From a2e53e3c7e0b72087efcf1bd032ecc511950a056 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 10 Jun 2025 18:33:34 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-mxjq-xrv7-m36q.json | 2 +- .../GHSA-rp98-9vmx-835h.json | 2 +- .../GHSA-5vgq-r8m3-f582.json | 4 +- .../GHSA-f25c-wxgv-xhrw.json | 4 +- .../GHSA-f44w-q987-x489.json | 4 +- .../GHSA-jmmr-w66h-7p5r.json | 4 +- .../GHSA-rpvm-69vv-cpww.json | 4 +- .../GHSA-fgw8-wccj-749x.json | 4 +- .../GHSA-wpmj-mx2h-xgfx.json | 2 +- .../GHSA-x7x2-6gw9-jg8m.json | 2 +- .../GHSA-mjcq-3whq-7xjh.json | 6 +- .../GHSA-p986-xv2x-2cjm.json | 6 +- .../GHSA-q7v7-jhxh-rv68.json | 6 +- .../GHSA-qpcv-fjxx-24cv.json | 6 +- .../GHSA-26qv-p8cr-jxp5.json | 36 +++++++++++ .../GHSA-2972-gp35-c62r.json | 37 ++++++++++++ .../GHSA-2977-5php-6789.json | 33 ++++++++++ .../GHSA-29gg-qvj7-46c7.json | 36 +++++++++++ .../GHSA-2qpr-jh9p-xf8p.json | 36 +++++++++++ .../GHSA-2rm9-pcmr-fvfj.json | 36 +++++++++++ .../GHSA-2xg5-8frj-h6pm.json | 33 ++++++++++ .../GHSA-3388-v38c-c9p8.json | 36 +++++++++++ .../GHSA-33m4-3j2c-23xq.json | 36 +++++++++++ .../GHSA-3429-h97r-hqqx.json | 11 +++- .../GHSA-36wp-r9w6-8qw8.json | 36 +++++++++++ .../GHSA-37rv-hxgg-9qvj.json | 36 +++++++++++ .../GHSA-39rr-qw8q-xwq8.json | 36 +++++++++++ .../GHSA-3c9c-9w7c-4f9j.json | 33 ++++++++++ .../GHSA-3fxc-2crv-fg9x.json | 33 ++++++++++ .../GHSA-3hvp-qhfg-j3vj.json | 11 +++- .../GHSA-3pw3-xj49-rf2v.json | 36 +++++++++++ .../GHSA-3qr8-pm5h-36f2.json | 36 +++++++++++ .../GHSA-3vh9-fqgx-vjph.json | 36 +++++++++++ .../GHSA-3vr5-764g-c3pw.json | 36 +++++++++++ .../GHSA-4478-2hcg-975m.json | 40 +++++++++++++ .../GHSA-47gg-69h8-fx9p.json | 36 +++++++++++ .../GHSA-4f6r-97c9-vqq2.json | 36 +++++++++++ .../GHSA-4fhp-55v2-x26m.json | 40 +++++++++++++ .../GHSA-4mqg-7w7j-8x9r.json | 36 +++++++++++ .../GHSA-4qxh-75jf-785r.json | 36 +++++++++++ .../GHSA-4xxv-xhhw-92fw.json | 36 +++++++++++ .../GHSA-5g9w-3gm4-chjj.json | 36 +++++++++++ .../GHSA-5hq7-95mx-pcjq.json | 40 +++++++++++++ .../GHSA-5mq4-g7c8-jh32.json | 36 +++++++++++ .../GHSA-5mw4-49p3-cwrw.json | 36 +++++++++++ .../GHSA-5w9f-hfhx-jg4h.json | 36 +++++++++++ .../GHSA-5xp9-26pv-gh7v.json | 36 +++++++++++ .../GHSA-638c-8f6r-29v5.json | 36 +++++++++++ .../GHSA-662v-v5hp-qhxj.json | 36 +++++++++++ .../GHSA-69hm-8j4h-xgr9.json | 60 +++++++++++++++++++ .../GHSA-6gj9-8hxg-8qqp.json | 36 +++++++++++ .../GHSA-6rqm-284m-8hjf.json | 36 +++++++++++ .../GHSA-6v8f-m582-f3gv.json | 36 +++++++++++ .../GHSA-6w39-p77c-pmpq.json | 60 +++++++++++++++++++ .../GHSA-6wvr-wrjw-5g3c.json | 11 +++- .../GHSA-6xmj-596p-g7g7.json | 36 +++++++++++ .../GHSA-7952-5h7p-gw4m.json | 36 +++++++++++ .../GHSA-796j-mc2v-jwpj.json | 11 +++- .../GHSA-7g9m-wm2f-95fg.json | 37 ++++++++++++ .../GHSA-7p8p-77rq-jh4w.json | 36 +++++++++++ .../GHSA-7px7-38p7-4p29.json | 36 +++++++++++ .../GHSA-7rc6-r844-3mww.json | 36 +++++++++++ .../GHSA-7rhv-xm4q-wh42.json | 33 ++++++++++ .../GHSA-7v3j-qcv2-4wc4.json | 36 +++++++++++ .../GHSA-7xv5-2vc8-mjgv.json | 36 +++++++++++ .../GHSA-82vq-mq3h-xx6f.json | 2 +- .../GHSA-8375-2vj2-7p5f.json | 36 +++++++++++ .../GHSA-863r-cfhv-7rmg.json | 40 +++++++++++++ .../GHSA-872c-cmq4-p7wq.json | 36 +++++++++++ .../GHSA-87xg-g898-rh5q.json | 36 +++++++++++ .../GHSA-8gqq-cqfg-7f8m.json | 36 +++++++++++ .../GHSA-8pqc-m8ff-xf67.json | 36 +++++++++++ .../GHSA-8rxv-vgf4-465c.json | 40 +++++++++++++ .../GHSA-95wq-9rmf-rwff.json | 36 +++++++++++ .../GHSA-9h68-3v3c-5fmj.json | 36 +++++++++++ .../GHSA-9h9j-567f-gg4h.json | 36 +++++++++++ .../GHSA-9qp5-76v7-3g7w.json | 36 +++++++++++ .../GHSA-9qr2-qm38-64g4.json | 36 +++++++++++ .../GHSA-9vpr-8qr7-4pg3.json | 6 +- .../GHSA-9xq9-jfj9-8mqm.json | 37 ++++++++++++ .../GHSA-c4r7-vqgv-hxrw.json | 36 +++++++++++ .../GHSA-c5jx-h8px-jrgh.json | 36 +++++++++++ .../GHSA-cfjg-2jr6-cgph.json | 36 +++++++++++ .../GHSA-f9xh-499r-w9qx.json | 11 +++- .../GHSA-ffgw-jrq3-grx9.json | 36 +++++++++++ .../GHSA-fgf2-43wx-4mv7.json | 36 +++++++++++ .../GHSA-fj2f-gvvm-wc28.json | 36 +++++++++++ .../GHSA-fx7x-v68g-vhq5.json | 36 +++++++++++ .../GHSA-g2pj-xmxq-3r9q.json | 36 +++++++++++ .../GHSA-g682-7gqf-wrjp.json | 36 +++++++++++ .../GHSA-ggm3-fwfv-cfp9.json | 36 +++++++++++ .../GHSA-gjgx-8hwj-f6gq.json | 36 +++++++++++ .../GHSA-gq6p-h9r9-9hcw.json | 56 +++++++++++++++++ .../GHSA-h6c8-xhhw-v4mw.json | 36 +++++++++++ .../GHSA-hcp3-9rg5-2f9p.json | 36 +++++++++++ .../GHSA-hm9j-wvvg-pwv5.json | 36 +++++++++++ .../GHSA-hrvw-6x9w-9pw3.json | 36 +++++++++++ .../GHSA-hxxf-pxh8-jxxh.json | 36 +++++++++++ .../GHSA-j4v3-52c8-2m66.json | 36 +++++++++++ .../GHSA-j8f6-cp2r-rhv6.json | 36 +++++++++++ .../GHSA-j934-vjh5-vf9r.json | 36 +++++++++++ .../GHSA-jh64-9f55-5hrx.json | 36 +++++++++++ .../GHSA-jvcx-4h9f-wx33.json | 36 +++++++++++ .../GHSA-jvmq-cr7f-mvjw.json | 36 +++++++++++ .../GHSA-m9m6-qv46-g5mf.json | 36 +++++++++++ .../GHSA-m9pg-v9j9-9qr5.json | 36 +++++++++++ .../GHSA-mp2w-h9wf-5497.json | 36 +++++++++++ .../GHSA-mq97-x574-83g4.json | 36 +++++++++++ .../GHSA-mxm2-mfw2-4435.json | 36 +++++++++++ .../GHSA-p844-6jfp-89rq.json | 36 +++++++++++ .../GHSA-p8ff-4rqf-9m2x.json | 36 +++++++++++ .../GHSA-pc2h-32rh-xhfp.json | 36 +++++++++++ .../GHSA-pf5j-488q-mf84.json | 36 +++++++++++ .../GHSA-pgmv-r49r-93pq.json | 36 +++++++++++ .../GHSA-pp47-c46r-hhxq.json | 36 +++++++++++ .../GHSA-q57w-gqgq-cx44.json | 36 +++++++++++ .../GHSA-q5qw-7fqr-83mr.json | 36 +++++++++++ .../GHSA-q6xx-gv82-hc4m.json | 36 +++++++++++ .../GHSA-q86x-v28r-5px8.json | 36 +++++++++++ .../GHSA-qcp9-xrh4-rcw2.json | 36 +++++++++++ .../GHSA-qfp6-39x3-xvfc.json | 15 +++-- .../GHSA-qr4w-3pf4-j7r3.json | 36 +++++++++++ .../GHSA-qrmg-6fh3-mgv2.json | 36 +++++++++++ .../GHSA-qvxq-cwr5-42fq.json | 36 +++++++++++ .../GHSA-r2j8-539m-45q5.json | 36 +++++++++++ .../GHSA-r487-9vv5-75gg.json | 36 +++++++++++ .../GHSA-r68q-hvfv-hjmc.json | 36 +++++++++++ .../GHSA-rh2j-rr9g-4x8v.json | 36 +++++++++++ .../GHSA-rm75-x9p3-8pwv.json | 40 +++++++++++++ .../GHSA-rq5m-6c4v-55rj.json | 36 +++++++++++ .../GHSA-rq9r-qvwg-829q.json | 33 ++++++++++ .../GHSA-rv7r-h58x-hgr3.json | 36 +++++++++++ .../GHSA-v3q5-6pw5-p5vj.json | 36 +++++++++++ .../GHSA-v4cq-8jgx-x3gq.json | 36 +++++++++++ .../GHSA-v528-vhc9-x7fv.json | 36 +++++++++++ .../GHSA-v89x-hh3f-24gf.json | 36 +++++++++++ .../GHSA-vjfq-34vr-xpmm.json | 36 +++++++++++ .../GHSA-vm3p-hcg2-mr89.json | 36 +++++++++++ .../GHSA-vv73-f4gc-gghx.json | 40 +++++++++++++ .../GHSA-vvqg-cgqr-c8gc.json | 36 +++++++++++ .../GHSA-w4gj-hg5c-7gfx.json | 36 +++++++++++ .../GHSA-w4jq-2vxf-ppgg.json | 36 +++++++++++ .../GHSA-w6vw-7jjr-cmhh.json | 36 +++++++++++ .../GHSA-w7fw-3vx9-4jr9.json | 36 +++++++++++ .../GHSA-w8fx-6j6j-879c.json | 36 +++++++++++ .../GHSA-x74g-wm25-p2p5.json | 36 +++++++++++ .../GHSA-x7v7-vjcv-xqj4.json | 36 +++++++++++ .../GHSA-xqjp-6x3w-8653.json | 36 +++++++++++ 148 files changed, 4715 insertions(+), 36 deletions(-) create mode 100644 advisories/unreviewed/2025/06/GHSA-26qv-p8cr-jxp5/GHSA-26qv-p8cr-jxp5.json create mode 100644 advisories/unreviewed/2025/06/GHSA-2972-gp35-c62r/GHSA-2972-gp35-c62r.json create mode 100644 advisories/unreviewed/2025/06/GHSA-2977-5php-6789/GHSA-2977-5php-6789.json create mode 100644 advisories/unreviewed/2025/06/GHSA-29gg-qvj7-46c7/GHSA-29gg-qvj7-46c7.json create mode 100644 advisories/unreviewed/2025/06/GHSA-2qpr-jh9p-xf8p/GHSA-2qpr-jh9p-xf8p.json create mode 100644 advisories/unreviewed/2025/06/GHSA-2rm9-pcmr-fvfj/GHSA-2rm9-pcmr-fvfj.json create mode 100644 advisories/unreviewed/2025/06/GHSA-2xg5-8frj-h6pm/GHSA-2xg5-8frj-h6pm.json create mode 100644 advisories/unreviewed/2025/06/GHSA-3388-v38c-c9p8/GHSA-3388-v38c-c9p8.json create mode 100644 advisories/unreviewed/2025/06/GHSA-33m4-3j2c-23xq/GHSA-33m4-3j2c-23xq.json create mode 100644 advisories/unreviewed/2025/06/GHSA-36wp-r9w6-8qw8/GHSA-36wp-r9w6-8qw8.json create mode 100644 advisories/unreviewed/2025/06/GHSA-37rv-hxgg-9qvj/GHSA-37rv-hxgg-9qvj.json create mode 100644 advisories/unreviewed/2025/06/GHSA-39rr-qw8q-xwq8/GHSA-39rr-qw8q-xwq8.json create mode 100644 advisories/unreviewed/2025/06/GHSA-3c9c-9w7c-4f9j/GHSA-3c9c-9w7c-4f9j.json create mode 100644 advisories/unreviewed/2025/06/GHSA-3fxc-2crv-fg9x/GHSA-3fxc-2crv-fg9x.json create mode 100644 advisories/unreviewed/2025/06/GHSA-3pw3-xj49-rf2v/GHSA-3pw3-xj49-rf2v.json create mode 100644 advisories/unreviewed/2025/06/GHSA-3qr8-pm5h-36f2/GHSA-3qr8-pm5h-36f2.json create mode 100644 advisories/unreviewed/2025/06/GHSA-3vh9-fqgx-vjph/GHSA-3vh9-fqgx-vjph.json create mode 100644 advisories/unreviewed/2025/06/GHSA-3vr5-764g-c3pw/GHSA-3vr5-764g-c3pw.json create mode 100644 advisories/unreviewed/2025/06/GHSA-4478-2hcg-975m/GHSA-4478-2hcg-975m.json create mode 100644 advisories/unreviewed/2025/06/GHSA-47gg-69h8-fx9p/GHSA-47gg-69h8-fx9p.json create mode 100644 advisories/unreviewed/2025/06/GHSA-4f6r-97c9-vqq2/GHSA-4f6r-97c9-vqq2.json create mode 100644 advisories/unreviewed/2025/06/GHSA-4fhp-55v2-x26m/GHSA-4fhp-55v2-x26m.json create mode 100644 advisories/unreviewed/2025/06/GHSA-4mqg-7w7j-8x9r/GHSA-4mqg-7w7j-8x9r.json create mode 100644 advisories/unreviewed/2025/06/GHSA-4qxh-75jf-785r/GHSA-4qxh-75jf-785r.json create mode 100644 advisories/unreviewed/2025/06/GHSA-4xxv-xhhw-92fw/GHSA-4xxv-xhhw-92fw.json create mode 100644 advisories/unreviewed/2025/06/GHSA-5g9w-3gm4-chjj/GHSA-5g9w-3gm4-chjj.json create mode 100644 advisories/unreviewed/2025/06/GHSA-5hq7-95mx-pcjq/GHSA-5hq7-95mx-pcjq.json create mode 100644 advisories/unreviewed/2025/06/GHSA-5mq4-g7c8-jh32/GHSA-5mq4-g7c8-jh32.json create mode 100644 advisories/unreviewed/2025/06/GHSA-5mw4-49p3-cwrw/GHSA-5mw4-49p3-cwrw.json create mode 100644 advisories/unreviewed/2025/06/GHSA-5w9f-hfhx-jg4h/GHSA-5w9f-hfhx-jg4h.json create mode 100644 advisories/unreviewed/2025/06/GHSA-5xp9-26pv-gh7v/GHSA-5xp9-26pv-gh7v.json create mode 100644 advisories/unreviewed/2025/06/GHSA-638c-8f6r-29v5/GHSA-638c-8f6r-29v5.json create mode 100644 advisories/unreviewed/2025/06/GHSA-662v-v5hp-qhxj/GHSA-662v-v5hp-qhxj.json create mode 100644 advisories/unreviewed/2025/06/GHSA-69hm-8j4h-xgr9/GHSA-69hm-8j4h-xgr9.json create mode 100644 advisories/unreviewed/2025/06/GHSA-6gj9-8hxg-8qqp/GHSA-6gj9-8hxg-8qqp.json create mode 100644 advisories/unreviewed/2025/06/GHSA-6rqm-284m-8hjf/GHSA-6rqm-284m-8hjf.json create mode 100644 advisories/unreviewed/2025/06/GHSA-6v8f-m582-f3gv/GHSA-6v8f-m582-f3gv.json create mode 100644 advisories/unreviewed/2025/06/GHSA-6w39-p77c-pmpq/GHSA-6w39-p77c-pmpq.json create mode 100644 advisories/unreviewed/2025/06/GHSA-6xmj-596p-g7g7/GHSA-6xmj-596p-g7g7.json create mode 100644 advisories/unreviewed/2025/06/GHSA-7952-5h7p-gw4m/GHSA-7952-5h7p-gw4m.json create mode 100644 advisories/unreviewed/2025/06/GHSA-7g9m-wm2f-95fg/GHSA-7g9m-wm2f-95fg.json create mode 100644 advisories/unreviewed/2025/06/GHSA-7p8p-77rq-jh4w/GHSA-7p8p-77rq-jh4w.json create mode 100644 advisories/unreviewed/2025/06/GHSA-7px7-38p7-4p29/GHSA-7px7-38p7-4p29.json create mode 100644 advisories/unreviewed/2025/06/GHSA-7rc6-r844-3mww/GHSA-7rc6-r844-3mww.json create mode 100644 advisories/unreviewed/2025/06/GHSA-7rhv-xm4q-wh42/GHSA-7rhv-xm4q-wh42.json create mode 100644 advisories/unreviewed/2025/06/GHSA-7v3j-qcv2-4wc4/GHSA-7v3j-qcv2-4wc4.json create mode 100644 advisories/unreviewed/2025/06/GHSA-7xv5-2vc8-mjgv/GHSA-7xv5-2vc8-mjgv.json create mode 100644 advisories/unreviewed/2025/06/GHSA-8375-2vj2-7p5f/GHSA-8375-2vj2-7p5f.json create mode 100644 advisories/unreviewed/2025/06/GHSA-863r-cfhv-7rmg/GHSA-863r-cfhv-7rmg.json create mode 100644 advisories/unreviewed/2025/06/GHSA-872c-cmq4-p7wq/GHSA-872c-cmq4-p7wq.json create mode 100644 advisories/unreviewed/2025/06/GHSA-87xg-g898-rh5q/GHSA-87xg-g898-rh5q.json create mode 100644 advisories/unreviewed/2025/06/GHSA-8gqq-cqfg-7f8m/GHSA-8gqq-cqfg-7f8m.json create mode 100644 advisories/unreviewed/2025/06/GHSA-8pqc-m8ff-xf67/GHSA-8pqc-m8ff-xf67.json create mode 100644 advisories/unreviewed/2025/06/GHSA-8rxv-vgf4-465c/GHSA-8rxv-vgf4-465c.json create mode 100644 advisories/unreviewed/2025/06/GHSA-95wq-9rmf-rwff/GHSA-95wq-9rmf-rwff.json create mode 100644 advisories/unreviewed/2025/06/GHSA-9h68-3v3c-5fmj/GHSA-9h68-3v3c-5fmj.json create mode 100644 advisories/unreviewed/2025/06/GHSA-9h9j-567f-gg4h/GHSA-9h9j-567f-gg4h.json create mode 100644 advisories/unreviewed/2025/06/GHSA-9qp5-76v7-3g7w/GHSA-9qp5-76v7-3g7w.json create mode 100644 advisories/unreviewed/2025/06/GHSA-9qr2-qm38-64g4/GHSA-9qr2-qm38-64g4.json create mode 100644 advisories/unreviewed/2025/06/GHSA-9xq9-jfj9-8mqm/GHSA-9xq9-jfj9-8mqm.json create mode 100644 advisories/unreviewed/2025/06/GHSA-c4r7-vqgv-hxrw/GHSA-c4r7-vqgv-hxrw.json create mode 100644 advisories/unreviewed/2025/06/GHSA-c5jx-h8px-jrgh/GHSA-c5jx-h8px-jrgh.json create mode 100644 advisories/unreviewed/2025/06/GHSA-cfjg-2jr6-cgph/GHSA-cfjg-2jr6-cgph.json create mode 100644 advisories/unreviewed/2025/06/GHSA-ffgw-jrq3-grx9/GHSA-ffgw-jrq3-grx9.json create mode 100644 advisories/unreviewed/2025/06/GHSA-fgf2-43wx-4mv7/GHSA-fgf2-43wx-4mv7.json create mode 100644 advisories/unreviewed/2025/06/GHSA-fj2f-gvvm-wc28/GHSA-fj2f-gvvm-wc28.json create mode 100644 advisories/unreviewed/2025/06/GHSA-fx7x-v68g-vhq5/GHSA-fx7x-v68g-vhq5.json create mode 100644 advisories/unreviewed/2025/06/GHSA-g2pj-xmxq-3r9q/GHSA-g2pj-xmxq-3r9q.json create mode 100644 advisories/unreviewed/2025/06/GHSA-g682-7gqf-wrjp/GHSA-g682-7gqf-wrjp.json create mode 100644 advisories/unreviewed/2025/06/GHSA-ggm3-fwfv-cfp9/GHSA-ggm3-fwfv-cfp9.json create mode 100644 advisories/unreviewed/2025/06/GHSA-gjgx-8hwj-f6gq/GHSA-gjgx-8hwj-f6gq.json create mode 100644 advisories/unreviewed/2025/06/GHSA-gq6p-h9r9-9hcw/GHSA-gq6p-h9r9-9hcw.json create mode 100644 advisories/unreviewed/2025/06/GHSA-h6c8-xhhw-v4mw/GHSA-h6c8-xhhw-v4mw.json create mode 100644 advisories/unreviewed/2025/06/GHSA-hcp3-9rg5-2f9p/GHSA-hcp3-9rg5-2f9p.json create mode 100644 advisories/unreviewed/2025/06/GHSA-hm9j-wvvg-pwv5/GHSA-hm9j-wvvg-pwv5.json create mode 100644 advisories/unreviewed/2025/06/GHSA-hrvw-6x9w-9pw3/GHSA-hrvw-6x9w-9pw3.json create mode 100644 advisories/unreviewed/2025/06/GHSA-hxxf-pxh8-jxxh/GHSA-hxxf-pxh8-jxxh.json create mode 100644 advisories/unreviewed/2025/06/GHSA-j4v3-52c8-2m66/GHSA-j4v3-52c8-2m66.json create mode 100644 advisories/unreviewed/2025/06/GHSA-j8f6-cp2r-rhv6/GHSA-j8f6-cp2r-rhv6.json create mode 100644 advisories/unreviewed/2025/06/GHSA-j934-vjh5-vf9r/GHSA-j934-vjh5-vf9r.json create mode 100644 advisories/unreviewed/2025/06/GHSA-jh64-9f55-5hrx/GHSA-jh64-9f55-5hrx.json create mode 100644 advisories/unreviewed/2025/06/GHSA-jvcx-4h9f-wx33/GHSA-jvcx-4h9f-wx33.json create mode 100644 advisories/unreviewed/2025/06/GHSA-jvmq-cr7f-mvjw/GHSA-jvmq-cr7f-mvjw.json create mode 100644 advisories/unreviewed/2025/06/GHSA-m9m6-qv46-g5mf/GHSA-m9m6-qv46-g5mf.json create mode 100644 advisories/unreviewed/2025/06/GHSA-m9pg-v9j9-9qr5/GHSA-m9pg-v9j9-9qr5.json create mode 100644 advisories/unreviewed/2025/06/GHSA-mp2w-h9wf-5497/GHSA-mp2w-h9wf-5497.json create mode 100644 advisories/unreviewed/2025/06/GHSA-mq97-x574-83g4/GHSA-mq97-x574-83g4.json create mode 100644 advisories/unreviewed/2025/06/GHSA-mxm2-mfw2-4435/GHSA-mxm2-mfw2-4435.json create mode 100644 advisories/unreviewed/2025/06/GHSA-p844-6jfp-89rq/GHSA-p844-6jfp-89rq.json create mode 100644 advisories/unreviewed/2025/06/GHSA-p8ff-4rqf-9m2x/GHSA-p8ff-4rqf-9m2x.json create mode 100644 advisories/unreviewed/2025/06/GHSA-pc2h-32rh-xhfp/GHSA-pc2h-32rh-xhfp.json create mode 100644 advisories/unreviewed/2025/06/GHSA-pf5j-488q-mf84/GHSA-pf5j-488q-mf84.json create mode 100644 advisories/unreviewed/2025/06/GHSA-pgmv-r49r-93pq/GHSA-pgmv-r49r-93pq.json create mode 100644 advisories/unreviewed/2025/06/GHSA-pp47-c46r-hhxq/GHSA-pp47-c46r-hhxq.json create mode 100644 advisories/unreviewed/2025/06/GHSA-q57w-gqgq-cx44/GHSA-q57w-gqgq-cx44.json create mode 100644 advisories/unreviewed/2025/06/GHSA-q5qw-7fqr-83mr/GHSA-q5qw-7fqr-83mr.json create mode 100644 advisories/unreviewed/2025/06/GHSA-q6xx-gv82-hc4m/GHSA-q6xx-gv82-hc4m.json create mode 100644 advisories/unreviewed/2025/06/GHSA-q86x-v28r-5px8/GHSA-q86x-v28r-5px8.json create mode 100644 advisories/unreviewed/2025/06/GHSA-qcp9-xrh4-rcw2/GHSA-qcp9-xrh4-rcw2.json create mode 100644 advisories/unreviewed/2025/06/GHSA-qr4w-3pf4-j7r3/GHSA-qr4w-3pf4-j7r3.json create mode 100644 advisories/unreviewed/2025/06/GHSA-qrmg-6fh3-mgv2/GHSA-qrmg-6fh3-mgv2.json create mode 100644 advisories/unreviewed/2025/06/GHSA-qvxq-cwr5-42fq/GHSA-qvxq-cwr5-42fq.json create mode 100644 advisories/unreviewed/2025/06/GHSA-r2j8-539m-45q5/GHSA-r2j8-539m-45q5.json create mode 100644 advisories/unreviewed/2025/06/GHSA-r487-9vv5-75gg/GHSA-r487-9vv5-75gg.json create mode 100644 advisories/unreviewed/2025/06/GHSA-r68q-hvfv-hjmc/GHSA-r68q-hvfv-hjmc.json create mode 100644 advisories/unreviewed/2025/06/GHSA-rh2j-rr9g-4x8v/GHSA-rh2j-rr9g-4x8v.json create mode 100644 advisories/unreviewed/2025/06/GHSA-rm75-x9p3-8pwv/GHSA-rm75-x9p3-8pwv.json create mode 100644 advisories/unreviewed/2025/06/GHSA-rq5m-6c4v-55rj/GHSA-rq5m-6c4v-55rj.json create mode 100644 advisories/unreviewed/2025/06/GHSA-rq9r-qvwg-829q/GHSA-rq9r-qvwg-829q.json create mode 100644 advisories/unreviewed/2025/06/GHSA-rv7r-h58x-hgr3/GHSA-rv7r-h58x-hgr3.json create mode 100644 advisories/unreviewed/2025/06/GHSA-v3q5-6pw5-p5vj/GHSA-v3q5-6pw5-p5vj.json create mode 100644 advisories/unreviewed/2025/06/GHSA-v4cq-8jgx-x3gq/GHSA-v4cq-8jgx-x3gq.json create mode 100644 advisories/unreviewed/2025/06/GHSA-v528-vhc9-x7fv/GHSA-v528-vhc9-x7fv.json create mode 100644 advisories/unreviewed/2025/06/GHSA-v89x-hh3f-24gf/GHSA-v89x-hh3f-24gf.json create mode 100644 advisories/unreviewed/2025/06/GHSA-vjfq-34vr-xpmm/GHSA-vjfq-34vr-xpmm.json create mode 100644 advisories/unreviewed/2025/06/GHSA-vm3p-hcg2-mr89/GHSA-vm3p-hcg2-mr89.json create mode 100644 advisories/unreviewed/2025/06/GHSA-vv73-f4gc-gghx/GHSA-vv73-f4gc-gghx.json create mode 100644 advisories/unreviewed/2025/06/GHSA-vvqg-cgqr-c8gc/GHSA-vvqg-cgqr-c8gc.json create mode 100644 advisories/unreviewed/2025/06/GHSA-w4gj-hg5c-7gfx/GHSA-w4gj-hg5c-7gfx.json create mode 100644 advisories/unreviewed/2025/06/GHSA-w4jq-2vxf-ppgg/GHSA-w4jq-2vxf-ppgg.json create mode 100644 advisories/unreviewed/2025/06/GHSA-w6vw-7jjr-cmhh/GHSA-w6vw-7jjr-cmhh.json create mode 100644 advisories/unreviewed/2025/06/GHSA-w7fw-3vx9-4jr9/GHSA-w7fw-3vx9-4jr9.json create mode 100644 advisories/unreviewed/2025/06/GHSA-w8fx-6j6j-879c/GHSA-w8fx-6j6j-879c.json create mode 100644 advisories/unreviewed/2025/06/GHSA-x74g-wm25-p2p5/GHSA-x74g-wm25-p2p5.json create mode 100644 advisories/unreviewed/2025/06/GHSA-x7v7-vjcv-xqj4/GHSA-x7v7-vjcv-xqj4.json create mode 100644 advisories/unreviewed/2025/06/GHSA-xqjp-6x3w-8653/GHSA-xqjp-6x3w-8653.json diff --git a/advisories/unreviewed/2024/01/GHSA-mxjq-xrv7-m36q/GHSA-mxjq-xrv7-m36q.json b/advisories/unreviewed/2024/01/GHSA-mxjq-xrv7-m36q/GHSA-mxjq-xrv7-m36q.json index b49d99d0214..3c871ad779a 100644 --- a/advisories/unreviewed/2024/01/GHSA-mxjq-xrv7-m36q/GHSA-mxjq-xrv7-m36q.json +++ b/advisories/unreviewed/2024/01/GHSA-mxjq-xrv7-m36q/GHSA-mxjq-xrv7-m36q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mxjq-xrv7-m36q", - "modified": "2024-01-29T18:31:48Z", + "modified": "2025-06-10T18:32:10Z", "published": "2024-01-23T21:30:21Z", "aliases": [ "CVE-2023-52327" diff --git a/advisories/unreviewed/2024/01/GHSA-rp98-9vmx-835h/GHSA-rp98-9vmx-835h.json b/advisories/unreviewed/2024/01/GHSA-rp98-9vmx-835h/GHSA-rp98-9vmx-835h.json index 09d890da55e..fed88774db8 100644 --- a/advisories/unreviewed/2024/01/GHSA-rp98-9vmx-835h/GHSA-rp98-9vmx-835h.json +++ b/advisories/unreviewed/2024/01/GHSA-rp98-9vmx-835h/GHSA-rp98-9vmx-835h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rp98-9vmx-835h", - "modified": "2024-01-24T18:31:00Z", + "modified": "2025-06-10T18:32:10Z", "published": "2024-01-17T03:30:55Z", "aliases": [ "CVE-2023-36235" diff --git a/advisories/unreviewed/2024/07/GHSA-5vgq-r8m3-f582/GHSA-5vgq-r8m3-f582.json b/advisories/unreviewed/2024/07/GHSA-5vgq-r8m3-f582/GHSA-5vgq-r8m3-f582.json index 0bc519c96d3..541f1b12daf 100644 --- a/advisories/unreviewed/2024/07/GHSA-5vgq-r8m3-f582/GHSA-5vgq-r8m3-f582.json +++ b/advisories/unreviewed/2024/07/GHSA-5vgq-r8m3-f582/GHSA-5vgq-r8m3-f582.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-f25c-wxgv-xhrw/GHSA-f25c-wxgv-xhrw.json b/advisories/unreviewed/2024/07/GHSA-f25c-wxgv-xhrw/GHSA-f25c-wxgv-xhrw.json index b92f99b0b13..92bf6af9972 100644 --- a/advisories/unreviewed/2024/07/GHSA-f25c-wxgv-xhrw/GHSA-f25c-wxgv-xhrw.json +++ b/advisories/unreviewed/2024/07/GHSA-f25c-wxgv-xhrw/GHSA-f25c-wxgv-xhrw.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-f44w-q987-x489/GHSA-f44w-q987-x489.json b/advisories/unreviewed/2024/07/GHSA-f44w-q987-x489/GHSA-f44w-q987-x489.json index e2f8544465c..f17f9430ec2 100644 --- a/advisories/unreviewed/2024/07/GHSA-f44w-q987-x489/GHSA-f44w-q987-x489.json +++ b/advisories/unreviewed/2024/07/GHSA-f44w-q987-x489/GHSA-f44w-q987-x489.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-jmmr-w66h-7p5r/GHSA-jmmr-w66h-7p5r.json b/advisories/unreviewed/2024/07/GHSA-jmmr-w66h-7p5r/GHSA-jmmr-w66h-7p5r.json index ccc8b5846ff..616bd62de10 100644 --- a/advisories/unreviewed/2024/07/GHSA-jmmr-w66h-7p5r/GHSA-jmmr-w66h-7p5r.json +++ b/advisories/unreviewed/2024/07/GHSA-jmmr-w66h-7p5r/GHSA-jmmr-w66h-7p5r.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-rpvm-69vv-cpww/GHSA-rpvm-69vv-cpww.json b/advisories/unreviewed/2024/07/GHSA-rpvm-69vv-cpww/GHSA-rpvm-69vv-cpww.json index 303593c30ef..12c3ac53d57 100644 --- a/advisories/unreviewed/2024/07/GHSA-rpvm-69vv-cpww/GHSA-rpvm-69vv-cpww.json +++ b/advisories/unreviewed/2024/07/GHSA-rpvm-69vv-cpww/GHSA-rpvm-69vv-cpww.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/08/GHSA-fgw8-wccj-749x/GHSA-fgw8-wccj-749x.json b/advisories/unreviewed/2024/08/GHSA-fgw8-wccj-749x/GHSA-fgw8-wccj-749x.json index b06f97a1bf3..e33d5973366 100644 --- a/advisories/unreviewed/2024/08/GHSA-fgw8-wccj-749x/GHSA-fgw8-wccj-749x.json +++ b/advisories/unreviewed/2024/08/GHSA-fgw8-wccj-749x/GHSA-fgw8-wccj-749x.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-wpmj-mx2h-xgfx/GHSA-wpmj-mx2h-xgfx.json b/advisories/unreviewed/2025/03/GHSA-wpmj-mx2h-xgfx/GHSA-wpmj-mx2h-xgfx.json index 85a06248bd2..ff2f1adc417 100644 --- a/advisories/unreviewed/2025/03/GHSA-wpmj-mx2h-xgfx/GHSA-wpmj-mx2h-xgfx.json +++ b/advisories/unreviewed/2025/03/GHSA-wpmj-mx2h-xgfx/GHSA-wpmj-mx2h-xgfx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wpmj-mx2h-xgfx", - "modified": "2025-03-11T12:30:59Z", + "modified": "2025-06-10T18:32:15Z", "published": "2025-03-11T12:30:59Z", "aliases": [ "CVE-2024-56181" diff --git a/advisories/unreviewed/2025/03/GHSA-x7x2-6gw9-jg8m/GHSA-x7x2-6gw9-jg8m.json b/advisories/unreviewed/2025/03/GHSA-x7x2-6gw9-jg8m/GHSA-x7x2-6gw9-jg8m.json index f305b012909..bfd01e24590 100644 --- a/advisories/unreviewed/2025/03/GHSA-x7x2-6gw9-jg8m/GHSA-x7x2-6gw9-jg8m.json +++ b/advisories/unreviewed/2025/03/GHSA-x7x2-6gw9-jg8m/GHSA-x7x2-6gw9-jg8m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x7x2-6gw9-jg8m", - "modified": "2025-03-11T12:30:58Z", + "modified": "2025-06-10T18:32:16Z", "published": "2025-03-11T12:30:58Z", "aliases": [ "CVE-2024-56182" diff --git a/advisories/unreviewed/2025/05/GHSA-mjcq-3whq-7xjh/GHSA-mjcq-3whq-7xjh.json b/advisories/unreviewed/2025/05/GHSA-mjcq-3whq-7xjh/GHSA-mjcq-3whq-7xjh.json index 37a24ed3dcd..961a7bd1b66 100644 --- a/advisories/unreviewed/2025/05/GHSA-mjcq-3whq-7xjh/GHSA-mjcq-3whq-7xjh.json +++ b/advisories/unreviewed/2025/05/GHSA-mjcq-3whq-7xjh/GHSA-mjcq-3whq-7xjh.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mjcq-3whq-7xjh", - "modified": "2025-05-21T21:31:37Z", + "modified": "2025-06-10T18:32:17Z", "published": "2025-05-21T21:31:37Z", "aliases": [ "CVE-2021-25254" ], "details": "Yandex Browser Lite for Android before 21.1.0 allows remote attackers to spoof the address bar.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2025/05/GHSA-p986-xv2x-2cjm/GHSA-p986-xv2x-2cjm.json b/advisories/unreviewed/2025/05/GHSA-p986-xv2x-2cjm/GHSA-p986-xv2x-2cjm.json index f4537e0e280..424a0c8e70a 100644 --- a/advisories/unreviewed/2025/05/GHSA-p986-xv2x-2cjm/GHSA-p986-xv2x-2cjm.json +++ b/advisories/unreviewed/2025/05/GHSA-p986-xv2x-2cjm/GHSA-p986-xv2x-2cjm.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p986-xv2x-2cjm", - "modified": "2025-05-21T21:31:37Z", + "modified": "2025-06-10T18:32:17Z", "published": "2025-05-21T21:31:37Z", "aliases": [ "CVE-2021-25255" ], "details": "Yandex Browser Lite for Android prior to version 21.1.0 allows remote attackers to cause a denial of service.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2025/05/GHSA-q7v7-jhxh-rv68/GHSA-q7v7-jhxh-rv68.json b/advisories/unreviewed/2025/05/GHSA-q7v7-jhxh-rv68/GHSA-q7v7-jhxh-rv68.json index c6aaaca1975..59369de9c8a 100644 --- a/advisories/unreviewed/2025/05/GHSA-q7v7-jhxh-rv68/GHSA-q7v7-jhxh-rv68.json +++ b/advisories/unreviewed/2025/05/GHSA-q7v7-jhxh-rv68/GHSA-q7v7-jhxh-rv68.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q7v7-jhxh-rv68", - "modified": "2025-05-13T12:31:36Z", + "modified": "2025-06-10T18:32:16Z", "published": "2025-05-13T12:31:36Z", "aliases": [ "CVE-2025-32454" @@ -23,6 +23,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32454" }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-486186.html" + }, { "type": "WEB", "url": "https://cert-portal.siemens.com/productcert/html/ssa-542540.html" diff --git a/advisories/unreviewed/2025/05/GHSA-qpcv-fjxx-24cv/GHSA-qpcv-fjxx-24cv.json b/advisories/unreviewed/2025/05/GHSA-qpcv-fjxx-24cv/GHSA-qpcv-fjxx-24cv.json index 8df72d23252..0c8b4062ebd 100644 --- a/advisories/unreviewed/2025/05/GHSA-qpcv-fjxx-24cv/GHSA-qpcv-fjxx-24cv.json +++ b/advisories/unreviewed/2025/05/GHSA-qpcv-fjxx-24cv/GHSA-qpcv-fjxx-24cv.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qpcv-fjxx-24cv", - "modified": "2025-05-21T21:31:37Z", + "modified": "2025-06-10T18:32:17Z", "published": "2025-05-21T21:31:37Z", "aliases": [ "CVE-2021-25262" ], "details": "Yandex Browser for Android prior to version 21.3.0 allows remote attackers to perform IDN homograph attack.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2025/06/GHSA-26qv-p8cr-jxp5/GHSA-26qv-p8cr-jxp5.json b/advisories/unreviewed/2025/06/GHSA-26qv-p8cr-jxp5/GHSA-26qv-p8cr-jxp5.json new file mode 100644 index 00000000000..3b674c995ad --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-26qv-p8cr-jxp5/GHSA-26qv-p8cr-jxp5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-26qv-p8cr-jxp5", + "modified": "2025-06-10T18:32:28Z", + "published": "2025-06-10T18:32:28Z", + "aliases": [ + "CVE-2025-33053" + ], + "details": "External control of file name or path in WebDAV allows an unauthorized attacker to execute code over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33053" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-33053" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-73" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:22:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-2972-gp35-c62r/GHSA-2972-gp35-c62r.json b/advisories/unreviewed/2025/06/GHSA-2972-gp35-c62r/GHSA-2972-gp35-c62r.json new file mode 100644 index 00000000000..8cc1dad2188 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-2972-gp35-c62r/GHSA-2972-gp35-c62r.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2972-gp35-c62r", + "modified": "2025-06-10T18:32:31Z", + "published": "2025-06-10T18:32:31Z", + "aliases": [ + "CVE-2024-37395" + ], + "details": "A stored cross-site scripting (XSS) vulnerability in the Public Survey function of REDCap 13.1.9 allows authenticated users to execute arbitrary web script or HTML by injecting a crafted payload into the 'Survey Title' and 'Survey Instructions' fields. This vulnerability could be exploited by attackers to execute malicious scripts when the survey is accessed through its public link. It is advised to update to version 14.2.1 or later to fix this issue.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37395" + }, + { + "type": "WEB", + "url": "https://www.evms.edu/research/resources_services/redcap/redcap_change_log" + }, + { + "type": "WEB", + "url": "https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/multiple-cross-site-scripting-xss-vulnerabilities-in-redcap-cve-2024-37394-cve-2024-37395-and-cve-2024-37396" + }, + { + "type": "WEB", + "url": "https://www.trustwave.com/hubfs/Web/Library/Advisories_txt/TWSL2024-003_XSS_REDCap_1.txt" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T18:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-2977-5php-6789/GHSA-2977-5php-6789.json b/advisories/unreviewed/2025/06/GHSA-2977-5php-6789/GHSA-2977-5php-6789.json new file mode 100644 index 00000000000..aa0a1977b42 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-2977-5php-6789/GHSA-2977-5php-6789.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2977-5php-6789", + "modified": "2025-06-10T18:32:27Z", + "published": "2025-06-10T18:32:27Z", + "aliases": [ + "CVE-2024-57189" + ], + "details": "In Erxes <1.6.2, an authenticated attacker can write to arbitrary files on the system using a Path Traversal vulnerability in the importHistoriesCreate GraphQL mutation handler.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57189" + }, + { + "type": "WEB", + "url": "https://github.com/erxes/erxes/commit/d626070a0fcd435ae29e689aca051ccfb440c2f3" + }, + { + "type": "WEB", + "url": "https://www.sonarsource.com/blog/micro-services-major-headaches-detecting-vulnerabilities-in-erxes-microservices" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:20:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-29gg-qvj7-46c7/GHSA-29gg-qvj7-46c7.json b/advisories/unreviewed/2025/06/GHSA-29gg-qvj7-46c7/GHSA-29gg-qvj7-46c7.json new file mode 100644 index 00000000000..31b6c083664 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-29gg-qvj7-46c7/GHSA-29gg-qvj7-46c7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-29gg-qvj7-46c7", + "modified": "2025-06-10T18:32:30Z", + "published": "2025-06-10T18:32:30Z", + "aliases": [ + "CVE-2025-47165" + ], + "details": "Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47165" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47165" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:23:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-2qpr-jh9p-xf8p/GHSA-2qpr-jh9p-xf8p.json b/advisories/unreviewed/2025/06/GHSA-2qpr-jh9p-xf8p/GHSA-2qpr-jh9p-xf8p.json new file mode 100644 index 00000000000..30f487fe9c4 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-2qpr-jh9p-xf8p/GHSA-2qpr-jh9p-xf8p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2qpr-jh9p-xf8p", + "modified": "2025-06-10T18:32:29Z", + "published": "2025-06-10T18:32:29Z", + "aliases": [ + "CVE-2025-33065" + ], + "details": "Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33065" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-33065" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:22:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-2rm9-pcmr-fvfj/GHSA-2rm9-pcmr-fvfj.json b/advisories/unreviewed/2025/06/GHSA-2rm9-pcmr-fvfj/GHSA-2rm9-pcmr-fvfj.json new file mode 100644 index 00000000000..73a3c3b5522 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-2rm9-pcmr-fvfj/GHSA-2rm9-pcmr-fvfj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2rm9-pcmr-fvfj", + "modified": "2025-06-10T18:32:31Z", + "published": "2025-06-10T18:32:31Z", + "aliases": [ + "CVE-2025-47175" + ], + "details": "Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47175" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47175" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:23:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-2xg5-8frj-h6pm/GHSA-2xg5-8frj-h6pm.json b/advisories/unreviewed/2025/06/GHSA-2xg5-8frj-h6pm/GHSA-2xg5-8frj-h6pm.json new file mode 100644 index 00000000000..1d6ddb1a47f --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-2xg5-8frj-h6pm/GHSA-2xg5-8frj-h6pm.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2xg5-8frj-h6pm", + "modified": "2025-06-10T18:32:26Z", + "published": "2025-06-10T18:32:26Z", + "aliases": [ + "CVE-2025-44044" + ], + "details": "Keyoti SearchUnit prior to 9.0.0. is vulnerable to XML External Entity (XXE). An attacker who can force a vulnerable SearchUnit host into parsing maliciously crafted XML and/or DTD files can exfiltrate some files from the underlying operating system.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44044" + }, + { + "type": "WEB", + "url": "https://keyoti.com/products/search/dotNetWeb/HtmlHelp9/?topic=UserGuide/Release%20Notes.htm" + }, + { + "type": "WEB", + "url": "https://www.sprocketsecurity.com/blog/cve-alert-cve-2025-44043-cve-2025-44044-the-search-bar-hacks-arent-dead-yet" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T16:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-3388-v38c-c9p8/GHSA-3388-v38c-c9p8.json b/advisories/unreviewed/2025/06/GHSA-3388-v38c-c9p8/GHSA-3388-v38c-c9p8.json new file mode 100644 index 00000000000..a7889c927f5 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-3388-v38c-c9p8/GHSA-3388-v38c-c9p8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3388-v38c-c9p8", + "modified": "2025-06-10T18:32:31Z", + "published": "2025-06-10T18:32:31Z", + "aliases": [ + "CVE-2025-47174" + ], + "details": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47174" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47174" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:23:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-33m4-3j2c-23xq/GHSA-33m4-3j2c-23xq.json b/advisories/unreviewed/2025/06/GHSA-33m4-3j2c-23xq/GHSA-33m4-3j2c-23xq.json new file mode 100644 index 00000000000..2e2b337e1f1 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-33m4-3j2c-23xq/GHSA-33m4-3j2c-23xq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-33m4-3j2c-23xq", + "modified": "2025-06-10T18:32:27Z", + "published": "2025-06-10T18:32:26Z", + "aliases": [ + "CVE-2024-43706" + ], + "details": "Improper authorization in Kibana can lead to privilege abuse via a direct HTTP request to a Synthetic monitor endpoint.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43706" + }, + { + "type": "WEB", + "url": "https://discuss.elastic.co/t/kibana-8-12-1-security-update-esa-2024-21/379064" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:19:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-3429-h97r-hqqx/GHSA-3429-h97r-hqqx.json b/advisories/unreviewed/2025/06/GHSA-3429-h97r-hqqx/GHSA-3429-h97r-hqqx.json index de028cd73ec..38d4399f704 100644 --- a/advisories/unreviewed/2025/06/GHSA-3429-h97r-hqqx/GHSA-3429-h97r-hqqx.json +++ b/advisories/unreviewed/2025/06/GHSA-3429-h97r-hqqx/GHSA-3429-h97r-hqqx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3429-h97r-hqqx", - "modified": "2025-06-10T12:30:19Z", + "modified": "2025-06-10T18:32:25Z", "published": "2025-06-10T12:30:19Z", "aliases": [ "CVE-2025-43701" ], "details": "Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows exposure of Custom Settings data. \n\nThis impacts OmniStudio: before version 254.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-281" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-10T12:15:24Z" diff --git a/advisories/unreviewed/2025/06/GHSA-36wp-r9w6-8qw8/GHSA-36wp-r9w6-8qw8.json b/advisories/unreviewed/2025/06/GHSA-36wp-r9w6-8qw8/GHSA-36wp-r9w6-8qw8.json new file mode 100644 index 00000000000..dd93d864d15 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-36wp-r9w6-8qw8/GHSA-36wp-r9w6-8qw8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-36wp-r9w6-8qw8", + "modified": "2025-06-10T18:32:31Z", + "published": "2025-06-10T18:32:31Z", + "aliases": [ + "CVE-2025-47969" + ], + "details": "Exposure of sensitive information to an unauthorized actor in Windows Hello allows an authorized attacker to disclose information locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47969" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47969" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:24:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-37rv-hxgg-9qvj/GHSA-37rv-hxgg-9qvj.json b/advisories/unreviewed/2025/06/GHSA-37rv-hxgg-9qvj/GHSA-37rv-hxgg-9qvj.json new file mode 100644 index 00000000000..afd9f1ec1e4 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-37rv-hxgg-9qvj/GHSA-37rv-hxgg-9qvj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-37rv-hxgg-9qvj", + "modified": "2025-06-10T18:32:28Z", + "published": "2025-06-10T18:32:28Z", + "aliases": [ + "CVE-2025-33050" + ], + "details": "Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33050" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-33050" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-693" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:22:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-39rr-qw8q-xwq8/GHSA-39rr-qw8q-xwq8.json b/advisories/unreviewed/2025/06/GHSA-39rr-qw8q-xwq8/GHSA-39rr-qw8q-xwq8.json new file mode 100644 index 00000000000..ac4be762d2e --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-39rr-qw8q-xwq8/GHSA-39rr-qw8q-xwq8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-39rr-qw8q-xwq8", + "modified": "2025-06-10T18:32:27Z", + "published": "2025-06-10T18:32:27Z", + "aliases": [ + "CVE-2025-24069" + ], + "details": "Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24069" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24069" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:21:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-3c9c-9w7c-4f9j/GHSA-3c9c-9w7c-4f9j.json b/advisories/unreviewed/2025/06/GHSA-3c9c-9w7c-4f9j/GHSA-3c9c-9w7c-4f9j.json new file mode 100644 index 00000000000..35882ab1e17 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-3c9c-9w7c-4f9j/GHSA-3c9c-9w7c-4f9j.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3c9c-9w7c-4f9j", + "modified": "2025-06-10T18:32:26Z", + "published": "2025-06-10T18:32:26Z", + "aliases": [ + "CVE-2025-44043" + ], + "details": "Keyoti SearchUnit prior to 9.0.0. is vulnerable to Server-Side Request Forgery (SSRF) in /Keyoti_SearchEngine_Web_Common/SearchService.svc/GetResults and /Keyoti_SearchEngine_Web_Common/SearchService.svc/GetLocationAndContentCategories. An attacker can specify their own SMB server as the indexDirectory value when making POST requests to the affected components. In doing so an attacker can get the SearchUnit server to read and write configuration and log files from/to the attackers server.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44043" + }, + { + "type": "WEB", + "url": "https://keyoti.com/products/search/dotNetWeb/HtmlHelp9/?topic=UserGuide/Release%20Notes.htm" + }, + { + "type": "WEB", + "url": "https://www.sprocketsecurity.com/blog/cve-alert-cve-2025-44043-cve-2025-44044-the-search-bar-hacks-arent-dead-yet" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T16:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-3fxc-2crv-fg9x/GHSA-3fxc-2crv-fg9x.json b/advisories/unreviewed/2025/06/GHSA-3fxc-2crv-fg9x/GHSA-3fxc-2crv-fg9x.json new file mode 100644 index 00000000000..bc5b1eb3f1e --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-3fxc-2crv-fg9x/GHSA-3fxc-2crv-fg9x.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3fxc-2crv-fg9x", + "modified": "2025-06-10T18:32:32Z", + "published": "2025-06-10T18:32:32Z", + "aliases": [ + "CVE-2025-2884" + ], + "details": "TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with the signature key's algorithm. See Errata 1.83 of TCG standard TPM2.0", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2884" + }, + { + "type": "WEB", + "url": "https://trustedcomputinggroup.org/about/security" + }, + { + "type": "WEB", + "url": "https://trustedcomputinggroup.org/wp-content/uploads/TPM2.0-Library-Spec-v1.83-Errata_v1_pub.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T18:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-3hvp-qhfg-j3vj/GHSA-3hvp-qhfg-j3vj.json b/advisories/unreviewed/2025/06/GHSA-3hvp-qhfg-j3vj/GHSA-3hvp-qhfg-j3vj.json index 3f61136903b..9d097325c2d 100644 --- a/advisories/unreviewed/2025/06/GHSA-3hvp-qhfg-j3vj/GHSA-3hvp-qhfg-j3vj.json +++ b/advisories/unreviewed/2025/06/GHSA-3hvp-qhfg-j3vj/GHSA-3hvp-qhfg-j3vj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3hvp-qhfg-j3vj", - "modified": "2025-06-10T12:30:19Z", + "modified": "2025-06-10T18:32:25Z", "published": "2025-06-10T12:30:18Z", "aliases": [ "CVE-2025-43699" ], "details": "Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows bypass of field level security controls for OmniUICard objects. \n\nThis impacts OmniStudio: before Spring 2025", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-281" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-10T12:15:24Z" diff --git a/advisories/unreviewed/2025/06/GHSA-3pw3-xj49-rf2v/GHSA-3pw3-xj49-rf2v.json b/advisories/unreviewed/2025/06/GHSA-3pw3-xj49-rf2v/GHSA-3pw3-xj49-rf2v.json new file mode 100644 index 00000000000..4b03f7312df --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-3pw3-xj49-rf2v/GHSA-3pw3-xj49-rf2v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3pw3-xj49-rf2v", + "modified": "2025-06-10T18:32:28Z", + "published": "2025-06-10T18:32:28Z", + "aliases": [ + "CVE-2025-33059" + ], + "details": "Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33059" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-33059" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:22:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-3qr8-pm5h-36f2/GHSA-3qr8-pm5h-36f2.json b/advisories/unreviewed/2025/06/GHSA-3qr8-pm5h-36f2/GHSA-3qr8-pm5h-36f2.json new file mode 100644 index 00000000000..903f4032333 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-3qr8-pm5h-36f2/GHSA-3qr8-pm5h-36f2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qr8-pm5h-36f2", + "modified": "2025-06-10T18:32:27Z", + "published": "2025-06-10T18:32:27Z", + "aliases": [ + "CVE-2024-45329" + ], + "details": "A authorization bypass through user-controlled key in Fortinet FortiPortal versions 7.4.0, versions 7.2.0 through 7.2.5, and versions 7.0.0 through 7.0.8 may allow an authenticated attacker to view unauthorized device information via key modification in API requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45329" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-274" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:19:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-3vh9-fqgx-vjph/GHSA-3vh9-fqgx-vjph.json b/advisories/unreviewed/2025/06/GHSA-3vh9-fqgx-vjph/GHSA-3vh9-fqgx-vjph.json new file mode 100644 index 00000000000..69593026170 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-3vh9-fqgx-vjph/GHSA-3vh9-fqgx-vjph.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3vh9-fqgx-vjph", + "modified": "2025-06-10T18:32:28Z", + "published": "2025-06-10T18:32:28Z", + "aliases": [ + "CVE-2025-32713" + ], + "details": "Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32713" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-32713" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:21:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-3vr5-764g-c3pw/GHSA-3vr5-764g-c3pw.json b/advisories/unreviewed/2025/06/GHSA-3vr5-764g-c3pw/GHSA-3vr5-764g-c3pw.json new file mode 100644 index 00000000000..86dd7824343 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-3vr5-764g-c3pw/GHSA-3vr5-764g-c3pw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3vr5-764g-c3pw", + "modified": "2025-06-10T18:32:27Z", + "published": "2025-06-10T18:32:27Z", + "aliases": [ + "CVE-2024-50562" + ], + "details": "An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions may allow an attacker in possession of a cookie used to log in the SSL-VPN portal to log in again, although the session has expired or was logged out.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50562" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-339" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-613" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:19:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-4478-2hcg-975m/GHSA-4478-2hcg-975m.json b/advisories/unreviewed/2025/06/GHSA-4478-2hcg-975m/GHSA-4478-2hcg-975m.json new file mode 100644 index 00000000000..1e150ce36aa --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-4478-2hcg-975m/GHSA-4478-2hcg-975m.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4478-2hcg-975m", + "modified": "2025-06-10T18:32:25Z", + "published": "2025-06-10T18:32:25Z", + "aliases": [ + "CVE-2025-40567" + ], + "details": "A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.2), SCALANCE XC316-8 (6GK5324-8TS00-2AC2) (All versions < V3.2), SCALANCE XC324-4 (6GK5328-4TS00-2AC2) (All versions < V3.2), SCALANCE XC324-4 EEC (6GK5328-4TS00-2EC2) (All versions < V3.2), SCALANCE XC332 (6GK5332-0GA00-2AC2) (All versions < V3.2), SCALANCE XC416-8 (6GK5424-8TR00-2AC2) (All versions < V3.2), SCALANCE XC424-4 (6GK5428-4TR00-2AC2) (All versions < V3.2), SCALANCE XC432 (6GK5432-0GR00-2AC2) (All versions < V3.2), SCALANCE XCH328 (6GK5328-4TS01-2EC2) (All versions < V3.2), SCALANCE XCM324 (6GK5324-8TS01-2AC2) (All versions < V3.2), SCALANCE XCM328 (6GK5328-4TS01-2AC2) (All versions < V3.2), SCALANCE XCM332 (6GK5332-0GA01-2AC2) (All versions < V3.2), SCALANCE XR302-32 (6GK5334-5TS00-2AR3) (All versions < V3.2), SCALANCE XR302-32 (6GK5334-5TS00-3AR3) (All versions < V3.2), SCALANCE XR302-32 (6GK5334-5TS00-4AR3) (All versions < V3.2), SCALANCE XR322-12 (6GK5334-3TS00-2AR3) (All versions < V3.2), SCALANCE XR322-12 (6GK5334-3TS00-3AR3) (All versions < V3.2), SCALANCE XR322-12 (6GK5334-3TS00-4AR3) (All versions < V3.2), SCALANCE XR326-8 (6GK5334-2TS00-2AR3) (All versions < V3.2), SCALANCE XR326-8 (6GK5334-2TS00-3AR3) (All versions < V3.2), SCALANCE XR326-8 (6GK5334-2TS00-4AR3) (All versions < V3.2), SCALANCE XR326-8 EEC (6GK5334-2TS00-2ER3) (All versions < V3.2), SCALANCE XR502-32 (6GK5534-5TR00-2AR3) (All versions < V3.2), SCALANCE XR502-32 (6GK5534-5TR00-3AR3) (All versions < V3.2), SCALANCE XR502-32 (6GK5534-5TR00-4AR3) (All versions < V3.2), SCALANCE XR522-12 (6GK5534-3TR00-2AR3) (All versions < V3.2), SCALANCE XR522-12 (6GK5534-3TR00-3AR3) (All versions < V3.2), SCALANCE XR522-12 (6GK5534-3TR00-4AR3) (All versions < V3.2), SCALANCE XR526-8 (6GK5534-2TR00-2AR3) (All versions < V3.2), SCALANCE XR526-8 (6GK5534-2TR00-3AR3) (All versions < V3.2), SCALANCE XR526-8 (6GK5534-2TR00-4AR3) (All versions < V3.2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3) (All versions < V3.2), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3) (All versions < V3.2), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3) (All versions < V3.2), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3) (All versions < V3.2), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3) (All versions < V3.2), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3) (All versions < V3.2), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3) (All versions < V3.2), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3) (All versions < V3.2), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3) (All versions < V3.2), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3) (All versions < V3.2). The \"Load Rollback\" functionality in the web interface of affected products contains an incorrect authorization check vulnerability. This could allow an authenticated remote attacker with \"guest\" role to make the affected product roll back configuration changes made by privileged users.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40567" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-693776.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-47gg-69h8-fx9p/GHSA-47gg-69h8-fx9p.json b/advisories/unreviewed/2025/06/GHSA-47gg-69h8-fx9p/GHSA-47gg-69h8-fx9p.json new file mode 100644 index 00000000000..63ab3033163 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-47gg-69h8-fx9p/GHSA-47gg-69h8-fx9p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-47gg-69h8-fx9p", + "modified": "2025-06-10T18:32:27Z", + "published": "2025-06-10T18:32:27Z", + "aliases": [ + "CVE-2025-24471" + ], + "details": "An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below, version 7.4.7 and below may allow an EAP verified remote user to connect from FortiClient via revoked certificate.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24471" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-544" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:21:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-4f6r-97c9-vqq2/GHSA-4f6r-97c9-vqq2.json b/advisories/unreviewed/2025/06/GHSA-4f6r-97c9-vqq2/GHSA-4f6r-97c9-vqq2.json new file mode 100644 index 00000000000..cfea460addd --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-4f6r-97c9-vqq2/GHSA-4f6r-97c9-vqq2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4f6r-97c9-vqq2", + "modified": "2025-06-10T18:32:27Z", + "published": "2025-06-10T18:32:27Z", + "aliases": [ + "CVE-2025-25250" + ], + "details": "An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] in FortiOS version 7.6.0, version 7.4.7 and below, 7.2 all versions, 7.0 all versions, 6.4 all versions SSL-VPN web-mode may allow an authenticated user to access full SSL-VPN settings via crafted URL.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25250" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-257" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:21:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-4fhp-55v2-x26m/GHSA-4fhp-55v2-x26m.json b/advisories/unreviewed/2025/06/GHSA-4fhp-55v2-x26m/GHSA-4fhp-55v2-x26m.json new file mode 100644 index 00000000000..4784dd82d42 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-4fhp-55v2-x26m/GHSA-4fhp-55v2-x26m.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4fhp-55v2-x26m", + "modified": "2025-06-10T18:32:25Z", + "published": "2025-06-10T18:32:25Z", + "aliases": [ + "CVE-2024-41797" + ], + "details": "A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.1), SCALANCE XC316-8 (6GK5324-8TS00-2AC2) (All versions < V3.1), SCALANCE XC324-4 (6GK5328-4TS00-2AC2) (All versions < V3.1), SCALANCE XC324-4 EEC (6GK5328-4TS00-2EC2) (All versions < V3.1), SCALANCE XC332 (6GK5332-0GA00-2AC2) (All versions < V3.1), SCALANCE XC416-8 (6GK5424-8TR00-2AC2) (All versions < V3.1), SCALANCE XC424-4 (6GK5428-4TR00-2AC2) (All versions < V3.1), SCALANCE XC432 (6GK5432-0GR00-2AC2) (All versions < V3.1), SCALANCE XCH328 (6GK5328-4TS01-2EC2) (All versions < V3.1), SCALANCE XCM324 (6GK5324-8TS01-2AC2) (All versions < V3.1), SCALANCE XCM328 (6GK5328-4TS01-2AC2) (All versions < V3.1), SCALANCE XCM332 (6GK5332-0GA01-2AC2) (All versions < V3.1), SCALANCE XR302-32 (6GK5334-5TS00-2AR3) (All versions < V3.1), SCALANCE XR302-32 (6GK5334-5TS00-3AR3) (All versions < V3.1), SCALANCE XR302-32 (6GK5334-5TS00-4AR3) (All versions < V3.1), SCALANCE XR322-12 (6GK5334-3TS00-2AR3) (All versions < V3.1), SCALANCE XR322-12 (6GK5334-3TS00-3AR3) (All versions < V3.1), SCALANCE XR322-12 (6GK5334-3TS00-4AR3) (All versions < V3.1), SCALANCE XR326-8 (6GK5334-2TS00-2AR3) (All versions < V3.1), SCALANCE XR326-8 (6GK5334-2TS00-3AR3) (All versions < V3.1), SCALANCE XR326-8 (6GK5334-2TS00-4AR3) (All versions < V3.1), SCALANCE XR326-8 EEC (6GK5334-2TS00-2ER3) (All versions < V3.1), SCALANCE XR502-32 (6GK5534-5TR00-2AR3) (All versions < V3.1), SCALANCE XR502-32 (6GK5534-5TR00-3AR3) (All versions < V3.1), SCALANCE XR502-32 (6GK5534-5TR00-4AR3) (All versions < V3.1), SCALANCE XR522-12 (6GK5534-3TR00-2AR3) (All versions < V3.1), SCALANCE XR522-12 (6GK5534-3TR00-3AR3) (All versions < V3.1), SCALANCE XR522-12 (6GK5534-3TR00-4AR3) (All versions < V3.1), SCALANCE XR526-8 (6GK5534-2TR00-2AR3) (All versions < V3.1), SCALANCE XR526-8 (6GK5534-2TR00-3AR3) (All versions < V3.1), SCALANCE XR526-8 (6GK5534-2TR00-4AR3) (All versions < V3.1), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3) (All versions < V3.1), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3) (All versions < V3.1), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3) (All versions < V3.1), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3) (All versions < V3.1), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3) (All versions < V3.1), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3) (All versions < V3.1), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3) (All versions < V3.1), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3) (All versions < V3.1), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3) (All versions < V3.1), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3) (All versions < V3.1). Affected devices contain an incorrect authorization check vulnerability. This could allow an authenticated remote attacker with \"guest\" role to invoke an internal \"do system\" command which exceeds their privileges. This command allows the execution of certain low-risk actions, the most critical of which is clearing the local system log.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41797" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-633269.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T16:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-4mqg-7w7j-8x9r/GHSA-4mqg-7w7j-8x9r.json b/advisories/unreviewed/2025/06/GHSA-4mqg-7w7j-8x9r/GHSA-4mqg-7w7j-8x9r.json new file mode 100644 index 00000000000..7e98d00a5a2 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-4mqg-7w7j-8x9r/GHSA-4mqg-7w7j-8x9r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4mqg-7w7j-8x9r", + "modified": "2025-06-10T18:32:29Z", + "published": "2025-06-10T18:32:29Z", + "aliases": [ + "CVE-2025-33069" + ], + "details": "Improper verification of cryptographic signature in App Control for Business (WDAC) allows an unauthorized attacker to bypass a security feature locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33069" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-33069" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-347" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:22:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-4qxh-75jf-785r/GHSA-4qxh-75jf-785r.json b/advisories/unreviewed/2025/06/GHSA-4qxh-75jf-785r/GHSA-4qxh-75jf-785r.json new file mode 100644 index 00000000000..c328fb3652e --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-4qxh-75jf-785r/GHSA-4qxh-75jf-785r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4qxh-75jf-785r", + "modified": "2025-06-10T18:32:28Z", + "published": "2025-06-10T18:32:28Z", + "aliases": [ + "CVE-2025-32725" + ], + "details": "Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32725" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-32725" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-693" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:22:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-4xxv-xhhw-92fw/GHSA-4xxv-xhhw-92fw.json b/advisories/unreviewed/2025/06/GHSA-4xxv-xhhw-92fw/GHSA-4xxv-xhhw-92fw.json new file mode 100644 index 00000000000..be12c1468bf --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-4xxv-xhhw-92fw/GHSA-4xxv-xhhw-92fw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4xxv-xhhw-92fw", + "modified": "2025-06-10T18:32:30Z", + "published": "2025-06-10T18:32:30Z", + "aliases": [ + "CVE-2025-47164" + ], + "details": "Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47164" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47164" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:23:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-5g9w-3gm4-chjj/GHSA-5g9w-3gm4-chjj.json b/advisories/unreviewed/2025/06/GHSA-5g9w-3gm4-chjj/GHSA-5g9w-3gm4-chjj.json new file mode 100644 index 00000000000..7eec028d4f2 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-5g9w-3gm4-chjj/GHSA-5g9w-3gm4-chjj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5g9w-3gm4-chjj", + "modified": "2025-06-10T18:32:32Z", + "published": "2025-06-10T18:32:32Z", + "aliases": [ + "CVE-2025-43581" + ], + "details": "Substance3D - Sampler versions 5.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43581" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d-sampler/apsb25-55.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T18:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-5hq7-95mx-pcjq/GHSA-5hq7-95mx-pcjq.json b/advisories/unreviewed/2025/06/GHSA-5hq7-95mx-pcjq/GHSA-5hq7-95mx-pcjq.json new file mode 100644 index 00000000000..3873464e94a --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-5hq7-95mx-pcjq/GHSA-5hq7-95mx-pcjq.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5hq7-95mx-pcjq", + "modified": "2025-06-10T18:32:25Z", + "published": "2025-06-10T18:32:25Z", + "aliases": [ + "CVE-2025-40591" + ], + "details": "A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versions < V2.16.5), RUGGEDCOM ROX RX1400 (All versions < V2.16.5), RUGGEDCOM ROX RX1500 (All versions < V2.16.5), RUGGEDCOM ROX RX1501 (All versions < V2.16.5), RUGGEDCOM ROX RX1510 (All versions < V2.16.5), RUGGEDCOM ROX RX1511 (All versions < V2.16.5), RUGGEDCOM ROX RX1512 (All versions < V2.16.5), RUGGEDCOM ROX RX1524 (All versions < V2.16.5), RUGGEDCOM ROX RX1536 (All versions < V2.16.5), RUGGEDCOM ROX RX5000 (All versions < V2.16.5). The 'Log Viewers' tool in the web interface of affected devices is vulnerable to command injection due to missing server side input sanitation. This could allow an authenticated remote attacker to execute the 'tail' command with root privileges and disclose contents of all files in the filesystem.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40591" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-301229.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-602" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-5mq4-g7c8-jh32/GHSA-5mq4-g7c8-jh32.json b/advisories/unreviewed/2025/06/GHSA-5mq4-g7c8-jh32/GHSA-5mq4-g7c8-jh32.json new file mode 100644 index 00000000000..6aa6d34efb2 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-5mq4-g7c8-jh32/GHSA-5mq4-g7c8-jh32.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5mq4-g7c8-jh32", + "modified": "2025-06-10T18:32:31Z", + "published": "2025-06-10T18:32:31Z", + "aliases": [ + "CVE-2025-47173" + ], + "details": "Improper input validation in Microsoft Office allows an unauthorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47173" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47173" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-641" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:23:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-5mw4-49p3-cwrw/GHSA-5mw4-49p3-cwrw.json b/advisories/unreviewed/2025/06/GHSA-5mw4-49p3-cwrw/GHSA-5mw4-49p3-cwrw.json new file mode 100644 index 00000000000..09ead9e39b1 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-5mw4-49p3-cwrw/GHSA-5mw4-49p3-cwrw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5mw4-49p3-cwrw", + "modified": "2025-06-10T18:32:28Z", + "published": "2025-06-10T18:32:28Z", + "aliases": [ + "CVE-2025-32721" + ], + "details": "Improper link resolution before file access ('link following') in Windows Recovery Driver allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32721" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-32721" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:22:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-5w9f-hfhx-jg4h/GHSA-5w9f-hfhx-jg4h.json b/advisories/unreviewed/2025/06/GHSA-5w9f-hfhx-jg4h/GHSA-5w9f-hfhx-jg4h.json new file mode 100644 index 00000000000..46100b13f87 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-5w9f-hfhx-jg4h/GHSA-5w9f-hfhx-jg4h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5w9f-hfhx-jg4h", + "modified": "2025-06-10T18:32:32Z", + "published": "2025-06-10T18:32:32Z", + "aliases": [ + "CVE-2025-0052" + ], + "details": "Improper input validation performed during the authentication process of FlashBlade could lead to a system Denial of Service.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0052" + }, + { + "type": "WEB", + "url": "https://support.purestorage.com/bundle/m_security_bulletins/page/Pure_Security/topics/concept/c_security_bulletins.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T18:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-5xp9-26pv-gh7v/GHSA-5xp9-26pv-gh7v.json b/advisories/unreviewed/2025/06/GHSA-5xp9-26pv-gh7v/GHSA-5xp9-26pv-gh7v.json new file mode 100644 index 00000000000..d72a43fc4b6 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-5xp9-26pv-gh7v/GHSA-5xp9-26pv-gh7v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5xp9-26pv-gh7v", + "modified": "2025-06-10T18:32:27Z", + "published": "2025-06-10T18:32:27Z", + "aliases": [ + "CVE-2025-22256" + ], + "details": "A improper handling of insufficient permissions or privileges in Fortinet FortiPAM 1.4.0 through 1.4.1, 1.3.0, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSRA 1.4.0 through 1.4.1 allows attacker to improper access control via specially crafted HTTP requests", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22256" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-25-008" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-280" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:21:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-638c-8f6r-29v5/GHSA-638c-8f6r-29v5.json b/advisories/unreviewed/2025/06/GHSA-638c-8f6r-29v5/GHSA-638c-8f6r-29v5.json new file mode 100644 index 00000000000..1a1f1807ea6 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-638c-8f6r-29v5/GHSA-638c-8f6r-29v5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-638c-8f6r-29v5", + "modified": "2025-06-10T18:32:30Z", + "published": "2025-06-10T18:32:30Z", + "aliases": [ + "CVE-2025-47168" + ], + "details": "Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47168" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47168" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:23:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-662v-v5hp-qhxj/GHSA-662v-v5hp-qhxj.json b/advisories/unreviewed/2025/06/GHSA-662v-v5hp-qhxj/GHSA-662v-v5hp-qhxj.json new file mode 100644 index 00000000000..ebeb1924a55 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-662v-v5hp-qhxj/GHSA-662v-v5hp-qhxj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-662v-v5hp-qhxj", + "modified": "2025-06-10T18:32:29Z", + "published": "2025-06-10T18:32:28Z", + "aliases": [ + "CVE-2025-33061" + ], + "details": "Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33061" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-33061" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:22:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-69hm-8j4h-xgr9/GHSA-69hm-8j4h-xgr9.json b/advisories/unreviewed/2025/06/GHSA-69hm-8j4h-xgr9/GHSA-69hm-8j4h-xgr9.json new file mode 100644 index 00000000000..63077b23c16 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-69hm-8j4h-xgr9/GHSA-69hm-8j4h-xgr9.json @@ -0,0 +1,60 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-69hm-8j4h-xgr9", + "modified": "2025-06-10T18:32:31Z", + "published": "2025-06-10T18:32:31Z", + "aliases": [ + "CVE-2025-5969" + ], + "details": "A vulnerability has been found in D-Link DIR-632 FW103B08 and classified as critical. Affected by this vulnerability is the function FUN_00425fd8 of the file /biurl_grou of the component HTTP POST Request Handler. The manipulation leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5969" + }, + { + "type": "WEB", + "url": "https://github.com/xiaobor123/vul-finds/tree/main/vul-find-dir632-dlink-FUN_00425fd8" + }, + { + "type": "WEB", + "url": "https://github.com/xiaobor123/vul-finds/tree/main/vul-find-dir632-dlink-FUN_00425fd8#poc" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311845" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311845" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.592336" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:25:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-6gj9-8hxg-8qqp/GHSA-6gj9-8hxg-8qqp.json b/advisories/unreviewed/2025/06/GHSA-6gj9-8hxg-8qqp/GHSA-6gj9-8hxg-8qqp.json new file mode 100644 index 00000000000..c1b9b6a08bb --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-6gj9-8hxg-8qqp/GHSA-6gj9-8hxg-8qqp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6gj9-8hxg-8qqp", + "modified": "2025-06-10T18:32:31Z", + "published": "2025-06-10T18:32:31Z", + "aliases": [ + "CVE-2025-47977" + ], + "details": "Improper neutralization of input during web page generation ('cross-site scripting') in Nuance Digital Engagement Platform allows an authorized attacker to perform spoofing over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47977" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47977" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:24:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-6rqm-284m-8hjf/GHSA-6rqm-284m-8hjf.json b/advisories/unreviewed/2025/06/GHSA-6rqm-284m-8hjf/GHSA-6rqm-284m-8hjf.json new file mode 100644 index 00000000000..21029520c4a --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-6rqm-284m-8hjf/GHSA-6rqm-284m-8hjf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6rqm-284m-8hjf", + "modified": "2025-06-10T18:32:28Z", + "published": "2025-06-10T18:32:28Z", + "aliases": [ + "CVE-2025-32724" + ], + "details": "Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32724" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-32724" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:22:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-6v8f-m582-f3gv/GHSA-6v8f-m582-f3gv.json b/advisories/unreviewed/2025/06/GHSA-6v8f-m582-f3gv/GHSA-6v8f-m582-f3gv.json new file mode 100644 index 00000000000..0c9da1081cc --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-6v8f-m582-f3gv/GHSA-6v8f-m582-f3gv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6v8f-m582-f3gv", + "modified": "2025-06-10T18:32:28Z", + "published": "2025-06-10T18:32:28Z", + "aliases": [ + "CVE-2025-32714" + ], + "details": "Improper access control in Windows Installer allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32714" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-32714" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:21:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-6w39-p77c-pmpq/GHSA-6w39-p77c-pmpq.json b/advisories/unreviewed/2025/06/GHSA-6w39-p77c-pmpq/GHSA-6w39-p77c-pmpq.json new file mode 100644 index 00000000000..a52997594ee --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-6w39-p77c-pmpq/GHSA-6w39-p77c-pmpq.json @@ -0,0 +1,60 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6w39-p77c-pmpq", + "modified": "2025-06-10T18:32:32Z", + "published": "2025-06-10T18:32:32Z", + "aliases": [ + "CVE-2025-5971" + ], + "details": "A vulnerability was found in code-projects School Fees Payment System 1.0. It has been classified as critical. This affects an unknown part of the file /ajx.php. The manipulation of the argument name_startsWith leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5971" + }, + { + "type": "WEB", + "url": "https://github.com/qingchuana/q1ngchuan/issues/6" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311847" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311847" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.592339" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.592441" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T18:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-6wvr-wrjw-5g3c/GHSA-6wvr-wrjw-5g3c.json b/advisories/unreviewed/2025/06/GHSA-6wvr-wrjw-5g3c/GHSA-6wvr-wrjw-5g3c.json index 20a7e886375..8fcacdacbf9 100644 --- a/advisories/unreviewed/2025/06/GHSA-6wvr-wrjw-5g3c/GHSA-6wvr-wrjw-5g3c.json +++ b/advisories/unreviewed/2025/06/GHSA-6wvr-wrjw-5g3c/GHSA-6wvr-wrjw-5g3c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6wvr-wrjw-5g3c", - "modified": "2025-06-10T12:30:19Z", + "modified": "2025-06-10T18:32:25Z", "published": "2025-06-10T12:30:18Z", "aliases": [ "CVE-2025-43700" ], "details": "Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows exposure of encrypted data. \n\nThis impacts OmniStudio: before Spring 2025.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-281" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-10T12:15:24Z" diff --git a/advisories/unreviewed/2025/06/GHSA-6xmj-596p-g7g7/GHSA-6xmj-596p-g7g7.json b/advisories/unreviewed/2025/06/GHSA-6xmj-596p-g7g7/GHSA-6xmj-596p-g7g7.json new file mode 100644 index 00000000000..d8fdfff0f51 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-6xmj-596p-g7g7/GHSA-6xmj-596p-g7g7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6xmj-596p-g7g7", + "modified": "2025-06-10T18:32:27Z", + "published": "2025-06-10T18:32:27Z", + "aliases": [ + "CVE-2024-54019" + ], + "details": "A improper validation of certificate with host mismatch in Fortinet FortiClientWindows version 7.4.0, versions 7.2.0 through 7.2.6, and 7.0 all versions allow an unauthorized attacker to redirect VPN connections via DNS spoofing or another form of redirection.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54019" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-365" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-297" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:19:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-7952-5h7p-gw4m/GHSA-7952-5h7p-gw4m.json b/advisories/unreviewed/2025/06/GHSA-7952-5h7p-gw4m/GHSA-7952-5h7p-gw4m.json new file mode 100644 index 00000000000..fd9380cef1c --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-7952-5h7p-gw4m/GHSA-7952-5h7p-gw4m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7952-5h7p-gw4m", + "modified": "2025-06-10T18:32:32Z", + "published": "2025-06-10T18:32:32Z", + "aliases": [ + "CVE-2025-2474" + ], + "details": "Out-of-bounds write in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition or execute code in the context of the process using the image codec.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2474" + }, + { + "type": "WEB", + "url": "https://support.blackberry.com/pkb/s/article/140646" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T18:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-796j-mc2v-jwpj/GHSA-796j-mc2v-jwpj.json b/advisories/unreviewed/2025/06/GHSA-796j-mc2v-jwpj/GHSA-796j-mc2v-jwpj.json index 9b5cc154188..a0db75cb371 100644 --- a/advisories/unreviewed/2025/06/GHSA-796j-mc2v-jwpj/GHSA-796j-mc2v-jwpj.json +++ b/advisories/unreviewed/2025/06/GHSA-796j-mc2v-jwpj/GHSA-796j-mc2v-jwpj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-796j-mc2v-jwpj", - "modified": "2025-06-09T06:30:22Z", + "modified": "2025-06-10T18:32:19Z", "published": "2025-06-09T06:30:22Z", "aliases": [ "CVE-2025-3582" ], "details": "The Newsletter WordPress plugin before 8.85 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-09T06:15:25Z" diff --git a/advisories/unreviewed/2025/06/GHSA-7g9m-wm2f-95fg/GHSA-7g9m-wm2f-95fg.json b/advisories/unreviewed/2025/06/GHSA-7g9m-wm2f-95fg/GHSA-7g9m-wm2f-95fg.json new file mode 100644 index 00000000000..a568acc36f1 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-7g9m-wm2f-95fg/GHSA-7g9m-wm2f-95fg.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7g9m-wm2f-95fg", + "modified": "2025-06-10T18:32:31Z", + "published": "2025-06-10T18:32:31Z", + "aliases": [ + "CVE-2024-37394" + ], + "details": "A stored cross-site scripting (XSS) vulnerability in the Project Dashboards of REDCap 13.1.9 allows authenticated users to execute arbitrary web script or HTML by injecting a crafted payload into the 'Dashboard title' and 'Dashboard content' text boxes. This can lead to the execution of malicious scripts when the dashboard is viewed. Users are recommended to update to version 14.2.1 or later to mitigate this vulnerability.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37394" + }, + { + "type": "WEB", + "url": "https://www.evms.edu/research/resources_services/redcap/redcap_change_log" + }, + { + "type": "WEB", + "url": "https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/multiple-cross-site-scripting-xss-vulnerabilities-in-redcap-cve-2024-37394-cve-2024-37395-and-cve-2024-37396" + }, + { + "type": "WEB", + "url": "https://www.trustwave.com/hubfs/Web/Library/Advisories_txt/TWSL2024-003_XSS_REDCap_1.txt" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T18:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-7p8p-77rq-jh4w/GHSA-7p8p-77rq-jh4w.json b/advisories/unreviewed/2025/06/GHSA-7p8p-77rq-jh4w/GHSA-7p8p-77rq-jh4w.json new file mode 100644 index 00000000000..f8e8aeed6c8 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-7p8p-77rq-jh4w/GHSA-7p8p-77rq-jh4w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7p8p-77rq-jh4w", + "modified": "2025-06-10T18:32:28Z", + "published": "2025-06-10T18:32:28Z", + "aliases": [ + "CVE-2025-33052" + ], + "details": "Use of uninitialized resource in Windows DWM Core Library allows an authorized attacker to disclose information locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33052" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-33052" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-908" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:22:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-7px7-38p7-4p29/GHSA-7px7-38p7-4p29.json b/advisories/unreviewed/2025/06/GHSA-7px7-38p7-4p29/GHSA-7px7-38p7-4p29.json new file mode 100644 index 00000000000..3b0c737d3d1 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-7px7-38p7-4p29/GHSA-7px7-38p7-4p29.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7px7-38p7-4p29", + "modified": "2025-06-10T18:32:32Z", + "published": "2025-06-10T18:32:32Z", + "aliases": [ + "CVE-2025-43588" + ], + "details": "Substance3D - Sampler versions 5.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43588" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d-sampler/apsb25-55.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T18:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-7rc6-r844-3mww/GHSA-7rc6-r844-3mww.json b/advisories/unreviewed/2025/06/GHSA-7rc6-r844-3mww/GHSA-7rc6-r844-3mww.json new file mode 100644 index 00000000000..7ec67ffbab1 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-7rc6-r844-3mww/GHSA-7rc6-r844-3mww.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7rc6-r844-3mww", + "modified": "2025-06-10T18:32:26Z", + "published": "2025-06-10T18:32:26Z", + "aliases": [ + "CVE-2023-20599" + ], + "details": "Improper register access control in ASP may allow a privileged attacker to perform unauthorized access to ASP’s Crypto Co-Processor (CCP) registers from x86, resulting in potential loss of control of cryptographic key pointer/index, leading to loss of integrity or confidentiality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20599" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7039.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1262" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:17:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-7rhv-xm4q-wh42/GHSA-7rhv-xm4q-wh42.json b/advisories/unreviewed/2025/06/GHSA-7rhv-xm4q-wh42/GHSA-7rhv-xm4q-wh42.json new file mode 100644 index 00000000000..6ed24690ff9 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-7rhv-xm4q-wh42/GHSA-7rhv-xm4q-wh42.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7rhv-xm4q-wh42", + "modified": "2025-06-10T18:32:27Z", + "published": "2025-06-10T18:32:27Z", + "aliases": [ + "CVE-2024-57190" + ], + "details": "Erxes <1.6.1 is vulnerable to Incorrect Access Control. An attacker can bypass authentication by providing a \"User\" HTTP header that contains any user, allowing them to talk to any GraphQL endpoint.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57190" + }, + { + "type": "WEB", + "url": "https://github.com/erxes/erxes/commit/4ed2ca797241d2ba0c9083feeadd9755c1310ce8" + }, + { + "type": "WEB", + "url": "https://www.sonarsource.com/blog/micro-services-major-headaches-detecting-vulnerabilities-in-erxes-microservices" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:20:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-7v3j-qcv2-4wc4/GHSA-7v3j-qcv2-4wc4.json b/advisories/unreviewed/2025/06/GHSA-7v3j-qcv2-4wc4/GHSA-7v3j-qcv2-4wc4.json new file mode 100644 index 00000000000..cf4ea08e56f --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-7v3j-qcv2-4wc4/GHSA-7v3j-qcv2-4wc4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7v3j-qcv2-4wc4", + "modified": "2025-06-10T18:32:31Z", + "published": "2025-06-10T18:32:31Z", + "aliases": [ + "CVE-2025-47176" + ], + "details": "'.../...//' in Microsoft Office Outlook allows an authorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47176" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47176" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:23:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-7xv5-2vc8-mjgv/GHSA-7xv5-2vc8-mjgv.json b/advisories/unreviewed/2025/06/GHSA-7xv5-2vc8-mjgv/GHSA-7xv5-2vc8-mjgv.json new file mode 100644 index 00000000000..3e4015fdb82 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-7xv5-2vc8-mjgv/GHSA-7xv5-2vc8-mjgv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7xv5-2vc8-mjgv", + "modified": "2025-06-10T18:32:30Z", + "published": "2025-06-10T18:32:30Z", + "aliases": [ + "CVE-2025-47160" + ], + "details": "Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47160" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47160" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-693" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:23:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-82vq-mq3h-xx6f/GHSA-82vq-mq3h-xx6f.json b/advisories/unreviewed/2025/06/GHSA-82vq-mq3h-xx6f/GHSA-82vq-mq3h-xx6f.json index e72c5e73352..38203cbff6d 100644 --- a/advisories/unreviewed/2025/06/GHSA-82vq-mq3h-xx6f/GHSA-82vq-mq3h-xx6f.json +++ b/advisories/unreviewed/2025/06/GHSA-82vq-mq3h-xx6f/GHSA-82vq-mq3h-xx6f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-82vq-mq3h-xx6f", - "modified": "2025-06-10T00:30:30Z", + "modified": "2025-06-10T18:32:21Z", "published": "2025-06-10T00:30:30Z", "aliases": [ "CVE-2025-26468" diff --git a/advisories/unreviewed/2025/06/GHSA-8375-2vj2-7p5f/GHSA-8375-2vj2-7p5f.json b/advisories/unreviewed/2025/06/GHSA-8375-2vj2-7p5f/GHSA-8375-2vj2-7p5f.json new file mode 100644 index 00000000000..241413b4fe3 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-8375-2vj2-7p5f/GHSA-8375-2vj2-7p5f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8375-2vj2-7p5f", + "modified": "2025-06-10T18:32:29Z", + "published": "2025-06-10T18:32:29Z", + "aliases": [ + "CVE-2025-43590" + ], + "details": "InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43590" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/indesign/apsb25-53.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:23:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-863r-cfhv-7rmg/GHSA-863r-cfhv-7rmg.json b/advisories/unreviewed/2025/06/GHSA-863r-cfhv-7rmg/GHSA-863r-cfhv-7rmg.json new file mode 100644 index 00000000000..d676356d16a --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-863r-cfhv-7rmg/GHSA-863r-cfhv-7rmg.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-863r-cfhv-7rmg", + "modified": "2025-06-10T18:32:32Z", + "published": "2025-06-10T18:32:32Z", + "aliases": [ + "CVE-2025-5943" + ], + "details": "MicroDicom \n\nDICOM Viewer suffers from an out-of-bounds write vulnerability. Remote attackers are able to exploit this issue to potentially execute arbitrary code on affected installations of DICOM Viewer. User interaction is required to exploit the vulnerability in that the user must either visit a malicious website or open a malicious DICOM file locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5943" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-160-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T18:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-872c-cmq4-p7wq/GHSA-872c-cmq4-p7wq.json b/advisories/unreviewed/2025/06/GHSA-872c-cmq4-p7wq/GHSA-872c-cmq4-p7wq.json new file mode 100644 index 00000000000..456c6c7f836 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-872c-cmq4-p7wq/GHSA-872c-cmq4-p7wq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-872c-cmq4-p7wq", + "modified": "2025-06-10T18:32:31Z", + "published": "2025-06-10T18:32:31Z", + "aliases": [ + "CVE-2025-47962" + ], + "details": "Improper access control in Windows SDK allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47962" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47962" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:24:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-87xg-g898-rh5q/GHSA-87xg-g898-rh5q.json b/advisories/unreviewed/2025/06/GHSA-87xg-g898-rh5q/GHSA-87xg-g898-rh5q.json new file mode 100644 index 00000000000..3b77bf6785b --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-87xg-g898-rh5q/GHSA-87xg-g898-rh5q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-87xg-g898-rh5q", + "modified": "2025-06-10T18:32:32Z", + "published": "2025-06-10T18:32:32Z", + "aliases": [ + "CVE-2025-36575" + ], + "details": "Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Exposure of Sensitive Information Through Data Queries vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-36575" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000325679/dsa-2025-226" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-202" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T18:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-8gqq-cqfg-7f8m/GHSA-8gqq-cqfg-7f8m.json b/advisories/unreviewed/2025/06/GHSA-8gqq-cqfg-7f8m/GHSA-8gqq-cqfg-7f8m.json new file mode 100644 index 00000000000..e56f8bd08eb --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-8gqq-cqfg-7f8m/GHSA-8gqq-cqfg-7f8m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8gqq-cqfg-7f8m", + "modified": "2025-06-10T18:32:28Z", + "published": "2025-06-10T18:32:28Z", + "aliases": [ + "CVE-2025-32718" + ], + "details": "Integer overflow or wraparound in Windows SMB allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32718" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-32718" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:21:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-8pqc-m8ff-xf67/GHSA-8pqc-m8ff-xf67.json b/advisories/unreviewed/2025/06/GHSA-8pqc-m8ff-xf67/GHSA-8pqc-m8ff-xf67.json new file mode 100644 index 00000000000..bd41e1db26a --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-8pqc-m8ff-xf67/GHSA-8pqc-m8ff-xf67.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8pqc-m8ff-xf67", + "modified": "2025-06-10T18:32:28Z", + "published": "2025-06-10T18:32:28Z", + "aliases": [ + "CVE-2025-33055" + ], + "details": "Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33055" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-33055" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:22:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-8rxv-vgf4-465c/GHSA-8rxv-vgf4-465c.json b/advisories/unreviewed/2025/06/GHSA-8rxv-vgf4-465c/GHSA-8rxv-vgf4-465c.json new file mode 100644 index 00000000000..a8fa8999f3c --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-8rxv-vgf4-465c/GHSA-8rxv-vgf4-465c.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8rxv-vgf4-465c", + "modified": "2025-06-10T18:32:25Z", + "published": "2025-06-10T18:32:25Z", + "aliases": [ + "CVE-2025-40585" + ], + "details": "A vulnerability has been identified in Energy Services (All versions with G5DFR). Affected solutions using G5DFR contain default credentials. This could allow an attacker to gain control of G5DFR component and tamper with outputs from the device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40585" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-345750.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-95wq-9rmf-rwff/GHSA-95wq-9rmf-rwff.json b/advisories/unreviewed/2025/06/GHSA-95wq-9rmf-rwff/GHSA-95wq-9rmf-rwff.json new file mode 100644 index 00000000000..b2e77c7b548 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-95wq-9rmf-rwff/GHSA-95wq-9rmf-rwff.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-95wq-9rmf-rwff", + "modified": "2025-06-10T18:32:32Z", + "published": "2025-06-10T18:32:32Z", + "aliases": [ + "CVE-2025-36580" + ], + "details": "Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-36580" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000325679/dsa-2025-226" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T18:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-9h68-3v3c-5fmj/GHSA-9h68-3v3c-5fmj.json b/advisories/unreviewed/2025/06/GHSA-9h68-3v3c-5fmj/GHSA-9h68-3v3c-5fmj.json new file mode 100644 index 00000000000..f27826e2ba6 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-9h68-3v3c-5fmj/GHSA-9h68-3v3c-5fmj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9h68-3v3c-5fmj", + "modified": "2025-06-10T18:32:30Z", + "published": "2025-06-10T18:32:30Z", + "aliases": [ + "CVE-2025-47170" + ], + "details": "Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47170" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47170" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:23:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-9h9j-567f-gg4h/GHSA-9h9j-567f-gg4h.json b/advisories/unreviewed/2025/06/GHSA-9h9j-567f-gg4h/GHSA-9h9j-567f-gg4h.json new file mode 100644 index 00000000000..43a15bee646 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-9h9j-567f-gg4h/GHSA-9h9j-567f-gg4h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9h9j-567f-gg4h", + "modified": "2025-06-10T18:32:31Z", + "published": "2025-06-10T18:32:31Z", + "aliases": [ + "CVE-2025-47955" + ], + "details": "Improper privilege management in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47955" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47955" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:24:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-9qp5-76v7-3g7w/GHSA-9qp5-76v7-3g7w.json b/advisories/unreviewed/2025/06/GHSA-9qp5-76v7-3g7w/GHSA-9qp5-76v7-3g7w.json new file mode 100644 index 00000000000..95a4e8efb46 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-9qp5-76v7-3g7w/GHSA-9qp5-76v7-3g7w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qp5-76v7-3g7w", + "modified": "2025-06-10T18:32:30Z", + "published": "2025-06-10T18:32:30Z", + "aliases": [ + "CVE-2025-47169" + ], + "details": "Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47169" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47169" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:23:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-9qr2-qm38-64g4/GHSA-9qr2-qm38-64g4.json b/advisories/unreviewed/2025/06/GHSA-9qr2-qm38-64g4/GHSA-9qr2-qm38-64g4.json new file mode 100644 index 00000000000..b5a896be173 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-9qr2-qm38-64g4/GHSA-9qr2-qm38-64g4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qr2-qm38-64g4", + "modified": "2025-06-10T18:32:28Z", + "published": "2025-06-10T18:32:28Z", + "aliases": [ + "CVE-2025-33056" + ], + "details": "Improper access control in Microsoft Local Security Authority Server (lsasrv) allows an unauthorized attacker to deny service over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33056" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-33056" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:22:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-9vpr-8qr7-4pg3/GHSA-9vpr-8qr7-4pg3.json b/advisories/unreviewed/2025/06/GHSA-9vpr-8qr7-4pg3/GHSA-9vpr-8qr7-4pg3.json index 6477509e719..16c40025a6b 100644 --- a/advisories/unreviewed/2025/06/GHSA-9vpr-8qr7-4pg3/GHSA-9vpr-8qr7-4pg3.json +++ b/advisories/unreviewed/2025/06/GHSA-9vpr-8qr7-4pg3/GHSA-9vpr-8qr7-4pg3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9vpr-8qr7-4pg3", - "modified": "2025-06-10T15:30:48Z", + "modified": "2025-06-10T18:32:25Z", "published": "2025-06-10T15:30:48Z", "aliases": [ "CVE-2025-37100" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-22" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/06/GHSA-9xq9-jfj9-8mqm/GHSA-9xq9-jfj9-8mqm.json b/advisories/unreviewed/2025/06/GHSA-9xq9-jfj9-8mqm/GHSA-9xq9-jfj9-8mqm.json new file mode 100644 index 00000000000..dcb33db2e1a --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-9xq9-jfj9-8mqm/GHSA-9xq9-jfj9-8mqm.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9xq9-jfj9-8mqm", + "modified": "2025-06-10T18:32:31Z", + "published": "2025-06-10T18:32:31Z", + "aliases": [ + "CVE-2024-37396" + ], + "details": "A stored cross-site scripting (XSS) vulnerability in the Calendar function of REDCap 13.1.9 allows authenticated users to execute arbitrary web script or HTML by injecting a crafted payload into the 'Notes' field of a calendar event. This could lead to the execution of malicious scripts when the event is viewed. Updating to version 14.2.1 or later is recommended to remediate this vulnerability.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37396" + }, + { + "type": "WEB", + "url": "https://www.evms.edu/research/resources_services/redcap/redcap_change_log" + }, + { + "type": "WEB", + "url": "https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/multiple-cross-site-scripting-xss-vulnerabilities-in-redcap-cve-2024-37394-cve-2024-37395-and-cve-2024-37396" + }, + { + "type": "WEB", + "url": "https://www.trustwave.com/hubfs/Web/Library/Advisories_txt/TWSL2024-003_XSS_REDCap_1.txt" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T18:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-c4r7-vqgv-hxrw/GHSA-c4r7-vqgv-hxrw.json b/advisories/unreviewed/2025/06/GHSA-c4r7-vqgv-hxrw/GHSA-c4r7-vqgv-hxrw.json new file mode 100644 index 00000000000..449b900e1e6 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-c4r7-vqgv-hxrw/GHSA-c4r7-vqgv-hxrw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c4r7-vqgv-hxrw", + "modified": "2025-06-10T18:32:30Z", + "published": "2025-06-10T18:32:30Z", + "aliases": [ + "CVE-2025-47163" + ], + "details": "Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47163" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47163" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:23:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-c5jx-h8px-jrgh/GHSA-c5jx-h8px-jrgh.json b/advisories/unreviewed/2025/06/GHSA-c5jx-h8px-jrgh/GHSA-c5jx-h8px-jrgh.json new file mode 100644 index 00000000000..d0d278ccd12 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-c5jx-h8px-jrgh/GHSA-c5jx-h8px-jrgh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c5jx-h8px-jrgh", + "modified": "2025-06-10T18:32:29Z", + "published": "2025-06-10T18:32:29Z", + "aliases": [ + "CVE-2025-33070" + ], + "details": "Use of uninitialized resource in Windows Netlogon allows an unauthorized attacker to elevate privileges over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33070" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-33070" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-908" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:22:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-cfjg-2jr6-cgph/GHSA-cfjg-2jr6-cgph.json b/advisories/unreviewed/2025/06/GHSA-cfjg-2jr6-cgph/GHSA-cfjg-2jr6-cgph.json new file mode 100644 index 00000000000..b9124a045ae --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-cfjg-2jr6-cgph/GHSA-cfjg-2jr6-cgph.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cfjg-2jr6-cgph", + "modified": "2025-06-10T18:32:29Z", + "published": "2025-06-10T18:32:29Z", + "aliases": [ + "CVE-2025-33073" + ], + "details": "Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33073" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-33073" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:23:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-f9xh-499r-w9qx/GHSA-f9xh-499r-w9qx.json b/advisories/unreviewed/2025/06/GHSA-f9xh-499r-w9qx/GHSA-f9xh-499r-w9qx.json index a90ba87be44..59a528f0986 100644 --- a/advisories/unreviewed/2025/06/GHSA-f9xh-499r-w9qx/GHSA-f9xh-499r-w9qx.json +++ b/advisories/unreviewed/2025/06/GHSA-f9xh-499r-w9qx/GHSA-f9xh-499r-w9qx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f9xh-499r-w9qx", - "modified": "2025-06-09T06:30:22Z", + "modified": "2025-06-10T18:32:19Z", "published": "2025-06-09T06:30:22Z", "aliases": [ "CVE-2025-3581" ], "details": "The Newsletter WordPress plugin before 8.8.5 does not validate and escape some of its Widget options before outputting them back in a page/post where the block is embed, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-09T06:15:25Z" diff --git a/advisories/unreviewed/2025/06/GHSA-ffgw-jrq3-grx9/GHSA-ffgw-jrq3-grx9.json b/advisories/unreviewed/2025/06/GHSA-ffgw-jrq3-grx9/GHSA-ffgw-jrq3-grx9.json new file mode 100644 index 00000000000..9bf5f1b67e2 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-ffgw-jrq3-grx9/GHSA-ffgw-jrq3-grx9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ffgw-jrq3-grx9", + "modified": "2025-06-10T18:32:28Z", + "published": "2025-06-10T18:32:28Z", + "aliases": [ + "CVE-2025-32720" + ], + "details": "Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32720" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-32720" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:22:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-fgf2-43wx-4mv7/GHSA-fgf2-43wx-4mv7.json b/advisories/unreviewed/2025/06/GHSA-fgf2-43wx-4mv7/GHSA-fgf2-43wx-4mv7.json new file mode 100644 index 00000000000..c847a51654d --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-fgf2-43wx-4mv7/GHSA-fgf2-43wx-4mv7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fgf2-43wx-4mv7", + "modified": "2025-06-10T18:32:27Z", + "published": "2025-06-10T18:32:27Z", + "aliases": [ + "CVE-2025-24068" + ], + "details": "Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24068" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24068" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:21:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-fj2f-gvvm-wc28/GHSA-fj2f-gvvm-wc28.json b/advisories/unreviewed/2025/06/GHSA-fj2f-gvvm-wc28/GHSA-fj2f-gvvm-wc28.json new file mode 100644 index 00000000000..f31dec94d0f --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-fj2f-gvvm-wc28/GHSA-fj2f-gvvm-wc28.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fj2f-gvvm-wc28", + "modified": "2025-06-10T18:32:32Z", + "published": "2025-06-10T18:32:32Z", + "aliases": [ + "CVE-2025-0051" + ], + "details": "Improper input validation performed during the authentication process of FlashArray could lead to a system Denial of Service.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0051" + }, + { + "type": "WEB", + "url": "https://support.purestorage.com/bundle/m_security_bulletins/page/Pure_Security/topics/concept/c_security_bulletins.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T18:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-fx7x-v68g-vhq5/GHSA-fx7x-v68g-vhq5.json b/advisories/unreviewed/2025/06/GHSA-fx7x-v68g-vhq5/GHSA-fx7x-v68g-vhq5.json new file mode 100644 index 00000000000..bfa633792d8 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-fx7x-v68g-vhq5/GHSA-fx7x-v68g-vhq5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fx7x-v68g-vhq5", + "modified": "2025-06-10T18:32:29Z", + "published": "2025-06-10T18:32:29Z", + "aliases": [ + "CVE-2025-33067" + ], + "details": "Improper privilege management in Windows Kernel allows an unauthorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33067" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-33067" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:22:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-g2pj-xmxq-3r9q/GHSA-g2pj-xmxq-3r9q.json b/advisories/unreviewed/2025/06/GHSA-g2pj-xmxq-3r9q/GHSA-g2pj-xmxq-3r9q.json new file mode 100644 index 00000000000..552fafd07cd --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-g2pj-xmxq-3r9q/GHSA-g2pj-xmxq-3r9q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g2pj-xmxq-3r9q", + "modified": "2025-06-10T18:32:25Z", + "published": "2025-06-10T18:32:25Z", + "aliases": [ + "CVE-2025-27206" + ], + "details": "Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain limited write access. Exploitation of this issue does not require user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27206" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb25-50.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-g682-7gqf-wrjp/GHSA-g682-7gqf-wrjp.json b/advisories/unreviewed/2025/06/GHSA-g682-7gqf-wrjp/GHSA-g682-7gqf-wrjp.json new file mode 100644 index 00000000000..730b5dba183 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-g682-7gqf-wrjp/GHSA-g682-7gqf-wrjp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g682-7gqf-wrjp", + "modified": "2025-06-10T18:32:29Z", + "published": "2025-06-10T18:32:29Z", + "aliases": [ + "CVE-2025-47104" + ], + "details": "InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47104" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/indesign/apsb25-53.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:23:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-ggm3-fwfv-cfp9/GHSA-ggm3-fwfv-cfp9.json b/advisories/unreviewed/2025/06/GHSA-ggm3-fwfv-cfp9/GHSA-ggm3-fwfv-cfp9.json new file mode 100644 index 00000000000..2300f2ba78c --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-ggm3-fwfv-cfp9/GHSA-ggm3-fwfv-cfp9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ggm3-fwfv-cfp9", + "modified": "2025-06-10T18:32:28Z", + "published": "2025-06-10T18:32:28Z", + "aliases": [ + "CVE-2025-32715" + ], + "details": "Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32715" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-32715" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:21:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-gjgx-8hwj-f6gq/GHSA-gjgx-8hwj-f6gq.json b/advisories/unreviewed/2025/06/GHSA-gjgx-8hwj-f6gq/GHSA-gjgx-8hwj-f6gq.json new file mode 100644 index 00000000000..3712821f758 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-gjgx-8hwj-f6gq/GHSA-gjgx-8hwj-f6gq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gjgx-8hwj-f6gq", + "modified": "2025-06-10T18:32:29Z", + "published": "2025-06-10T18:32:29Z", + "aliases": [ + "CVE-2025-33066" + ], + "details": "Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33066" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-33066" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:22:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-gq6p-h9r9-9hcw/GHSA-gq6p-h9r9-9hcw.json b/advisories/unreviewed/2025/06/GHSA-gq6p-h9r9-9hcw/GHSA-gq6p-h9r9-9hcw.json new file mode 100644 index 00000000000..8045a47361f --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-gq6p-h9r9-9hcw/GHSA-gq6p-h9r9-9hcw.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gq6p-h9r9-9hcw", + "modified": "2025-06-10T18:32:32Z", + "published": "2025-06-10T18:32:31Z", + "aliases": [ + "CVE-2025-5970" + ], + "details": "A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/add-subadmin.php. The manipulation of the argument fullname leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5970" + }, + { + "type": "WEB", + "url": "https://github.com/kakalalaww/CVE/issues/4" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311846" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311846" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.592338" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:25:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-h6c8-xhhw-v4mw/GHSA-h6c8-xhhw-v4mw.json b/advisories/unreviewed/2025/06/GHSA-h6c8-xhhw-v4mw/GHSA-h6c8-xhhw-v4mw.json new file mode 100644 index 00000000000..1d6f6957d00 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-h6c8-xhhw-v4mw/GHSA-h6c8-xhhw-v4mw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h6c8-xhhw-v4mw", + "modified": "2025-06-10T18:32:29Z", + "published": "2025-06-10T18:32:29Z", + "aliases": [ + "CVE-2025-47105" + ], + "details": "InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47105" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/indesign/apsb25-53.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:23:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-hcp3-9rg5-2f9p/GHSA-hcp3-9rg5-2f9p.json b/advisories/unreviewed/2025/06/GHSA-hcp3-9rg5-2f9p/GHSA-hcp3-9rg5-2f9p.json new file mode 100644 index 00000000000..0a26a602815 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-hcp3-9rg5-2f9p/GHSA-hcp3-9rg5-2f9p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hcp3-9rg5-2f9p", + "modified": "2025-06-10T18:32:27Z", + "published": "2025-06-10T18:32:26Z", + "aliases": [ + "CVE-2024-32119" + ], + "details": "An improper authentication vulnerability [CWE-287] in Fortinet FortiClientEMS version 7.4.0 and before 7.2.4 allows an unauthenticated attacker with the knowledge of the targeted user's FCTUID and VDOM to perform operations such as uploading or tagging on behalf of the targeted user via specially crafted TCP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32119" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-23-375" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1390" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:19:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-hm9j-wvvg-pwv5/GHSA-hm9j-wvvg-pwv5.json b/advisories/unreviewed/2025/06/GHSA-hm9j-wvvg-pwv5/GHSA-hm9j-wvvg-pwv5.json new file mode 100644 index 00000000000..a7ab7fe95dd --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-hm9j-wvvg-pwv5/GHSA-hm9j-wvvg-pwv5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hm9j-wvvg-pwv5", + "modified": "2025-06-10T18:32:29Z", + "published": "2025-06-10T18:32:29Z", + "aliases": [ + "CVE-2025-33060" + ], + "details": "Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33060" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-33060" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:22:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-hrvw-6x9w-9pw3/GHSA-hrvw-6x9w-9pw3.json b/advisories/unreviewed/2025/06/GHSA-hrvw-6x9w-9pw3/GHSA-hrvw-6x9w-9pw3.json new file mode 100644 index 00000000000..e57f893b3ea --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-hrvw-6x9w-9pw3/GHSA-hrvw-6x9w-9pw3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hrvw-6x9w-9pw3", + "modified": "2025-06-10T18:32:28Z", + "published": "2025-06-10T18:32:28Z", + "aliases": [ + "CVE-2025-32712" + ], + "details": "Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32712" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-32712" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:21:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-hxxf-pxh8-jxxh/GHSA-hxxf-pxh8-jxxh.json b/advisories/unreviewed/2025/06/GHSA-hxxf-pxh8-jxxh/GHSA-hxxf-pxh8-jxxh.json new file mode 100644 index 00000000000..27aab50a01f --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-hxxf-pxh8-jxxh/GHSA-hxxf-pxh8-jxxh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hxxf-pxh8-jxxh", + "modified": "2025-06-10T18:32:27Z", + "published": "2025-06-10T18:32:27Z", + "aliases": [ + "CVE-2023-29184" + ], + "details": "An incomplete cleanup vulnerability [CWE-459] in FortiOS 7.2 all versions and before & FortiProxy version 7.2.0 through 7.2.2 and before 7.0.8 allows a VDOM privileged attacker to add SSH key files on the system silently via crafted CLI requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29184" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-23-008" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-459" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:17:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-j4v3-52c8-2m66/GHSA-j4v3-52c8-2m66.json b/advisories/unreviewed/2025/06/GHSA-j4v3-52c8-2m66/GHSA-j4v3-52c8-2m66.json new file mode 100644 index 00000000000..6678576e565 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-j4v3-52c8-2m66/GHSA-j4v3-52c8-2m66.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j4v3-52c8-2m66", + "modified": "2025-06-10T18:32:30Z", + "published": "2025-06-10T18:32:30Z", + "aliases": [ + "CVE-2025-47171" + ], + "details": "Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47171" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47171" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:23:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-j8f6-cp2r-rhv6/GHSA-j8f6-cp2r-rhv6.json b/advisories/unreviewed/2025/06/GHSA-j8f6-cp2r-rhv6/GHSA-j8f6-cp2r-rhv6.json new file mode 100644 index 00000000000..3e36dc5526a --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-j8f6-cp2r-rhv6/GHSA-j8f6-cp2r-rhv6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j8f6-cp2r-rhv6", + "modified": "2025-06-10T18:32:28Z", + "published": "2025-06-10T18:32:28Z", + "aliases": [ + "CVE-2025-32719" + ], + "details": "Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32719" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-32719" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:22:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-j934-vjh5-vf9r/GHSA-j934-vjh5-vf9r.json b/advisories/unreviewed/2025/06/GHSA-j934-vjh5-vf9r/GHSA-j934-vjh5-vf9r.json new file mode 100644 index 00000000000..a55677a68bf --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-j934-vjh5-vf9r/GHSA-j934-vjh5-vf9r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j934-vjh5-vf9r", + "modified": "2025-06-10T18:32:26Z", + "published": "2025-06-10T18:32:26Z", + "aliases": [ + "CVE-2025-47110" + ], + "details": "Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47110" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb25-50.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T16:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-jh64-9f55-5hrx/GHSA-jh64-9f55-5hrx.json b/advisories/unreviewed/2025/06/GHSA-jh64-9f55-5hrx/GHSA-jh64-9f55-5hrx.json new file mode 100644 index 00000000000..5be1d82e05f --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-jh64-9f55-5hrx/GHSA-jh64-9f55-5hrx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jh64-9f55-5hrx", + "modified": "2025-06-10T18:32:27Z", + "published": "2025-06-10T18:32:27Z", + "aliases": [ + "CVE-2025-24065" + ], + "details": "Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24065" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24065" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:21:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-jvcx-4h9f-wx33/GHSA-jvcx-4h9f-wx33.json b/advisories/unreviewed/2025/06/GHSA-jvcx-4h9f-wx33/GHSA-jvcx-4h9f-wx33.json new file mode 100644 index 00000000000..38a055e6f69 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-jvcx-4h9f-wx33/GHSA-jvcx-4h9f-wx33.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jvcx-4h9f-wx33", + "modified": "2025-06-10T18:32:30Z", + "published": "2025-06-10T18:32:30Z", + "aliases": [ + "CVE-2025-47166" + ], + "details": "Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47166" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47166" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:23:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-jvmq-cr7f-mvjw/GHSA-jvmq-cr7f-mvjw.json b/advisories/unreviewed/2025/06/GHSA-jvmq-cr7f-mvjw/GHSA-jvmq-cr7f-mvjw.json new file mode 100644 index 00000000000..aae8ac1eb53 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-jvmq-cr7f-mvjw/GHSA-jvmq-cr7f-mvjw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jvmq-cr7f-mvjw", + "modified": "2025-06-10T18:32:26Z", + "published": "2025-06-10T18:32:26Z", + "aliases": [ + "CVE-2023-48786" + ], + "details": "A server-side request forgery vulnerability [CWE-918] in Fortinet FortiClientEMS version 7.4.0 through 7.4.2 and before 7.2.6 may allow an authenticated attacker to perform internal requests via crafted HTTP or HTTPS requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48786" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-23-342" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:18:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-m9m6-qv46-g5mf/GHSA-m9m6-qv46-g5mf.json b/advisories/unreviewed/2025/06/GHSA-m9m6-qv46-g5mf/GHSA-m9m6-qv46-g5mf.json new file mode 100644 index 00000000000..322e37efd84 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-m9m6-qv46-g5mf/GHSA-m9m6-qv46-g5mf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m9m6-qv46-g5mf", + "modified": "2025-06-10T18:32:29Z", + "published": "2025-06-10T18:32:29Z", + "aliases": [ + "CVE-2025-33064" + ], + "details": "Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33064" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-33064" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:22:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-m9pg-v9j9-9qr5/GHSA-m9pg-v9j9-9qr5.json b/advisories/unreviewed/2025/06/GHSA-m9pg-v9j9-9qr5/GHSA-m9pg-v9j9-9qr5.json new file mode 100644 index 00000000000..edacfe7b4c4 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-m9pg-v9j9-9qr5/GHSA-m9pg-v9j9-9qr5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m9pg-v9j9-9qr5", + "modified": "2025-06-10T18:32:29Z", + "published": "2025-06-10T18:32:29Z", + "aliases": [ + "CVE-2025-33063" + ], + "details": "Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33063" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-33063" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:22:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-mp2w-h9wf-5497/GHSA-mp2w-h9wf-5497.json b/advisories/unreviewed/2025/06/GHSA-mp2w-h9wf-5497/GHSA-mp2w-h9wf-5497.json new file mode 100644 index 00000000000..aa183a63ab0 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-mp2w-h9wf-5497/GHSA-mp2w-h9wf-5497.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mp2w-h9wf-5497", + "modified": "2025-06-10T18:32:27Z", + "published": "2025-06-10T18:32:27Z", + "aliases": [ + "CVE-2025-22251" + ], + "details": "An improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an unauthenticated attacker to inject unauthorized sessions via crafted FGSP session synchronization packets.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22251" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-287" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-923" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:21:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-mq97-x574-83g4/GHSA-mq97-x574-83g4.json b/advisories/unreviewed/2025/06/GHSA-mq97-x574-83g4/GHSA-mq97-x574-83g4.json new file mode 100644 index 00000000000..f4a66b537c0 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-mq97-x574-83g4/GHSA-mq97-x574-83g4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mq97-x574-83g4", + "modified": "2025-06-10T18:32:31Z", + "published": "2025-06-10T18:32:31Z", + "aliases": [ + "CVE-2025-47956" + ], + "details": "External control of file name or path in Windows Security App allows an authorized attacker to perform spoofing locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47956" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47956" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-73" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:24:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-mxm2-mfw2-4435/GHSA-mxm2-mfw2-4435.json b/advisories/unreviewed/2025/06/GHSA-mxm2-mfw2-4435/GHSA-mxm2-mfw2-4435.json new file mode 100644 index 00000000000..ae595a94342 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-mxm2-mfw2-4435/GHSA-mxm2-mfw2-4435.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mxm2-mfw2-4435", + "modified": "2025-06-10T18:32:31Z", + "published": "2025-06-10T18:32:31Z", + "aliases": [ + "CVE-2025-47968" + ], + "details": "Improper input validation in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47968" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47968" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:24:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-p844-6jfp-89rq/GHSA-p844-6jfp-89rq.json b/advisories/unreviewed/2025/06/GHSA-p844-6jfp-89rq/GHSA-p844-6jfp-89rq.json new file mode 100644 index 00000000000..b1f973b5e29 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-p844-6jfp-89rq/GHSA-p844-6jfp-89rq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p844-6jfp-89rq", + "modified": "2025-06-10T18:32:29Z", + "published": "2025-06-10T18:32:29Z", + "aliases": [ + "CVE-2025-33112" + ], + "details": "IBM AIX 7.3 and IBM VIOS 4.1.1 Perl implementation could allow a non-privileged local user to exploit a vulnerability to execute arbitrary code due to improper neutralization of pathname input.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33112" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7236103" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-23" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:23:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-p8ff-4rqf-9m2x/GHSA-p8ff-4rqf-9m2x.json b/advisories/unreviewed/2025/06/GHSA-p8ff-4rqf-9m2x/GHSA-p8ff-4rqf-9m2x.json new file mode 100644 index 00000000000..1df5207b95b --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-p8ff-4rqf-9m2x/GHSA-p8ff-4rqf-9m2x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p8ff-4rqf-9m2x", + "modified": "2025-06-10T18:32:26Z", + "published": "2025-06-10T18:32:26Z", + "aliases": [ + "CVE-2025-4678" + ], + "details": "Improper Neutralization of Special Elements in the chromium_path variable may allow OS command injection. This issue affects Pandora ITSM 5.0.105.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:D/RE:M/U:Green" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4678" + }, + { + "type": "WEB", + "url": "https://pandorafms.com/en/security/common-vulnerabilities-and-exposures" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T16:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-pc2h-32rh-xhfp/GHSA-pc2h-32rh-xhfp.json b/advisories/unreviewed/2025/06/GHSA-pc2h-32rh-xhfp/GHSA-pc2h-32rh-xhfp.json new file mode 100644 index 00000000000..f0adfee6e2f --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-pc2h-32rh-xhfp/GHSA-pc2h-32rh-xhfp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pc2h-32rh-xhfp", + "modified": "2025-06-10T18:32:27Z", + "published": "2025-06-10T18:32:27Z", + "aliases": [ + "CVE-2025-30321" + ], + "details": "InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption in service. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30321" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/indesign/apsb25-53.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:21:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-pf5j-488q-mf84/GHSA-pf5j-488q-mf84.json b/advisories/unreviewed/2025/06/GHSA-pf5j-488q-mf84/GHSA-pf5j-488q-mf84.json new file mode 100644 index 00000000000..d6445369fdd --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-pf5j-488q-mf84/GHSA-pf5j-488q-mf84.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pf5j-488q-mf84", + "modified": "2025-06-10T18:32:26Z", + "published": "2025-06-10T18:32:26Z", + "aliases": [ + "CVE-2025-4653" + ], + "details": "Improper Neutralization of Special Elements in the backup name field may allow OS command injection. This issue affects Pandora ITSM 5.0.105.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:D/RE:M/U:Green" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4653" + }, + { + "type": "WEB", + "url": "https://pandorafms.com/en/security/common-vulnerabilities-and-exposures" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T16:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-pgmv-r49r-93pq/GHSA-pgmv-r49r-93pq.json b/advisories/unreviewed/2025/06/GHSA-pgmv-r49r-93pq/GHSA-pgmv-r49r-93pq.json new file mode 100644 index 00000000000..a2ce9226ffa --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-pgmv-r49r-93pq/GHSA-pgmv-r49r-93pq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pgmv-r49r-93pq", + "modified": "2025-06-10T18:32:32Z", + "published": "2025-06-10T18:32:32Z", + "aliases": [ + "CVE-2025-36577" + ], + "details": "Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-36577" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000325679/dsa-2025-226" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T18:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-pp47-c46r-hhxq/GHSA-pp47-c46r-hhxq.json b/advisories/unreviewed/2025/06/GHSA-pp47-c46r-hhxq/GHSA-pp47-c46r-hhxq.json new file mode 100644 index 00000000000..e9f61ec0282 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-pp47-c46r-hhxq/GHSA-pp47-c46r-hhxq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pp47-c46r-hhxq", + "modified": "2025-06-10T18:32:32Z", + "published": "2025-06-10T18:32:32Z", + "aliases": [ + "CVE-2025-36578" + ], + "details": "Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-36578" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000325679/dsa-2025-226" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T18:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-q57w-gqgq-cx44/GHSA-q57w-gqgq-cx44.json b/advisories/unreviewed/2025/06/GHSA-q57w-gqgq-cx44/GHSA-q57w-gqgq-cx44.json new file mode 100644 index 00000000000..1cd4cc9201d --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-q57w-gqgq-cx44/GHSA-q57w-gqgq-cx44.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q57w-gqgq-cx44", + "modified": "2025-06-10T18:32:29Z", + "published": "2025-06-10T18:32:28Z", + "aliases": [ + "CVE-2025-33057" + ], + "details": "Null pointer dereference in Windows Local Security Authority (LSA) allows an authorized attacker to deny service over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33057" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-33057" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:22:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-q5qw-7fqr-83mr/GHSA-q5qw-7fqr-83mr.json b/advisories/unreviewed/2025/06/GHSA-q5qw-7fqr-83mr/GHSA-q5qw-7fqr-83mr.json new file mode 100644 index 00000000000..00d8c5c4f52 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-q5qw-7fqr-83mr/GHSA-q5qw-7fqr-83mr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q5qw-7fqr-83mr", + "modified": "2025-06-10T18:32:28Z", + "published": "2025-06-10T18:32:28Z", + "aliases": [ + "CVE-2025-32716" + ], + "details": "Out-of-bounds read in Windows Media allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32716" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-32716" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:21:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-q6xx-gv82-hc4m/GHSA-q6xx-gv82-hc4m.json b/advisories/unreviewed/2025/06/GHSA-q6xx-gv82-hc4m/GHSA-q6xx-gv82-hc4m.json new file mode 100644 index 00000000000..4003f57bbd5 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-q6xx-gv82-hc4m/GHSA-q6xx-gv82-hc4m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q6xx-gv82-hc4m", + "modified": "2025-06-10T18:32:27Z", + "published": "2025-06-10T18:32:27Z", + "aliases": [ + "CVE-2024-50568" + ], + "details": "A channel accessible by non-endpoint vulnerability [CWE-300] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7 and before 7.0.14 & FortiProxy version 7.4.0 through 7.4.3, 7.2.0 through 7.2.9 and before 7.0.16 allows an unauthenticated attacker with the knowledge of device specific data to spoof the identity of a downstream device of the security fabric via crafted TCP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50568" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-058" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-300" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:19:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-q86x-v28r-5px8/GHSA-q86x-v28r-5px8.json b/advisories/unreviewed/2025/06/GHSA-q86x-v28r-5px8/GHSA-q86x-v28r-5px8.json new file mode 100644 index 00000000000..7df2755fb8c --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-q86x-v28r-5px8/GHSA-q86x-v28r-5px8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q86x-v28r-5px8", + "modified": "2025-06-10T18:32:29Z", + "published": "2025-06-10T18:32:29Z", + "aliases": [ + "CVE-2025-33071" + ], + "details": "Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33071" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-33071" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:22:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-qcp9-xrh4-rcw2/GHSA-qcp9-xrh4-rcw2.json b/advisories/unreviewed/2025/06/GHSA-qcp9-xrh4-rcw2/GHSA-qcp9-xrh4-rcw2.json new file mode 100644 index 00000000000..be8bacff501 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-qcp9-xrh4-rcw2/GHSA-qcp9-xrh4-rcw2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qcp9-xrh4-rcw2", + "modified": "2025-06-10T18:32:32Z", + "published": "2025-06-10T18:32:32Z", + "aliases": [ + "CVE-2025-36574" + ], + "details": "Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Absolute Path Traversal vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure and Unauthorized access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-36574" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000325679/dsa-2025-226" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-36" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T18:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-qfp6-39x3-xvfc/GHSA-qfp6-39x3-xvfc.json b/advisories/unreviewed/2025/06/GHSA-qfp6-39x3-xvfc/GHSA-qfp6-39x3-xvfc.json index 952b45cdd87..10427d73188 100644 --- a/advisories/unreviewed/2025/06/GHSA-qfp6-39x3-xvfc/GHSA-qfp6-39x3-xvfc.json +++ b/advisories/unreviewed/2025/06/GHSA-qfp6-39x3-xvfc/GHSA-qfp6-39x3-xvfc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qfp6-39x3-xvfc", - "modified": "2025-06-09T18:32:13Z", + "modified": "2025-06-10T18:32:19Z", "published": "2025-06-09T18:32:13Z", "aliases": [ "CVE-2025-46178" ], "details": "Cross-Site Scripting (XSS) vulnerability exists in askquery.php via the eid parameter in the CloudClassroom PHP Project. This allows remote attackers to inject arbitrary JavaScript in the context of a victim s browser session by sending a crafted URL, leading to session hijacking or defacement.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-09T16:15:40Z" diff --git a/advisories/unreviewed/2025/06/GHSA-qr4w-3pf4-j7r3/GHSA-qr4w-3pf4-j7r3.json b/advisories/unreviewed/2025/06/GHSA-qr4w-3pf4-j7r3/GHSA-qr4w-3pf4-j7r3.json new file mode 100644 index 00000000000..6e2c05f9174 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-qr4w-3pf4-j7r3/GHSA-qr4w-3pf4-j7r3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qr4w-3pf4-j7r3", + "modified": "2025-06-10T18:32:27Z", + "published": "2025-06-10T18:32:27Z", + "aliases": [ + "CVE-2025-31104" + ], + "details": "An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiADC 7.6.0 through 7.6.1, 7.4.0 through 7.4.6, 7.2.0 through 7.2.7, 7.1.0 through 7.1.4, 7.0 all versions, 6.2 all versions, 6.1 all versions may allow an authenticated attacker to execute unauthorized code via crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31104" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-25-099" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:21:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-qrmg-6fh3-mgv2/GHSA-qrmg-6fh3-mgv2.json b/advisories/unreviewed/2025/06/GHSA-qrmg-6fh3-mgv2/GHSA-qrmg-6fh3-mgv2.json new file mode 100644 index 00000000000..e4b2b1cb360 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-qrmg-6fh3-mgv2/GHSA-qrmg-6fh3-mgv2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qrmg-6fh3-mgv2", + "modified": "2025-06-10T18:32:30Z", + "published": "2025-06-10T18:32:30Z", + "aliases": [ + "CVE-2025-47167" + ], + "details": "Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47167" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47167" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-843" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:23:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-qvxq-cwr5-42fq/GHSA-qvxq-cwr5-42fq.json b/advisories/unreviewed/2025/06/GHSA-qvxq-cwr5-42fq/GHSA-qvxq-cwr5-42fq.json new file mode 100644 index 00000000000..7da1b2085a9 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-qvxq-cwr5-42fq/GHSA-qvxq-cwr5-42fq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qvxq-cwr5-42fq", + "modified": "2025-06-10T18:32:29Z", + "published": "2025-06-10T18:32:29Z", + "aliases": [ + "CVE-2025-33068" + ], + "details": "Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33068" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-33068" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:22:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-r2j8-539m-45q5/GHSA-r2j8-539m-45q5.json b/advisories/unreviewed/2025/06/GHSA-r2j8-539m-45q5/GHSA-r2j8-539m-45q5.json new file mode 100644 index 00000000000..89b4a60e984 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-r2j8-539m-45q5/GHSA-r2j8-539m-45q5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r2j8-539m-45q5", + "modified": "2025-06-10T18:32:27Z", + "published": "2025-06-10T18:32:27Z", + "aliases": [ + "CVE-2025-22254" + ], + "details": "An Improper Privilege Management vulnerability [CWE-269] affecting Fortinet FortiOS version 7.6.0 through 7.6.1, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16 and before 6.4.15, FortiProxy version 7.6.0 through 7.6.1 and before 7.4.7 & FortiWeb version 7.6.0 through 7.6.1 and before 7.4.6 allows an authenticated attacker with at least read-only admin permissions to gain super-admin privileges via crafted requests to Node.js websocket module.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22254" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-25-006" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:21:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-r487-9vv5-75gg/GHSA-r487-9vv5-75gg.json b/advisories/unreviewed/2025/06/GHSA-r487-9vv5-75gg/GHSA-r487-9vv5-75gg.json new file mode 100644 index 00000000000..7ce1bef270f --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-r487-9vv5-75gg/GHSA-r487-9vv5-75gg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r487-9vv5-75gg", + "modified": "2025-06-10T18:32:26Z", + "published": "2025-06-10T18:32:26Z", + "aliases": [ + "CVE-2025-43585" + ], + "details": "Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access leading to a limited impact to confidentiality and a high impact to integrity. Exploitation of this issue does not require user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43585" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb25-50.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T16:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-r68q-hvfv-hjmc/GHSA-r68q-hvfv-hjmc.json b/advisories/unreviewed/2025/06/GHSA-r68q-hvfv-hjmc/GHSA-r68q-hvfv-hjmc.json new file mode 100644 index 00000000000..7190c180b6f --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-r68q-hvfv-hjmc/GHSA-r68q-hvfv-hjmc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r68q-hvfv-hjmc", + "modified": "2025-06-10T18:32:28Z", + "published": "2025-06-10T18:32:28Z", + "aliases": [ + "CVE-2025-32722" + ], + "details": "Improper access control in Windows Storage Port Driver allows an authorized attacker to disclose information locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32722" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-32722" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:22:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-rh2j-rr9g-4x8v/GHSA-rh2j-rr9g-4x8v.json b/advisories/unreviewed/2025/06/GHSA-rh2j-rr9g-4x8v/GHSA-rh2j-rr9g-4x8v.json new file mode 100644 index 00000000000..c6897670885 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-rh2j-rr9g-4x8v/GHSA-rh2j-rr9g-4x8v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rh2j-rr9g-4x8v", + "modified": "2025-06-10T18:32:30Z", + "published": "2025-06-10T18:32:29Z", + "aliases": [ + "CVE-2025-47106" + ], + "details": "InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47106" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/indesign/apsb25-53.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:23:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-rm75-x9p3-8pwv/GHSA-rm75-x9p3-8pwv.json b/advisories/unreviewed/2025/06/GHSA-rm75-x9p3-8pwv/GHSA-rm75-x9p3-8pwv.json new file mode 100644 index 00000000000..55698b17cd4 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-rm75-x9p3-8pwv/GHSA-rm75-x9p3-8pwv.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rm75-x9p3-8pwv", + "modified": "2025-06-10T18:32:25Z", + "published": "2025-06-10T18:32:25Z", + "aliases": [ + "CVE-2025-40569" + ], + "details": "A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.2), SCALANCE XC316-8 (6GK5324-8TS00-2AC2) (All versions < V3.2), SCALANCE XC324-4 (6GK5328-4TS00-2AC2) (All versions < V3.2), SCALANCE XC324-4 EEC (6GK5328-4TS00-2EC2) (All versions < V3.2), SCALANCE XC332 (6GK5332-0GA00-2AC2) (All versions < V3.2), SCALANCE XC416-8 (6GK5424-8TR00-2AC2) (All versions < V3.2), SCALANCE XC424-4 (6GK5428-4TR00-2AC2) (All versions < V3.2), SCALANCE XC432 (6GK5432-0GR00-2AC2) (All versions < V3.2), SCALANCE XCH328 (6GK5328-4TS01-2EC2) (All versions < V3.2), SCALANCE XCM324 (6GK5324-8TS01-2AC2) (All versions < V3.2), SCALANCE XCM328 (6GK5328-4TS01-2AC2) (All versions < V3.2), SCALANCE XCM332 (6GK5332-0GA01-2AC2) (All versions < V3.2), SCALANCE XR302-32 (6GK5334-5TS00-2AR3) (All versions < V3.2), SCALANCE XR302-32 (6GK5334-5TS00-3AR3) (All versions < V3.2), SCALANCE XR302-32 (6GK5334-5TS00-4AR3) (All versions < V3.2), SCALANCE XR322-12 (6GK5334-3TS00-2AR3) (All versions < V3.2), SCALANCE XR322-12 (6GK5334-3TS00-3AR3) (All versions < V3.2), SCALANCE XR322-12 (6GK5334-3TS00-4AR3) (All versions < V3.2), SCALANCE XR326-8 (6GK5334-2TS00-2AR3) (All versions < V3.2), SCALANCE XR326-8 (6GK5334-2TS00-3AR3) (All versions < V3.2), SCALANCE XR326-8 (6GK5334-2TS00-4AR3) (All versions < V3.2), SCALANCE XR326-8 EEC (6GK5334-2TS00-2ER3) (All versions < V3.2), SCALANCE XR502-32 (6GK5534-5TR00-2AR3) (All versions < V3.2), SCALANCE XR502-32 (6GK5534-5TR00-3AR3) (All versions < V3.2), SCALANCE XR502-32 (6GK5534-5TR00-4AR3) (All versions < V3.2), SCALANCE XR522-12 (6GK5534-3TR00-2AR3) (All versions < V3.2), SCALANCE XR522-12 (6GK5534-3TR00-3AR3) (All versions < V3.2), SCALANCE XR522-12 (6GK5534-3TR00-4AR3) (All versions < V3.2), SCALANCE XR526-8 (6GK5534-2TR00-2AR3) (All versions < V3.2), SCALANCE XR526-8 (6GK5534-2TR00-3AR3) (All versions < V3.2), SCALANCE XR526-8 (6GK5534-2TR00-4AR3) (All versions < V3.2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3) (All versions < V3.2), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3) (All versions < V3.2), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3) (All versions < V3.2), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3) (All versions < V3.2), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3) (All versions < V3.2), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3) (All versions < V3.2), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3) (All versions < V3.2), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3) (All versions < V3.2), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3) (All versions < V3.2), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3) (All versions < V3.2). The \"Load Configuration from Local PC\" functionality in the web interface of affected products contains a race condition vulnerability. This could allow an authenticated remote attacker to make the affected product load an attacker controlled configuration instead of the legitimate one. Successful exploitation requires that a legitimate administrator invokes the functionality and the attacker wins the race condition.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40569" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-693776.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-rq5m-6c4v-55rj/GHSA-rq5m-6c4v-55rj.json b/advisories/unreviewed/2025/06/GHSA-rq5m-6c4v-55rj/GHSA-rq5m-6c4v-55rj.json new file mode 100644 index 00000000000..03f96e32558 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-rq5m-6c4v-55rj/GHSA-rq5m-6c4v-55rj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rq5m-6c4v-55rj", + "modified": "2025-06-10T18:32:31Z", + "published": "2025-06-10T18:32:31Z", + "aliases": [ + "CVE-2025-47172" + ], + "details": "Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47172" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47172" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:23:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-rq9r-qvwg-829q/GHSA-rq9r-qvwg-829q.json b/advisories/unreviewed/2025/06/GHSA-rq9r-qvwg-829q/GHSA-rq9r-qvwg-829q.json new file mode 100644 index 00000000000..9b94a004e7a --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-rq9r-qvwg-829q/GHSA-rq9r-qvwg-829q.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rq9r-qvwg-829q", + "modified": "2025-06-10T18:32:27Z", + "published": "2025-06-10T18:32:27Z", + "aliases": [ + "CVE-2024-57186" + ], + "details": "In Erxes <1.6.2, an unauthenticated attacker can read arbitrary files from the system using a Path Traversal vulnerability in the /read-file endpoint handler.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57186" + }, + { + "type": "WEB", + "url": "https://github.com/erxes/erxes/commit/d626070a0fcd435ae29e689aca051ccfb440c2f3" + }, + { + "type": "WEB", + "url": "https://www.sonarsource.com/blog/micro-services-major-headaches-detecting-vulnerabilities-in-erxes-microservices" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:19:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-rv7r-h58x-hgr3/GHSA-rv7r-h58x-hgr3.json b/advisories/unreviewed/2025/06/GHSA-rv7r-h58x-hgr3/GHSA-rv7r-h58x-hgr3.json new file mode 100644 index 00000000000..f9592d7a771 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-rv7r-h58x-hgr3/GHSA-rv7r-h58x-hgr3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rv7r-h58x-hgr3", + "modified": "2025-06-10T18:32:32Z", + "published": "2025-06-10T18:32:32Z", + "aliases": [ + "CVE-2025-36576" + ], + "details": "Dell Wyse Management Suite, versions prior to WMS 5.2, contain a Cross-Site Request Forgery (CSRF) vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-36576" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000325679/dsa-2025-226" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T18:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-v3q5-6pw5-p5vj/GHSA-v3q5-6pw5-p5vj.json b/advisories/unreviewed/2025/06/GHSA-v3q5-6pw5-p5vj/GHSA-v3q5-6pw5-p5vj.json new file mode 100644 index 00000000000..d2bdef565a3 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-v3q5-6pw5-p5vj/GHSA-v3q5-6pw5-p5vj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v3q5-6pw5-p5vj", + "modified": "2025-06-10T18:32:29Z", + "published": "2025-06-10T18:32:29Z", + "aliases": [ + "CVE-2025-43558" + ], + "details": "InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43558" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/indesign/apsb25-53.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:23:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-v4cq-8jgx-x3gq/GHSA-v4cq-8jgx-x3gq.json b/advisories/unreviewed/2025/06/GHSA-v4cq-8jgx-x3gq/GHSA-v4cq-8jgx-x3gq.json new file mode 100644 index 00000000000..edc8612046a --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-v4cq-8jgx-x3gq/GHSA-v4cq-8jgx-x3gq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v4cq-8jgx-x3gq", + "modified": "2025-06-10T18:32:30Z", + "published": "2025-06-10T18:32:29Z", + "aliases": [ + "CVE-2025-47108" + ], + "details": "Substance3D - Painter versions 11.0.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47108" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_painter/apsb25-58.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:23:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-v528-vhc9-x7fv/GHSA-v528-vhc9-x7fv.json b/advisories/unreviewed/2025/06/GHSA-v528-vhc9-x7fv/GHSA-v528-vhc9-x7fv.json new file mode 100644 index 00000000000..b927632d00f --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-v528-vhc9-x7fv/GHSA-v528-vhc9-x7fv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v528-vhc9-x7fv", + "modified": "2025-06-10T18:32:25Z", + "published": "2025-06-10T18:32:25Z", + "aliases": [ + "CVE-2025-27207" + ], + "details": "Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access Control vulnerability that could result in privilege escalation. A low privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27207" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb25-50.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-v89x-hh3f-24gf/GHSA-v89x-hh3f-24gf.json b/advisories/unreviewed/2025/06/GHSA-v89x-hh3f-24gf/GHSA-v89x-hh3f-24gf.json new file mode 100644 index 00000000000..2ffe588d6ed --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-v89x-hh3f-24gf/GHSA-v89x-hh3f-24gf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v89x-hh3f-24gf", + "modified": "2025-06-10T18:32:27Z", + "published": "2025-06-10T18:32:27Z", + "aliases": [ + "CVE-2025-32710" + ], + "details": "Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32710" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-32710" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:21:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-vjfq-34vr-xpmm/GHSA-vjfq-34vr-xpmm.json b/advisories/unreviewed/2025/06/GHSA-vjfq-34vr-xpmm/GHSA-vjfq-34vr-xpmm.json new file mode 100644 index 00000000000..c2d82229d59 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-vjfq-34vr-xpmm/GHSA-vjfq-34vr-xpmm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vjfq-34vr-xpmm", + "modified": "2025-06-10T18:32:27Z", + "published": "2025-06-10T18:32:27Z", + "aliases": [ + "CVE-2025-29828" + ], + "details": "Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to execute code over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29828" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29828" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-401" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:21:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-vm3p-hcg2-mr89/GHSA-vm3p-hcg2-mr89.json b/advisories/unreviewed/2025/06/GHSA-vm3p-hcg2-mr89/GHSA-vm3p-hcg2-mr89.json new file mode 100644 index 00000000000..61776df0ad7 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-vm3p-hcg2-mr89/GHSA-vm3p-hcg2-mr89.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vm3p-hcg2-mr89", + "modified": "2025-06-10T18:32:29Z", + "published": "2025-06-10T18:32:28Z", + "aliases": [ + "CVE-2025-33062" + ], + "details": "Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33062" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-33062" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:22:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-vv73-f4gc-gghx/GHSA-vv73-f4gc-gghx.json b/advisories/unreviewed/2025/06/GHSA-vv73-f4gc-gghx/GHSA-vv73-f4gc-gghx.json new file mode 100644 index 00000000000..3c6df0de787 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-vv73-f4gc-gghx/GHSA-vv73-f4gc-gghx.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vv73-f4gc-gghx", + "modified": "2025-06-10T18:32:25Z", + "published": "2025-06-10T18:32:25Z", + "aliases": [ + "CVE-2025-40568" + ], + "details": "A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.2), SCALANCE XC316-8 (6GK5324-8TS00-2AC2) (All versions < V3.2), SCALANCE XC324-4 (6GK5328-4TS00-2AC2) (All versions < V3.2), SCALANCE XC324-4 EEC (6GK5328-4TS00-2EC2) (All versions < V3.2), SCALANCE XC332 (6GK5332-0GA00-2AC2) (All versions < V3.2), SCALANCE XC416-8 (6GK5424-8TR00-2AC2) (All versions < V3.2), SCALANCE XC424-4 (6GK5428-4TR00-2AC2) (All versions < V3.2), SCALANCE XC432 (6GK5432-0GR00-2AC2) (All versions < V3.2), SCALANCE XCH328 (6GK5328-4TS01-2EC2) (All versions < V3.2), SCALANCE XCM324 (6GK5324-8TS01-2AC2) (All versions < V3.2), SCALANCE XCM328 (6GK5328-4TS01-2AC2) (All versions < V3.2), SCALANCE XCM332 (6GK5332-0GA01-2AC2) (All versions < V3.2), SCALANCE XR302-32 (6GK5334-5TS00-2AR3) (All versions < V3.2), SCALANCE XR302-32 (6GK5334-5TS00-3AR3) (All versions < V3.2), SCALANCE XR302-32 (6GK5334-5TS00-4AR3) (All versions < V3.2), SCALANCE XR322-12 (6GK5334-3TS00-2AR3) (All versions < V3.2), SCALANCE XR322-12 (6GK5334-3TS00-3AR3) (All versions < V3.2), SCALANCE XR322-12 (6GK5334-3TS00-4AR3) (All versions < V3.2), SCALANCE XR326-8 (6GK5334-2TS00-2AR3) (All versions < V3.2), SCALANCE XR326-8 (6GK5334-2TS00-3AR3) (All versions < V3.2), SCALANCE XR326-8 (6GK5334-2TS00-4AR3) (All versions < V3.2), SCALANCE XR326-8 EEC (6GK5334-2TS00-2ER3) (All versions < V3.2), SCALANCE XR502-32 (6GK5534-5TR00-2AR3) (All versions < V3.2), SCALANCE XR502-32 (6GK5534-5TR00-3AR3) (All versions < V3.2), SCALANCE XR502-32 (6GK5534-5TR00-4AR3) (All versions < V3.2), SCALANCE XR522-12 (6GK5534-3TR00-2AR3) (All versions < V3.2), SCALANCE XR522-12 (6GK5534-3TR00-3AR3) (All versions < V3.2), SCALANCE XR522-12 (6GK5534-3TR00-4AR3) (All versions < V3.2), SCALANCE XR526-8 (6GK5534-2TR00-2AR3) (All versions < V3.2), SCALANCE XR526-8 (6GK5534-2TR00-3AR3) (All versions < V3.2), SCALANCE XR526-8 (6GK5534-2TR00-4AR3) (All versions < V3.2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3) (All versions < V3.2), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3) (All versions < V3.2), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3) (All versions < V3.2), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3) (All versions < V3.2), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3) (All versions < V3.2), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3) (All versions < V3.2), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3) (All versions < V3.2), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3) (All versions < V3.2), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3) (All versions < V3.2), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3) (All versions < V3.2). An internal session termination functionality in the web interface of affected products contains an incorrect authorization check vulnerability. This could allow an authenticated remote attacker with \"guest\" role to terminate legitimate users' sessions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40568" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-693776.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-vvqg-cgqr-c8gc/GHSA-vvqg-cgqr-c8gc.json b/advisories/unreviewed/2025/06/GHSA-vvqg-cgqr-c8gc/GHSA-vvqg-cgqr-c8gc.json new file mode 100644 index 00000000000..67e6e723934 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-vvqg-cgqr-c8gc/GHSA-vvqg-cgqr-c8gc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vvqg-cgqr-c8gc", + "modified": "2025-06-10T18:32:29Z", + "published": "2025-06-10T18:32:29Z", + "aliases": [ + "CVE-2025-33075" + ], + "details": "Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to elevate privileges locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33075" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-33075" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:23:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-w4gj-hg5c-7gfx/GHSA-w4gj-hg5c-7gfx.json b/advisories/unreviewed/2025/06/GHSA-w4gj-hg5c-7gfx/GHSA-w4gj-hg5c-7gfx.json new file mode 100644 index 00000000000..31822c341fa --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-w4gj-hg5c-7gfx/GHSA-w4gj-hg5c-7gfx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w4gj-hg5c-7gfx", + "modified": "2025-06-10T18:32:29Z", + "published": "2025-06-10T18:32:29Z", + "aliases": [ + "CVE-2025-43589" + ], + "details": "InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43589" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/indesign/apsb25-53.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:23:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-w4jq-2vxf-ppgg/GHSA-w4jq-2vxf-ppgg.json b/advisories/unreviewed/2025/06/GHSA-w4jq-2vxf-ppgg/GHSA-w4jq-2vxf-ppgg.json new file mode 100644 index 00000000000..eef88f26209 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-w4jq-2vxf-ppgg/GHSA-w4jq-2vxf-ppgg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w4jq-2vxf-ppgg", + "modified": "2025-06-10T18:32:28Z", + "published": "2025-06-10T18:32:27Z", + "aliases": [ + "CVE-2025-30317" + ], + "details": "InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30317" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/indesign/apsb25-53.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:21:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-w6vw-7jjr-cmhh/GHSA-w6vw-7jjr-cmhh.json b/advisories/unreviewed/2025/06/GHSA-w6vw-7jjr-cmhh/GHSA-w6vw-7jjr-cmhh.json new file mode 100644 index 00000000000..1deaa022eb4 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-w6vw-7jjr-cmhh/GHSA-w6vw-7jjr-cmhh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w6vw-7jjr-cmhh", + "modified": "2025-06-10T18:32:31Z", + "published": "2025-06-10T18:32:31Z", + "aliases": [ + "CVE-2025-47957" + ], + "details": "Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47957" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47957" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:24:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-w7fw-3vx9-4jr9/GHSA-w7fw-3vx9-4jr9.json b/advisories/unreviewed/2025/06/GHSA-w7fw-3vx9-4jr9/GHSA-w7fw-3vx9-4jr9.json new file mode 100644 index 00000000000..1774ffa014d --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-w7fw-3vx9-4jr9/GHSA-w7fw-3vx9-4jr9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w7fw-3vx9-4jr9", + "modified": "2025-06-10T18:32:31Z", + "published": "2025-06-10T18:32:31Z", + "aliases": [ + "CVE-2025-47953" + ], + "details": "Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47953" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47953" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-641" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:24:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-w8fx-6j6j-879c/GHSA-w8fx-6j6j-879c.json b/advisories/unreviewed/2025/06/GHSA-w8fx-6j6j-879c/GHSA-w8fx-6j6j-879c.json new file mode 100644 index 00000000000..73dd4fd7ff4 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-w8fx-6j6j-879c/GHSA-w8fx-6j6j-879c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w8fx-6j6j-879c", + "modified": "2025-06-10T18:32:28Z", + "published": "2025-06-10T18:32:28Z", + "aliases": [ + "CVE-2025-33058" + ], + "details": "Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33058" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-33058" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:22:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-x74g-wm25-p2p5/GHSA-x74g-wm25-p2p5.json b/advisories/unreviewed/2025/06/GHSA-x74g-wm25-p2p5/GHSA-x74g-wm25-p2p5.json new file mode 100644 index 00000000000..ec403be920b --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-x74g-wm25-p2p5/GHSA-x74g-wm25-p2p5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x74g-wm25-p2p5", + "modified": "2025-06-10T18:32:29Z", + "published": "2025-06-10T18:32:29Z", + "aliases": [ + "CVE-2025-43593" + ], + "details": "InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43593" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/indesign/apsb25-53.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:23:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-x7v7-vjcv-xqj4/GHSA-x7v7-vjcv-xqj4.json b/advisories/unreviewed/2025/06/GHSA-x7v7-vjcv-xqj4/GHSA-x7v7-vjcv-xqj4.json new file mode 100644 index 00000000000..c0b0da84e0c --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-x7v7-vjcv-xqj4/GHSA-x7v7-vjcv-xqj4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x7v7-vjcv-xqj4", + "modified": "2025-06-10T18:32:26Z", + "published": "2025-06-10T18:32:26Z", + "aliases": [ + "CVE-2025-43586" + ], + "details": "Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access Control vulnerability that could result in privilege escalation. A low privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized elevated access. Exploitation of this issue does not require user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43586" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb25-50.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T16:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-xqjp-6x3w-8653/GHSA-xqjp-6x3w-8653.json b/advisories/unreviewed/2025/06/GHSA-xqjp-6x3w-8653/GHSA-xqjp-6x3w-8653.json new file mode 100644 index 00000000000..1b2066c135b --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-xqjp-6x3w-8653/GHSA-xqjp-6x3w-8653.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xqjp-6x3w-8653", + "modified": "2025-06-10T18:32:30Z", + "published": "2025-06-10T18:32:30Z", + "aliases": [ + "CVE-2025-47162" + ], + "details": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47162" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47162" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T17:23:26Z" + } +} \ No newline at end of file