diff --git a/advisories/unreviewed/2022/09/GHSA-3q84-3x2q-qwx9/GHSA-3q84-3x2q-qwx9.json b/advisories/unreviewed/2022/09/GHSA-3q84-3x2q-qwx9/GHSA-3q84-3x2q-qwx9.json index 3c90dc58360..3e2b67480c5 100644 --- a/advisories/unreviewed/2022/09/GHSA-3q84-3x2q-qwx9/GHSA-3q84-3x2q-qwx9.json +++ b/advisories/unreviewed/2022/09/GHSA-3q84-3x2q-qwx9/GHSA-3q84-3x2q-qwx9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3q84-3x2q-qwx9", - "modified": "2022-09-29T00:00:21Z", + "modified": "2025-05-21T21:31:08Z", "published": "2022-09-27T00:00:19Z", "aliases": [ "CVE-2022-3042" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://crbug.com/1338553" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" @@ -38,6 +42,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-362", "CWE-416" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/09/GHSA-3w67-7h76-28wg/GHSA-3w67-7h76-28wg.json b/advisories/unreviewed/2022/09/GHSA-3w67-7h76-28wg/GHSA-3w67-7h76-28wg.json index 62b7daa5bb2..7b8f3a4a6dc 100644 --- a/advisories/unreviewed/2022/09/GHSA-3w67-7h76-28wg/GHSA-3w67-7h76-28wg.json +++ b/advisories/unreviewed/2022/09/GHSA-3w67-7h76-28wg/GHSA-3w67-7h76-28wg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3w67-7h76-28wg", - "modified": "2022-09-28T00:00:24Z", + "modified": "2025-05-21T21:31:08Z", "published": "2022-09-27T00:00:19Z", "aliases": [ "CVE-2022-3041" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://crbug.com/1345947" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" diff --git a/advisories/unreviewed/2022/09/GHSA-69p6-xm96-58f8/GHSA-69p6-xm96-58f8.json b/advisories/unreviewed/2022/09/GHSA-69p6-xm96-58f8/GHSA-69p6-xm96-58f8.json index 63e4992c8ef..8d24179bfaf 100644 --- a/advisories/unreviewed/2022/09/GHSA-69p6-xm96-58f8/GHSA-69p6-xm96-58f8.json +++ b/advisories/unreviewed/2022/09/GHSA-69p6-xm96-58f8/GHSA-69p6-xm96-58f8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-69p6-xm96-58f8", - "modified": "2022-09-28T00:00:24Z", + "modified": "2025-05-21T21:31:07Z", "published": "2022-09-27T00:00:21Z", "aliases": [ "CVE-2021-41437" @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-436" + "CWE-436", + "CWE-74" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/09/GHSA-73qx-mm4g-5qj8/GHSA-73qx-mm4g-5qj8.json b/advisories/unreviewed/2022/09/GHSA-73qx-mm4g-5qj8/GHSA-73qx-mm4g-5qj8.json index 4d4cc788998..f8700a83bde 100644 --- a/advisories/unreviewed/2022/09/GHSA-73qx-mm4g-5qj8/GHSA-73qx-mm4g-5qj8.json +++ b/advisories/unreviewed/2022/09/GHSA-73qx-mm4g-5qj8/GHSA-73qx-mm4g-5qj8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-73qx-mm4g-5qj8", - "modified": "2022-09-29T00:00:24Z", + "modified": "2025-05-21T21:31:05Z", "published": "2022-09-27T00:00:21Z", "aliases": [ "CVE-2021-24890" diff --git a/advisories/unreviewed/2022/09/GHSA-847g-6mcg-4c4x/GHSA-847g-6mcg-4c4x.json b/advisories/unreviewed/2022/09/GHSA-847g-6mcg-4c4x/GHSA-847g-6mcg-4c4x.json index aa7e7ddb6bc..b5ad5a499a0 100644 --- a/advisories/unreviewed/2022/09/GHSA-847g-6mcg-4c4x/GHSA-847g-6mcg-4c4x.json +++ b/advisories/unreviewed/2022/09/GHSA-847g-6mcg-4c4x/GHSA-847g-6mcg-4c4x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-847g-6mcg-4c4x", - "modified": "2022-09-29T00:00:21Z", + "modified": "2025-05-21T21:31:08Z", "published": "2022-09-27T00:00:20Z", "aliases": [ "CVE-2022-3053" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://crbug.com/1267867" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" diff --git a/advisories/unreviewed/2022/09/GHSA-8pf4-f4w9-6h78/GHSA-8pf4-f4w9-6h78.json b/advisories/unreviewed/2022/09/GHSA-8pf4-f4w9-6h78/GHSA-8pf4-f4w9-6h78.json index 954a07524f8..7d14cece0f1 100644 --- a/advisories/unreviewed/2022/09/GHSA-8pf4-f4w9-6h78/GHSA-8pf4-f4w9-6h78.json +++ b/advisories/unreviewed/2022/09/GHSA-8pf4-f4w9-6h78/GHSA-8pf4-f4w9-6h78.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8pf4-f4w9-6h78", - "modified": "2022-09-28T00:00:26Z", + "modified": "2025-05-21T21:31:08Z", "published": "2022-09-27T00:00:19Z", "aliases": [ "CVE-2022-3040" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://crbug.com/1341539" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" @@ -38,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-416" + "CWE-416", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/09/GHSA-8r7r-5qgr-54w2/GHSA-8r7r-5qgr-54w2.json b/advisories/unreviewed/2022/09/GHSA-8r7r-5qgr-54w2/GHSA-8r7r-5qgr-54w2.json index 0489f0209a8..438ee657241 100644 --- a/advisories/unreviewed/2022/09/GHSA-8r7r-5qgr-54w2/GHSA-8r7r-5qgr-54w2.json +++ b/advisories/unreviewed/2022/09/GHSA-8r7r-5qgr-54w2/GHSA-8r7r-5qgr-54w2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8r7r-5qgr-54w2", - "modified": "2022-09-29T00:00:23Z", + "modified": "2025-05-21T21:31:09Z", "published": "2022-09-27T00:00:20Z", "aliases": [ "CVE-2022-3055" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://crbug.com/1351969" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" diff --git a/advisories/unreviewed/2022/09/GHSA-942p-xpw9-vwwr/GHSA-942p-xpw9-vwwr.json b/advisories/unreviewed/2022/09/GHSA-942p-xpw9-vwwr/GHSA-942p-xpw9-vwwr.json index fdac117b228..31b43e4f35c 100644 --- a/advisories/unreviewed/2022/09/GHSA-942p-xpw9-vwwr/GHSA-942p-xpw9-vwwr.json +++ b/advisories/unreviewed/2022/09/GHSA-942p-xpw9-vwwr/GHSA-942p-xpw9-vwwr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-942p-xpw9-vwwr", - "modified": "2022-09-28T00:00:25Z", + "modified": "2025-05-21T21:31:08Z", "published": "2022-09-27T00:00:19Z", "aliases": [ "CVE-2022-3039" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://crbug.com/1343348" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" diff --git a/advisories/unreviewed/2022/09/GHSA-fx38-9486-jfwx/GHSA-fx38-9486-jfwx.json b/advisories/unreviewed/2022/09/GHSA-fx38-9486-jfwx/GHSA-fx38-9486-jfwx.json index e909a674057..77021c86f57 100644 --- a/advisories/unreviewed/2022/09/GHSA-fx38-9486-jfwx/GHSA-fx38-9486-jfwx.json +++ b/advisories/unreviewed/2022/09/GHSA-fx38-9486-jfwx/GHSA-fx38-9486-jfwx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fx38-9486-jfwx", - "modified": "2022-09-29T00:00:21Z", + "modified": "2025-05-21T21:31:08Z", "published": "2022-09-27T00:00:20Z", "aliases": [ "CVE-2022-3054" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://crbug.com/1290236" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" diff --git a/advisories/unreviewed/2022/09/GHSA-gjwh-89f3-gfwj/GHSA-gjwh-89f3-gfwj.json b/advisories/unreviewed/2022/09/GHSA-gjwh-89f3-gfwj/GHSA-gjwh-89f3-gfwj.json index d87f94446a4..402cadbc7bf 100644 --- a/advisories/unreviewed/2022/09/GHSA-gjwh-89f3-gfwj/GHSA-gjwh-89f3-gfwj.json +++ b/advisories/unreviewed/2022/09/GHSA-gjwh-89f3-gfwj/GHSA-gjwh-89f3-gfwj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gjwh-89f3-gfwj", - "modified": "2022-09-29T00:00:20Z", + "modified": "2025-05-21T21:31:08Z", "published": "2022-09-27T00:00:20Z", "aliases": [ "CVE-2022-3052" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://crbug.com/1346154" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" diff --git a/advisories/unreviewed/2022/09/GHSA-gwrf-xxxj-ch7q/GHSA-gwrf-xxxj-ch7q.json b/advisories/unreviewed/2022/09/GHSA-gwrf-xxxj-ch7q/GHSA-gwrf-xxxj-ch7q.json index 32206d67984..3cb1143008e 100644 --- a/advisories/unreviewed/2022/09/GHSA-gwrf-xxxj-ch7q/GHSA-gwrf-xxxj-ch7q.json +++ b/advisories/unreviewed/2022/09/GHSA-gwrf-xxxj-ch7q/GHSA-gwrf-xxxj-ch7q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gwrf-xxxj-ch7q", - "modified": "2022-09-29T00:00:22Z", + "modified": "2025-05-21T21:31:09Z", "published": "2022-09-27T00:00:20Z", "aliases": [ "CVE-2022-3197" diff --git a/advisories/unreviewed/2022/09/GHSA-h289-vmhx-86f3/GHSA-h289-vmhx-86f3.json b/advisories/unreviewed/2022/09/GHSA-h289-vmhx-86f3/GHSA-h289-vmhx-86f3.json index 48a547a7a29..95197e2a88e 100644 --- a/advisories/unreviewed/2022/09/GHSA-h289-vmhx-86f3/GHSA-h289-vmhx-86f3.json +++ b/advisories/unreviewed/2022/09/GHSA-h289-vmhx-86f3/GHSA-h289-vmhx-86f3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h289-vmhx-86f3", - "modified": "2022-09-29T00:00:23Z", + "modified": "2025-05-21T21:31:08Z", "published": "2022-09-27T00:00:19Z", "aliases": [ "CVE-2022-3043" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://crbug.com/1336979" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" diff --git a/advisories/unreviewed/2022/09/GHSA-jcrm-h74j-pg7j/GHSA-jcrm-h74j-pg7j.json b/advisories/unreviewed/2022/09/GHSA-jcrm-h74j-pg7j/GHSA-jcrm-h74j-pg7j.json index 1e0b5805e45..b1771f2538e 100644 --- a/advisories/unreviewed/2022/09/GHSA-jcrm-h74j-pg7j/GHSA-jcrm-h74j-pg7j.json +++ b/advisories/unreviewed/2022/09/GHSA-jcrm-h74j-pg7j/GHSA-jcrm-h74j-pg7j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jcrm-h74j-pg7j", - "modified": "2022-09-29T00:00:21Z", + "modified": "2025-05-21T21:31:07Z", "published": "2022-09-27T00:00:19Z", "aliases": [ "CVE-2022-2859" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://crbug.com/1338412" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" diff --git a/advisories/unreviewed/2022/09/GHSA-v29c-v9hp-cr23/GHSA-v29c-v9hp-cr23.json b/advisories/unreviewed/2022/09/GHSA-v29c-v9hp-cr23/GHSA-v29c-v9hp-cr23.json index cd462e38e6c..1023e1d5e17 100644 --- a/advisories/unreviewed/2022/09/GHSA-v29c-v9hp-cr23/GHSA-v29c-v9hp-cr23.json +++ b/advisories/unreviewed/2022/09/GHSA-v29c-v9hp-cr23/GHSA-v29c-v9hp-cr23.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v29c-v9hp-cr23", - "modified": "2022-09-29T00:00:21Z", + "modified": "2025-05-21T21:31:07Z", "published": "2022-09-27T00:00:19Z", "aliases": [ "CVE-2022-2860" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://crbug.com/1345193" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" diff --git a/advisories/unreviewed/2022/09/GHSA-w3h3-52fr-jjhw/GHSA-w3h3-52fr-jjhw.json b/advisories/unreviewed/2022/09/GHSA-w3h3-52fr-jjhw/GHSA-w3h3-52fr-jjhw.json index 3b4f0061d67..13231c02654 100644 --- a/advisories/unreviewed/2022/09/GHSA-w3h3-52fr-jjhw/GHSA-w3h3-52fr-jjhw.json +++ b/advisories/unreviewed/2022/09/GHSA-w3h3-52fr-jjhw/GHSA-w3h3-52fr-jjhw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w3h3-52fr-jjhw", - "modified": "2022-09-29T00:00:21Z", + "modified": "2025-05-21T21:31:07Z", "published": "2022-09-27T00:00:19Z", "aliases": [ "CVE-2022-2858" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://crbug.com/1341918" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" diff --git a/advisories/unreviewed/2022/09/GHSA-w7p3-hmmp-qmx6/GHSA-w7p3-hmmp-qmx6.json b/advisories/unreviewed/2022/09/GHSA-w7p3-hmmp-qmx6/GHSA-w7p3-hmmp-qmx6.json index 30c6a070e5c..2d879c1730a 100644 --- a/advisories/unreviewed/2022/09/GHSA-w7p3-hmmp-qmx6/GHSA-w7p3-hmmp-qmx6.json +++ b/advisories/unreviewed/2022/09/GHSA-w7p3-hmmp-qmx6/GHSA-w7p3-hmmp-qmx6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w7p3-hmmp-qmx6", - "modified": "2022-09-29T00:00:23Z", + "modified": "2025-05-21T21:31:05Z", "published": "2022-09-27T00:00:22Z", "aliases": [ "CVE-2022-41347" diff --git a/advisories/unreviewed/2022/09/GHSA-wfwp-jxjq-2m26/GHSA-wfwp-jxjq-2m26.json b/advisories/unreviewed/2022/09/GHSA-wfwp-jxjq-2m26/GHSA-wfwp-jxjq-2m26.json index 8c281cb31ca..bbe3ef38560 100644 --- a/advisories/unreviewed/2022/09/GHSA-wfwp-jxjq-2m26/GHSA-wfwp-jxjq-2m26.json +++ b/advisories/unreviewed/2022/09/GHSA-wfwp-jxjq-2m26/GHSA-wfwp-jxjq-2m26.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wfwp-jxjq-2m26", - "modified": "2022-09-29T00:00:21Z", + "modified": "2025-05-21T21:31:07Z", "published": "2022-09-27T00:00:19Z", "aliases": [ "CVE-2022-2861" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://crbug.com/1346236" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" @@ -34,6 +38,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-79", "CWE-863" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/09/GHSA-xv7p-vwj6-p73h/GHSA-xv7p-vwj6-p73h.json b/advisories/unreviewed/2022/09/GHSA-xv7p-vwj6-p73h/GHSA-xv7p-vwj6-p73h.json index b3d360bb5f2..4e8c5aac644 100644 --- a/advisories/unreviewed/2022/09/GHSA-xv7p-vwj6-p73h/GHSA-xv7p-vwj6-p73h.json +++ b/advisories/unreviewed/2022/09/GHSA-xv7p-vwj6-p73h/GHSA-xv7p-vwj6-p73h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xv7p-vwj6-p73h", - "modified": "2022-09-29T00:00:22Z", + "modified": "2025-05-21T21:31:09Z", "published": "2022-09-27T00:00:20Z", "aliases": [ "CVE-2022-3196" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://crbug.com/1358090" }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/40060720" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" diff --git a/advisories/unreviewed/2024/05/GHSA-8962-3h36-6xxf/GHSA-8962-3h36-6xxf.json b/advisories/unreviewed/2024/05/GHSA-8962-3h36-6xxf/GHSA-8962-3h36-6xxf.json index 8e831c5d4e9..a0d47e21fc5 100644 --- a/advisories/unreviewed/2024/05/GHSA-8962-3h36-6xxf/GHSA-8962-3h36-6xxf.json +++ b/advisories/unreviewed/2024/05/GHSA-8962-3h36-6xxf/GHSA-8962-3h36-6xxf.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-8vj3-86c4-xhm3/GHSA-8vj3-86c4-xhm3.json b/advisories/unreviewed/2024/05/GHSA-8vj3-86c4-xhm3/GHSA-8vj3-86c4-xhm3.json index 3e3f5895db7..c21ca3350fc 100644 --- a/advisories/unreviewed/2024/05/GHSA-8vj3-86c4-xhm3/GHSA-8vj3-86c4-xhm3.json +++ b/advisories/unreviewed/2024/05/GHSA-8vj3-86c4-xhm3/GHSA-8vj3-86c4-xhm3.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-f2gx-4fp8-9978/GHSA-f2gx-4fp8-9978.json b/advisories/unreviewed/2024/05/GHSA-f2gx-4fp8-9978/GHSA-f2gx-4fp8-9978.json index 4923aa53c9a..a0f3ef0b3c1 100644 --- a/advisories/unreviewed/2024/05/GHSA-f2gx-4fp8-9978/GHSA-f2gx-4fp8-9978.json +++ b/advisories/unreviewed/2024/05/GHSA-f2gx-4fp8-9978/GHSA-f2gx-4fp8-9978.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-hw5v-77jj-prp8/GHSA-hw5v-77jj-prp8.json b/advisories/unreviewed/2024/05/GHSA-hw5v-77jj-prp8/GHSA-hw5v-77jj-prp8.json index 32d6e5b7d05..f8bd84014ab 100644 --- a/advisories/unreviewed/2024/05/GHSA-hw5v-77jj-prp8/GHSA-hw5v-77jj-prp8.json +++ b/advisories/unreviewed/2024/05/GHSA-hw5v-77jj-prp8/GHSA-hw5v-77jj-prp8.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-918" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-jj5x-5vg3-9m7f/GHSA-jj5x-5vg3-9m7f.json b/advisories/unreviewed/2024/05/GHSA-jj5x-5vg3-9m7f/GHSA-jj5x-5vg3-9m7f.json index a9df303030f..0bde293a736 100644 --- a/advisories/unreviewed/2024/05/GHSA-jj5x-5vg3-9m7f/GHSA-jj5x-5vg3-9m7f.json +++ b/advisories/unreviewed/2024/05/GHSA-jj5x-5vg3-9m7f/GHSA-jj5x-5vg3-9m7f.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-mqv8-r98f-v6vp/GHSA-mqv8-r98f-v6vp.json b/advisories/unreviewed/2024/05/GHSA-mqv8-r98f-v6vp/GHSA-mqv8-r98f-v6vp.json index 4153be4b919..4c5df5bddfc 100644 --- a/advisories/unreviewed/2024/05/GHSA-mqv8-r98f-v6vp/GHSA-mqv8-r98f-v6vp.json +++ b/advisories/unreviewed/2024/05/GHSA-mqv8-r98f-v6vp/GHSA-mqv8-r98f-v6vp.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-p45m-mr9q-rx4p/GHSA-p45m-mr9q-rx4p.json b/advisories/unreviewed/2024/05/GHSA-p45m-mr9q-rx4p/GHSA-p45m-mr9q-rx4p.json index af2d26a3c72..c9562105e6d 100644 --- a/advisories/unreviewed/2024/05/GHSA-p45m-mr9q-rx4p/GHSA-p45m-mr9q-rx4p.json +++ b/advisories/unreviewed/2024/05/GHSA-p45m-mr9q-rx4p/GHSA-p45m-mr9q-rx4p.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-q96x-mjr8-2jrj/GHSA-q96x-mjr8-2jrj.json b/advisories/unreviewed/2024/05/GHSA-q96x-mjr8-2jrj/GHSA-q96x-mjr8-2jrj.json index 7f09bbf5af6..0145e9e6d65 100644 --- a/advisories/unreviewed/2024/05/GHSA-q96x-mjr8-2jrj/GHSA-q96x-mjr8-2jrj.json +++ b/advisories/unreviewed/2024/05/GHSA-q96x-mjr8-2jrj/GHSA-q96x-mjr8-2jrj.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-rq46-9225-gj4f/GHSA-rq46-9225-gj4f.json b/advisories/unreviewed/2024/05/GHSA-rq46-9225-gj4f/GHSA-rq46-9225-gj4f.json index c4a74dd88e9..eebb31605af 100644 --- a/advisories/unreviewed/2024/05/GHSA-rq46-9225-gj4f/GHSA-rq46-9225-gj4f.json +++ b/advisories/unreviewed/2024/05/GHSA-rq46-9225-gj4f/GHSA-rq46-9225-gj4f.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-xrf7-7j85-g93c/GHSA-xrf7-7j85-g93c.json b/advisories/unreviewed/2024/05/GHSA-xrf7-7j85-g93c/GHSA-xrf7-7j85-g93c.json index 06850803be4..f93415886dd 100644 --- a/advisories/unreviewed/2024/05/GHSA-xrf7-7j85-g93c/GHSA-xrf7-7j85-g93c.json +++ b/advisories/unreviewed/2024/05/GHSA-xrf7-7j85-g93c/GHSA-xrf7-7j85-g93c.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-5g6x-fqcp-phwv/GHSA-5g6x-fqcp-phwv.json b/advisories/unreviewed/2024/06/GHSA-5g6x-fqcp-phwv/GHSA-5g6x-fqcp-phwv.json index 01667712058..67ded44156b 100644 --- a/advisories/unreviewed/2024/06/GHSA-5g6x-fqcp-phwv/GHSA-5g6x-fqcp-phwv.json +++ b/advisories/unreviewed/2024/06/GHSA-5g6x-fqcp-phwv/GHSA-5g6x-fqcp-phwv.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-j32x-p3fr-rqvr/GHSA-j32x-p3fr-rqvr.json b/advisories/unreviewed/2024/06/GHSA-j32x-p3fr-rqvr/GHSA-j32x-p3fr-rqvr.json index 7893fe0ec37..1bdd2d64cd8 100644 --- a/advisories/unreviewed/2024/06/GHSA-j32x-p3fr-rqvr/GHSA-j32x-p3fr-rqvr.json +++ b/advisories/unreviewed/2024/06/GHSA-j32x-p3fr-rqvr/GHSA-j32x-p3fr-rqvr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-f4jx-rpw7-5p2c/GHSA-f4jx-rpw7-5p2c.json b/advisories/unreviewed/2024/07/GHSA-f4jx-rpw7-5p2c/GHSA-f4jx-rpw7-5p2c.json index 8084f549af5..c8d288764b3 100644 --- a/advisories/unreviewed/2024/07/GHSA-f4jx-rpw7-5p2c/GHSA-f4jx-rpw7-5p2c.json +++ b/advisories/unreviewed/2024/07/GHSA-f4jx-rpw7-5p2c/GHSA-f4jx-rpw7-5p2c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f4jx-rpw7-5p2c", - "modified": "2024-07-09T06:30:41Z", + "modified": "2025-05-21T21:31:12Z", "published": "2024-07-09T06:30:41Z", "aliases": [ "CVE-2024-6334" ], "details": "The Easy Table of Contents WordPress plugin before 2.0.67.1 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-09T06:15:03Z" diff --git a/advisories/unreviewed/2024/07/GHSA-wh6w-2qc6-mq3c/GHSA-wh6w-2qc6-mq3c.json b/advisories/unreviewed/2024/07/GHSA-wh6w-2qc6-mq3c/GHSA-wh6w-2qc6-mq3c.json index e94fe43fafa..1569e488cf5 100644 --- a/advisories/unreviewed/2024/07/GHSA-wh6w-2qc6-mq3c/GHSA-wh6w-2qc6-mq3c.json +++ b/advisories/unreviewed/2024/07/GHSA-wh6w-2qc6-mq3c/GHSA-wh6w-2qc6-mq3c.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-502" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-xccx-m7hh-9748/GHSA-xccx-m7hh-9748.json b/advisories/unreviewed/2024/07/GHSA-xccx-m7hh-9748/GHSA-xccx-m7hh-9748.json index 199318047a8..6eeb4ac1b36 100644 --- a/advisories/unreviewed/2024/07/GHSA-xccx-m7hh-9748/GHSA-xccx-m7hh-9748.json +++ b/advisories/unreviewed/2024/07/GHSA-xccx-m7hh-9748/GHSA-xccx-m7hh-9748.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-xgv9-3cm6-qccq/GHSA-xgv9-3cm6-qccq.json b/advisories/unreviewed/2024/07/GHSA-xgv9-3cm6-qccq/GHSA-xgv9-3cm6-qccq.json index de993012f3c..fb713cdb227 100644 --- a/advisories/unreviewed/2024/07/GHSA-xgv9-3cm6-qccq/GHSA-xgv9-3cm6-qccq.json +++ b/advisories/unreviewed/2024/07/GHSA-xgv9-3cm6-qccq/GHSA-xgv9-3cm6-qccq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xgv9-3cm6-qccq", - "modified": "2024-07-12T12:30:38Z", + "modified": "2025-05-21T21:31:12Z", "published": "2024-07-12T12:30:38Z", "aliases": [ "CVE-2024-6328" @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/08/GHSA-m362-99m5-p5fq/GHSA-m362-99m5-p5fq.json b/advisories/unreviewed/2024/08/GHSA-m362-99m5-p5fq/GHSA-m362-99m5-p5fq.json index ca55905e513..6c39afe11c9 100644 --- a/advisories/unreviewed/2024/08/GHSA-m362-99m5-p5fq/GHSA-m362-99m5-p5fq.json +++ b/advisories/unreviewed/2024/08/GHSA-m362-99m5-p5fq/GHSA-m362-99m5-p5fq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m362-99m5-p5fq", - "modified": "2024-08-15T03:30:28Z", + "modified": "2025-05-21T21:31:12Z", "published": "2024-08-15T03:30:28Z", "aliases": [ "CVE-2024-7628" @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-288" + "CWE-288", + "CWE-306" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-268p-8m6q-3rq7/GHSA-268p-8m6q-3rq7.json b/advisories/unreviewed/2025/02/GHSA-268p-8m6q-3rq7/GHSA-268p-8m6q-3rq7.json index 1aaaa4e4f93..b50f282711d 100644 --- a/advisories/unreviewed/2025/02/GHSA-268p-8m6q-3rq7/GHSA-268p-8m6q-3rq7.json +++ b/advisories/unreviewed/2025/02/GHSA-268p-8m6q-3rq7/GHSA-268p-8m6q-3rq7.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-m4p3-9x42-5p6v/GHSA-m4p3-9x42-5p6v.json b/advisories/unreviewed/2025/02/GHSA-m4p3-9x42-5p6v/GHSA-m4p3-9x42-5p6v.json index 577fee88db8..e6cc0d6fbe3 100644 --- a/advisories/unreviewed/2025/02/GHSA-m4p3-9x42-5p6v/GHSA-m4p3-9x42-5p6v.json +++ b/advisories/unreviewed/2025/02/GHSA-m4p3-9x42-5p6v/GHSA-m4p3-9x42-5p6v.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-3336-3gjj-jp53/GHSA-3336-3gjj-jp53.json b/advisories/unreviewed/2025/03/GHSA-3336-3gjj-jp53/GHSA-3336-3gjj-jp53.json index 0c3aaf66a88..0992b186f65 100644 --- a/advisories/unreviewed/2025/03/GHSA-3336-3gjj-jp53/GHSA-3336-3gjj-jp53.json +++ b/advisories/unreviewed/2025/03/GHSA-3336-3gjj-jp53/GHSA-3336-3gjj-jp53.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3336-3gjj-jp53", - "modified": "2025-03-07T12:31:59Z", + "modified": "2025-05-21T21:31:16Z", "published": "2025-03-07T12:31:59Z", "aliases": [ "CVE-2024-13805" diff --git a/advisories/unreviewed/2025/03/GHSA-3g3r-jxgh-3hv4/GHSA-3g3r-jxgh-3hv4.json b/advisories/unreviewed/2025/03/GHSA-3g3r-jxgh-3hv4/GHSA-3g3r-jxgh-3hv4.json index b581dae1f20..743b55d9aff 100644 --- a/advisories/unreviewed/2025/03/GHSA-3g3r-jxgh-3hv4/GHSA-3g3r-jxgh-3hv4.json +++ b/advisories/unreviewed/2025/03/GHSA-3g3r-jxgh-3hv4/GHSA-3g3r-jxgh-3hv4.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-6cq7-qpq2-9r7r/GHSA-6cq7-qpq2-9r7r.json b/advisories/unreviewed/2025/03/GHSA-6cq7-qpq2-9r7r/GHSA-6cq7-qpq2-9r7r.json index b6c5487ea7b..a6d362a372f 100644 --- a/advisories/unreviewed/2025/03/GHSA-6cq7-qpq2-9r7r/GHSA-6cq7-qpq2-9r7r.json +++ b/advisories/unreviewed/2025/03/GHSA-6cq7-qpq2-9r7r/GHSA-6cq7-qpq2-9r7r.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-97pj-56mh-q46x/GHSA-97pj-56mh-q46x.json b/advisories/unreviewed/2025/03/GHSA-97pj-56mh-q46x/GHSA-97pj-56mh-q46x.json index 9ebcb75027d..1b43e73d111 100644 --- a/advisories/unreviewed/2025/03/GHSA-97pj-56mh-q46x/GHSA-97pj-56mh-q46x.json +++ b/advisories/unreviewed/2025/03/GHSA-97pj-56mh-q46x/GHSA-97pj-56mh-q46x.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-h9g2-p624-7h5h/GHSA-h9g2-p624-7h5h.json b/advisories/unreviewed/2025/03/GHSA-h9g2-p624-7h5h/GHSA-h9g2-p624-7h5h.json index 3b31aac52ea..ad65fd73aee 100644 --- a/advisories/unreviewed/2025/03/GHSA-h9g2-p624-7h5h/GHSA-h9g2-p624-7h5h.json +++ b/advisories/unreviewed/2025/03/GHSA-h9g2-p624-7h5h/GHSA-h9g2-p624-7h5h.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-q45v-67x3-jj8w/GHSA-q45v-67x3-jj8w.json b/advisories/unreviewed/2025/03/GHSA-q45v-67x3-jj8w/GHSA-q45v-67x3-jj8w.json index b393b8f7055..f1fc7d0848c 100644 --- a/advisories/unreviewed/2025/03/GHSA-q45v-67x3-jj8w/GHSA-q45v-67x3-jj8w.json +++ b/advisories/unreviewed/2025/03/GHSA-q45v-67x3-jj8w/GHSA-q45v-67x3-jj8w.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-q6qg-c79q-f6q2/GHSA-q6qg-c79q-f6q2.json b/advisories/unreviewed/2025/03/GHSA-q6qg-c79q-f6q2/GHSA-q6qg-c79q-f6q2.json index aabdcd04b03..9edf60fa56e 100644 --- a/advisories/unreviewed/2025/03/GHSA-q6qg-c79q-f6q2/GHSA-q6qg-c79q-f6q2.json +++ b/advisories/unreviewed/2025/03/GHSA-q6qg-c79q-f6q2/GHSA-q6qg-c79q-f6q2.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-4r8p-gh25-7c48/GHSA-4r8p-gh25-7c48.json b/advisories/unreviewed/2025/04/GHSA-4r8p-gh25-7c48/GHSA-4r8p-gh25-7c48.json index e67ad7aa6d7..131519042e2 100644 --- a/advisories/unreviewed/2025/04/GHSA-4r8p-gh25-7c48/GHSA-4r8p-gh25-7c48.json +++ b/advisories/unreviewed/2025/04/GHSA-4r8p-gh25-7c48/GHSA-4r8p-gh25-7c48.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-434" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-c7gj-f6xr-p7wp/GHSA-c7gj-f6xr-p7wp.json b/advisories/unreviewed/2025/04/GHSA-c7gj-f6xr-p7wp/GHSA-c7gj-f6xr-p7wp.json index 1fc40ee9c08..33eb35c3463 100644 --- a/advisories/unreviewed/2025/04/GHSA-c7gj-f6xr-p7wp/GHSA-c7gj-f6xr-p7wp.json +++ b/advisories/unreviewed/2025/04/GHSA-c7gj-f6xr-p7wp/GHSA-c7gj-f6xr-p7wp.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-434" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-qg6g-c2hr-fv6w/GHSA-qg6g-c2hr-fv6w.json b/advisories/unreviewed/2025/04/GHSA-qg6g-c2hr-fv6w/GHSA-qg6g-c2hr-fv6w.json index 9ea2d61664e..273d01518dd 100644 --- a/advisories/unreviewed/2025/04/GHSA-qg6g-c2hr-fv6w/GHSA-qg6g-c2hr-fv6w.json +++ b/advisories/unreviewed/2025/04/GHSA-qg6g-c2hr-fv6w/GHSA-qg6g-c2hr-fv6w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qg6g-c2hr-fv6w", - "modified": "2025-04-16T00:31:37Z", + "modified": "2025-05-21T21:31:16Z", "published": "2025-04-16T00:31:37Z", "aliases": [ "CVE-2025-26998" diff --git a/advisories/unreviewed/2025/05/GHSA-239f-qw85-5278/GHSA-239f-qw85-5278.json b/advisories/unreviewed/2025/05/GHSA-239f-qw85-5278/GHSA-239f-qw85-5278.json index 7f0c0548328..4adaf3e237c 100644 --- a/advisories/unreviewed/2025/05/GHSA-239f-qw85-5278/GHSA-239f-qw85-5278.json +++ b/advisories/unreviewed/2025/05/GHSA-239f-qw85-5278/GHSA-239f-qw85-5278.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-39f6-jqc4-9rwp/GHSA-39f6-jqc4-9rwp.json b/advisories/unreviewed/2025/05/GHSA-39f6-jqc4-9rwp/GHSA-39f6-jqc4-9rwp.json index ef231d6377a..c7fccbb846c 100644 --- a/advisories/unreviewed/2025/05/GHSA-39f6-jqc4-9rwp/GHSA-39f6-jqc4-9rwp.json +++ b/advisories/unreviewed/2025/05/GHSA-39f6-jqc4-9rwp/GHSA-39f6-jqc4-9rwp.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-3fvj-h452-qf8c/GHSA-3fvj-h452-qf8c.json b/advisories/unreviewed/2025/05/GHSA-3fvj-h452-qf8c/GHSA-3fvj-h452-qf8c.json new file mode 100644 index 00000000000..8fa43069fa8 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3fvj-h452-qf8c/GHSA-3fvj-h452-qf8c.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3fvj-h452-qf8c", + "modified": "2025-05-21T21:31:37Z", + "published": "2025-05-21T21:31:37Z", + "aliases": [ + "CVE-2025-3781" + ], + "details": "The Raisely Donation Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's raisely_donation_form shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3781" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/raisely-donation-form/trunk/inc/base/providers/shortcodes.php#L46" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/raisely-donation-form/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0716485b-e94b-4e09-9c01-1059017bfcc8?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T12:16:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3fw2-84cv-23rm/GHSA-3fw2-84cv-23rm.json b/advisories/unreviewed/2025/05/GHSA-3fw2-84cv-23rm/GHSA-3fw2-84cv-23rm.json new file mode 100644 index 00000000000..fe9d5cfd31a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3fw2-84cv-23rm/GHSA-3fw2-84cv-23rm.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3fw2-84cv-23rm", + "modified": "2025-05-21T21:31:41Z", + "published": "2025-05-21T21:31:41Z", + "aliases": [ + "CVE-2025-5050" + ], + "details": "A vulnerability was found in FreeFloat FTP Server 1.0. It has been rated as critical. This issue affects some unknown processing of the component BELL Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5050" + }, + { + "type": "WEB", + "url": "https://fitoxs.com/exploit/exploit-bbcf0f842f1c5385430b6992995a8eb068c58dfbaae38ffb7df1d2c69041bc7c.txt" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309869" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309869" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.581282" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T19:16:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3phq-v5rj-pfgp/GHSA-3phq-v5rj-pfgp.json b/advisories/unreviewed/2025/05/GHSA-3phq-v5rj-pfgp/GHSA-3phq-v5rj-pfgp.json index d9fea393084..fd29d277a69 100644 --- a/advisories/unreviewed/2025/05/GHSA-3phq-v5rj-pfgp/GHSA-3phq-v5rj-pfgp.json +++ b/advisories/unreviewed/2025/05/GHSA-3phq-v5rj-pfgp/GHSA-3phq-v5rj-pfgp.json @@ -50,7 +50,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-42g7-qmp6-4p95/GHSA-42g7-qmp6-4p95.json b/advisories/unreviewed/2025/05/GHSA-42g7-qmp6-4p95/GHSA-42g7-qmp6-4p95.json new file mode 100644 index 00000000000..86839d88b72 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-42g7-qmp6-4p95/GHSA-42g7-qmp6-4p95.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-42g7-qmp6-4p95", + "modified": "2025-05-21T21:31:38Z", + "published": "2025-05-21T21:31:37Z", + "aliases": [ + "CVE-2025-4221" + ], + "details": "The Animated Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'auto-downloader' shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4221" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/animated-buttons/trunk/Animated_Buttons.php#L52" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e778399f-f7fe-47c5-9722-b833d78f475c?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T12:16:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-42qg-74gw-4v5q/GHSA-42qg-74gw-4v5q.json b/advisories/unreviewed/2025/05/GHSA-42qg-74gw-4v5q/GHSA-42qg-74gw-4v5q.json new file mode 100644 index 00000000000..eaf6715be57 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-42qg-74gw-4v5q/GHSA-42qg-74gw-4v5q.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-42qg-74gw-4v5q", + "modified": "2025-05-21T21:31:37Z", + "published": "2025-05-21T21:31:37Z", + "aliases": [ + "CVE-2025-4217" + ], + "details": "The WP YouTube Video Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ib_youtube' shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4217" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-youtube-video-optimizer/trunk/wp-youtube-video-optimizer.php#L20" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/71a933ef-f49d-4520-90d5-9957f72d7452?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T12:16:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-46rp-wqr5-v5mj/GHSA-46rp-wqr5-v5mj.json b/advisories/unreviewed/2025/05/GHSA-46rp-wqr5-v5mj/GHSA-46rp-wqr5-v5mj.json new file mode 100644 index 00000000000..9825a49c4d2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-46rp-wqr5-v5mj/GHSA-46rp-wqr5-v5mj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-46rp-wqr5-v5mj", + "modified": "2025-05-21T21:31:37Z", + "published": "2025-05-21T21:31:37Z", + "aliases": [ + "CVE-2025-1712" + ], + "details": "Argument injection in special agent configuration in Checkmk <2.4.0p1, <2.3.0p32, <2.2.0p42 and 2.1.0 allows authenticated attackers to write arbitrary files", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1712" + }, + { + "type": "WEB", + "url": "https://checkmk.com/werk/17996" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-88" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T09:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4r4w-cm3v-q4m9/GHSA-4r4w-cm3v-q4m9.json b/advisories/unreviewed/2025/05/GHSA-4r4w-cm3v-q4m9/GHSA-4r4w-cm3v-q4m9.json index 29d1d4b06dd..8f8d9e8718b 100644 --- a/advisories/unreviewed/2025/05/GHSA-4r4w-cm3v-q4m9/GHSA-4r4w-cm3v-q4m9.json +++ b/advisories/unreviewed/2025/05/GHSA-4r4w-cm3v-q4m9/GHSA-4r4w-cm3v-q4m9.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-52vv-jxvg-7g67/GHSA-52vv-jxvg-7g67.json b/advisories/unreviewed/2025/05/GHSA-52vv-jxvg-7g67/GHSA-52vv-jxvg-7g67.json new file mode 100644 index 00000000000..7659951797b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-52vv-jxvg-7g67/GHSA-52vv-jxvg-7g67.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-52vv-jxvg-7g67", + "modified": "2025-05-21T21:31:41Z", + "published": "2025-05-21T21:31:41Z", + "aliases": [ + "CVE-2025-45755" + ], + "details": "A Stored Cross-Site Scripting (XSS) vulnerability exists in Vtiger CRM Open Source Edition v8.3.0, exploitable via the Services Import feature. An attacker can craft a malicious CSV file containing an XSS payload, mapped to the Service Name field. When the file is uploaded, the application improperly sanitizes user input, leading to persistent script execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45755" + }, + { + "type": "WEB", + "url": "https://www.simonjuguna.com/cve-2025-45755-stored-cross-site-scripting-xss-vulnerability-in-vtiger-open-source-edition-v8-3-0" + }, + { + "type": "WEB", + "url": "https://www.vtiger.com/open-source-crm" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T20:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5xwv-wjhm-pv8f/GHSA-5xwv-wjhm-pv8f.json b/advisories/unreviewed/2025/05/GHSA-5xwv-wjhm-pv8f/GHSA-5xwv-wjhm-pv8f.json new file mode 100644 index 00000000000..d696f43b86e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5xwv-wjhm-pv8f/GHSA-5xwv-wjhm-pv8f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5xwv-wjhm-pv8f", + "modified": "2025-05-21T21:31:37Z", + "published": "2025-05-21T21:31:37Z", + "aliases": [ + "CVE-2019-16536" + ], + "details": "Stack overflow leading to DoS can be triggered by a malicious authenticated client in Clickhouse before 19.14.3.3.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-16536" + }, + { + "type": "WEB", + "url": "https://clickhouse.com/docs/whats-new/security-changelog" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T08:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6qr6-6c9q-cg4j/GHSA-6qr6-6c9q-cg4j.json b/advisories/unreviewed/2025/05/GHSA-6qr6-6c9q-cg4j/GHSA-6qr6-6c9q-cg4j.json new file mode 100644 index 00000000000..296b89e86eb --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6qr6-6c9q-cg4j/GHSA-6qr6-6c9q-cg4j.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6qr6-6c9q-cg4j", + "modified": "2025-05-21T21:31:37Z", + "published": "2025-05-21T21:31:37Z", + "aliases": [ + "CVE-2025-4219" + ], + "details": "The DPEPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dpe' shortcode in all versions up to, and including, 0.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4219" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/dpepress/trunk/dpepress.php#L72" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ccd273dc-9de3-4863-a787-db653f2003ca?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T12:16:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-735j-4gjq-vc2q/GHSA-735j-4gjq-vc2q.json b/advisories/unreviewed/2025/05/GHSA-735j-4gjq-vc2q/GHSA-735j-4gjq-vc2q.json index debbb6ee65f..9b646819c6f 100644 --- a/advisories/unreviewed/2025/05/GHSA-735j-4gjq-vc2q/GHSA-735j-4gjq-vc2q.json +++ b/advisories/unreviewed/2025/05/GHSA-735j-4gjq-vc2q/GHSA-735j-4gjq-vc2q.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-7mfw-wgr7-m3jg/GHSA-7mfw-wgr7-m3jg.json b/advisories/unreviewed/2025/05/GHSA-7mfw-wgr7-m3jg/GHSA-7mfw-wgr7-m3jg.json index ae5a89fb75c..bd71ee9952c 100644 --- a/advisories/unreviewed/2025/05/GHSA-7mfw-wgr7-m3jg/GHSA-7mfw-wgr7-m3jg.json +++ b/advisories/unreviewed/2025/05/GHSA-7mfw-wgr7-m3jg/GHSA-7mfw-wgr7-m3jg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7mfw-wgr7-m3jg", - "modified": "2025-05-21T18:33:32Z", + "modified": "2025-05-21T21:31:40Z", "published": "2025-05-21T18:33:32Z", "aliases": [ "CVE-2025-5020" ], "details": "Opening maliciously-crafted URLs in Firefox from other apps such as Safari could have allowed attackers to spoof website addresses if the URLs utilized non-HTTP schemes used internally by the Firefox iOS client This vulnerability affects Firefox for iOS < 139.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-939" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-21T18:15:53Z" diff --git a/advisories/unreviewed/2025/05/GHSA-7mjm-qh4m-vj6r/GHSA-7mjm-qh4m-vj6r.json b/advisories/unreviewed/2025/05/GHSA-7mjm-qh4m-vj6r/GHSA-7mjm-qh4m-vj6r.json index 3b21f798425..49481c49734 100644 --- a/advisories/unreviewed/2025/05/GHSA-7mjm-qh4m-vj6r/GHSA-7mjm-qh4m-vj6r.json +++ b/advisories/unreviewed/2025/05/GHSA-7mjm-qh4m-vj6r/GHSA-7mjm-qh4m-vj6r.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-7vv6-fh9h-ff3m/GHSA-7vv6-fh9h-ff3m.json b/advisories/unreviewed/2025/05/GHSA-7vv6-fh9h-ff3m/GHSA-7vv6-fh9h-ff3m.json index 667db047d3e..df1395988d4 100644 --- a/advisories/unreviewed/2025/05/GHSA-7vv6-fh9h-ff3m/GHSA-7vv6-fh9h-ff3m.json +++ b/advisories/unreviewed/2025/05/GHSA-7vv6-fh9h-ff3m/GHSA-7vv6-fh9h-ff3m.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-88w2-frvv-mx6x/GHSA-88w2-frvv-mx6x.json b/advisories/unreviewed/2025/05/GHSA-88w2-frvv-mx6x/GHSA-88w2-frvv-mx6x.json index b23d69a458b..6e2218d5bbe 100644 --- a/advisories/unreviewed/2025/05/GHSA-88w2-frvv-mx6x/GHSA-88w2-frvv-mx6x.json +++ b/advisories/unreviewed/2025/05/GHSA-88w2-frvv-mx6x/GHSA-88w2-frvv-mx6x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-88w2-frvv-mx6x", - "modified": "2025-05-21T18:33:31Z", + "modified": "2025-05-21T21:31:40Z", "published": "2025-05-21T18:33:31Z", "aliases": [ "CVE-2025-25539" ], "details": "Local File Inclusion vulnerability in Vasco v3.14and before allows a remote attacker to obtain sensitive information via help menu.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-98" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-21T17:15:57Z" diff --git a/advisories/unreviewed/2025/05/GHSA-8g7p-j56f-qh5f/GHSA-8g7p-j56f-qh5f.json b/advisories/unreviewed/2025/05/GHSA-8g7p-j56f-qh5f/GHSA-8g7p-j56f-qh5f.json new file mode 100644 index 00000000000..a257add2588 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8g7p-j56f-qh5f/GHSA-8g7p-j56f-qh5f.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8g7p-j56f-qh5f", + "modified": "2025-05-21T21:31:41Z", + "published": "2025-05-21T21:31:41Z", + "aliases": [ + "CVE-2025-46412" + ], + "details": "Affected Vertiv products do not properly protect webserver functions that could allow an attacker to bypass authentication.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46412" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-140-10" + }, + { + "type": "WEB", + "url": "https://www.vertiv.com/en-us/support/security-support-center" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T20:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8jmx-gwp7-3j43/GHSA-8jmx-gwp7-3j43.json b/advisories/unreviewed/2025/05/GHSA-8jmx-gwp7-3j43/GHSA-8jmx-gwp7-3j43.json new file mode 100644 index 00000000000..60d4e1cdfdc --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8jmx-gwp7-3j43/GHSA-8jmx-gwp7-3j43.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8jmx-gwp7-3j43", + "modified": "2025-05-21T21:31:41Z", + "published": "2025-05-21T21:31:41Z", + "aliases": [ + "CVE-2025-36535" + ], + "details": "The embedded web server lacks authentication and access controls, allowing unrestricted remote access. This could lead to configuration changes, operational disruption, or arbitrary code execution depending on the environment and exposed functionality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-36535" + }, + { + "type": "WEB", + "url": "https://www.automationdirect.com/adc/shopping/catalog/communications/protocol_gateways/modbus_gateways/eki-1221-ce" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-140-09" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T20:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-978h-h4vr-gv38/GHSA-978h-h4vr-gv38.json b/advisories/unreviewed/2025/05/GHSA-978h-h4vr-gv38/GHSA-978h-h4vr-gv38.json new file mode 100644 index 00000000000..379325f292f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-978h-h4vr-gv38/GHSA-978h-h4vr-gv38.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-978h-h4vr-gv38", + "modified": "2025-05-21T21:31:37Z", + "published": "2025-05-21T21:31:37Z", + "aliases": [ + "CVE-2025-3750" + ], + "details": "The Network Posts Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘post_height’ parameter in all versions up to, and including, 7.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3750" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/network-posts-extended/trunk/network-posts-extended.php#L663" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/network-posts-extended/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/64a15397-0bd6-4be9-90e3-6cb1f56394ad?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T12:16:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-994p-m2fc-8rmp/GHSA-994p-m2fc-8rmp.json b/advisories/unreviewed/2025/05/GHSA-994p-m2fc-8rmp/GHSA-994p-m2fc-8rmp.json new file mode 100644 index 00000000000..7ed6e16ac43 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-994p-m2fc-8rmp/GHSA-994p-m2fc-8rmp.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-994p-m2fc-8rmp", + "modified": "2025-05-21T21:31:37Z", + "published": "2025-05-21T21:31:37Z", + "aliases": [ + "CVE-2025-4105" + ], + "details": "The Splitit plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on several functions in the 'splitIt-flexfields-payment-gateway.php' file in all versions up to, and including, 4.2.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change plugin settings, including changing the environment from sandbox to production and vice versa.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4105" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/splitit-installment-payments/tags/4.2.6/splitIt-flexfields-payment-gateway.php#L1927" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/splitit-installment-payments/tags/4.2.6/splitIt-flexfields-payment-gateway.php#L765" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6471b075-8115-4d38-a7dd-2308dca69f15?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T12:16:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9m66-g6x7-m6cw/GHSA-9m66-g6x7-m6cw.json b/advisories/unreviewed/2025/05/GHSA-9m66-g6x7-m6cw/GHSA-9m66-g6x7-m6cw.json new file mode 100644 index 00000000000..8f62e75590a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9m66-g6x7-m6cw/GHSA-9m66-g6x7-m6cw.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9m66-g6x7-m6cw", + "modified": "2025-05-21T21:31:37Z", + "published": "2025-05-21T21:31:37Z", + "aliases": [ + "CVE-2024-12561" + ], + "details": "The Affiliate Sales in Google Analytics and other tools plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.4.9. This is due to insufficient validation on the redirect url supplied via the 'afflink' parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12561" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wecantrack/trunk/WecantrackApp.php#L66" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a4b205ab-f042-46d9-a331-f18809477384?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T12:16:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9mgg-ww23-jfhc/GHSA-9mgg-ww23-jfhc.json b/advisories/unreviewed/2025/05/GHSA-9mgg-ww23-jfhc/GHSA-9mgg-ww23-jfhc.json index 0a5b601120a..1bb69cabdba 100644 --- a/advisories/unreviewed/2025/05/GHSA-9mgg-ww23-jfhc/GHSA-9mgg-ww23-jfhc.json +++ b/advisories/unreviewed/2025/05/GHSA-9mgg-ww23-jfhc/GHSA-9mgg-ww23-jfhc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9mgg-ww23-jfhc", - "modified": "2025-05-21T18:33:30Z", + "modified": "2025-05-21T21:31:38Z", "published": "2025-05-21T18:33:30Z", "aliases": [ "CVE-2025-27997" ], "details": "An issue in Blizzard Battle.net v2.40.0.15267 allows attackers to escalate privileges via placing a crafted shell script or executable into the C:\\ProgramData directory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-427" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-21T16:15:30Z" diff --git a/advisories/unreviewed/2025/05/GHSA-c49m-468j-4qm9/GHSA-c49m-468j-4qm9.json b/advisories/unreviewed/2025/05/GHSA-c49m-468j-4qm9/GHSA-c49m-468j-4qm9.json new file mode 100644 index 00000000000..9427bd99a8e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c49m-468j-4qm9/GHSA-c49m-468j-4qm9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c49m-468j-4qm9", + "modified": "2025-05-21T21:31:40Z", + "published": "2025-05-21T21:31:40Z", + "aliases": [ + "CVE-2025-3751" + ], + "details": "The component listed above contains a vulnerability that can be exploited by an attacker to perform a SQL Injection attack. This could lead to unauthorised access to the database and exposure of sensitive information", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3751" + }, + { + "type": "WEB", + "url": "https://community.tibco.com/advisories/tibco-security-advisory-may-13-2025-tibco-activematrix-businessworks-cve-2025-3751-r221" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T19:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c8hr-6m27-p6qr/GHSA-c8hr-6m27-p6qr.json b/advisories/unreviewed/2025/05/GHSA-c8hr-6m27-p6qr/GHSA-c8hr-6m27-p6qr.json new file mode 100644 index 00000000000..67c34683a8c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c8hr-6m27-p6qr/GHSA-c8hr-6m27-p6qr.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c8hr-6m27-p6qr", + "modified": "2025-05-21T21:31:41Z", + "published": "2025-05-21T21:31:41Z", + "aliases": [ + "CVE-2025-5053" + ], + "details": "A vulnerability, which was classified as critical, has been found in FreeFloat FTP Server 1.0. Affected by this issue is some unknown functionality of the component MDIR Command Handler. The manipulation leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5053" + }, + { + "type": "WEB", + "url": "https://fitoxs.com/exploit/exploit-844fd54e7c56f8d038fc23d799cbff05d37452bc15f9a7203808d082de4a475f.txt" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309872" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309872" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.581285" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T21:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-cmvj-3pj4-hrr7/GHSA-cmvj-3pj4-hrr7.json b/advisories/unreviewed/2025/05/GHSA-cmvj-3pj4-hrr7/GHSA-cmvj-3pj4-hrr7.json index 78a0d99bce3..87c5c14cde8 100644 --- a/advisories/unreviewed/2025/05/GHSA-cmvj-3pj4-hrr7/GHSA-cmvj-3pj4-hrr7.json +++ b/advisories/unreviewed/2025/05/GHSA-cmvj-3pj4-hrr7/GHSA-cmvj-3pj4-hrr7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cmvj-3pj4-hrr7", - "modified": "2025-05-21T18:33:30Z", + "modified": "2025-05-21T21:31:38Z", "published": "2025-05-21T18:33:30Z", "aliases": [ "CVE-2025-27998" ], "details": "An issue in Valvesoftware Steam Client Steam Client 1738026274 allows attackers to escalate privileges via a crafted executable or DLL.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-21T16:15:31Z" diff --git a/advisories/unreviewed/2025/05/GHSA-cp28-vxmv-5fj9/GHSA-cp28-vxmv-5fj9.json b/advisories/unreviewed/2025/05/GHSA-cp28-vxmv-5fj9/GHSA-cp28-vxmv-5fj9.json index 1bfe6252e4c..cb922a7d4a2 100644 --- a/advisories/unreviewed/2025/05/GHSA-cp28-vxmv-5fj9/GHSA-cp28-vxmv-5fj9.json +++ b/advisories/unreviewed/2025/05/GHSA-cp28-vxmv-5fj9/GHSA-cp28-vxmv-5fj9.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-crjp-8g5r-p85r/GHSA-crjp-8g5r-p85r.json b/advisories/unreviewed/2025/05/GHSA-crjp-8g5r-p85r/GHSA-crjp-8g5r-p85r.json index da64e6bb40e..3d64e33c0f6 100644 --- a/advisories/unreviewed/2025/05/GHSA-crjp-8g5r-p85r/GHSA-crjp-8g5r-p85r.json +++ b/advisories/unreviewed/2025/05/GHSA-crjp-8g5r-p85r/GHSA-crjp-8g5r-p85r.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-ff3g-4fq3-jf4p/GHSA-ff3g-4fq3-jf4p.json b/advisories/unreviewed/2025/05/GHSA-ff3g-4fq3-jf4p/GHSA-ff3g-4fq3-jf4p.json new file mode 100644 index 00000000000..8ed136adeb7 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-ff3g-4fq3-jf4p/GHSA-ff3g-4fq3-jf4p.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ff3g-4fq3-jf4p", + "modified": "2025-05-21T21:31:37Z", + "published": "2025-05-21T21:31:37Z", + "aliases": [ + "CVE-2025-4969" + ], + "details": "A vulnerability was found in the libsoup package. This flaw stems from its failure to correctly verify the termination of multipart HTTP messages. This can allow a remote attacker to send a specially crafted multipart HTTP body, causing the libsoup-consuming server to read beyond its allocated memory boundaries (out-of-bounds read).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4969" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-4969" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2367552" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T06:16:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g4h5-fxmv-9q6m/GHSA-g4h5-fxmv-9q6m.json b/advisories/unreviewed/2025/05/GHSA-g4h5-fxmv-9q6m/GHSA-g4h5-fxmv-9q6m.json index ce033cdaa4d..a2a4603b359 100644 --- a/advisories/unreviewed/2025/05/GHSA-g4h5-fxmv-9q6m/GHSA-g4h5-fxmv-9q6m.json +++ b/advisories/unreviewed/2025/05/GHSA-g4h5-fxmv-9q6m/GHSA-g4h5-fxmv-9q6m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g4h5-fxmv-9q6m", - "modified": "2025-05-20T18:30:58Z", + "modified": "2025-05-21T21:31:34Z", "published": "2025-05-20T18:30:58Z", "aliases": [ "CVE-2025-44084" ], "details": "D-link DI-8100 16.07.26A1 is vulnerable to Command Injection. An attacker can exploit this vulnerability by crafting specific HTTP requests, triggering the command execution flaw and gaining the highest privilege shell access to the firmware system.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-20T17:15:49Z" diff --git a/advisories/unreviewed/2025/05/GHSA-ghp6-vq6h-h34h/GHSA-ghp6-vq6h-h34h.json b/advisories/unreviewed/2025/05/GHSA-ghp6-vq6h-h34h/GHSA-ghp6-vq6h-h34h.json new file mode 100644 index 00000000000..626514038da --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-ghp6-vq6h-h34h/GHSA-ghp6-vq6h-h34h.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ghp6-vq6h-h34h", + "modified": "2025-05-21T21:31:41Z", + "published": "2025-05-21T21:31:41Z", + "aliases": [ + "CVE-2025-5051" + ], + "details": "A vulnerability classified as critical has been found in FreeFloat FTP Server 1.0. Affected is an unknown function of the component BINARY Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5051" + }, + { + "type": "WEB", + "url": "https://fitoxs.com/exploit/exploit-4c025558ea74cba6eda5d8483c3d65f16de258eef4b3a5fcc50b4278c120e558.txt" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309870" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309870" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.581283" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T20:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gm5r-42wg-m55j/GHSA-gm5r-42wg-m55j.json b/advisories/unreviewed/2025/05/GHSA-gm5r-42wg-m55j/GHSA-gm5r-42wg-m55j.json index 808cc9623de..2fa9f8170be 100644 --- a/advisories/unreviewed/2025/05/GHSA-gm5r-42wg-m55j/GHSA-gm5r-42wg-m55j.json +++ b/advisories/unreviewed/2025/05/GHSA-gm5r-42wg-m55j/GHSA-gm5r-42wg-m55j.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-h5xv-74x6-xp2m/GHSA-h5xv-74x6-xp2m.json b/advisories/unreviewed/2025/05/GHSA-h5xv-74x6-xp2m/GHSA-h5xv-74x6-xp2m.json new file mode 100644 index 00000000000..f9b99bb676e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h5xv-74x6-xp2m/GHSA-h5xv-74x6-xp2m.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h5xv-74x6-xp2m", + "modified": "2025-05-21T21:31:41Z", + "published": "2025-05-21T21:31:41Z", + "aliases": [ + "CVE-2025-41426" + ], + "details": "Affected Vertiv products contain a stack based buffer overflow vulnerability. An attacker could exploit this vulnerability to gain code execution on the device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-41426" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-140-10" + }, + { + "type": "WEB", + "url": "https://www.vertiv.com/en-us/support/security-support-center" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T20:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h63w-98j8-p38r/GHSA-h63w-98j8-p38r.json b/advisories/unreviewed/2025/05/GHSA-h63w-98j8-p38r/GHSA-h63w-98j8-p38r.json index bd635315a09..38c6c6190ff 100644 --- a/advisories/unreviewed/2025/05/GHSA-h63w-98j8-p38r/GHSA-h63w-98j8-p38r.json +++ b/advisories/unreviewed/2025/05/GHSA-h63w-98j8-p38r/GHSA-h63w-98j8-p38r.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-hchj-55px-fgw7/GHSA-hchj-55px-fgw7.json b/advisories/unreviewed/2025/05/GHSA-hchj-55px-fgw7/GHSA-hchj-55px-fgw7.json new file mode 100644 index 00000000000..ce73ea12585 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hchj-55px-fgw7/GHSA-hchj-55px-fgw7.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hchj-55px-fgw7", + "modified": "2025-05-21T21:31:40Z", + "published": "2025-05-21T21:31:40Z", + "aliases": [ + "CVE-2025-27558" + ], + "details": "IEEE P802.11-REVme D1.1 through D7.0 allows FragAttacks against mesh networks. In mesh networks using Wi-Fi Protected Access (WPA, WPA2, or WPA3) or Wired Equivalent Privacy (WEP), an adversary can exploit this vulnerability to inject arbitrary frames towards devices that support receiving non-SSP A-MSDU frames. NOTE: this issue exists because of an incorrect fix for CVE-2020-24588. P802.11-REVme, as of early 2025, is a planned release of the 802.11 standard.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27558" + }, + { + "type": "WEB", + "url": "https://github.com/vanhoefm/fragattacks-survey-public/blob/main/README.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T19:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hp89-xxh7-4ph4/GHSA-hp89-xxh7-4ph4.json b/advisories/unreviewed/2025/05/GHSA-hp89-xxh7-4ph4/GHSA-hp89-xxh7-4ph4.json new file mode 100644 index 00000000000..d33f542c6f9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hp89-xxh7-4ph4/GHSA-hp89-xxh7-4ph4.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hp89-xxh7-4ph4", + "modified": "2025-05-21T21:31:41Z", + "published": "2025-05-21T21:31:41Z", + "aliases": [ + "CVE-2025-5049" + ], + "details": "A vulnerability was found in FreeFloat FTP Server 1.0. It has been declared as critical. This vulnerability affects unknown code of the component APPEND Command Handler. The manipulation leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5049" + }, + { + "type": "WEB", + "url": "https://fitoxs.com/exploit/e837c056f1ced605a9574541c7bf9861982bbf52ac5da3a5c5b637dbbadb49b7-exploit.txt" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309868" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309868" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.581278" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T19:16:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-j2vv-r926-8gq3/GHSA-j2vv-r926-8gq3.json b/advisories/unreviewed/2025/05/GHSA-j2vv-r926-8gq3/GHSA-j2vv-r926-8gq3.json index b96dc8cc5d4..0a54791d438 100644 --- a/advisories/unreviewed/2025/05/GHSA-j2vv-r926-8gq3/GHSA-j2vv-r926-8gq3.json +++ b/advisories/unreviewed/2025/05/GHSA-j2vv-r926-8gq3/GHSA-j2vv-r926-8gq3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j2vv-r926-8gq3", - "modified": "2025-05-21T18:33:30Z", + "modified": "2025-05-21T21:31:38Z", "published": "2025-05-21T18:33:30Z", "aliases": [ "CVE-2024-56428" ], "details": "The local iLabClient database in itech iLabClient 3.7.1 allows local attackers to read cleartext credentials (from the CONFIGS table) for their servers configured in the client.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-312" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-21T17:15:55Z" diff --git a/advisories/unreviewed/2025/05/GHSA-j8pp-q5m4-fqpf/GHSA-j8pp-q5m4-fqpf.json b/advisories/unreviewed/2025/05/GHSA-j8pp-q5m4-fqpf/GHSA-j8pp-q5m4-fqpf.json new file mode 100644 index 00000000000..8c3583cba05 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-j8pp-q5m4-fqpf/GHSA-j8pp-q5m4-fqpf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j8pp-q5m4-fqpf", + "modified": "2025-05-21T21:31:40Z", + "published": "2025-05-21T21:31:40Z", + "aliases": [ + "CVE-2025-2261" + ], + "details": "Stored XSS in TIBCO ActiveMatrix Administrator allows malicious data to appear to be part of the website and run within user's browser under the privileges of the web application.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2261" + }, + { + "type": "WEB", + "url": "https://community.tibco.com/advisories/tibco-security-advisory-may-13-2025-tibco-bpm-enterprise-cve-2025-2261-r220" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T19:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jpg6-jwqc-47r4/GHSA-jpg6-jwqc-47r4.json b/advisories/unreviewed/2025/05/GHSA-jpg6-jwqc-47r4/GHSA-jpg6-jwqc-47r4.json index dce1eed899d..17dc5c949b3 100644 --- a/advisories/unreviewed/2025/05/GHSA-jpg6-jwqc-47r4/GHSA-jpg6-jwqc-47r4.json +++ b/advisories/unreviewed/2025/05/GHSA-jpg6-jwqc-47r4/GHSA-jpg6-jwqc-47r4.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-m464-q4xf-9rw5/GHSA-m464-q4xf-9rw5.json b/advisories/unreviewed/2025/05/GHSA-m464-q4xf-9rw5/GHSA-m464-q4xf-9rw5.json new file mode 100644 index 00000000000..625d74eb79c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-m464-q4xf-9rw5/GHSA-m464-q4xf-9rw5.json @@ -0,0 +1,60 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m464-q4xf-9rw5", + "modified": "2025-05-21T21:31:38Z", + "published": "2025-05-21T21:31:38Z", + "aliases": [ + "CVE-2025-4611" + ], + "details": "The Slim SEO – Fast & Automated WordPress SEO Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's slim_seo_breadcrumbs shortcode in all versions up to, and including, 4.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4611" + }, + { + "type": "WEB", + "url": "https://github.com/elightup/slim-seo/commit/b475dceff3a6bd94335d5a79eb12cdd92e2c8350" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/slim-seo/tags/4.5.3/src/Breadcrumbs.php#L109" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/slim-seo/tags/4.5.3/src/Breadcrumbs.php#L37" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/slim-seo/tags/4.5.3/src/Breadcrumbs.php#L85" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3296099" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/slim-seo/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6318a1cf-716f-450c-a1c2-497de8095daa?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T12:16:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mjcq-3whq-7xjh/GHSA-mjcq-3whq-7xjh.json b/advisories/unreviewed/2025/05/GHSA-mjcq-3whq-7xjh/GHSA-mjcq-3whq-7xjh.json new file mode 100644 index 00000000000..37a24ed3dcd --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mjcq-3whq-7xjh/GHSA-mjcq-3whq-7xjh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mjcq-3whq-7xjh", + "modified": "2025-05-21T21:31:37Z", + "published": "2025-05-21T21:31:37Z", + "aliases": [ + "CVE-2021-25254" + ], + "details": "Yandex Browser Lite for Android before 21.1.0 allows remote attackers to spoof the address bar.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-25254" + }, + { + "type": "WEB", + "url": "https://yandex.com/bugbounty/i/hall-of-fame-browser" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-116" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T07:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p52j-q8rr-82g2/GHSA-p52j-q8rr-82g2.json b/advisories/unreviewed/2025/05/GHSA-p52j-q8rr-82g2/GHSA-p52j-q8rr-82g2.json new file mode 100644 index 00000000000..767aeb7408f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p52j-q8rr-82g2/GHSA-p52j-q8rr-82g2.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p52j-q8rr-82g2", + "modified": "2025-05-21T21:31:41Z", + "published": "2025-05-21T21:31:41Z", + "aliases": [ + "CVE-2025-5052" + ], + "details": "A vulnerability classified as critical was found in FreeFloat FTP Server 1.0. Affected by this vulnerability is an unknown functionality of the component LS Command Handler. The manipulation leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5052" + }, + { + "type": "WEB", + "url": "https://fitoxs.com/exploit/exploit-bbcf0f842f1c5385430b6992995a8eb068c58dfbaae38ffb7df1d2c69041bc7c1.txt" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309871" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309871" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.581284" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T21:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p986-xv2x-2cjm/GHSA-p986-xv2x-2cjm.json b/advisories/unreviewed/2025/05/GHSA-p986-xv2x-2cjm/GHSA-p986-xv2x-2cjm.json new file mode 100644 index 00000000000..f4537e0e280 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p986-xv2x-2cjm/GHSA-p986-xv2x-2cjm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p986-xv2x-2cjm", + "modified": "2025-05-21T21:31:37Z", + "published": "2025-05-21T21:31:37Z", + "aliases": [ + "CVE-2021-25255" + ], + "details": "Yandex Browser Lite for Android prior to version 21.1.0 allows remote attackers to cause a denial of service.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-25255" + }, + { + "type": "WEB", + "url": "https://yandex.com/bugbounty/i/hall-of-fame-browser" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T07:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-phwm-q22c-gqgm/GHSA-phwm-q22c-gqgm.json b/advisories/unreviewed/2025/05/GHSA-phwm-q22c-gqgm/GHSA-phwm-q22c-gqgm.json index 9c727dfa5da..71f0a3a4422 100644 --- a/advisories/unreviewed/2025/05/GHSA-phwm-q22c-gqgm/GHSA-phwm-q22c-gqgm.json +++ b/advisories/unreviewed/2025/05/GHSA-phwm-q22c-gqgm/GHSA-phwm-q22c-gqgm.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-q462-2796-rfg7/GHSA-q462-2796-rfg7.json b/advisories/unreviewed/2025/05/GHSA-q462-2796-rfg7/GHSA-q462-2796-rfg7.json new file mode 100644 index 00000000000..a8391558837 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q462-2796-rfg7/GHSA-q462-2796-rfg7.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q462-2796-rfg7", + "modified": "2025-05-21T21:31:37Z", + "published": "2025-05-21T21:31:37Z", + "aliases": [ + "CVE-2025-4524" + ], + "details": "The Madara – Responsive and modern WordPress theme for manga sites theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.2.2 via the 'template' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4524" + }, + { + "type": "WEB", + "url": "https://mangabooth.com/product/wp-manga-theme-madara" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a3ee01da-218a-421d-8f9c-1dc6c056ef74?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T07:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qf5x-7jf5-56qp/GHSA-qf5x-7jf5-56qp.json b/advisories/unreviewed/2025/05/GHSA-qf5x-7jf5-56qp/GHSA-qf5x-7jf5-56qp.json new file mode 100644 index 00000000000..554da6093de --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qf5x-7jf5-56qp/GHSA-qf5x-7jf5-56qp.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qf5x-7jf5-56qp", + "modified": "2025-05-21T21:31:40Z", + "published": "2025-05-21T21:31:40Z", + "aliases": [ + "CVE-2024-57529" + ], + "details": "Cross Site Scripting vulnerability in Jeppesen JetPlanner Pro v.1.6.2.20 allows a remote attacker to execute arbitrary code.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57529" + }, + { + "type": "WEB", + "url": "https://medium.com/@a77777mad/xss-vulnerability-discovered-in-jetplanner-pro-a-popular-flight-planning-solution-2dd48a7f6e72" + }, + { + "type": "WEB", + "url": "http://jeppesen.com" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T19:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qpcv-fjxx-24cv/GHSA-qpcv-fjxx-24cv.json b/advisories/unreviewed/2025/05/GHSA-qpcv-fjxx-24cv/GHSA-qpcv-fjxx-24cv.json new file mode 100644 index 00000000000..8df72d23252 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qpcv-fjxx-24cv/GHSA-qpcv-fjxx-24cv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qpcv-fjxx-24cv", + "modified": "2025-05-21T21:31:37Z", + "published": "2025-05-21T21:31:37Z", + "aliases": [ + "CVE-2021-25262" + ], + "details": "Yandex Browser for Android prior to version 21.3.0 allows remote attackers to perform IDN homograph attack.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-25262" + }, + { + "type": "WEB", + "url": "https://yandex.com/bugbounty/i/hall-of-fame-browser" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-116" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T07:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qx88-qw7m-mgq7/GHSA-qx88-qw7m-mgq7.json b/advisories/unreviewed/2025/05/GHSA-qx88-qw7m-mgq7/GHSA-qx88-qw7m-mgq7.json index 393fda16c07..1d646875a58 100644 --- a/advisories/unreviewed/2025/05/GHSA-qx88-qw7m-mgq7/GHSA-qx88-qw7m-mgq7.json +++ b/advisories/unreviewed/2025/05/GHSA-qx88-qw7m-mgq7/GHSA-qx88-qw7m-mgq7.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-rc3j-9c9w-j5qc/GHSA-rc3j-9c9w-j5qc.json b/advisories/unreviewed/2025/05/GHSA-rc3j-9c9w-j5qc/GHSA-rc3j-9c9w-j5qc.json index 64f2b4632e9..ec8a0d7ad9a 100644 --- a/advisories/unreviewed/2025/05/GHSA-rc3j-9c9w-j5qc/GHSA-rc3j-9c9w-j5qc.json +++ b/advisories/unreviewed/2025/05/GHSA-rc3j-9c9w-j5qc/GHSA-rc3j-9c9w-j5qc.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-rfvm-7wp6-hchg/GHSA-rfvm-7wp6-hchg.json b/advisories/unreviewed/2025/05/GHSA-rfvm-7wp6-hchg/GHSA-rfvm-7wp6-hchg.json new file mode 100644 index 00000000000..7f6e90420e9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rfvm-7wp6-hchg/GHSA-rfvm-7wp6-hchg.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rfvm-7wp6-hchg", + "modified": "2025-05-21T21:31:37Z", + "published": "2025-05-21T21:31:37Z", + "aliases": [ + "CVE-2025-1415" + ], + "details": "A low-privileged user is able to obtain information about tasks executed on devices controlled by Proget MDM (Mobile Device Management), as well as details of the devices like their UUIDs needed for exploitation of CVE-2025-1416.\n\nIn order to perform the attack, one has to know a task_id, but since it's a low integer and there is no limit of requests an attacker can perform to a vulnerable endpoint, the task_id might be simply brute forced.\n\nThis issue has been fixed in 2.17.5 version of Konsola Proget (server part of the MDM suite).", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1415" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2025/05/CVE-2025-1415" + }, + { + "type": "WEB", + "url": "https://proget.pl/en/mobile-device-management" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T12:16:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rm9f-vcmm-7x46/GHSA-rm9f-vcmm-7x46.json b/advisories/unreviewed/2025/05/GHSA-rm9f-vcmm-7x46/GHSA-rm9f-vcmm-7x46.json index dbd69f8326a..2200eb6f560 100644 --- a/advisories/unreviewed/2025/05/GHSA-rm9f-vcmm-7x46/GHSA-rm9f-vcmm-7x46.json +++ b/advisories/unreviewed/2025/05/GHSA-rm9f-vcmm-7x46/GHSA-rm9f-vcmm-7x46.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-v8g8-7xq6-7fpp/GHSA-v8g8-7xq6-7fpp.json b/advisories/unreviewed/2025/05/GHSA-v8g8-7xq6-7fpp/GHSA-v8g8-7xq6-7fpp.json index 38f99d2cb0d..e5c2a28e748 100644 --- a/advisories/unreviewed/2025/05/GHSA-v8g8-7xq6-7fpp/GHSA-v8g8-7xq6-7fpp.json +++ b/advisories/unreviewed/2025/05/GHSA-v8g8-7xq6-7fpp/GHSA-v8g8-7xq6-7fpp.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-vj38-xwp2-x5gc/GHSA-vj38-xwp2-x5gc.json b/advisories/unreviewed/2025/05/GHSA-vj38-xwp2-x5gc/GHSA-vj38-xwp2-x5gc.json new file mode 100644 index 00000000000..3467f95bae5 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vj38-xwp2-x5gc/GHSA-vj38-xwp2-x5gc.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vj38-xwp2-x5gc", + "modified": "2025-05-21T21:31:41Z", + "published": "2025-05-21T21:31:41Z", + "aliases": [ + "CVE-2025-44040" + ], + "details": "An issue in OrangeHRM v.5.7 allows an attacker to escalate privileges via the UserService.php and the checkFOrOldHash function", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44040" + }, + { + "type": "WEB", + "url": "https://github.com/hexomedin3/advisories/tree/main/CVE-2025-44040" + }, + { + "type": "WEB", + "url": "https://github.com/orangehrm/orangehrm/releases/tag/v5.7" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T21:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vr5w-fmp9-m564/GHSA-vr5w-fmp9-m564.json b/advisories/unreviewed/2025/05/GHSA-vr5w-fmp9-m564/GHSA-vr5w-fmp9-m564.json new file mode 100644 index 00000000000..8e82afbea6e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vr5w-fmp9-m564/GHSA-vr5w-fmp9-m564.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vr5w-fmp9-m564", + "modified": "2025-05-21T21:31:37Z", + "published": "2025-05-21T21:31:36Z", + "aliases": [ + "CVE-2025-4094" + ], + "details": "The DIGITS: WordPress Mobile Number Signup and Login WordPress plugin before 8.4.6.1 does not rate limit OTP validation attempts, making it straightforward for attackers to bruteforce them.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4094" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/b5f0a263-644b-4954-a1f0-d08e2149edbb" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T06:16:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vrgv-fv58-v6jg/GHSA-vrgv-fv58-v6jg.json b/advisories/unreviewed/2025/05/GHSA-vrgv-fv58-v6jg/GHSA-vrgv-fv58-v6jg.json new file mode 100644 index 00000000000..8ce0539321b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vrgv-fv58-v6jg/GHSA-vrgv-fv58-v6jg.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vrgv-fv58-v6jg", + "modified": "2025-05-21T21:31:37Z", + "published": "2025-05-21T21:31:37Z", + "aliases": [ + "CVE-2025-5013" + ], + "details": "A vulnerability, which was classified as problematic, was found in HkCms up to 2.3.2.240702. This affects an unknown part of the file /index.php/search/index.html of the component Search. The manipulation of the argument keyword leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5013" + }, + { + "type": "WEB", + "url": "https://gitee.com/Hk_Cms/HkCms/issues/IBZ2G7" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309729" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309729" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T06:16:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vrpq-qp53-qv56/GHSA-vrpq-qp53-qv56.json b/advisories/unreviewed/2025/05/GHSA-vrpq-qp53-qv56/GHSA-vrpq-qp53-qv56.json new file mode 100644 index 00000000000..972878777e8 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vrpq-qp53-qv56/GHSA-vrpq-qp53-qv56.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vrpq-qp53-qv56", + "modified": "2025-05-21T21:31:37Z", + "published": "2025-05-21T21:31:37Z", + "aliases": [ + "CVE-2025-4949" + ], + "details": "In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML External Entity (XXE) attacks when parsing XML files. This vulnerability can lead to information disclosure, denial of service, and other security issues.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:D/RE:L/U:Green" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4949" + }, + { + "type": "WEB", + "url": "https://gitlab.eclipse.org/security/cve-assignement/-/issues/64" + }, + { + "type": "WEB", + "url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/281" + }, + { + "type": "WEB", + "url": "https://projects.eclipse.org/projects/technology.jgit/releases/7.2.1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-611" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T07:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w34f-x9rj-jg28/GHSA-w34f-x9rj-jg28.json b/advisories/unreviewed/2025/05/GHSA-w34f-x9rj-jg28/GHSA-w34f-x9rj-jg28.json new file mode 100644 index 00000000000..6b6c54e06f2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w34f-x9rj-jg28/GHSA-w34f-x9rj-jg28.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w34f-x9rj-jg28", + "modified": "2025-05-21T21:31:40Z", + "published": "2025-05-21T21:31:40Z", + "aliases": [ + "CVE-2025-45752" + ], + "details": "A vulnerability in SeedDMS 6.0.32 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting the zip import functionality in the Extension Manager.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45752" + }, + { + "type": "WEB", + "url": "https://www.simonjuguna.com/cve-2025-45752-authenticated-remote-code-execution-vulnerability-in-seeddms-v6-0-32" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T19:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wvh4-qfmr-fv6q/GHSA-wvh4-qfmr-fv6q.json b/advisories/unreviewed/2025/05/GHSA-wvh4-qfmr-fv6q/GHSA-wvh4-qfmr-fv6q.json index e72c919e5ed..aaa35307bcd 100644 --- a/advisories/unreviewed/2025/05/GHSA-wvh4-qfmr-fv6q/GHSA-wvh4-qfmr-fv6q.json +++ b/advisories/unreviewed/2025/05/GHSA-wvh4-qfmr-fv6q/GHSA-wvh4-qfmr-fv6q.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-x6qv-rrjj-869w/GHSA-x6qv-rrjj-869w.json b/advisories/unreviewed/2025/05/GHSA-x6qv-rrjj-869w/GHSA-x6qv-rrjj-869w.json index 0e685a7c1ea..3a13a9350a8 100644 --- a/advisories/unreviewed/2025/05/GHSA-x6qv-rrjj-869w/GHSA-x6qv-rrjj-869w.json +++ b/advisories/unreviewed/2025/05/GHSA-x6qv-rrjj-869w/GHSA-x6qv-rrjj-869w.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-xm6v-3wmv-c56v/GHSA-xm6v-3wmv-c56v.json b/advisories/unreviewed/2025/05/GHSA-xm6v-3wmv-c56v/GHSA-xm6v-3wmv-c56v.json new file mode 100644 index 00000000000..45e83b32fdc --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xm6v-3wmv-c56v/GHSA-xm6v-3wmv-c56v.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xm6v-3wmv-c56v", + "modified": "2025-05-21T21:31:38Z", + "published": "2025-05-21T21:31:38Z", + "aliases": [ + "CVE-2025-4803" + ], + "details": "The Glossary by WPPedia – Best Glossary plugin for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.0 via deserialization of untrusted input from the 'posttypes' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4803" + }, + { + "type": "WEB", + "url": "https://github.com/bfiessinger/wppedia/blob/1d0b8568349c9c9479372f845a812eb2aa4b3d09/core/classes/traits/trait-sanitizes-data.php#L64" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wppedia/tags/1.3.0/core/classes/class-options.php#L396" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wppedia/tags/1.3.0/core/classes/traits/trait-sanitizes-data.php#L64" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/53fb54bc-6eaa-4e99-a41c-e59a9bae81e5?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T12:16:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xmq3-c6r3-6cm9/GHSA-xmq3-c6r3-6cm9.json b/advisories/unreviewed/2025/05/GHSA-xmq3-c6r3-6cm9/GHSA-xmq3-c6r3-6cm9.json index bb3e667d664..8ed708b4f6c 100644 --- a/advisories/unreviewed/2025/05/GHSA-xmq3-c6r3-6cm9/GHSA-xmq3-c6r3-6cm9.json +++ b/advisories/unreviewed/2025/05/GHSA-xmq3-c6r3-6cm9/GHSA-xmq3-c6r3-6cm9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xmq3-c6r3-6cm9", - "modified": "2025-05-21T18:33:31Z", + "modified": "2025-05-21T21:31:40Z", "published": "2025-05-21T18:33:31Z", "aliases": [ "CVE-2025-45754" ], "details": "A stored cross-site scripting (XSS) vulnerability exists in SeedDMS 6.0.32. This vulnerability allows an attacker to inject malicious JavaScript payloads by creating a document with an XSS payload as the document name.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-21T17:15:58Z" diff --git a/advisories/unreviewed/2025/05/GHSA-xwcp-6g2q-65gm/GHSA-xwcp-6g2q-65gm.json b/advisories/unreviewed/2025/05/GHSA-xwcp-6g2q-65gm/GHSA-xwcp-6g2q-65gm.json new file mode 100644 index 00000000000..0d0a2b15f17 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xwcp-6g2q-65gm/GHSA-xwcp-6g2q-65gm.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xwcp-6g2q-65gm", + "modified": "2025-05-21T21:31:40Z", + "published": "2025-05-21T21:31:40Z", + "aliases": [ + "CVE-2025-44083" + ], + "details": "An issue in D-Link DI-8100 16.07.26A1 allows a remote attacker to bypass administrator login authentication", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44083" + }, + { + "type": "WEB", + "url": "https://github.com/piposy/IOTsec/blob/main/Dlink/DI8100/DI8100-A1-1.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T19:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xwrv-8p5w-52hj/GHSA-xwrv-8p5w-52hj.json b/advisories/unreviewed/2025/05/GHSA-xwrv-8p5w-52hj/GHSA-xwrv-8p5w-52hj.json new file mode 100644 index 00000000000..a0f8e56bc4f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xwrv-8p5w-52hj/GHSA-xwrv-8p5w-52hj.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xwrv-8p5w-52hj", + "modified": "2025-05-21T21:31:41Z", + "published": "2025-05-21T21:31:41Z", + "aliases": [ + "CVE-2025-45753" + ], + "details": "A vulnerability in Vtiger CRM Open Source Edition v8.3.0 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting the ZIP import functionality in the Module Import feature.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45753" + }, + { + "type": "WEB", + "url": "https://www.simonjuguna.com/cve-2025-45753-authenticated-remote-code-execution-vulnerability-in-vtiger-open-source-edition-v8-3-0" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-21T21:16:03Z" + } +} \ No newline at end of file