From adb584b25ec0a85f724812c23fe310d5c0494e12 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 13 May 2025 00:32:21 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-cxqp-32c8-ch8c.json | 4 +- .../GHSA-r5xr-mfqp-qmrq.json | 4 +- .../GHSA-27f3-wjfj-399m.json | 15 +++-- .../GHSA-289j-qjv7-62fr.json | 49 ++++++++++++++++ .../GHSA-2fgw-qh65-pxv5.json | 37 ++++++++++++ .../GHSA-2xqw-mg48-p4j5.json | 37 ++++++++++++ .../GHSA-3jpv-h4fh-v8h9.json | 53 +++++++++++++++++ .../GHSA-422f-7vrg-37qx.json | 49 ++++++++++++++++ .../GHSA-53gq-27mh-rqhg.json | 53 +++++++++++++++++ .../GHSA-53jv-fmw5-42vr.json | 29 ++++++++++ .../GHSA-53qx-2hww-8c99.json | 37 ++++++++++++ .../GHSA-59ch-hp3c-w6qw.json | 57 +++++++++++++++++++ .../GHSA-5cxg-299x-c7pc.json | 15 +++-- .../GHSA-5f3f-773x-9jx9.json | 33 +++++++++++ .../GHSA-6mhh-cg8v-6pjf.json | 29 ++++++++++ .../GHSA-6q9m-6mf7-r8rx.json | 15 +++-- .../GHSA-7j7h-p7m5-p62q.json | 41 +++++++++++++ .../GHSA-7mch-v7x5-pxc4.json | 49 ++++++++++++++++ .../GHSA-7r5r-3362-27j8.json | 29 ++++++++++ .../GHSA-7x75-24xr-g7wf.json | 29 ++++++++++ .../GHSA-89f5-mmjh-cmgw.json | 57 +++++++++++++++++++ .../GHSA-8fqh-f3cp-hqjx.json | 15 +++-- .../GHSA-8r9h-wv72-5pmq.json | 40 +++++++++++++ .../GHSA-92r8-8gff-fhp3.json | 57 +++++++++++++++++++ .../GHSA-92vp-xx8f-fhpw.json | 33 +++++++++++ .../GHSA-98m8-9qp9-q867.json | 49 ++++++++++++++++ .../GHSA-9v48-2prj-rqc9.json | 57 +++++++++++++++++++ .../GHSA-9vv2-f3c8-m9x6.json | 15 +++-- .../GHSA-9vxc-6m6g-68f3.json | 37 ++++++++++++ .../GHSA-9wc3-7frf-f65v.json | 49 ++++++++++++++++ .../GHSA-c46v-w72p-r2mx.json | 57 +++++++++++++++++++ .../GHSA-c629-xm2q-h69v.json | 37 ++++++++++++ .../GHSA-cfhv-gvm8-4fxv.json | 15 +++-- .../GHSA-cp2m-j67p-96qc.json | 37 ++++++++++++ .../GHSA-f233-mjh6-2vxg.json | 37 ++++++++++++ .../GHSA-f2w6-r722-5fr8.json | 6 +- .../GHSA-f74c-m4cg-rgj3.json | 15 +++-- .../GHSA-fcrm-wvmg-6h7p.json | 57 +++++++++++++++++++ .../GHSA-fm6m-rfgf-h7gm.json | 37 ++++++++++++ .../GHSA-fp6q-7cxg-f24x.json | 53 +++++++++++++++++ .../GHSA-fppm-pf9p-6ph2.json | 49 ++++++++++++++++ .../GHSA-g47c-fvq8-4266.json | 37 ++++++++++++ .../GHSA-g988-pqhg-r7m5.json | 15 +++-- .../GHSA-gc4x-2qcw-h9vv.json | 57 +++++++++++++++++++ .../GHSA-gcw6-vg32-9cqw.json | 45 +++++++++++++++ .../GHSA-gp6q-p5qw-43q6.json | 15 +++-- .../GHSA-gphm-c4cj-h98g.json | 29 ++++++++++ .../GHSA-h347-278r-gx23.json | 33 +++++++++++ .../GHSA-h5hr-h582-r8wp.json | 33 +++++++++++ .../GHSA-h6hm-v4gg-9cgp.json | 29 ++++++++++ .../GHSA-h8j4-8q54-qmm9.json | 57 +++++++++++++++++++ .../GHSA-hhpv-c9vh-9v76.json | 57 +++++++++++++++++++ .../GHSA-hj49-gv4m-x7jm.json | 41 +++++++++++++ .../GHSA-hmx3-4jmc-jf5r.json | 29 ++++++++++ .../GHSA-hp57-25gh-2gjp.json | 11 +++- .../GHSA-j6wh-9fq4-rcrh.json | 41 +++++++++++++ .../GHSA-jfxw-jpwh-7j8j.json | 49 ++++++++++++++++ .../GHSA-jg4r-7hcf-wqjr.json | 29 ++++++++++ .../GHSA-jgxh-h9f6-9wh2.json | 49 ++++++++++++++++ .../GHSA-m53m-r8mm-799v.json | 15 +++-- .../GHSA-mv5r-fm5f-wm4v.json | 29 ++++++++++ .../GHSA-pc2j-fvgw-h6vh.json | 37 ++++++++++++ .../GHSA-pj3j-8874-c986.json | 15 +++-- .../GHSA-pmf4-qhrq-85qv.json | 15 +++-- .../GHSA-px42-xr3h-wjv8.json | 15 +++-- .../GHSA-q67x-mx4c-h9qv.json | 37 ++++++++++++ .../GHSA-qfr5-98gw-pmcj.json | 57 +++++++++++++++++++ .../GHSA-qvqh-wfm7-mh52.json | 29 ++++++++++ .../GHSA-r5x9-vf8c-hh3f.json | 29 ++++++++++ .../GHSA-rv3r-4pvf-f5pm.json | 29 ++++++++++ .../GHSA-rvh4-h7j5-46g3.json | 29 ++++++++++ .../GHSA-rwxj-39xx-47jr.json | 53 +++++++++++++++++ .../GHSA-rxjj-p248-4ffv.json | 15 +++-- .../GHSA-v2qw-mwg5-px4g.json | 33 +++++++++++ .../GHSA-v8vh-f89p-82w5.json | 29 ++++++++++ .../GHSA-vqww-7r9g-2fhx.json | 15 +++-- .../GHSA-w97v-vj4h-46rv.json | 29 ++++++++++ .../GHSA-whm5-2rx4-qhv5.json | 37 ++++++++++++ .../GHSA-wv7w-fgmw-6vg2.json | 53 +++++++++++++++++ .../GHSA-x3g7-56f2-8w33.json | 15 +++-- .../GHSA-x696-h3x7-xxjp.json | 29 ++++++++++ .../GHSA-x6ph-hgqm-c68g.json | 29 ++++++++++ .../GHSA-xf4q-c7gc-gpgr.json | 41 +++++++++++++ .../GHSA-xh5p-rm5r-7f82.json | 41 +++++++++++++ .../GHSA-xq63-2jcc-9gm3.json | 37 ++++++++++++ 85 files changed, 2850 insertions(+), 71 deletions(-) create mode 100644 advisories/unreviewed/2025/05/GHSA-289j-qjv7-62fr/GHSA-289j-qjv7-62fr.json create mode 100644 advisories/unreviewed/2025/05/GHSA-2fgw-qh65-pxv5/GHSA-2fgw-qh65-pxv5.json create mode 100644 advisories/unreviewed/2025/05/GHSA-2xqw-mg48-p4j5/GHSA-2xqw-mg48-p4j5.json create mode 100644 advisories/unreviewed/2025/05/GHSA-3jpv-h4fh-v8h9/GHSA-3jpv-h4fh-v8h9.json create mode 100644 advisories/unreviewed/2025/05/GHSA-422f-7vrg-37qx/GHSA-422f-7vrg-37qx.json create mode 100644 advisories/unreviewed/2025/05/GHSA-53gq-27mh-rqhg/GHSA-53gq-27mh-rqhg.json create mode 100644 advisories/unreviewed/2025/05/GHSA-53jv-fmw5-42vr/GHSA-53jv-fmw5-42vr.json create mode 100644 advisories/unreviewed/2025/05/GHSA-53qx-2hww-8c99/GHSA-53qx-2hww-8c99.json create mode 100644 advisories/unreviewed/2025/05/GHSA-59ch-hp3c-w6qw/GHSA-59ch-hp3c-w6qw.json create mode 100644 advisories/unreviewed/2025/05/GHSA-5f3f-773x-9jx9/GHSA-5f3f-773x-9jx9.json create mode 100644 advisories/unreviewed/2025/05/GHSA-6mhh-cg8v-6pjf/GHSA-6mhh-cg8v-6pjf.json create mode 100644 advisories/unreviewed/2025/05/GHSA-7j7h-p7m5-p62q/GHSA-7j7h-p7m5-p62q.json create mode 100644 advisories/unreviewed/2025/05/GHSA-7mch-v7x5-pxc4/GHSA-7mch-v7x5-pxc4.json create mode 100644 advisories/unreviewed/2025/05/GHSA-7r5r-3362-27j8/GHSA-7r5r-3362-27j8.json create mode 100644 advisories/unreviewed/2025/05/GHSA-7x75-24xr-g7wf/GHSA-7x75-24xr-g7wf.json create mode 100644 advisories/unreviewed/2025/05/GHSA-89f5-mmjh-cmgw/GHSA-89f5-mmjh-cmgw.json create mode 100644 advisories/unreviewed/2025/05/GHSA-8r9h-wv72-5pmq/GHSA-8r9h-wv72-5pmq.json create mode 100644 advisories/unreviewed/2025/05/GHSA-92r8-8gff-fhp3/GHSA-92r8-8gff-fhp3.json create mode 100644 advisories/unreviewed/2025/05/GHSA-92vp-xx8f-fhpw/GHSA-92vp-xx8f-fhpw.json create mode 100644 advisories/unreviewed/2025/05/GHSA-98m8-9qp9-q867/GHSA-98m8-9qp9-q867.json create mode 100644 advisories/unreviewed/2025/05/GHSA-9v48-2prj-rqc9/GHSA-9v48-2prj-rqc9.json create mode 100644 advisories/unreviewed/2025/05/GHSA-9vxc-6m6g-68f3/GHSA-9vxc-6m6g-68f3.json create mode 100644 advisories/unreviewed/2025/05/GHSA-9wc3-7frf-f65v/GHSA-9wc3-7frf-f65v.json create mode 100644 advisories/unreviewed/2025/05/GHSA-c46v-w72p-r2mx/GHSA-c46v-w72p-r2mx.json create mode 100644 advisories/unreviewed/2025/05/GHSA-c629-xm2q-h69v/GHSA-c629-xm2q-h69v.json create mode 100644 advisories/unreviewed/2025/05/GHSA-cp2m-j67p-96qc/GHSA-cp2m-j67p-96qc.json create mode 100644 advisories/unreviewed/2025/05/GHSA-f233-mjh6-2vxg/GHSA-f233-mjh6-2vxg.json create mode 100644 advisories/unreviewed/2025/05/GHSA-fcrm-wvmg-6h7p/GHSA-fcrm-wvmg-6h7p.json create mode 100644 advisories/unreviewed/2025/05/GHSA-fm6m-rfgf-h7gm/GHSA-fm6m-rfgf-h7gm.json create mode 100644 advisories/unreviewed/2025/05/GHSA-fp6q-7cxg-f24x/GHSA-fp6q-7cxg-f24x.json create mode 100644 advisories/unreviewed/2025/05/GHSA-fppm-pf9p-6ph2/GHSA-fppm-pf9p-6ph2.json create mode 100644 advisories/unreviewed/2025/05/GHSA-g47c-fvq8-4266/GHSA-g47c-fvq8-4266.json create mode 100644 advisories/unreviewed/2025/05/GHSA-gc4x-2qcw-h9vv/GHSA-gc4x-2qcw-h9vv.json create mode 100644 advisories/unreviewed/2025/05/GHSA-gcw6-vg32-9cqw/GHSA-gcw6-vg32-9cqw.json create mode 100644 advisories/unreviewed/2025/05/GHSA-gphm-c4cj-h98g/GHSA-gphm-c4cj-h98g.json create mode 100644 advisories/unreviewed/2025/05/GHSA-h347-278r-gx23/GHSA-h347-278r-gx23.json create mode 100644 advisories/unreviewed/2025/05/GHSA-h5hr-h582-r8wp/GHSA-h5hr-h582-r8wp.json create mode 100644 advisories/unreviewed/2025/05/GHSA-h6hm-v4gg-9cgp/GHSA-h6hm-v4gg-9cgp.json create mode 100644 advisories/unreviewed/2025/05/GHSA-h8j4-8q54-qmm9/GHSA-h8j4-8q54-qmm9.json create mode 100644 advisories/unreviewed/2025/05/GHSA-hhpv-c9vh-9v76/GHSA-hhpv-c9vh-9v76.json create mode 100644 advisories/unreviewed/2025/05/GHSA-hj49-gv4m-x7jm/GHSA-hj49-gv4m-x7jm.json create mode 100644 advisories/unreviewed/2025/05/GHSA-hmx3-4jmc-jf5r/GHSA-hmx3-4jmc-jf5r.json create mode 100644 advisories/unreviewed/2025/05/GHSA-j6wh-9fq4-rcrh/GHSA-j6wh-9fq4-rcrh.json create mode 100644 advisories/unreviewed/2025/05/GHSA-jfxw-jpwh-7j8j/GHSA-jfxw-jpwh-7j8j.json create mode 100644 advisories/unreviewed/2025/05/GHSA-jg4r-7hcf-wqjr/GHSA-jg4r-7hcf-wqjr.json create mode 100644 advisories/unreviewed/2025/05/GHSA-jgxh-h9f6-9wh2/GHSA-jgxh-h9f6-9wh2.json create mode 100644 advisories/unreviewed/2025/05/GHSA-mv5r-fm5f-wm4v/GHSA-mv5r-fm5f-wm4v.json create mode 100644 advisories/unreviewed/2025/05/GHSA-pc2j-fvgw-h6vh/GHSA-pc2j-fvgw-h6vh.json create mode 100644 advisories/unreviewed/2025/05/GHSA-q67x-mx4c-h9qv/GHSA-q67x-mx4c-h9qv.json create mode 100644 advisories/unreviewed/2025/05/GHSA-qfr5-98gw-pmcj/GHSA-qfr5-98gw-pmcj.json create mode 100644 advisories/unreviewed/2025/05/GHSA-qvqh-wfm7-mh52/GHSA-qvqh-wfm7-mh52.json create mode 100644 advisories/unreviewed/2025/05/GHSA-r5x9-vf8c-hh3f/GHSA-r5x9-vf8c-hh3f.json create mode 100644 advisories/unreviewed/2025/05/GHSA-rv3r-4pvf-f5pm/GHSA-rv3r-4pvf-f5pm.json create mode 100644 advisories/unreviewed/2025/05/GHSA-rvh4-h7j5-46g3/GHSA-rvh4-h7j5-46g3.json create mode 100644 advisories/unreviewed/2025/05/GHSA-rwxj-39xx-47jr/GHSA-rwxj-39xx-47jr.json create mode 100644 advisories/unreviewed/2025/05/GHSA-v2qw-mwg5-px4g/GHSA-v2qw-mwg5-px4g.json create mode 100644 advisories/unreviewed/2025/05/GHSA-v8vh-f89p-82w5/GHSA-v8vh-f89p-82w5.json create mode 100644 advisories/unreviewed/2025/05/GHSA-w97v-vj4h-46rv/GHSA-w97v-vj4h-46rv.json create mode 100644 advisories/unreviewed/2025/05/GHSA-whm5-2rx4-qhv5/GHSA-whm5-2rx4-qhv5.json create mode 100644 advisories/unreviewed/2025/05/GHSA-wv7w-fgmw-6vg2/GHSA-wv7w-fgmw-6vg2.json create mode 100644 advisories/unreviewed/2025/05/GHSA-x696-h3x7-xxjp/GHSA-x696-h3x7-xxjp.json create mode 100644 advisories/unreviewed/2025/05/GHSA-x6ph-hgqm-c68g/GHSA-x6ph-hgqm-c68g.json create mode 100644 advisories/unreviewed/2025/05/GHSA-xf4q-c7gc-gpgr/GHSA-xf4q-c7gc-gpgr.json create mode 100644 advisories/unreviewed/2025/05/GHSA-xh5p-rm5r-7f82/GHSA-xh5p-rm5r-7f82.json create mode 100644 advisories/unreviewed/2025/05/GHSA-xq63-2jcc-9gm3/GHSA-xq63-2jcc-9gm3.json diff --git a/advisories/unreviewed/2024/03/GHSA-cxqp-32c8-ch8c/GHSA-cxqp-32c8-ch8c.json b/advisories/unreviewed/2024/03/GHSA-cxqp-32c8-ch8c/GHSA-cxqp-32c8-ch8c.json index f109d253b36..7d30ac13720 100644 --- a/advisories/unreviewed/2024/03/GHSA-cxqp-32c8-ch8c/GHSA-cxqp-32c8-ch8c.json +++ b/advisories/unreviewed/2024/03/GHSA-cxqp-32c8-ch8c/GHSA-cxqp-32c8-ch8c.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-cxqp-32c8-ch8c", - "modified": "2024-03-20T15:32:57Z", + "modified": "2025-05-13T00:31:10Z", "published": "2024-03-20T15:32:57Z", "aliases": [ "CVE-2024-2721" ], - "details": "Deserialization of Untrusted Data vulnerability in Social Media Share Buttons By Sygnoos Social Media Share Buttons.This issue affects Social Media Share Buttons: from n/a through 2.1.0.\n\n", + "details": "Deserialization of Untrusted Data vulnerability in Social Media Share Buttons By Sygnoos Social Media Share Buttons.This issue affects Social Media Share Buttons: from n/a through 2.1.0.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-r5xr-mfqp-qmrq/GHSA-r5xr-mfqp-qmrq.json b/advisories/unreviewed/2024/03/GHSA-r5xr-mfqp-qmrq/GHSA-r5xr-mfqp-qmrq.json index b972034eaf8..a88e492ba5b 100644 --- a/advisories/unreviewed/2024/03/GHSA-r5xr-mfqp-qmrq/GHSA-r5xr-mfqp-qmrq.json +++ b/advisories/unreviewed/2024/03/GHSA-r5xr-mfqp-qmrq/GHSA-r5xr-mfqp-qmrq.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-27f3-wjfj-399m/GHSA-27f3-wjfj-399m.json b/advisories/unreviewed/2025/05/GHSA-27f3-wjfj-399m/GHSA-27f3-wjfj-399m.json index 11ffa74d825..f9ba1065737 100644 --- a/advisories/unreviewed/2025/05/GHSA-27f3-wjfj-399m/GHSA-27f3-wjfj-399m.json +++ b/advisories/unreviewed/2025/05/GHSA-27f3-wjfj-399m/GHSA-27f3-wjfj-399m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-27f3-wjfj-399m", - "modified": "2025-05-12T18:31:46Z", + "modified": "2025-05-13T00:31:12Z", "published": "2025-05-12T18:31:46Z", "aliases": [ "CVE-2025-45779" ], "details": "Tenda AC10 V1.0re_V15.03.06.46 is vulnerable to Buffer Overflow in the formSetPPTPUserList handler via the list POST parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T17:15:47Z" diff --git a/advisories/unreviewed/2025/05/GHSA-289j-qjv7-62fr/GHSA-289j-qjv7-62fr.json b/advisories/unreviewed/2025/05/GHSA-289j-qjv7-62fr/GHSA-289j-qjv7-62fr.json new file mode 100644 index 00000000000..3108801e866 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-289j-qjv7-62fr/GHSA-289j-qjv7-62fr.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-289j-qjv7-62fr", + "modified": "2025-05-13T00:31:15Z", + "published": "2025-05-13T00:31:15Z", + "aliases": [ + "CVE-2025-31257" + ], + "details": "This issue was addressed with improved memory handling. This issue is fixed in watchOS 11.5, tvOS 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, Safari 18.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31257" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122404" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122716" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122719" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122720" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122721" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122722" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2fgw-qh65-pxv5/GHSA-2fgw-qh65-pxv5.json b/advisories/unreviewed/2025/05/GHSA-2fgw-qh65-pxv5/GHSA-2fgw-qh65-pxv5.json new file mode 100644 index 00000000000..b0b75cf6c74 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2fgw-qh65-pxv5/GHSA-2fgw-qh65-pxv5.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2fgw-qh65-pxv5", + "modified": "2025-05-13T00:31:13Z", + "published": "2025-05-13T00:31:13Z", + "aliases": [ + "CVE-2025-30442" + ], + "details": "The issue was addressed with improved input sanitization. This issue is fixed in macOS Sequoia 15.4, macOS Ventura 13.7.6, macOS Sonoma 14.7.6. An app may be able to gain elevated privileges.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30442" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122717" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122718" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2xqw-mg48-p4j5/GHSA-2xqw-mg48-p4j5.json b/advisories/unreviewed/2025/05/GHSA-2xqw-mg48-p4j5/GHSA-2xqw-mg48-p4j5.json new file mode 100644 index 00000000000..c60c06df61f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2xqw-mg48-p4j5/GHSA-2xqw-mg48-p4j5.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2xqw-mg48-p4j5", + "modified": "2025-05-13T00:31:14Z", + "published": "2025-05-13T00:31:14Z", + "aliases": [ + "CVE-2025-31232" + ], + "details": "A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. A sandboxed app may be able to access sensitive user data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31232" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122716" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122717" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122718" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3jpv-h4fh-v8h9/GHSA-3jpv-h4fh-v8h9.json b/advisories/unreviewed/2025/05/GHSA-3jpv-h4fh-v8h9/GHSA-3jpv-h4fh-v8h9.json new file mode 100644 index 00000000000..a3e3f538ff8 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3jpv-h4fh-v8h9/GHSA-3jpv-h4fh-v8h9.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3jpv-h4fh-v8h9", + "modified": "2025-05-13T00:31:14Z", + "published": "2025-05-13T00:31:14Z", + "aliases": [ + "CVE-2025-31215" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in watchOS 11.5, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, Safari 18.5. Processing maliciously crafted web content may lead to an unexpected process crash.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31215" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122404" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122405" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122716" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122719" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122720" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122721" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122722" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-422f-7vrg-37qx/GHSA-422f-7vrg-37qx.json b/advisories/unreviewed/2025/05/GHSA-422f-7vrg-37qx/GHSA-422f-7vrg-37qx.json new file mode 100644 index 00000000000..d01ff8c6639 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-422f-7vrg-37qx/GHSA-422f-7vrg-37qx.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-422f-7vrg-37qx", + "modified": "2025-05-13T00:31:13Z", + "published": "2025-05-13T00:31:13Z", + "aliases": [ + "CVE-2025-30448" + ], + "details": "This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sonoma 14.7.6, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, visionOS 2.5, macOS Ventura 13.7.6, macOS Sequoia 15.4. An attacker may be able to turn on sharing of an iCloud folder without authentication.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30448" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122404" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122405" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122717" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122718" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122721" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-53gq-27mh-rqhg/GHSA-53gq-27mh-rqhg.json b/advisories/unreviewed/2025/05/GHSA-53gq-27mh-rqhg/GHSA-53gq-27mh-rqhg.json new file mode 100644 index 00000000000..9f0aa4d3aa3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-53gq-27mh-rqhg/GHSA-53gq-27mh-rqhg.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-53gq-27mh-rqhg", + "modified": "2025-05-13T00:31:14Z", + "published": "2025-05-13T00:31:14Z", + "aliases": [ + "CVE-2025-31222" + ], + "details": "A correctness issue was addressed with improved checks. This issue is fixed in watchOS 11.5, macOS Sonoma 14.7.6, tvOS 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, macOS Ventura 13.7.6. A user may be able to elevate privileges.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31222" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122404" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122716" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122717" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122718" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122720" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122721" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122722" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-53jv-fmw5-42vr/GHSA-53jv-fmw5-42vr.json b/advisories/unreviewed/2025/05/GHSA-53jv-fmw5-42vr/GHSA-53jv-fmw5-42vr.json new file mode 100644 index 00000000000..9c1a2acd6f4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-53jv-fmw5-42vr/GHSA-53jv-fmw5-42vr.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-53jv-fmw5-42vr", + "modified": "2025-05-13T00:31:15Z", + "published": "2025-05-13T00:31:15Z", + "aliases": [ + "CVE-2025-31250" + ], + "details": "An information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.5. An app may be able to access sensitive user data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31250" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122716" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-53qx-2hww-8c99/GHSA-53qx-2hww-8c99.json b/advisories/unreviewed/2025/05/GHSA-53qx-2hww-8c99/GHSA-53qx-2hww-8c99.json new file mode 100644 index 00000000000..290ea38b8ae --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-53qx-2hww-8c99/GHSA-53qx-2hww-8c99.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-53qx-2hww-8c99", + "modified": "2025-05-13T00:31:15Z", + "published": "2025-05-13T00:31:15Z", + "aliases": [ + "CVE-2025-31240" + ], + "details": "This issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. Mounting a maliciously crafted AFP network share may lead to system termination.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31240" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122716" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122717" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122718" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-59ch-hp3c-w6qw/GHSA-59ch-hp3c-w6qw.json b/advisories/unreviewed/2025/05/GHSA-59ch-hp3c-w6qw/GHSA-59ch-hp3c-w6qw.json new file mode 100644 index 00000000000..15d66a5a420 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-59ch-hp3c-w6qw/GHSA-59ch-hp3c-w6qw.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-59ch-hp3c-w6qw", + "modified": "2025-05-13T00:31:14Z", + "published": "2025-05-13T00:31:14Z", + "aliases": [ + "CVE-2025-31219" + ], + "details": "The issue was addressed with improved memory handling. This issue is fixed in watchOS 11.5, macOS Sonoma 14.7.6, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, macOS Ventura 13.7.6. An attacker may be able to cause unexpected system termination or corrupt kernel memory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31219" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122404" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122405" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122716" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122717" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122718" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122720" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122721" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122722" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5cxg-299x-c7pc/GHSA-5cxg-299x-c7pc.json b/advisories/unreviewed/2025/05/GHSA-5cxg-299x-c7pc/GHSA-5cxg-299x-c7pc.json index b85c12c5945..47a03f105a7 100644 --- a/advisories/unreviewed/2025/05/GHSA-5cxg-299x-c7pc/GHSA-5cxg-299x-c7pc.json +++ b/advisories/unreviewed/2025/05/GHSA-5cxg-299x-c7pc/GHSA-5cxg-299x-c7pc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5cxg-299x-c7pc", - "modified": "2025-05-12T18:31:45Z", + "modified": "2025-05-13T00:31:12Z", "published": "2025-05-12T18:31:45Z", "aliases": [ "CVE-2025-44022" ], "details": "An issue in vvveb CMS v.1.0.6 allows a remote attacker to execute arbitrary code via the Plugin mechanism.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T16:15:25Z" diff --git a/advisories/unreviewed/2025/05/GHSA-5f3f-773x-9jx9/GHSA-5f3f-773x-9jx9.json b/advisories/unreviewed/2025/05/GHSA-5f3f-773x-9jx9/GHSA-5f3f-773x-9jx9.json new file mode 100644 index 00000000000..923ed6ce79e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5f3f-773x-9jx9/GHSA-5f3f-773x-9jx9.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5f3f-773x-9jx9", + "modified": "2025-05-13T00:31:15Z", + "published": "2025-05-13T00:31:15Z", + "aliases": [ + "CVE-2025-31246" + ], + "details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6. Connecting to a malicious AFP server may corrupt kernel memory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31246" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122716" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122717" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6mhh-cg8v-6pjf/GHSA-6mhh-cg8v-6pjf.json b/advisories/unreviewed/2025/05/GHSA-6mhh-cg8v-6pjf/GHSA-6mhh-cg8v-6pjf.json new file mode 100644 index 00000000000..f74837a790b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6mhh-cg8v-6pjf/GHSA-6mhh-cg8v-6pjf.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6mhh-cg8v-6pjf", + "modified": "2025-05-13T00:31:14Z", + "published": "2025-05-13T00:31:14Z", + "aliases": [ + "CVE-2025-31225" + ], + "details": "A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 18.5 and iPadOS 18.5. Call history from deleted apps may still appear in spotlight search results.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31225" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122404" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6q9m-6mf7-r8rx/GHSA-6q9m-6mf7-r8rx.json b/advisories/unreviewed/2025/05/GHSA-6q9m-6mf7-r8rx/GHSA-6q9m-6mf7-r8rx.json index 95286cda2bf..26a089fc1e1 100644 --- a/advisories/unreviewed/2025/05/GHSA-6q9m-6mf7-r8rx/GHSA-6q9m-6mf7-r8rx.json +++ b/advisories/unreviewed/2025/05/GHSA-6q9m-6mf7-r8rx/GHSA-6q9m-6mf7-r8rx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6q9m-6mf7-r8rx", - "modified": "2025-05-12T18:31:45Z", + "modified": "2025-05-13T00:31:12Z", "published": "2025-05-12T18:31:45Z", "aliases": [ "CVE-2025-44830" ], "details": "EngineerCMS v1.02 through v.2.0.5 has a SQL injection vulnerability in the /project/addprojtemplet interface.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T16:15:25Z" diff --git a/advisories/unreviewed/2025/05/GHSA-7j7h-p7m5-p62q/GHSA-7j7h-p7m5-p62q.json b/advisories/unreviewed/2025/05/GHSA-7j7h-p7m5-p62q/GHSA-7j7h-p7m5-p62q.json new file mode 100644 index 00000000000..f378a6aa403 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7j7h-p7m5-p62q/GHSA-7j7h-p7m5-p62q.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7j7h-p7m5-p62q", + "modified": "2025-05-13T00:31:14Z", + "published": "2025-05-13T00:31:14Z", + "aliases": [ + "CVE-2025-31220" + ], + "details": "A privacy issue was addressed by removing sensitive data. This issue is fixed in iPadOS 17.7.7, macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. A malicious app may be able to read sensitive location information.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31220" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122405" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122716" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122717" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122718" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7mch-v7x5-pxc4/GHSA-7mch-v7x5-pxc4.json b/advisories/unreviewed/2025/05/GHSA-7mch-v7x5-pxc4/GHSA-7mch-v7x5-pxc4.json new file mode 100644 index 00000000000..39466793e32 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7mch-v7x5-pxc4/GHSA-7mch-v7x5-pxc4.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7mch-v7x5-pxc4", + "modified": "2025-05-13T00:31:12Z", + "published": "2025-05-13T00:31:12Z", + "aliases": [ + "CVE-2025-24223" + ], + "details": "The issue was addressed with improved memory handling. This issue is fixed in watchOS 11.5, tvOS 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, Safari 18.5. Processing maliciously crafted web content may lead to memory corruption.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24223" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122404" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122716" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122719" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122720" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122721" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122722" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7r5r-3362-27j8/GHSA-7r5r-3362-27j8.json b/advisories/unreviewed/2025/05/GHSA-7r5r-3362-27j8/GHSA-7r5r-3362-27j8.json new file mode 100644 index 00000000000..042715595d7 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7r5r-3362-27j8/GHSA-7r5r-3362-27j8.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7r5r-3362-27j8", + "modified": "2025-05-13T00:31:16Z", + "published": "2025-05-13T00:31:16Z", + "aliases": [ + "CVE-2025-31259" + ], + "details": "The issue was addressed with improved input sanitization. This issue is fixed in macOS Sequoia 15.5. An app may be able to gain elevated privileges.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31259" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122716" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7x75-24xr-g7wf/GHSA-7x75-24xr-g7wf.json b/advisories/unreviewed/2025/05/GHSA-7x75-24xr-g7wf/GHSA-7x75-24xr-g7wf.json new file mode 100644 index 00000000000..018d1b78e58 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7x75-24xr-g7wf/GHSA-7x75-24xr-g7wf.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7x75-24xr-g7wf", + "modified": "2025-05-13T00:31:15Z", + "published": "2025-05-13T00:31:15Z", + "aliases": [ + "CVE-2025-31236" + ], + "details": "An information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.5. An app may be able to access sensitive user data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31236" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122716" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-89f5-mmjh-cmgw/GHSA-89f5-mmjh-cmgw.json b/advisories/unreviewed/2025/05/GHSA-89f5-mmjh-cmgw/GHSA-89f5-mmjh-cmgw.json new file mode 100644 index 00000000000..639b2168616 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-89f5-mmjh-cmgw/GHSA-89f5-mmjh-cmgw.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-89f5-mmjh-cmgw", + "modified": "2025-05-13T00:31:14Z", + "published": "2025-05-13T00:31:14Z", + "aliases": [ + "CVE-2025-31233" + ], + "details": "The issue was addressed with improved input sanitization. This issue is fixed in watchOS 11.5, macOS Sonoma 14.7.6, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, macOS Ventura 13.7.6. Processing a maliciously crafted video file may lead to unexpected app termination or corrupt process memory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31233" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122404" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122405" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122716" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122717" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122718" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122720" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122721" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122722" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8fqh-f3cp-hqjx/GHSA-8fqh-f3cp-hqjx.json b/advisories/unreviewed/2025/05/GHSA-8fqh-f3cp-hqjx/GHSA-8fqh-f3cp-hqjx.json index f77ba6146ae..0ec3bdb6be8 100644 --- a/advisories/unreviewed/2025/05/GHSA-8fqh-f3cp-hqjx/GHSA-8fqh-f3cp-hqjx.json +++ b/advisories/unreviewed/2025/05/GHSA-8fqh-f3cp-hqjx/GHSA-8fqh-f3cp-hqjx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8fqh-f3cp-hqjx", - "modified": "2025-05-12T15:30:44Z", + "modified": "2025-05-13T00:31:12Z", "published": "2025-05-12T15:30:44Z", "aliases": [ "CVE-2025-46611" ], "details": "Cross Site Scripting vulnerability in ARTEC EMA Mail v6.92 allows an attacker to execute arbitrary code via a crafted script.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T15:16:01Z" diff --git a/advisories/unreviewed/2025/05/GHSA-8r9h-wv72-5pmq/GHSA-8r9h-wv72-5pmq.json b/advisories/unreviewed/2025/05/GHSA-8r9h-wv72-5pmq/GHSA-8r9h-wv72-5pmq.json new file mode 100644 index 00000000000..90b340cc648 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8r9h-wv72-5pmq/GHSA-8r9h-wv72-5pmq.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8r9h-wv72-5pmq", + "modified": "2025-05-13T00:31:16Z", + "published": "2025-05-13T00:31:16Z", + "aliases": [ + "CVE-2023-49641" + ], + "details": "Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the loginCheck.php resource does not validate the characters received and they are sent unfiltered to the database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49641" + }, + { + "type": "WEB", + "url": "https://fluidattacks.com/advisories/zimerman" + }, + { + "type": "WEB", + "url": "https://www.kashipara.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T00:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-92r8-8gff-fhp3/GHSA-92r8-8gff-fhp3.json b/advisories/unreviewed/2025/05/GHSA-92r8-8gff-fhp3/GHSA-92r8-8gff-fhp3.json new file mode 100644 index 00000000000..052920b2855 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-92r8-8gff-fhp3/GHSA-92r8-8gff-fhp3.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-92r8-8gff-fhp3", + "modified": "2025-05-13T00:31:13Z", + "published": "2025-05-13T00:31:13Z", + "aliases": [ + "CVE-2025-31208" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in watchOS 11.5, macOS Sonoma 14.7.6, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, macOS Ventura 13.7.6. Parsing a file may lead to an unexpected app termination.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31208" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122404" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122405" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122716" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122717" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122718" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122720" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122721" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122722" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-92vp-xx8f-fhpw/GHSA-92vp-xx8f-fhpw.json b/advisories/unreviewed/2025/05/GHSA-92vp-xx8f-fhpw/GHSA-92vp-xx8f-fhpw.json new file mode 100644 index 00000000000..52cfeb06de1 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-92vp-xx8f-fhpw/GHSA-92vp-xx8f-fhpw.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-92vp-xx8f-fhpw", + "modified": "2025-05-13T00:31:13Z", + "published": "2025-05-13T00:31:13Z", + "aliases": [ + "CVE-2025-31210" + ], + "details": "The issue was addressed with improved UI. This issue is fixed in iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5. Processing web content may lead to a denial-of-service.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31210" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122404" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122405" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-98m8-9qp9-q867/GHSA-98m8-9qp9-q867.json b/advisories/unreviewed/2025/05/GHSA-98m8-9qp9-q867/GHSA-98m8-9qp9-q867.json new file mode 100644 index 00000000000..1366d42cd3f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-98m8-9qp9-q867/GHSA-98m8-9qp9-q867.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-98m8-9qp9-q867", + "modified": "2025-05-13T00:31:14Z", + "published": "2025-05-13T00:31:14Z", + "aliases": [ + "CVE-2025-31226" + ], + "details": "A logic issue was addressed with improved checks. This issue is fixed in watchOS 11.5, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5. Processing a maliciously crafted image may lead to a denial-of-service.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31226" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122404" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122405" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122716" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122720" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122721" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122722" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9v48-2prj-rqc9/GHSA-9v48-2prj-rqc9.json b/advisories/unreviewed/2025/05/GHSA-9v48-2prj-rqc9/GHSA-9v48-2prj-rqc9.json new file mode 100644 index 00000000000..0a62be16cdc --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9v48-2prj-rqc9/GHSA-9v48-2prj-rqc9.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9v48-2prj-rqc9", + "modified": "2025-05-13T00:31:14Z", + "published": "2025-05-13T00:31:14Z", + "aliases": [ + "CVE-2025-31221" + ], + "details": "An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 11.5, macOS Sonoma 14.7.6, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, macOS Ventura 13.7.6. A remote attacker may be able to leak memory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31221" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122404" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122405" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122716" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122717" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122718" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122720" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122721" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122722" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9vv2-f3c8-m9x6/GHSA-9vv2-f3c8-m9x6.json b/advisories/unreviewed/2025/05/GHSA-9vv2-f3c8-m9x6/GHSA-9vv2-f3c8-m9x6.json index 030e0ad1fd8..b62f2d77034 100644 --- a/advisories/unreviewed/2025/05/GHSA-9vv2-f3c8-m9x6/GHSA-9vv2-f3c8-m9x6.json +++ b/advisories/unreviewed/2025/05/GHSA-9vv2-f3c8-m9x6/GHSA-9vv2-f3c8-m9x6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9vv2-f3c8-m9x6", - "modified": "2025-05-08T21:32:57Z", + "modified": "2025-05-13T00:31:10Z", "published": "2025-05-08T21:32:57Z", "aliases": [ "CVE-2025-28074" ], "details": "phpList prior to 3.6.3 is vulnerable to Cross-Site Scripting (XSS) due to improper input sanitization in lt.php. The vulnerability is exploitable when the application dynamically references internal paths and processes untrusted input without escaping, allowing an attacker to inject malicious JavaScript.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-08T21:15:50Z" diff --git a/advisories/unreviewed/2025/05/GHSA-9vxc-6m6g-68f3/GHSA-9vxc-6m6g-68f3.json b/advisories/unreviewed/2025/05/GHSA-9vxc-6m6g-68f3/GHSA-9vxc-6m6g-68f3.json new file mode 100644 index 00000000000..2b2e7e1ec14 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9vxc-6m6g-68f3/GHSA-9vxc-6m6g-68f3.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9vxc-6m6g-68f3", + "modified": "2025-05-13T00:31:12Z", + "published": "2025-05-13T00:31:12Z", + "aliases": [ + "CVE-2025-24142" + ], + "details": "A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. An app may be able to access sensitive user data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24142" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122716" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122717" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122718" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9wc3-7frf-f65v/GHSA-9wc3-7frf-f65v.json b/advisories/unreviewed/2025/05/GHSA-9wc3-7frf-f65v/GHSA-9wc3-7frf-f65v.json new file mode 100644 index 00000000000..9bb25bf0025 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9wc3-7frf-f65v/GHSA-9wc3-7frf-f65v.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9wc3-7frf-f65v", + "modified": "2025-05-13T00:31:13Z", + "published": "2025-05-13T00:31:13Z", + "aliases": [ + "CVE-2025-31204" + ], + "details": "The issue was addressed with improved memory handling. This issue is fixed in watchOS 11.5, tvOS 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, Safari 18.5. Processing maliciously crafted web content may lead to memory corruption.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31204" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122404" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122716" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122719" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122720" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122721" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122722" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c46v-w72p-r2mx/GHSA-c46v-w72p-r2mx.json b/advisories/unreviewed/2025/05/GHSA-c46v-w72p-r2mx/GHSA-c46v-w72p-r2mx.json new file mode 100644 index 00000000000..764773e187f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c46v-w72p-r2mx/GHSA-c46v-w72p-r2mx.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c46v-w72p-r2mx", + "modified": "2025-05-13T00:31:15Z", + "published": "2025-05-13T00:31:15Z", + "aliases": [ + "CVE-2025-31251" + ], + "details": "The issue was addressed with improved input sanitization. This issue is fixed in watchOS 11.5, macOS Sonoma 14.7.6, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, macOS Ventura 13.7.6. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31251" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122404" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122405" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122716" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122717" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122718" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122720" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122721" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122722" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c629-xm2q-h69v/GHSA-c629-xm2q-h69v.json b/advisories/unreviewed/2025/05/GHSA-c629-xm2q-h69v/GHSA-c629-xm2q-h69v.json new file mode 100644 index 00000000000..f5573c39584 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c629-xm2q-h69v/GHSA-c629-xm2q-h69v.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c629-xm2q-h69v", + "modified": "2025-05-13T00:31:13Z", + "published": "2025-05-13T00:31:13Z", + "aliases": [ + "CVE-2025-31196" + ], + "details": "An out-of-bounds read was addressed with improved input validation. This issue is fixed in iPadOS 17.7.7, macOS Ventura 13.7.6, macOS Sonoma 14.7.6. Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31196" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122405" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122717" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122718" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-cfhv-gvm8-4fxv/GHSA-cfhv-gvm8-4fxv.json b/advisories/unreviewed/2025/05/GHSA-cfhv-gvm8-4fxv/GHSA-cfhv-gvm8-4fxv.json index 4ec451f07ea..87caad82808 100644 --- a/advisories/unreviewed/2025/05/GHSA-cfhv-gvm8-4fxv/GHSA-cfhv-gvm8-4fxv.json +++ b/advisories/unreviewed/2025/05/GHSA-cfhv-gvm8-4fxv/GHSA-cfhv-gvm8-4fxv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cfhv-gvm8-4fxv", - "modified": "2025-05-09T15:31:43Z", + "modified": "2025-05-13T00:31:11Z", "published": "2025-05-09T15:31:43Z", "aliases": [ "CVE-2025-45885" ], "details": "PHPGURUKUL Vehicle Parking Management System v1.13 is vulnerable to SQL injection in the /vpms/users/login.php file. Attackers can inject malicious code from the parameter 'emailcont' and use it directly in SQL queries.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-09T14:15:37Z" diff --git a/advisories/unreviewed/2025/05/GHSA-cp2m-j67p-96qc/GHSA-cp2m-j67p-96qc.json b/advisories/unreviewed/2025/05/GHSA-cp2m-j67p-96qc/GHSA-cp2m-j67p-96qc.json new file mode 100644 index 00000000000..6affa499ef1 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-cp2m-j67p-96qc/GHSA-cp2m-j67p-96qc.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cp2m-j67p-96qc", + "modified": "2025-05-13T00:31:13Z", + "published": "2025-05-13T00:31:13Z", + "aliases": [ + "CVE-2025-30440" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. An app may be able to bypass ASLR.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30440" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122716" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122717" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122718" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-f233-mjh6-2vxg/GHSA-f233-mjh6-2vxg.json b/advisories/unreviewed/2025/05/GHSA-f233-mjh6-2vxg/GHSA-f233-mjh6-2vxg.json new file mode 100644 index 00000000000..d50e664fb83 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-f233-mjh6-2vxg/GHSA-f233-mjh6-2vxg.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f233-mjh6-2vxg", + "modified": "2025-05-13T00:31:15Z", + "published": "2025-05-13T00:31:15Z", + "aliases": [ + "CVE-2025-31237" + ], + "details": "This issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. Mounting a maliciously crafted AFP network share may lead to system termination.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31237" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122716" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122717" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122718" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-f2w6-r722-5fr8/GHSA-f2w6-r722-5fr8.json b/advisories/unreviewed/2025/05/GHSA-f2w6-r722-5fr8/GHSA-f2w6-r722-5fr8.json index a3178b1fc5c..130d52a4dbf 100644 --- a/advisories/unreviewed/2025/05/GHSA-f2w6-r722-5fr8/GHSA-f2w6-r722-5fr8.json +++ b/advisories/unreviewed/2025/05/GHSA-f2w6-r722-5fr8/GHSA-f2w6-r722-5fr8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f2w6-r722-5fr8", - "modified": "2025-05-09T21:31:19Z", + "modified": "2025-05-13T00:31:10Z", "published": "2025-05-07T18:30:50Z", "aliases": [ "CVE-2025-47203" @@ -30,6 +30,10 @@ { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2025/05/09/4" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/05/12/6" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/05/GHSA-f74c-m4cg-rgj3/GHSA-f74c-m4cg-rgj3.json b/advisories/unreviewed/2025/05/GHSA-f74c-m4cg-rgj3/GHSA-f74c-m4cg-rgj3.json index 79376bf0e13..b8ee04ad4e8 100644 --- a/advisories/unreviewed/2025/05/GHSA-f74c-m4cg-rgj3/GHSA-f74c-m4cg-rgj3.json +++ b/advisories/unreviewed/2025/05/GHSA-f74c-m4cg-rgj3/GHSA-f74c-m4cg-rgj3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f74c-m4cg-rgj3", - "modified": "2025-05-12T15:30:43Z", + "modified": "2025-05-13T00:31:11Z", "published": "2025-05-12T15:30:43Z", "aliases": [ "CVE-2024-56524" ], "details": "Radware Cloud Web Application Firewall (WAF) before 2025-05-07 allows remote attackers to bypass firewall filters by adding a special character to the request.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-116" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T15:15:58Z" diff --git a/advisories/unreviewed/2025/05/GHSA-fcrm-wvmg-6h7p/GHSA-fcrm-wvmg-6h7p.json b/advisories/unreviewed/2025/05/GHSA-fcrm-wvmg-6h7p/GHSA-fcrm-wvmg-6h7p.json new file mode 100644 index 00000000000..0d0e5f9f555 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fcrm-wvmg-6h7p/GHSA-fcrm-wvmg-6h7p.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fcrm-wvmg-6h7p", + "modified": "2025-05-13T00:31:13Z", + "published": "2025-05-13T00:31:13Z", + "aliases": [ + "CVE-2025-31209" + ], + "details": "An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in watchOS 11.5, macOS Sonoma 14.7.6, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, macOS Ventura 13.7.6. Parsing a file may lead to disclosure of user information.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31209" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122404" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122405" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122716" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122717" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122718" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122720" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122721" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122722" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fm6m-rfgf-h7gm/GHSA-fm6m-rfgf-h7gm.json b/advisories/unreviewed/2025/05/GHSA-fm6m-rfgf-h7gm/GHSA-fm6m-rfgf-h7gm.json new file mode 100644 index 00000000000..c56d33ee665 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fm6m-rfgf-h7gm/GHSA-fm6m-rfgf-h7gm.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fm6m-rfgf-h7gm", + "modified": "2025-05-13T00:31:15Z", + "published": "2025-05-13T00:31:15Z", + "aliases": [ + "CVE-2025-31247" + ], + "details": "A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. An attacker may gain access to protected parts of the file system.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31247" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122716" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122717" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122718" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fp6q-7cxg-f24x/GHSA-fp6q-7cxg-f24x.json b/advisories/unreviewed/2025/05/GHSA-fp6q-7cxg-f24x/GHSA-fp6q-7cxg-f24x.json new file mode 100644 index 00000000000..c6418ef512d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fp6q-7cxg-f24x/GHSA-fp6q-7cxg-f24x.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fp6q-7cxg-f24x", + "modified": "2025-05-13T00:31:14Z", + "published": "2025-05-13T00:31:14Z", + "aliases": [ + "CVE-2025-31217" + ], + "details": "The issue was addressed with improved input validation. This issue is fixed in watchOS 11.5, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, Safari 18.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31217" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122404" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122405" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122716" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122719" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122720" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122721" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122722" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fppm-pf9p-6ph2/GHSA-fppm-pf9p-6ph2.json b/advisories/unreviewed/2025/05/GHSA-fppm-pf9p-6ph2/GHSA-fppm-pf9p-6ph2.json new file mode 100644 index 00000000000..15301f06073 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fppm-pf9p-6ph2/GHSA-fppm-pf9p-6ph2.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fppm-pf9p-6ph2", + "modified": "2025-05-13T00:31:14Z", + "published": "2025-05-13T00:31:14Z", + "aliases": [ + "CVE-2025-31223" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in watchOS 11.5, tvOS 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, Safari 18.5. Processing maliciously crafted web content may lead to memory corruption.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31223" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122404" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122716" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122719" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122720" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122721" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122722" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g47c-fvq8-4266/GHSA-g47c-fvq8-4266.json b/advisories/unreviewed/2025/05/GHSA-g47c-fvq8-4266/GHSA-g47c-fvq8-4266.json new file mode 100644 index 00000000000..36b44e7904a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g47c-fvq8-4266/GHSA-g47c-fvq8-4266.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g47c-fvq8-4266", + "modified": "2025-05-13T00:31:12Z", + "published": "2025-05-13T00:31:12Z", + "aliases": [ + "CVE-2025-24155" + ], + "details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3, macOS Ventura 13.7.6, macOS Sonoma 14.7.6. An app may be able to disclose kernel memory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24155" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122717" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122718" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g988-pqhg-r7m5/GHSA-g988-pqhg-r7m5.json b/advisories/unreviewed/2025/05/GHSA-g988-pqhg-r7m5/GHSA-g988-pqhg-r7m5.json index c96f325bc79..2f027f83057 100644 --- a/advisories/unreviewed/2025/05/GHSA-g988-pqhg-r7m5/GHSA-g988-pqhg-r7m5.json +++ b/advisories/unreviewed/2025/05/GHSA-g988-pqhg-r7m5/GHSA-g988-pqhg-r7m5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g988-pqhg-r7m5", - "modified": "2025-05-12T15:30:44Z", + "modified": "2025-05-13T00:31:11Z", "published": "2025-05-12T15:30:44Z", "aliases": [ "CVE-2025-26841" ], "details": "Cross Site Scripting vulnerability in WPEVEREST Everest Forms before 3.0.9 allows an attacker to execute arbitrary code via a file upload.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T15:15:59Z" diff --git a/advisories/unreviewed/2025/05/GHSA-gc4x-2qcw-h9vv/GHSA-gc4x-2qcw-h9vv.json b/advisories/unreviewed/2025/05/GHSA-gc4x-2qcw-h9vv/GHSA-gc4x-2qcw-h9vv.json new file mode 100644 index 00000000000..2c864e23871 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gc4x-2qcw-h9vv/GHSA-gc4x-2qcw-h9vv.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gc4x-2qcw-h9vv", + "modified": "2025-05-13T00:31:12Z", + "published": "2025-05-13T00:31:12Z", + "aliases": [ + "CVE-2025-24111" + ], + "details": "A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.3, visionOS 2.3, iPadOS 17.7.7, watchOS 11.3, macOS Sonoma 14.7.5, iOS 18.3 and iPadOS 18.3, tvOS 18.3, macOS Ventura 13.7.5. An app may be able to cause unexpected system termination.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24111" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122066" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122071" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122072" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122073" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122405" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gcw6-vg32-9cqw/GHSA-gcw6-vg32-9cqw.json b/advisories/unreviewed/2025/05/GHSA-gcw6-vg32-9cqw/GHSA-gcw6-vg32-9cqw.json new file mode 100644 index 00000000000..2a692ecb494 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gcw6-vg32-9cqw/GHSA-gcw6-vg32-9cqw.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gcw6-vg32-9cqw", + "modified": "2025-05-13T00:31:13Z", + "published": "2025-05-13T00:31:13Z", + "aliases": [ + "CVE-2025-31212" + ], + "details": "This issue was addressed through improved state management. This issue is fixed in watchOS 11.5, tvOS 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5. An app may be able to access sensitive user data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31212" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122404" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122716" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122720" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122721" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122722" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gp6q-p5qw-43q6/GHSA-gp6q-p5qw-43q6.json b/advisories/unreviewed/2025/05/GHSA-gp6q-p5qw-43q6/GHSA-gp6q-p5qw-43q6.json index 27cb7a04287..bee78cca36a 100644 --- a/advisories/unreviewed/2025/05/GHSA-gp6q-p5qw-43q6/GHSA-gp6q-p5qw-43q6.json +++ b/advisories/unreviewed/2025/05/GHSA-gp6q-p5qw-43q6/GHSA-gp6q-p5qw-43q6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gp6q-p5qw-43q6", - "modified": "2025-05-12T15:30:42Z", + "modified": "2025-05-13T00:31:11Z", "published": "2025-05-12T15:30:42Z", "aliases": [ "CVE-2025-45835" ], "details": "A null pointer dereference vulnerability was discovered in Netis WF2880 v2.1.40207. The vulnerability exists in the FUN_004904c8 function of the cgitest.cgi file. Attackers can trigger this vulnerability by controlling the environment variable value CONTENT_LENGTH, causing the program to crash and potentially leading to a denial-of-service (DoS) attack.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T14:15:26Z" diff --git a/advisories/unreviewed/2025/05/GHSA-gphm-c4cj-h98g/GHSA-gphm-c4cj-h98g.json b/advisories/unreviewed/2025/05/GHSA-gphm-c4cj-h98g/GHSA-gphm-c4cj-h98g.json new file mode 100644 index 00000000000..1a4a82b18fc --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gphm-c4cj-h98g/GHSA-gphm-c4cj-h98g.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gphm-c4cj-h98g", + "modified": "2025-05-13T00:31:14Z", + "published": "2025-05-13T00:31:14Z", + "aliases": [ + "CVE-2025-31227" + ], + "details": "A logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5. An attacker with physical access to a device may be able to access a deleted call recording.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31227" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122404" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h347-278r-gx23/GHSA-h347-278r-gx23.json b/advisories/unreviewed/2025/05/GHSA-h347-278r-gx23/GHSA-h347-278r-gx23.json new file mode 100644 index 00000000000..b90a2c49fad --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h347-278r-gx23/GHSA-h347-278r-gx23.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h347-278r-gx23", + "modified": "2025-05-13T00:31:12Z", + "published": "2025-05-13T00:31:12Z", + "aliases": [ + "CVE-2025-24225" + ], + "details": "An injection issue was addressed with improved input validation. This issue is fixed in iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5. Processing an email may lead to user interface spoofing.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24225" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122404" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122405" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h5hr-h582-r8wp/GHSA-h5hr-h582-r8wp.json b/advisories/unreviewed/2025/05/GHSA-h5hr-h582-r8wp/GHSA-h5hr-h582-r8wp.json new file mode 100644 index 00000000000..ecbd1ff7b31 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h5hr-h582-r8wp/GHSA-h5hr-h582-r8wp.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h5hr-h582-r8wp", + "modified": "2025-05-13T00:31:14Z", + "published": "2025-05-13T00:31:14Z", + "aliases": [ + "CVE-2025-31228" + ], + "details": "The issue was addressed with improved authentication. This issue is fixed in iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5. An attacker with physical access to a device may be able to access notes from the lock screen.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31228" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122404" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122405" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h6hm-v4gg-9cgp/GHSA-h6hm-v4gg-9cgp.json b/advisories/unreviewed/2025/05/GHSA-h6hm-v4gg-9cgp/GHSA-h6hm-v4gg-9cgp.json new file mode 100644 index 00000000000..efebbb4ff70 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h6hm-v4gg-9cgp/GHSA-h6hm-v4gg-9cgp.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h6hm-v4gg-9cgp", + "modified": "2025-05-13T00:31:12Z", + "published": "2025-05-13T00:31:12Z", + "aliases": [ + "CVE-2025-30436" + ], + "details": "This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.4 and iPadOS 18.4. An attacker may be able to use Siri to enable Auto-Answer Calls.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30436" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h8j4-8q54-qmm9/GHSA-h8j4-8q54-qmm9.json b/advisories/unreviewed/2025/05/GHSA-h8j4-8q54-qmm9/GHSA-h8j4-8q54-qmm9.json new file mode 100644 index 00000000000..27690ef9353 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h8j4-8q54-qmm9/GHSA-h8j4-8q54-qmm9.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h8j4-8q54-qmm9", + "modified": "2025-05-13T00:31:12Z", + "published": "2025-05-13T00:31:12Z", + "aliases": [ + "CVE-2025-24144" + ], + "details": "An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.6, visionOS 2.3, iPadOS 17.7.7, watchOS 11.3, macOS Ventura 13.7.6, iOS 18.3 and iPadOS 18.3, tvOS 18.3. An app may be able to leak sensitive kernel state.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24144" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122066" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122071" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122072" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122073" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122405" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122717" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122718" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hhpv-c9vh-9v76/GHSA-hhpv-c9vh-9v76.json b/advisories/unreviewed/2025/05/GHSA-hhpv-c9vh-9v76/GHSA-hhpv-c9vh-9v76.json new file mode 100644 index 00000000000..89465b35697 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hhpv-c9vh-9v76/GHSA-hhpv-c9vh-9v76.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hhpv-c9vh-9v76", + "modified": "2025-05-13T00:31:15Z", + "published": "2025-05-13T00:31:15Z", + "aliases": [ + "CVE-2025-31241" + ], + "details": "A double free issue was addressed with improved memory management. This issue is fixed in watchOS 11.5, macOS Sonoma 14.7.6, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, macOS Ventura 13.7.6. A remote attacker may cause an unexpected app termination.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31241" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122404" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122405" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122716" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122717" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122718" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122720" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122721" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122722" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hj49-gv4m-x7jm/GHSA-hj49-gv4m-x7jm.json b/advisories/unreviewed/2025/05/GHSA-hj49-gv4m-x7jm/GHSA-hj49-gv4m-x7jm.json new file mode 100644 index 00000000000..171de4b3b10 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hj49-gv4m-x7jm/GHSA-hj49-gv4m-x7jm.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hj49-gv4m-x7jm", + "modified": "2025-05-13T00:31:13Z", + "published": "2025-05-13T00:31:13Z", + "aliases": [ + "CVE-2025-31213" + ], + "details": "A logging issue was addressed with improved data redaction. This issue is fixed in iPadOS 17.7.7, macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. An app may be able to access associated usernames and websites in a user's iCloud Keychain.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31213" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122405" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122716" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122717" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122718" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hmx3-4jmc-jf5r/GHSA-hmx3-4jmc-jf5r.json b/advisories/unreviewed/2025/05/GHSA-hmx3-4jmc-jf5r/GHSA-hmx3-4jmc-jf5r.json new file mode 100644 index 00000000000..fe73696fd63 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hmx3-4jmc-jf5r/GHSA-hmx3-4jmc-jf5r.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hmx3-4jmc-jf5r", + "modified": "2025-05-13T00:31:15Z", + "published": "2025-05-13T00:31:15Z", + "aliases": [ + "CVE-2025-31258" + ], + "details": "This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.5. An app may be able to break out of its sandbox.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31258" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122716" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hp57-25gh-2gjp/GHSA-hp57-25gh-2gjp.json b/advisories/unreviewed/2025/05/GHSA-hp57-25gh-2gjp/GHSA-hp57-25gh-2gjp.json index ba893bf84b0..d5774638eb6 100644 --- a/advisories/unreviewed/2025/05/GHSA-hp57-25gh-2gjp/GHSA-hp57-25gh-2gjp.json +++ b/advisories/unreviewed/2025/05/GHSA-hp57-25gh-2gjp/GHSA-hp57-25gh-2gjp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hp57-25gh-2gjp", - "modified": "2025-05-09T15:31:43Z", + "modified": "2025-05-13T00:31:11Z", "published": "2025-05-09T15:31:43Z", "aliases": [ "CVE-2024-11861" ], "details": "EnerSys AMPA 22.09 and prior versions are vulnerable to command injection leading to privileged remote shell access.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-77" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-09T14:15:36Z" diff --git a/advisories/unreviewed/2025/05/GHSA-j6wh-9fq4-rcrh/GHSA-j6wh-9fq4-rcrh.json b/advisories/unreviewed/2025/05/GHSA-j6wh-9fq4-rcrh/GHSA-j6wh-9fq4-rcrh.json new file mode 100644 index 00000000000..15d95458d8d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-j6wh-9fq4-rcrh/GHSA-j6wh-9fq4-rcrh.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6wh-9fq4-rcrh", + "modified": "2025-05-13T00:31:15Z", + "published": "2025-05-13T00:31:15Z", + "aliases": [ + "CVE-2025-31234" + ], + "details": "The issue was addressed with improved input sanitization. This issue is fixed in visionOS 2.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5. An attacker may be able to cause unexpected system termination or corrupt kernel memory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31234" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122404" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122716" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122720" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122721" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jfxw-jpwh-7j8j/GHSA-jfxw-jpwh-7j8j.json b/advisories/unreviewed/2025/05/GHSA-jfxw-jpwh-7j8j/GHSA-jfxw-jpwh-7j8j.json new file mode 100644 index 00000000000..91ef712d5ce --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jfxw-jpwh-7j8j/GHSA-jfxw-jpwh-7j8j.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jfxw-jpwh-7j8j", + "modified": "2025-05-13T00:31:13Z", + "published": "2025-05-13T00:31:13Z", + "aliases": [ + "CVE-2025-31205" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in watchOS 11.5, tvOS 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, Safari 18.5. A malicious website may exfiltrate data cross-origin.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31205" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122404" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122716" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122719" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122720" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122721" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122722" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jg4r-7hcf-wqjr/GHSA-jg4r-7hcf-wqjr.json b/advisories/unreviewed/2025/05/GHSA-jg4r-7hcf-wqjr/GHSA-jg4r-7hcf-wqjr.json new file mode 100644 index 00000000000..79a4600c3de --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jg4r-7hcf-wqjr/GHSA-jg4r-7hcf-wqjr.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jg4r-7hcf-wqjr", + "modified": "2025-05-13T00:31:15Z", + "published": "2025-05-13T00:31:15Z", + "aliases": [ + "CVE-2025-31253" + ], + "details": "This issue was addressed through improved state management. This issue is fixed in iOS 18.5 and iPadOS 18.5. Muting the microphone during a FaceTime call may not result in audio being silenced.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31253" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122404" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jgxh-h9f6-9wh2/GHSA-jgxh-h9f6-9wh2.json b/advisories/unreviewed/2025/05/GHSA-jgxh-h9f6-9wh2/GHSA-jgxh-h9f6-9wh2.json new file mode 100644 index 00000000000..e9bf7d7758d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jgxh-h9f6-9wh2/GHSA-jgxh-h9f6-9wh2.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jgxh-h9f6-9wh2", + "modified": "2025-05-13T00:31:15Z", + "published": "2025-05-13T00:31:15Z", + "aliases": [ + "CVE-2025-31238" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in watchOS 11.5, tvOS 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, Safari 18.5. Processing maliciously crafted web content may lead to memory corruption.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31238" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122404" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122716" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122719" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122720" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122721" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122722" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-m53m-r8mm-799v/GHSA-m53m-r8mm-799v.json b/advisories/unreviewed/2025/05/GHSA-m53m-r8mm-799v/GHSA-m53m-r8mm-799v.json index a056bea89ed..333a5398b09 100644 --- a/advisories/unreviewed/2025/05/GHSA-m53m-r8mm-799v/GHSA-m53m-r8mm-799v.json +++ b/advisories/unreviewed/2025/05/GHSA-m53m-r8mm-799v/GHSA-m53m-r8mm-799v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m53m-r8mm-799v", - "modified": "2025-05-12T15:30:44Z", + "modified": "2025-05-13T00:31:11Z", "published": "2025-05-12T15:30:44Z", "aliases": [ "CVE-2025-26846" ], "details": "An issue was discovered in Znuny before 7.1.4. Permissions are not checked properly when using the Generic Interface to update ticket metadata.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-862" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T15:15:59Z" diff --git a/advisories/unreviewed/2025/05/GHSA-mv5r-fm5f-wm4v/GHSA-mv5r-fm5f-wm4v.json b/advisories/unreviewed/2025/05/GHSA-mv5r-fm5f-wm4v/GHSA-mv5r-fm5f-wm4v.json new file mode 100644 index 00000000000..227bf83c817 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mv5r-fm5f-wm4v/GHSA-mv5r-fm5f-wm4v.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mv5r-fm5f-wm4v", + "modified": "2025-05-13T00:31:13Z", + "published": "2025-05-13T00:31:13Z", + "aliases": [ + "CVE-2025-31195" + ], + "details": "The issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.4. An app may be able to break out of its sandbox.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31195" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-pc2j-fvgw-h6vh/GHSA-pc2j-fvgw-h6vh.json b/advisories/unreviewed/2025/05/GHSA-pc2j-fvgw-h6vh/GHSA-pc2j-fvgw-h6vh.json new file mode 100644 index 00000000000..c85d38db5a4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pc2j-fvgw-h6vh/GHSA-pc2j-fvgw-h6vh.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pc2j-fvgw-h6vh", + "modified": "2025-05-13T00:31:13Z", + "published": "2025-05-13T00:31:13Z", + "aliases": [ + "CVE-2025-30453" + ], + "details": "The issue was addressed with additional permissions checks. This issue is fixed in macOS Sequoia 15.4, macOS Ventura 13.7.6, macOS Sonoma 14.7.6. A malicious app may be able to gain root privileges.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30453" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122717" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122718" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-pj3j-8874-c986/GHSA-pj3j-8874-c986.json b/advisories/unreviewed/2025/05/GHSA-pj3j-8874-c986/GHSA-pj3j-8874-c986.json index ca4f44716dd..056f6c1aa91 100644 --- a/advisories/unreviewed/2025/05/GHSA-pj3j-8874-c986/GHSA-pj3j-8874-c986.json +++ b/advisories/unreviewed/2025/05/GHSA-pj3j-8874-c986/GHSA-pj3j-8874-c986.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pj3j-8874-c986", - "modified": "2025-05-09T18:30:38Z", + "modified": "2025-05-13T00:31:11Z", "published": "2025-05-09T18:30:38Z", "aliases": [ "CVE-2025-46193" ], "details": "SourceCodester Client Database Management System 1.0 is vulnerable to Remote code execution via Arbitrary file upload in user_proposal_update_order.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-09T16:15:25Z" diff --git a/advisories/unreviewed/2025/05/GHSA-pmf4-qhrq-85qv/GHSA-pmf4-qhrq-85qv.json b/advisories/unreviewed/2025/05/GHSA-pmf4-qhrq-85qv/GHSA-pmf4-qhrq-85qv.json index d89f36b55fb..c50aba6b308 100644 --- a/advisories/unreviewed/2025/05/GHSA-pmf4-qhrq-85qv/GHSA-pmf4-qhrq-85qv.json +++ b/advisories/unreviewed/2025/05/GHSA-pmf4-qhrq-85qv/GHSA-pmf4-qhrq-85qv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pmf4-qhrq-85qv", - "modified": "2025-05-12T15:30:42Z", + "modified": "2025-05-13T00:31:11Z", "published": "2025-05-12T15:30:42Z", "aliases": [ "CVE-2024-56523" ], "details": "Radware Cloud Web Application Firewall (WAF) before 2025-05-07 allows remote attackers to bypass firewall filters by placing random data in the HTTP request body when using the HTTP GET method.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-444" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T15:15:58Z" diff --git a/advisories/unreviewed/2025/05/GHSA-px42-xr3h-wjv8/GHSA-px42-xr3h-wjv8.json b/advisories/unreviewed/2025/05/GHSA-px42-xr3h-wjv8/GHSA-px42-xr3h-wjv8.json index 9b18d772b43..1d85d360779 100644 --- a/advisories/unreviewed/2025/05/GHSA-px42-xr3h-wjv8/GHSA-px42-xr3h-wjv8.json +++ b/advisories/unreviewed/2025/05/GHSA-px42-xr3h-wjv8/GHSA-px42-xr3h-wjv8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-px42-xr3h-wjv8", - "modified": "2025-05-09T15:31:43Z", + "modified": "2025-05-13T00:31:11Z", "published": "2025-05-09T15:31:43Z", "aliases": [ "CVE-2025-45887" ], "details": "Yifang CMS v2.0.2 is vulnerable to Server-Side Request Forgery (SSRF) in /api/file/getRemoteContent.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-918" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-09T15:15:57Z" diff --git a/advisories/unreviewed/2025/05/GHSA-q67x-mx4c-h9qv/GHSA-q67x-mx4c-h9qv.json b/advisories/unreviewed/2025/05/GHSA-q67x-mx4c-h9qv/GHSA-q67x-mx4c-h9qv.json new file mode 100644 index 00000000000..d2abcee965a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q67x-mx4c-h9qv/GHSA-q67x-mx4c-h9qv.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q67x-mx4c-h9qv", + "modified": "2025-05-13T00:31:12Z", + "published": "2025-05-13T00:31:12Z", + "aliases": [ + "CVE-2025-24274" + ], + "details": "An input validation issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. A malicious app may be able to gain root privileges.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24274" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122716" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122717" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122718" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qfr5-98gw-pmcj/GHSA-qfr5-98gw-pmcj.json b/advisories/unreviewed/2025/05/GHSA-qfr5-98gw-pmcj/GHSA-qfr5-98gw-pmcj.json new file mode 100644 index 00000000000..d87c1d7fd33 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qfr5-98gw-pmcj/GHSA-qfr5-98gw-pmcj.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qfr5-98gw-pmcj", + "modified": "2025-05-13T00:31:15Z", + "published": "2025-05-13T00:31:15Z", + "aliases": [ + "CVE-2025-31239" + ], + "details": "A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 11.5, macOS Sonoma 14.7.6, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, macOS Ventura 13.7.6. Parsing a file may lead to an unexpected app termination.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31239" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122404" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122405" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122716" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122717" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122718" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122720" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122721" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122722" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qvqh-wfm7-mh52/GHSA-qvqh-wfm7-mh52.json b/advisories/unreviewed/2025/05/GHSA-qvqh-wfm7-mh52/GHSA-qvqh-wfm7-mh52.json new file mode 100644 index 00000000000..d2d18709b17 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qvqh-wfm7-mh52/GHSA-qvqh-wfm7-mh52.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qvqh-wfm7-mh52", + "modified": "2025-05-13T00:31:12Z", + "published": "2025-05-13T00:31:12Z", + "aliases": [ + "CVE-2025-24222" + ], + "details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.5. Processing maliciously crafted web content may lead to an unexpected process crash.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24222" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122716" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-r5x9-vf8c-hh3f/GHSA-r5x9-vf8c-hh3f.json b/advisories/unreviewed/2025/05/GHSA-r5x9-vf8c-hh3f/GHSA-r5x9-vf8c-hh3f.json new file mode 100644 index 00000000000..a49b26f0fae --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-r5x9-vf8c-hh3f/GHSA-r5x9-vf8c-hh3f.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r5x9-vf8c-hh3f", + "modified": "2025-05-13T00:31:16Z", + "published": "2025-05-13T00:31:16Z", + "aliases": [ + "CVE-2025-31260" + ], + "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.5. An app may be able to access sensitive user data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31260" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122716" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rv3r-4pvf-f5pm/GHSA-rv3r-4pvf-f5pm.json b/advisories/unreviewed/2025/05/GHSA-rv3r-4pvf-f5pm/GHSA-rv3r-4pvf-f5pm.json new file mode 100644 index 00000000000..fb30e884fae --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rv3r-4pvf-f5pm/GHSA-rv3r-4pvf-f5pm.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rv3r-4pvf-f5pm", + "modified": "2025-05-13T00:31:15Z", + "published": "2025-05-13T00:31:15Z", + "aliases": [ + "CVE-2025-31249" + ], + "details": "A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5. An app may be able to access sensitive user data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31249" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122716" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rvh4-h7j5-46g3/GHSA-rvh4-h7j5-46g3.json b/advisories/unreviewed/2025/05/GHSA-rvh4-h7j5-46g3/GHSA-rvh4-h7j5-46g3.json new file mode 100644 index 00000000000..b0459ae3582 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rvh4-h7j5-46g3/GHSA-rvh4-h7j5-46g3.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rvh4-h7j5-46g3", + "modified": "2025-05-13T00:31:15Z", + "published": "2025-05-13T00:31:15Z", + "aliases": [ + "CVE-2025-31256" + ], + "details": "The issue was addressed with improved handling of caches. This issue is fixed in macOS Sequoia 15.5. Hot corner may unexpectedly reveal a user’s deleted notes.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31256" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122716" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rwxj-39xx-47jr/GHSA-rwxj-39xx-47jr.json b/advisories/unreviewed/2025/05/GHSA-rwxj-39xx-47jr/GHSA-rwxj-39xx-47jr.json new file mode 100644 index 00000000000..683864ba3bf --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rwxj-39xx-47jr/GHSA-rwxj-39xx-47jr.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rwxj-39xx-47jr", + "modified": "2025-05-13T00:31:15Z", + "published": "2025-05-13T00:31:15Z", + "aliases": [ + "CVE-2025-31245" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.7.6, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, macOS Ventura 13.7.6. An app may be able to cause unexpected system termination.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31245" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122404" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122405" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122716" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122717" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122718" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122720" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122721" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rxjj-p248-4ffv/GHSA-rxjj-p248-4ffv.json b/advisories/unreviewed/2025/05/GHSA-rxjj-p248-4ffv/GHSA-rxjj-p248-4ffv.json index ab2f99aaeb6..62d01655b0c 100644 --- a/advisories/unreviewed/2025/05/GHSA-rxjj-p248-4ffv/GHSA-rxjj-p248-4ffv.json +++ b/advisories/unreviewed/2025/05/GHSA-rxjj-p248-4ffv/GHSA-rxjj-p248-4ffv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rxjj-p248-4ffv", - "modified": "2025-05-08T21:32:57Z", + "modified": "2025-05-13T00:31:10Z", "published": "2025-05-08T21:32:57Z", "aliases": [ "CVE-2023-31585" ], "details": "Grocery-CMS-PHP-Restful-API v1.3 is vulnerable to File Upload via /admin/add-category.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-08T21:15:49Z" diff --git a/advisories/unreviewed/2025/05/GHSA-v2qw-mwg5-px4g/GHSA-v2qw-mwg5-px4g.json b/advisories/unreviewed/2025/05/GHSA-v2qw-mwg5-px4g/GHSA-v2qw-mwg5-px4g.json new file mode 100644 index 00000000000..974746eb5f2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v2qw-mwg5-px4g/GHSA-v2qw-mwg5-px4g.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v2qw-mwg5-px4g", + "modified": "2025-05-13T00:31:12Z", + "published": "2025-05-13T00:31:12Z", + "aliases": [ + "CVE-2025-24220" + ], + "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in iPadOS 17.7.7, iOS 18.4 and iPadOS 18.4. An app may be able to read a persistent device identifier.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24220" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122405" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v8vh-f89p-82w5/GHSA-v8vh-f89p-82w5.json b/advisories/unreviewed/2025/05/GHSA-v8vh-f89p-82w5/GHSA-v8vh-f89p-82w5.json new file mode 100644 index 00000000000..0d3ebf8a81d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v8vh-f89p-82w5/GHSA-v8vh-f89p-82w5.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v8vh-f89p-82w5", + "modified": "2025-05-13T00:31:15Z", + "published": "2025-05-13T00:31:15Z", + "aliases": [ + "CVE-2025-31244" + ], + "details": "A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.5. An app may be able to break out of its sandbox.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31244" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122716" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vqww-7r9g-2fhx/GHSA-vqww-7r9g-2fhx.json b/advisories/unreviewed/2025/05/GHSA-vqww-7r9g-2fhx/GHSA-vqww-7r9g-2fhx.json index d0156780268..2c339b8ab8d 100644 --- a/advisories/unreviewed/2025/05/GHSA-vqww-7r9g-2fhx/GHSA-vqww-7r9g-2fhx.json +++ b/advisories/unreviewed/2025/05/GHSA-vqww-7r9g-2fhx/GHSA-vqww-7r9g-2fhx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vqww-7r9g-2fhx", - "modified": "2025-05-12T15:30:44Z", + "modified": "2025-05-13T00:31:11Z", "published": "2025-05-12T15:30:44Z", "aliases": [ "CVE-2025-46610" ], "details": "ARTEC EMA Mail 6.92 allows CSRF.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T15:16:01Z" diff --git a/advisories/unreviewed/2025/05/GHSA-w97v-vj4h-46rv/GHSA-w97v-vj4h-46rv.json b/advisories/unreviewed/2025/05/GHSA-w97v-vj4h-46rv/GHSA-w97v-vj4h-46rv.json new file mode 100644 index 00000000000..a0091752786 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w97v-vj4h-46rv/GHSA-w97v-vj4h-46rv.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w97v-vj4h-46rv", + "modified": "2025-05-13T00:31:13Z", + "published": "2025-05-13T00:31:13Z", + "aliases": [ + "CVE-2025-31207" + ], + "details": "A logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5. An app may be able to enumerate a user's installed apps.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31207" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122404" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-whm5-2rx4-qhv5/GHSA-whm5-2rx4-qhv5.json b/advisories/unreviewed/2025/05/GHSA-whm5-2rx4-qhv5/GHSA-whm5-2rx4-qhv5.json new file mode 100644 index 00000000000..e4eb2facc97 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-whm5-2rx4-qhv5/GHSA-whm5-2rx4-qhv5.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-whm5-2rx4-qhv5", + "modified": "2025-05-13T00:31:14Z", + "published": "2025-05-13T00:31:14Z", + "aliases": [ + "CVE-2025-31224" + ], + "details": "A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. An app may be able to bypass certain Privacy preferences.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31224" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122716" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122717" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122718" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wv7w-fgmw-6vg2/GHSA-wv7w-fgmw-6vg2.json b/advisories/unreviewed/2025/05/GHSA-wv7w-fgmw-6vg2/GHSA-wv7w-fgmw-6vg2.json new file mode 100644 index 00000000000..a9daae0e189 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wv7w-fgmw-6vg2/GHSA-wv7w-fgmw-6vg2.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wv7w-fgmw-6vg2", + "modified": "2025-05-13T00:31:13Z", + "published": "2025-05-13T00:31:13Z", + "aliases": [ + "CVE-2025-31206" + ], + "details": "A type confusion issue was addressed with improved state handling. This issue is fixed in watchOS 11.5, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, Safari 18.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31206" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122404" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122405" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122716" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122719" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122720" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122721" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122722" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-x3g7-56f2-8w33/GHSA-x3g7-56f2-8w33.json b/advisories/unreviewed/2025/05/GHSA-x3g7-56f2-8w33/GHSA-x3g7-56f2-8w33.json index 1f02b37b085..75a21947e11 100644 --- a/advisories/unreviewed/2025/05/GHSA-x3g7-56f2-8w33/GHSA-x3g7-56f2-8w33.json +++ b/advisories/unreviewed/2025/05/GHSA-x3g7-56f2-8w33/GHSA-x3g7-56f2-8w33.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x3g7-56f2-8w33", - "modified": "2025-05-09T18:30:37Z", + "modified": "2025-05-13T00:31:11Z", "published": "2025-05-09T18:30:37Z", "aliases": [ "CVE-2025-28200" ], "details": "Victure RX1800 EN_V1.0.0_r12_110933 was discovered to utilize a weak default password which includes the last 8 digits of the Mac address.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-521" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-09T16:15:24Z" diff --git a/advisories/unreviewed/2025/05/GHSA-x696-h3x7-xxjp/GHSA-x696-h3x7-xxjp.json b/advisories/unreviewed/2025/05/GHSA-x696-h3x7-xxjp/GHSA-x696-h3x7-xxjp.json new file mode 100644 index 00000000000..f46f0346626 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-x696-h3x7-xxjp/GHSA-x696-h3x7-xxjp.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x696-h3x7-xxjp", + "modified": "2025-05-13T00:31:13Z", + "published": "2025-05-13T00:31:13Z", + "aliases": [ + "CVE-2025-31214" + ], + "details": "This issue was addressed through improved state management. This issue is fixed in iOS 18.5 and iPadOS 18.5. An attacker in a privileged network position may be able to intercept network traffic.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31214" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122404" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-x6ph-hgqm-c68g/GHSA-x6ph-hgqm-c68g.json b/advisories/unreviewed/2025/05/GHSA-x6ph-hgqm-c68g/GHSA-x6ph-hgqm-c68g.json new file mode 100644 index 00000000000..8f3b1f9c801 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-x6ph-hgqm-c68g/GHSA-x6ph-hgqm-c68g.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x6ph-hgqm-c68g", + "modified": "2025-05-13T00:31:14Z", + "published": "2025-05-13T00:31:14Z", + "aliases": [ + "CVE-2025-31218" + ], + "details": "This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.5. An app may be able to observe the hostnames of new network connections.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31218" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122716" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xf4q-c7gc-gpgr/GHSA-xf4q-c7gc-gpgr.json b/advisories/unreviewed/2025/05/GHSA-xf4q-c7gc-gpgr/GHSA-xf4q-c7gc-gpgr.json new file mode 100644 index 00000000000..3ac483a17cc --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xf4q-c7gc-gpgr/GHSA-xf4q-c7gc-gpgr.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xf4q-c7gc-gpgr", + "modified": "2025-05-13T00:31:15Z", + "published": "2025-05-13T00:31:15Z", + "aliases": [ + "CVE-2025-31242" + ], + "details": "A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iPadOS 17.7.7, macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. An app may be able to access sensitive user data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31242" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122405" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122716" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122717" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122718" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xh5p-rm5r-7f82/GHSA-xh5p-rm5r-7f82.json b/advisories/unreviewed/2025/05/GHSA-xh5p-rm5r-7f82/GHSA-xh5p-rm5r-7f82.json new file mode 100644 index 00000000000..bbed9420bc1 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xh5p-rm5r-7f82/GHSA-xh5p-rm5r-7f82.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xh5p-rm5r-7f82", + "modified": "2025-05-13T00:31:15Z", + "published": "2025-05-13T00:31:15Z", + "aliases": [ + "CVE-2025-31235" + ], + "details": "A double free issue was addressed with improved memory management. This issue is fixed in iPadOS 17.7.7, macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. An app may be able to cause unexpected system termination.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31235" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122405" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122716" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122717" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122718" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xq63-2jcc-9gm3/GHSA-xq63-2jcc-9gm3.json b/advisories/unreviewed/2025/05/GHSA-xq63-2jcc-9gm3/GHSA-xq63-2jcc-9gm3.json new file mode 100644 index 00000000000..dc319c0000d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xq63-2jcc-9gm3/GHSA-xq63-2jcc-9gm3.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xq63-2jcc-9gm3", + "modified": "2025-05-13T00:31:12Z", + "published": "2025-05-13T00:31:12Z", + "aliases": [ + "CVE-2025-24258" + ], + "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Ventura 13.7.6, macOS Sonoma 14.7.6. An app may be able to gain root privileges.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24258" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122717" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122718" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T22:15:20Z" + } +} \ No newline at end of file