.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47558" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mapsvg/vulnerability/wordpress-mapsvg-plugin-8-5-31-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mgj6-95h9-vg3g/GHSA-mgj6-95h9-vg3g.json b/advisories/unreviewed/2025/05/GHSA-mgj6-95h9-vg3g/GHSA-mgj6-95h9-vg3g.json index 984a9f70718..52be68cd6ef 100644 --- a/advisories/unreviewed/2025/05/GHSA-mgj6-95h9-vg3g/GHSA-mgj6-95h9-vg3g.json +++ b/advisories/unreviewed/2025/05/GHSA-mgj6-95h9-vg3g/GHSA-mgj6-95h9-vg3g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mgj6-95h9-vg3g", - "modified": "2025-05-22T21:30:47Z", + "modified": "2025-05-23T15:31:09Z", "published": "2025-05-22T21:30:47Z", "aliases": [ "CVE-2024-40459" ], "details": "An issue in Ocuco Innovation APPMANAGER.EXE v.2.10.24.51 allows a local attacker to escalate privileges via the application manager function", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-22T19:15:40Z" diff --git a/advisories/unreviewed/2025/05/GHSA-mjw8-4r4w-cj9r/GHSA-mjw8-4r4w-cj9r.json b/advisories/unreviewed/2025/05/GHSA-mjw8-4r4w-cj9r/GHSA-mjw8-4r4w-cj9r.json new file mode 100644 index 00000000000..4129b295f7f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mjw8-4r4w-cj9r/GHSA-mjw8-4r4w-cj9r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mjw8-4r4w-cj9r", + "modified": "2025-05-23T15:31:15Z", + "published": "2025-05-23T15:31:15Z", + "aliases": [ + "CVE-2025-47671" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LETSCMS MLM Software Binary MLM Plan allows SQL Injection. This issue affects Binary MLM Plan: from n/a through 3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47671" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/binary-mlm-plan/vulnerability/wordpress-binary-mlm-plan-3-0-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mpm6-wggf-97xv/GHSA-mpm6-wggf-97xv.json b/advisories/unreviewed/2025/05/GHSA-mpm6-wggf-97xv/GHSA-mpm6-wggf-97xv.json new file mode 100644 index 00000000000..030ff5ce039 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mpm6-wggf-97xv/GHSA-mpm6-wggf-97xv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mpm6-wggf-97xv", + "modified": "2025-05-23T15:31:09Z", + "published": "2025-05-23T15:31:09Z", + "aliases": [ + "CVE-2025-31632" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SpyroPress La Boom allows PHP Local File Inclusion. This issue affects La Boom: from n/a through 2.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31632" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/laboom/vulnerability/wordpress-la-boom-2-7-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mqcw-437p-q69q/GHSA-mqcw-437p-q69q.json b/advisories/unreviewed/2025/05/GHSA-mqcw-437p-q69q/GHSA-mqcw-437p-q69q.json new file mode 100644 index 00000000000..e1e27dfc67d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mqcw-437p-q69q/GHSA-mqcw-437p-q69q.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mqcw-437p-q69q", + "modified": "2025-05-23T15:31:09Z", + "published": "2025-05-23T15:31:09Z", + "aliases": [ + "CVE-2024-9163" + ], + "details": "A business logic error in GitLab CE/EE affecting all versions starting from 12.1 prior to 17.10.7, 17.11 prior to 17.11.3 and 18.0 prior to 18.0.1 where an attacker can cause a branch name confusion in confidential MRs.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9163" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2705566" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/493942" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-451" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mqvg-gc79-6rxx/GHSA-mqvg-gc79-6rxx.json b/advisories/unreviewed/2025/05/GHSA-mqvg-gc79-6rxx/GHSA-mqvg-gc79-6rxx.json new file mode 100644 index 00000000000..d4f1b7ec11f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mqvg-gc79-6rxx/GHSA-mqvg-gc79-6rxx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mqvg-gc79-6rxx", + "modified": "2025-05-23T15:31:14Z", + "published": "2025-05-23T15:31:14Z", + "aliases": [ + "CVE-2025-47631" + ], + "details": "Incorrect Privilege Assignment vulnerability in mojoomla Hospital Management System allows Privilege Escalation. This issue affects Hospital Management System: from 47.0(20 through 11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47631" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/hospital-management/vulnerability/wordpress-hospital-management-system-plugin-47-0-20-11-2023-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mvfc-pmj6-8j77/GHSA-mvfc-pmj6-8j77.json b/advisories/unreviewed/2025/05/GHSA-mvfc-pmj6-8j77/GHSA-mvfc-pmj6-8j77.json index afcfc48ceb4..f62c4791410 100644 --- a/advisories/unreviewed/2025/05/GHSA-mvfc-pmj6-8j77/GHSA-mvfc-pmj6-8j77.json +++ b/advisories/unreviewed/2025/05/GHSA-mvfc-pmj6-8j77/GHSA-mvfc-pmj6-8j77.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-p2p2-vfxx-r5rp/GHSA-p2p2-vfxx-r5rp.json b/advisories/unreviewed/2025/05/GHSA-p2p2-vfxx-r5rp/GHSA-p2p2-vfxx-r5rp.json new file mode 100644 index 00000000000..0eb4ef90919 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p2p2-vfxx-r5rp/GHSA-p2p2-vfxx-r5rp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p2p2-vfxx-r5rp", + "modified": "2025-05-23T15:31:15Z", + "published": "2025-05-23T15:31:15Z", + "aliases": [ + "CVE-2025-47658" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in ELEXtensions ELEX WordPress HelpDesk & Customer Ticketing System allows Upload a Web Shell to a Web Server. This issue affects ELEX WordPress HelpDesk & Customer Ticketing System: from n/a through 3.2.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47658" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/elex-helpdesk-customer-support-ticket-system/vulnerability/wordpress-elex-wordpress-helpdesk-customer-ticketing-system-3-2-7-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p39x-3wqr-ggff/GHSA-p39x-3wqr-ggff.json b/advisories/unreviewed/2025/05/GHSA-p39x-3wqr-ggff/GHSA-p39x-3wqr-ggff.json new file mode 100644 index 00000000000..cca8e03a351 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p39x-3wqr-ggff/GHSA-p39x-3wqr-ggff.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p39x-3wqr-ggff", + "modified": "2025-05-23T15:31:15Z", + "published": "2025-05-23T15:31:15Z", + "aliases": [ + "CVE-2025-47660" + ], + "details": "Deserialization of Untrusted Data vulnerability in Codexpert, Inc WC Affiliate allows Object Injection. This issue affects WC Affiliate: from n/a through 2.9.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47660" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wc-affiliate/vulnerability/wordpress-wc-affiliate-2-8-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p97h-v2qf-9878/GHSA-p97h-v2qf-9878.json b/advisories/unreviewed/2025/05/GHSA-p97h-v2qf-9878/GHSA-p97h-v2qf-9878.json new file mode 100644 index 00000000000..e45e6b661e0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p97h-v2qf-9878/GHSA-p97h-v2qf-9878.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p97h-v2qf-9878", + "modified": "2025-05-23T15:31:10Z", + "published": "2025-05-23T15:31:10Z", + "aliases": [ + "CVE-2025-39500" + ], + "details": "Deserialization of Untrusted Data vulnerability in GoodLayers Goodlayers Hostel allows Object Injection. This issue affects Goodlayers Hostel: from n/a through 3.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39500" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gdlr-hostel/vulnerability/wordpress-goodlayers-hostel-plugin-3-1-2-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p9wx-2529-fp83/GHSA-p9wx-2529-fp83.json b/advisories/unreviewed/2025/05/GHSA-p9wx-2529-fp83/GHSA-p9wx-2529-fp83.json new file mode 100644 index 00000000000..ece0717ac49 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p9wx-2529-fp83/GHSA-p9wx-2529-fp83.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p9wx-2529-fp83", + "modified": "2025-05-23T15:31:16Z", + "published": "2025-05-23T15:31:16Z", + "aliases": [ + "CVE-2018-25110" + ], + "details": "Marked prior to version 0.3.17 is vulnerable to a Regular Expression Denial of Service (ReDoS) attack due to catastrophic backtracking in several regular expressions used for parsing HTML tags and markdown links. An attacker can exploit this vulnerability by providing specially crafted markdown input, such as deeply nested or repetitively structured brackets or tag attributes, which cause the parser to hang and lead to a Denial of Service.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-25110" + }, + { + "type": "WEB", + "url": "https://github.com/markedjs/marked/issues/1070" + }, + { + "type": "WEB", + "url": "https://github.com/markedjs/marked/pull/1083" + }, + { + "type": "WEB", + "url": "https://github.com/markedjs/marked/commit/20bfc106013ed45713a21672ad4a34df94dcd485" + }, + { + "type": "WEB", + "url": "https://github.com/Checkmarx/Vulnerabilities-Proofs-of-Concept/tree/main/2018/CVE-2018-25110" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1333" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T15:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-pqgc-vw44-8qm5/GHSA-pqgc-vw44-8qm5.json b/advisories/unreviewed/2025/05/GHSA-pqgc-vw44-8qm5/GHSA-pqgc-vw44-8qm5.json new file mode 100644 index 00000000000..de59e1032f0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pqgc-vw44-8qm5/GHSA-pqgc-vw44-8qm5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pqgc-vw44-8qm5", + "modified": "2025-05-23T15:31:13Z", + "published": "2025-05-23T15:31:13Z", + "aliases": [ + "CVE-2025-47478" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid allows SQL Injection. This issue affects ProfileGrid : from n/a through 5.9.5.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47478" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/profilegrid-user-profiles-groups-and-communities/vulnerability/wordpress-profilegrid-5-9-5-0-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-pr3p-9qh5-qp2f/GHSA-pr3p-9qh5-qp2f.json b/advisories/unreviewed/2025/05/GHSA-pr3p-9qh5-qp2f/GHSA-pr3p-9qh5-qp2f.json new file mode 100644 index 00000000000..9e93c386be3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pr3p-9qh5-qp2f/GHSA-pr3p-9qh5-qp2f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pr3p-9qh5-qp2f", + "modified": "2025-05-23T15:31:10Z", + "published": "2025-05-23T15:31:10Z", + "aliases": [ + "CVE-2025-32292" + ], + "details": "Deserialization of Untrusted Data vulnerability in AncoraThemes Jarvis – Night Club, Concert, Festival WordPress allows Object Injection. This issue affects Jarvis – Night Club, Concert, Festival WordPress: from n/a through 1.8.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32292" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/jarvis/vulnerability/wordpress-jarvis-night-club-concert-festival-wordpress-1-8-11-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q52p-775j-hjv8/GHSA-q52p-775j-hjv8.json b/advisories/unreviewed/2025/05/GHSA-q52p-775j-hjv8/GHSA-q52p-775j-hjv8.json new file mode 100644 index 00000000000..18df95ce176 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q52p-775j-hjv8/GHSA-q52p-775j-hjv8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q52p-775j-hjv8", + "modified": "2025-05-23T15:31:13Z", + "published": "2025-05-23T15:31:13Z", + "aliases": [ + "CVE-2025-47461" + ], + "details": "Authentication Bypass Using an Alternate Path or Channel vulnerability in mediaticus Subaccounts for WooCommerce allows Authentication Abuse. This issue affects Subaccounts for WooCommerce: from n/a through 1.6.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47461" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/subaccounts-for-woocommerce/vulnerability/wordpress-subaccounts-for-woocommerce-plugin-1-6-6-account-takeover-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q749-5rmc-5pxm/GHSA-q749-5rmc-5pxm.json b/advisories/unreviewed/2025/05/GHSA-q749-5rmc-5pxm/GHSA-q749-5rmc-5pxm.json new file mode 100644 index 00000000000..93eb67c4251 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q749-5rmc-5pxm/GHSA-q749-5rmc-5pxm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q749-5rmc-5pxm", + "modified": "2025-05-23T15:31:14Z", + "published": "2025-05-23T15:31:14Z", + "aliases": [ + "CVE-2025-47535" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpopal Opal Woo Custom Product Variation allows Path Traversal. This issue affects Opal Woo Custom Product Variation: from n/a through 1.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47535" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/opal-woo-custom-product-variation/vulnerability/wordpress-opal-woo-custom-product-variation-1-2-0-arbitrary-file-deletion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qjr4-ppfx-2vc4/GHSA-qjr4-ppfx-2vc4.json b/advisories/unreviewed/2025/05/GHSA-qjr4-ppfx-2vc4/GHSA-qjr4-ppfx-2vc4.json new file mode 100644 index 00000000000..7399baf507d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qjr4-ppfx-2vc4/GHSA-qjr4-ppfx-2vc4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qjr4-ppfx-2vc4", + "modified": "2025-05-23T15:31:11Z", + "published": "2025-05-23T15:31:11Z", + "aliases": [ + "CVE-2025-46448" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in reifsnyderb Document Management System allows Reflected XSS. This issue affects Document Management System: from n/a through 1.24.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46448" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/dms/vulnerability/wordpress-document-management-system-1-24-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qw6m-wwcp-hjpw/GHSA-qw6m-wwcp-hjpw.json b/advisories/unreviewed/2025/05/GHSA-qw6m-wwcp-hjpw/GHSA-qw6m-wwcp-hjpw.json new file mode 100644 index 00000000000..103cfbf18f1 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qw6m-wwcp-hjpw/GHSA-qw6m-wwcp-hjpw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qw6m-wwcp-hjpw", + "modified": "2025-05-23T15:31:13Z", + "published": "2025-05-23T15:31:13Z", + "aliases": [ + "CVE-2025-47453" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Xylus Themes WP Smart Import allows PHP Local File Inclusion. This issue affects WP Smart Import: from n/a through 1.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47453" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-smart-import/vulnerability/wordpress-wp-smart-import-1-1-3-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qwmp-5m8m-pjvf/GHSA-qwmp-5m8m-pjvf.json b/advisories/unreviewed/2025/05/GHSA-qwmp-5m8m-pjvf/GHSA-qwmp-5m8m-pjvf.json new file mode 100644 index 00000000000..3687c794a76 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qwmp-5m8m-pjvf/GHSA-qwmp-5m8m-pjvf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qwmp-5m8m-pjvf", + "modified": "2025-05-23T15:31:14Z", + "published": "2025-05-23T15:31:14Z", + "aliases": [ + "CVE-2025-47541" + ], + "details": "Insertion of Sensitive Information Into Sent Data vulnerability in WPFunnels Mail Mint allows Retrieve Embedded Sensitive Data. This issue affects Mail Mint: from n/a through 1.17.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47541" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mail-mint/vulnerability/wordpress-mail-mint-1-17-7-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-201" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-r9pj-264x-c5c5/GHSA-r9pj-264x-c5c5.json b/advisories/unreviewed/2025/05/GHSA-r9pj-264x-c5c5/GHSA-r9pj-264x-c5c5.json new file mode 100644 index 00000000000..5d0f346d8b3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-r9pj-264x-c5c5/GHSA-r9pj-264x-c5c5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r9pj-264x-c5c5", + "modified": "2025-05-23T15:31:13Z", + "published": "2025-05-23T15:31:13Z", + "aliases": [ + "CVE-2025-46515" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M A Vinoth Kumar Category Widget allows Reflected XSS. This issue affects Category Widget: from n/a through 2.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46515" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/category-widget/vulnerability/wordpress-category-widget-plugin-2-0-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rhqf-r6rm-3j54/GHSA-rhqf-r6rm-3j54.json b/advisories/unreviewed/2025/05/GHSA-rhqf-r6rm-3j54/GHSA-rhqf-r6rm-3j54.json new file mode 100644 index 00000000000..76293520be6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rhqf-r6rm-3j54/GHSA-rhqf-r6rm-3j54.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rhqf-r6rm-3j54", + "modified": "2025-05-23T15:31:16Z", + "published": "2025-05-23T15:31:16Z", + "aliases": [ + "CVE-2025-48275" + ], + "details": "Missing Authorization vulnerability in dastan800 Visual Header allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Visual Header: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48275" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/visual-header/vulnerability/wordpress-visual-header-1-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rmxc-5894-fxhq/GHSA-rmxc-5894-fxhq.json b/advisories/unreviewed/2025/05/GHSA-rmxc-5894-fxhq/GHSA-rmxc-5894-fxhq.json new file mode 100644 index 00000000000..ed454f3516f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rmxc-5894-fxhq/GHSA-rmxc-5894-fxhq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rmxc-5894-fxhq", + "modified": "2025-05-23T15:31:12Z", + "published": "2025-05-23T15:31:12Z", + "aliases": [ + "CVE-2025-46493" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wordwebsoftware Crossword Compiler Puzzles allows Stored XSS. This issue affects Crossword Compiler Puzzles: from n/a through 5.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46493" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/crossword-compiler-puzzles/vulnerability/wordpress-crossword-compiler-puzzles-5-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rqwp-p4f7-h975/GHSA-rqwp-p4f7-h975.json b/advisories/unreviewed/2025/05/GHSA-rqwp-p4f7-h975/GHSA-rqwp-p4f7-h975.json new file mode 100644 index 00000000000..2274906ab1d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rqwp-p4f7-h975/GHSA-rqwp-p4f7-h975.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rqwp-p4f7-h975", + "modified": "2025-05-23T15:31:11Z", + "published": "2025-05-23T15:31:11Z", + "aliases": [ + "CVE-2025-46437" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tayoricom Tayori Form allows Reflected XSS. This issue affects Tayori Form: from n/a through 1.2.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46437" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/tayori/vulnerability/wordpress-tayori-form-plugin-1-2-9-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rvm6-q5vv-cfhx/GHSA-rvm6-q5vv-cfhx.json b/advisories/unreviewed/2025/05/GHSA-rvm6-q5vv-cfhx/GHSA-rvm6-q5vv-cfhx.json new file mode 100644 index 00000000000..3383054313b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rvm6-q5vv-cfhx/GHSA-rvm6-q5vv-cfhx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rvm6-q5vv-cfhx", + "modified": "2025-05-23T15:31:10Z", + "published": "2025-05-23T15:31:10Z", + "aliases": [ + "CVE-2025-39480" + ], + "details": "Deserialization of Untrusted Data vulnerability in ThemeMakers Car Dealer allows Object Injection. This issue affects Car Dealer: from n/a through 1.6.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39480" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/cardealer/vulnerability/wordpress-car-dealer-1-6-6-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v4pp-gcmm-cv95/GHSA-v4pp-gcmm-cv95.json b/advisories/unreviewed/2025/05/GHSA-v4pp-gcmm-cv95/GHSA-v4pp-gcmm-cv95.json new file mode 100644 index 00000000000..57c0ad609e9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v4pp-gcmm-cv95/GHSA-v4pp-gcmm-cv95.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v4pp-gcmm-cv95", + "modified": "2025-05-23T15:31:09Z", + "published": "2025-05-23T15:31:09Z", + "aliases": [ + "CVE-2025-31423" + ], + "details": "Deserialization of Untrusted Data vulnerability in AncoraThemes Umberto allows Object Injection. This issue affects Umberto: from n/a through 1.2.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31423" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/umberto/vulnerability/wordpress-umberto-1-2-8-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v5wj-4vcq-v5gw/GHSA-v5wj-4vcq-v5gw.json b/advisories/unreviewed/2025/05/GHSA-v5wj-4vcq-v5gw/GHSA-v5wj-4vcq-v5gw.json new file mode 100644 index 00000000000..4e963ed05eb --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v5wj-4vcq-v5gw/GHSA-v5wj-4vcq-v5gw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v5wj-4vcq-v5gw", + "modified": "2025-05-23T15:31:09Z", + "published": "2025-05-23T15:31:09Z", + "aliases": [ + "CVE-2025-31060" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme Capie allows PHP Local File Inclusion. This issue affects Capie: from n/a through 1.0.40.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31060" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/capie/vulnerability/wordpress-capie-1-0-40-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v6m7-qh5v-q2j5/GHSA-v6m7-qh5v-q2j5.json b/advisories/unreviewed/2025/05/GHSA-v6m7-qh5v-q2j5/GHSA-v6m7-qh5v-q2j5.json new file mode 100644 index 00000000000..6339f5ccc76 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v6m7-qh5v-q2j5/GHSA-v6m7-qh5v-q2j5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v6m7-qh5v-q2j5", + "modified": "2025-05-23T15:31:13Z", + "published": "2025-05-23T15:31:13Z", + "aliases": [ + "CVE-2025-47513" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in James Laforge Infocob CRM Forms allows Path Traversal. This issue affects Infocob CRM Forms: from n/a through 2.4.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47513" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/infocob-crm-forms/vulnerability/wordpress-infocob-crm-forms-plugin-2-4-0-arbitrary-file-download-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v7cm-mpcm-37f9/GHSA-v7cm-mpcm-37f9.json b/advisories/unreviewed/2025/05/GHSA-v7cm-mpcm-37f9/GHSA-v7cm-mpcm-37f9.json new file mode 100644 index 00000000000..86feda9f278 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v7cm-mpcm-37f9/GHSA-v7cm-mpcm-37f9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v7cm-mpcm-37f9", + "modified": "2025-05-23T15:31:09Z", + "published": "2025-05-23T15:31:09Z", + "aliases": [ + "CVE-2025-31430" + ], + "details": "Deserialization of Untrusted Data vulnerability in themeton The Business allows Object Injection. This issue affects The Business: from n/a through 1.6.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31430" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/nrgbusiness/vulnerability/wordpress-the-business-1-6-1-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v7m3-xg38-3qfq/GHSA-v7m3-xg38-3qfq.json b/advisories/unreviewed/2025/05/GHSA-v7m3-xg38-3qfq/GHSA-v7m3-xg38-3qfq.json new file mode 100644 index 00000000000..d19e17627e9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v7m3-xg38-3qfq/GHSA-v7m3-xg38-3qfq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v7m3-xg38-3qfq", + "modified": "2025-05-23T15:31:09Z", + "published": "2025-05-23T15:31:09Z", + "aliases": [ + "CVE-2025-31064" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Vizeon - Business Consulting allows PHP Local File Inclusion. This issue affects Vizeon - Business Consulting: from n/a through 1.1.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31064" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/vizeon/vulnerability/wordpress-vizeon-business-consulting-1-1-7-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v8q7-jm3p-3j3q/GHSA-v8q7-jm3p-3j3q.json b/advisories/unreviewed/2025/05/GHSA-v8q7-jm3p-3j3q/GHSA-v8q7-jm3p-3j3q.json new file mode 100644 index 00000000000..8cca7a4e16c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v8q7-jm3p-3j3q/GHSA-v8q7-jm3p-3j3q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v8q7-jm3p-3j3q", + "modified": "2025-05-23T15:31:10Z", + "published": "2025-05-23T15:31:10Z", + "aliases": [ + "CVE-2025-39501" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GoodLayers Goodlayers Hostel allows Blind SQL Injection. This issue affects Goodlayers Hostel: from n/a through 3.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39501" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gdlr-hostel/vulnerability/wordpress-goodlayers-hostel-plugin-3-1-2-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vcf3-77pf-w4hq/GHSA-vcf3-77pf-w4hq.json b/advisories/unreviewed/2025/05/GHSA-vcf3-77pf-w4hq/GHSA-vcf3-77pf-w4hq.json new file mode 100644 index 00000000000..714f5a347df --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vcf3-77pf-w4hq/GHSA-vcf3-77pf-w4hq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vcf3-77pf-w4hq", + "modified": "2025-05-23T15:31:10Z", + "published": "2025-05-23T15:31:10Z", + "aliases": [ + "CVE-2025-39490" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Backpack Traveler allows PHP Local File Inclusion. This issue affects Backpack Traveler: from n/a through 2.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39490" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/backpacktraveler/vulnerability/wordpress-backpack-traveler-2-7-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vphc-878c-44gv/GHSA-vphc-878c-44gv.json b/advisories/unreviewed/2025/05/GHSA-vphc-878c-44gv/GHSA-vphc-878c-44gv.json new file mode 100644 index 00000000000..e65ab5d64f4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vphc-878c-44gv/GHSA-vphc-878c-44gv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vphc-878c-44gv", + "modified": "2025-05-23T15:31:13Z", + "published": "2025-05-23T15:31:13Z", + "aliases": [ + "CVE-2025-47492" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in add-ons.org Drag and Drop File Upload for Elementor Forms allows Path Traversal. This issue affects Drag and Drop File Upload for Elementor Forms: from n/a through 1.4.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47492" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/drag-and-drop-file-upload-for-elementor-forms/vulnerability/wordpress-drag-and-drop-file-upload-for-elementor-forms-1-4-3-arbitrary-file-deletion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vrwv-78gw-c2wc/GHSA-vrwv-78gw-c2wc.json b/advisories/unreviewed/2025/05/GHSA-vrwv-78gw-c2wc/GHSA-vrwv-78gw-c2wc.json new file mode 100644 index 00000000000..ce6471cc05d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vrwv-78gw-c2wc/GHSA-vrwv-78gw-c2wc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vrwv-78gw-c2wc", + "modified": "2025-05-23T15:31:12Z", + "published": "2025-05-23T15:31:12Z", + "aliases": [ + "CVE-2025-46456" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jason Theme Blvd Sliders allows Reflected XSS. This issue affects Theme Blvd Sliders: from n/a through 1.2.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46456" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/theme-blvd-sliders/vulnerability/wordpress-theme-blvd-sliders-plugin-1-2-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w3mv-rjr4-wpcg/GHSA-w3mv-rjr4-wpcg.json b/advisories/unreviewed/2025/05/GHSA-w3mv-rjr4-wpcg/GHSA-w3mv-rjr4-wpcg.json new file mode 100644 index 00000000000..a62c3a6860c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w3mv-rjr4-wpcg/GHSA-w3mv-rjr4-wpcg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w3mv-rjr4-wpcg", + "modified": "2025-05-23T15:31:09Z", + "published": "2025-05-23T15:31:09Z", + "aliases": [ + "CVE-2025-31913" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme Ogami allows PHP Local File Inclusion. This issue affects Ogami: from n/a through 1.53.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31913" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/ogami/vulnerability/wordpress-ogami-1-53-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w4q4-qqj7-r6q8/GHSA-w4q4-qqj7-r6q8.json b/advisories/unreviewed/2025/05/GHSA-w4q4-qqj7-r6q8/GHSA-w4q4-qqj7-r6q8.json new file mode 100644 index 00000000000..c2d657b4d58 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w4q4-qqj7-r6q8/GHSA-w4q4-qqj7-r6q8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w4q4-qqj7-r6q8", + "modified": "2025-05-23T15:31:15Z", + "published": "2025-05-23T15:31:15Z", + "aliases": [ + "CVE-2025-48241" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Soft8Soft LLC Verge3D allows Reflected XSS. This issue affects Verge3D: from n/a through 4.9.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48241" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/verge3d/vulnerability/wordpress-verge3d-plugin-4-9-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wfv4-fr2r-9jgv/GHSA-wfv4-fr2r-9jgv.json b/advisories/unreviewed/2025/05/GHSA-wfv4-fr2r-9jgv/GHSA-wfv4-fr2r-9jgv.json new file mode 100644 index 00000000000..0ebd6694085 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wfv4-fr2r-9jgv/GHSA-wfv4-fr2r-9jgv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wfv4-fr2r-9jgv", + "modified": "2025-05-23T15:31:10Z", + "published": "2025-05-23T15:31:10Z", + "aliases": [ + "CVE-2025-32302" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Winnex allows PHP Local File Inclusion. This issue affects Winnex: from n/a through 1.3.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32302" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/winnex/vulnerability/wordpress-winnex-1-3-2-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wg2m-xw57-fqc9/GHSA-wg2m-xw57-fqc9.json b/advisories/unreviewed/2025/05/GHSA-wg2m-xw57-fqc9/GHSA-wg2m-xw57-fqc9.json index 618be0c0a44..b16e244d4c5 100644 --- a/advisories/unreviewed/2025/05/GHSA-wg2m-xw57-fqc9/GHSA-wg2m-xw57-fqc9.json +++ b/advisories/unreviewed/2025/05/GHSA-wg2m-xw57-fqc9/GHSA-wg2m-xw57-fqc9.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-wjqw-p7j2-5gx2/GHSA-wjqw-p7j2-5gx2.json b/advisories/unreviewed/2025/05/GHSA-wjqw-p7j2-5gx2/GHSA-wjqw-p7j2-5gx2.json new file mode 100644 index 00000000000..f5d26fea0e9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wjqw-p7j2-5gx2/GHSA-wjqw-p7j2-5gx2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wjqw-p7j2-5gx2", + "modified": "2025-05-23T15:31:11Z", + "published": "2025-05-23T15:31:11Z", + "aliases": [ + "CVE-2025-41379" + ], + "details": "The Intellian C700 web panel allows you to add firewall rules. Each of these rules has an associated ID, but there is a problem when adding a new rule, the ID used to create the database entry may be different from the JSON ID. If the rule needs to be deleted later, the system will use the JSON ID and therefore fail. This can be exploited by an attacker to create rules that cannot be deleted unless the device is reset to factory defaults.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-41379" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-intellian-technologies-iridium-certus" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wm4r-97wr-6vw2/GHSA-wm4r-97wr-6vw2.json b/advisories/unreviewed/2025/05/GHSA-wm4r-97wr-6vw2/GHSA-wm4r-97wr-6vw2.json new file mode 100644 index 00000000000..a49cc8857dd --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wm4r-97wr-6vw2/GHSA-wm4r-97wr-6vw2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wm4r-97wr-6vw2", + "modified": "2025-05-23T15:31:11Z", + "published": "2025-05-23T15:31:11Z", + "aliases": [ + "CVE-2025-46440" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mark kStats Reloaded allows Reflected XSS. This issue affects kStats Reloaded: from n/a through 0.7.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46440" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/kstats-reloaded/vulnerability/wordpress-kstats-reloaded-plugin-0-7-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wqj4-2vw3-c5jw/GHSA-wqj4-2vw3-c5jw.json b/advisories/unreviewed/2025/05/GHSA-wqj4-2vw3-c5jw/GHSA-wqj4-2vw3-c5jw.json new file mode 100644 index 00000000000..9c829bb3a14 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wqj4-2vw3-c5jw/GHSA-wqj4-2vw3-c5jw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wqj4-2vw3-c5jw", + "modified": "2025-05-23T15:31:14Z", + "published": "2025-05-23T15:31:14Z", + "aliases": [ + "CVE-2025-47539" + ], + "details": "Incorrect Privilege Assignment vulnerability in Themewinter Eventin allows Privilege Escalation. This issue affects Eventin: from n/a through 4.0.26.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47539" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-event-solution/vulnerability/wordpress-eventin-4-0-26-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wqrq-vwwp-qpvv/GHSA-wqrq-vwwp-qpvv.json b/advisories/unreviewed/2025/05/GHSA-wqrq-vwwp-qpvv/GHSA-wqrq-vwwp-qpvv.json index 7c5f1a97b50..50878379211 100644 --- a/advisories/unreviewed/2025/05/GHSA-wqrq-vwwp-qpvv/GHSA-wqrq-vwwp-qpvv.json +++ b/advisories/unreviewed/2025/05/GHSA-wqrq-vwwp-qpvv/GHSA-wqrq-vwwp-qpvv.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-wx7w-g52q-jg5g/GHSA-wx7w-g52q-jg5g.json b/advisories/unreviewed/2025/05/GHSA-wx7w-g52q-jg5g/GHSA-wx7w-g52q-jg5g.json new file mode 100644 index 00000000000..a6a80ff2f1d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wx7w-g52q-jg5g/GHSA-wx7w-g52q-jg5g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wx7w-g52q-jg5g", + "modified": "2025-05-23T15:31:12Z", + "published": "2025-05-23T15:31:12Z", + "aliases": [ + "CVE-2025-46488" + ], + "details": "Missing Authorization vulnerability in dastan800 Visual Builder allows Reflected XSS. This issue affects Visual Builder: from n/a through 1.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46488" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/visual-builder/vulnerability/wordpress-visual-builder-plugin-1-2-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T13:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-x6xg-9w9q-643p/GHSA-x6xg-9w9q-643p.json b/advisories/unreviewed/2025/05/GHSA-x6xg-9w9q-643p/GHSA-x6xg-9w9q-643p.json new file mode 100644 index 00000000000..e64574e065b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-x6xg-9w9q-643p/GHSA-x6xg-9w9q-643p.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x6xg-9w9q-643p", + "modified": "2025-05-23T15:31:17Z", + "published": "2025-05-23T15:31:17Z", + "aliases": [ + "CVE-2024-51108" + ], + "details": "Multiple stored cross-site scripting (XSS) vulnerabilities in the component /admin/card-bwdates-report.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the fromdate and todate parameters.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51108" + }, + { + "type": "WEB", + "url": "https://github.com/0xBhushan/Writeups/blob/main/CVE/phpGurukul/Medical%20Card%20Generation%20System/Stored%20XSS-Between%20Dates%20Reports.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xgcx-978m-c62h/GHSA-xgcx-978m-c62h.json b/advisories/unreviewed/2025/05/GHSA-xgcx-978m-c62h/GHSA-xgcx-978m-c62h.json new file mode 100644 index 00000000000..6586a73d59f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xgcx-978m-c62h/GHSA-xgcx-978m-c62h.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xgcx-978m-c62h", + "modified": "2025-05-23T15:31:17Z", + "published": "2025-05-23T15:31:17Z", + "aliases": [ + "CVE-2024-51107" + ], + "details": "Multiple stored cross-site scripting (XSS) vulnerabilities in the component /mcgs/admin/contactus.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the pagetitle, pagedes, and email parameters.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51107" + }, + { + "type": "WEB", + "url": "https://github.com/0xBhushan/Writeups/blob/main/CVE/phpGurukul/Medical%20Card%20Generation%20System/Stored%20XSS-Contact%20Us.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xp23-94cq-8m5g/GHSA-xp23-94cq-8m5g.json b/advisories/unreviewed/2025/05/GHSA-xp23-94cq-8m5g/GHSA-xp23-94cq-8m5g.json new file mode 100644 index 00000000000..bdfc1ccaa01 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xp23-94cq-8m5g/GHSA-xp23-94cq-8m5g.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xp23-94cq-8m5g", + "modified": "2025-05-23T15:31:16Z", + "published": "2025-05-23T15:31:16Z", + "aliases": [ + "CVE-2022-31812" + ], + "details": "A vulnerability has been identified in SiPass integrated (All versions < V2.95.3.18). Affected server applications contain an out of bounds read past the end of an allocated buffer while checking the integrity of incoming packets. This could allow an unauthenticated remote attacker to create a denial of service condition.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-31812" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-041082.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-23T15:15:21Z" + } +} \ No newline at end of file