From b52c2e2a0e6f9512d060b7481203c4f9b4eb7bc5 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 19 May 2025 18:32:43 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-27mv-5vpc-8g53.json | 6 +- .../GHSA-rr36-3hq5-mqj8.json | 4 +- .../GHSA-4q9h-rhrc-98f3.json | 3 +- .../GHSA-qrvg-mg33-q843.json | 6 +- .../GHSA-27mf-h76r-wrj9.json | 52 +++++++++++++++++ .../GHSA-292v-wgjp-vm43.json | 36 ++++++++++++ .../GHSA-2cr7-4mvv-cpm5.json | 3 +- .../GHSA-2m98-w299-f59w.json | 36 ++++++++++++ .../GHSA-2qw9-5pj2-hf6h.json | 36 ++++++++++++ .../GHSA-2r7h-jv72-f7xp.json | 36 ++++++++++++ .../GHSA-3349-q488-4m7r.json | 36 ++++++++++++ .../GHSA-3533-x66r-qv4w.json | 3 +- .../GHSA-37xj-x86x-8h3f.json | 36 ++++++++++++ .../GHSA-3f4g-72qh-pgc7.json | 36 ++++++++++++ .../GHSA-3gx9-8889-ccm7.json | 15 +++-- .../GHSA-3hhf-g967-wcf6.json | 36 ++++++++++++ .../GHSA-3vpx-xc92-826m.json | 36 ++++++++++++ .../GHSA-43hr-6fp9-6wgg.json | 15 +++-- .../GHSA-45rr-p56g-wc84.json | 3 +- .../GHSA-4ffv-mjwj-jpv4.json | 36 ++++++++++++ .../GHSA-4ggw-jqjj-86hc.json | 36 ++++++++++++ .../GHSA-4mvv-v35x-r8h9.json | 36 ++++++++++++ .../GHSA-4rxg-fmh7-xhh5.json | 3 +- .../GHSA-5c6q-hvvg-576r.json | 40 +++++++++++++ .../GHSA-5f94-w474-qm8f.json | 36 ++++++++++++ .../GHSA-5mh7-pwwr-gwf7.json | 36 ++++++++++++ .../GHSA-5p8g-r99q-6826.json | 36 ++++++++++++ .../GHSA-5r36-pxhw-fw6j.json | 15 +++-- .../GHSA-5xjr-6vjm-xc96.json | 3 +- .../GHSA-6366-5cxc-p7vq.json | 36 ++++++++++++ .../GHSA-66q6-24vw-2g98.json | 6 +- .../GHSA-67wj-6mjf-7pcq.json | 36 ++++++++++++ .../GHSA-6m6f-rwf2-ghvg.json | 15 +++-- .../GHSA-6wqv-328v-59px.json | 36 ++++++++++++ .../GHSA-7f8x-9x27-qrmg.json | 36 ++++++++++++ .../GHSA-7rm6-cjw9-cf8v.json | 11 +++- .../GHSA-7xmm-8q26-r88f.json | 36 ++++++++++++ .../GHSA-7xxp-38mj-pgpw.json | 36 ++++++++++++ .../GHSA-8f4v-pgv9-r6f5.json | 36 ++++++++++++ .../GHSA-8h35-v7xf-x336.json | 36 ++++++++++++ .../GHSA-8p9j-879p-799j.json | 15 +++-- .../GHSA-8qm7-2hp6-h7jr.json | 36 ++++++++++++ .../GHSA-9397-457v-6qhp.json | 56 +++++++++++++++++++ .../GHSA-9p4p-6vvc-6mcp.json | 36 ++++++++++++ .../GHSA-c2j9-c6rw-g8g7.json | 36 ++++++++++++ .../GHSA-c6gj-2jr9-8cjp.json | 36 ++++++++++++ .../GHSA-c9gm-698m-cjr7.json | 36 ++++++++++++ .../GHSA-cq8m-2x25-mgg8.json | 1 + .../GHSA-cr74-88qf-5463.json | 36 ++++++++++++ .../GHSA-cv2q-598m-m7h2.json | 3 +- .../GHSA-f2q5-wfpv-jc4m.json | 36 ++++++++++++ .../GHSA-f333-vhwv-jvmx.json | 15 +++-- .../GHSA-f6vc-5hqq-c3x2.json | 36 ++++++++++++ .../GHSA-fhx6-jcrh-354h.json | 36 ++++++++++++ .../GHSA-fp2g-4h6f-28h2.json | 11 +++- .../GHSA-frr9-jr53-8x43.json | 36 ++++++++++++ .../GHSA-fxh5-h665-pxfj.json | 3 +- .../GHSA-ggh3-rx92-gffh.json | 1 + .../GHSA-grxh-3m7g-g4pc.json | 54 ++++++++++++++++++ .../GHSA-h4v2-mpxm-7h3w.json | 36 ++++++++++++ .../GHSA-hcg6-8qj3-r5xc.json | 36 ++++++++++++ .../GHSA-hchw-qwx7-4w4c.json | 4 +- .../GHSA-hqf6-65hw-qq68.json | 36 ++++++++++++ .../GHSA-hw3m-mgfc-g5r4.json | 36 ++++++++++++ .../GHSA-hwpp-r7c7-mx9g.json | 36 ++++++++++++ .../GHSA-jwxw-jqxj-962v.json | 36 ++++++++++++ .../GHSA-m4gj-q4fx-v26f.json | 36 ++++++++++++ .../GHSA-m4w4-6mfj-fqh8.json | 56 +++++++++++++++++++ .../GHSA-mhg9-c8wr-hm8x.json | 36 ++++++++++++ .../GHSA-mjqj-43pc-37r9.json | 1 + .../GHSA-mr4j-xfv9-w967.json | 3 +- .../GHSA-mwcf-jv2p-mmpx.json | 40 +++++++++++++ .../GHSA-p9jx-jr54-2xq2.json | 3 +- .../GHSA-pc32-32fx-wxh7.json | 36 ++++++++++++ .../GHSA-pjx5-26hx-4cj5.json | 36 ++++++++++++ .../GHSA-pp7f-fm4q-phg7.json | 34 +++++++++++ .../GHSA-prf9-gx8m-9cfq.json | 36 ++++++++++++ .../GHSA-q2pv-8f62-27p3.json | 36 ++++++++++++ .../GHSA-q7qq-47m5-qqj6.json | 3 +- .../GHSA-qwwx-f8r3-v9pc.json | 56 +++++++++++++++++++ .../GHSA-r2q8-3rg5-p5rg.json | 15 +++-- .../GHSA-r3v9-92q2-pvmf.json | 15 +++-- .../GHSA-r53g-69jj-xq7x.json | 56 +++++++++++++++++++ .../GHSA-r593-5693-qv6x.json | 36 ++++++++++++ .../GHSA-rf2f-phpv-m2gx.json | 3 +- .../GHSA-rgrg-qwpp-28j8.json | 3 +- .../GHSA-rrcx-vcp9-h6c7.json | 15 +++-- .../GHSA-rw3p-877j-xxwm.json | 36 ++++++++++++ .../GHSA-v5vr-7qc6-xw56.json | 10 +++- .../GHSA-vfg9-gh45-wrq2.json | 3 +- .../GHSA-vfx3-xjmh-f34c.json | 36 ++++++++++++ .../GHSA-vgrj-mg42-7vqg.json | 15 +++-- .../GHSA-vh6g-f64r-5r5w.json | 36 ++++++++++++ .../GHSA-vqxf-9gx2-9j34.json | 36 ++++++++++++ .../GHSA-vqxg-8xhm-jf4p.json | 36 ++++++++++++ .../GHSA-w2cm-pc9j-3m28.json | 3 +- .../GHSA-wjv3-vv76-gqfj.json | 56 +++++++++++++++++++ .../GHSA-wr46-685x-rcr2.json | 3 +- .../GHSA-x47c-v779-7xcp.json | 36 ++++++++++++ .../GHSA-x725-g7rw-pw6q.json | 36 ++++++++++++ .../GHSA-x8r2-wrm6-4v97.json | 42 ++++++++++++++ .../GHSA-xh92-vqm9-v66r.json | 3 +- .../GHSA-xrjq-mmx8-72h6.json | 1 + 103 files changed, 2643 insertions(+), 70 deletions(-) create mode 100644 advisories/unreviewed/2025/05/GHSA-27mf-h76r-wrj9/GHSA-27mf-h76r-wrj9.json create mode 100644 advisories/unreviewed/2025/05/GHSA-292v-wgjp-vm43/GHSA-292v-wgjp-vm43.json create mode 100644 advisories/unreviewed/2025/05/GHSA-2m98-w299-f59w/GHSA-2m98-w299-f59w.json create mode 100644 advisories/unreviewed/2025/05/GHSA-2qw9-5pj2-hf6h/GHSA-2qw9-5pj2-hf6h.json create mode 100644 advisories/unreviewed/2025/05/GHSA-2r7h-jv72-f7xp/GHSA-2r7h-jv72-f7xp.json create mode 100644 advisories/unreviewed/2025/05/GHSA-3349-q488-4m7r/GHSA-3349-q488-4m7r.json create mode 100644 advisories/unreviewed/2025/05/GHSA-37xj-x86x-8h3f/GHSA-37xj-x86x-8h3f.json create mode 100644 advisories/unreviewed/2025/05/GHSA-3f4g-72qh-pgc7/GHSA-3f4g-72qh-pgc7.json create mode 100644 advisories/unreviewed/2025/05/GHSA-3hhf-g967-wcf6/GHSA-3hhf-g967-wcf6.json create mode 100644 advisories/unreviewed/2025/05/GHSA-3vpx-xc92-826m/GHSA-3vpx-xc92-826m.json create mode 100644 advisories/unreviewed/2025/05/GHSA-4ffv-mjwj-jpv4/GHSA-4ffv-mjwj-jpv4.json create mode 100644 advisories/unreviewed/2025/05/GHSA-4ggw-jqjj-86hc/GHSA-4ggw-jqjj-86hc.json create mode 100644 advisories/unreviewed/2025/05/GHSA-4mvv-v35x-r8h9/GHSA-4mvv-v35x-r8h9.json create mode 100644 advisories/unreviewed/2025/05/GHSA-5c6q-hvvg-576r/GHSA-5c6q-hvvg-576r.json create mode 100644 advisories/unreviewed/2025/05/GHSA-5f94-w474-qm8f/GHSA-5f94-w474-qm8f.json create mode 100644 advisories/unreviewed/2025/05/GHSA-5mh7-pwwr-gwf7/GHSA-5mh7-pwwr-gwf7.json create mode 100644 advisories/unreviewed/2025/05/GHSA-5p8g-r99q-6826/GHSA-5p8g-r99q-6826.json create mode 100644 advisories/unreviewed/2025/05/GHSA-6366-5cxc-p7vq/GHSA-6366-5cxc-p7vq.json create mode 100644 advisories/unreviewed/2025/05/GHSA-67wj-6mjf-7pcq/GHSA-67wj-6mjf-7pcq.json create mode 100644 advisories/unreviewed/2025/05/GHSA-6wqv-328v-59px/GHSA-6wqv-328v-59px.json create mode 100644 advisories/unreviewed/2025/05/GHSA-7f8x-9x27-qrmg/GHSA-7f8x-9x27-qrmg.json create mode 100644 advisories/unreviewed/2025/05/GHSA-7xmm-8q26-r88f/GHSA-7xmm-8q26-r88f.json create mode 100644 advisories/unreviewed/2025/05/GHSA-7xxp-38mj-pgpw/GHSA-7xxp-38mj-pgpw.json create mode 100644 advisories/unreviewed/2025/05/GHSA-8f4v-pgv9-r6f5/GHSA-8f4v-pgv9-r6f5.json create mode 100644 advisories/unreviewed/2025/05/GHSA-8h35-v7xf-x336/GHSA-8h35-v7xf-x336.json create mode 100644 advisories/unreviewed/2025/05/GHSA-8qm7-2hp6-h7jr/GHSA-8qm7-2hp6-h7jr.json create mode 100644 advisories/unreviewed/2025/05/GHSA-9397-457v-6qhp/GHSA-9397-457v-6qhp.json create mode 100644 advisories/unreviewed/2025/05/GHSA-9p4p-6vvc-6mcp/GHSA-9p4p-6vvc-6mcp.json create mode 100644 advisories/unreviewed/2025/05/GHSA-c2j9-c6rw-g8g7/GHSA-c2j9-c6rw-g8g7.json create mode 100644 advisories/unreviewed/2025/05/GHSA-c6gj-2jr9-8cjp/GHSA-c6gj-2jr9-8cjp.json create mode 100644 advisories/unreviewed/2025/05/GHSA-c9gm-698m-cjr7/GHSA-c9gm-698m-cjr7.json create mode 100644 advisories/unreviewed/2025/05/GHSA-cr74-88qf-5463/GHSA-cr74-88qf-5463.json create mode 100644 advisories/unreviewed/2025/05/GHSA-f2q5-wfpv-jc4m/GHSA-f2q5-wfpv-jc4m.json create mode 100644 advisories/unreviewed/2025/05/GHSA-f6vc-5hqq-c3x2/GHSA-f6vc-5hqq-c3x2.json create mode 100644 advisories/unreviewed/2025/05/GHSA-fhx6-jcrh-354h/GHSA-fhx6-jcrh-354h.json create mode 100644 advisories/unreviewed/2025/05/GHSA-frr9-jr53-8x43/GHSA-frr9-jr53-8x43.json create mode 100644 advisories/unreviewed/2025/05/GHSA-grxh-3m7g-g4pc/GHSA-grxh-3m7g-g4pc.json create mode 100644 advisories/unreviewed/2025/05/GHSA-h4v2-mpxm-7h3w/GHSA-h4v2-mpxm-7h3w.json create mode 100644 advisories/unreviewed/2025/05/GHSA-hcg6-8qj3-r5xc/GHSA-hcg6-8qj3-r5xc.json create mode 100644 advisories/unreviewed/2025/05/GHSA-hqf6-65hw-qq68/GHSA-hqf6-65hw-qq68.json create mode 100644 advisories/unreviewed/2025/05/GHSA-hw3m-mgfc-g5r4/GHSA-hw3m-mgfc-g5r4.json create mode 100644 advisories/unreviewed/2025/05/GHSA-hwpp-r7c7-mx9g/GHSA-hwpp-r7c7-mx9g.json create mode 100644 advisories/unreviewed/2025/05/GHSA-jwxw-jqxj-962v/GHSA-jwxw-jqxj-962v.json create mode 100644 advisories/unreviewed/2025/05/GHSA-m4gj-q4fx-v26f/GHSA-m4gj-q4fx-v26f.json create mode 100644 advisories/unreviewed/2025/05/GHSA-m4w4-6mfj-fqh8/GHSA-m4w4-6mfj-fqh8.json create mode 100644 advisories/unreviewed/2025/05/GHSA-mhg9-c8wr-hm8x/GHSA-mhg9-c8wr-hm8x.json create mode 100644 advisories/unreviewed/2025/05/GHSA-mwcf-jv2p-mmpx/GHSA-mwcf-jv2p-mmpx.json create mode 100644 advisories/unreviewed/2025/05/GHSA-pc32-32fx-wxh7/GHSA-pc32-32fx-wxh7.json create mode 100644 advisories/unreviewed/2025/05/GHSA-pjx5-26hx-4cj5/GHSA-pjx5-26hx-4cj5.json create mode 100644 advisories/unreviewed/2025/05/GHSA-pp7f-fm4q-phg7/GHSA-pp7f-fm4q-phg7.json create mode 100644 advisories/unreviewed/2025/05/GHSA-prf9-gx8m-9cfq/GHSA-prf9-gx8m-9cfq.json create mode 100644 advisories/unreviewed/2025/05/GHSA-q2pv-8f62-27p3/GHSA-q2pv-8f62-27p3.json create mode 100644 advisories/unreviewed/2025/05/GHSA-qwwx-f8r3-v9pc/GHSA-qwwx-f8r3-v9pc.json create mode 100644 advisories/unreviewed/2025/05/GHSA-r53g-69jj-xq7x/GHSA-r53g-69jj-xq7x.json create mode 100644 advisories/unreviewed/2025/05/GHSA-r593-5693-qv6x/GHSA-r593-5693-qv6x.json create mode 100644 advisories/unreviewed/2025/05/GHSA-rw3p-877j-xxwm/GHSA-rw3p-877j-xxwm.json create mode 100644 advisories/unreviewed/2025/05/GHSA-vfx3-xjmh-f34c/GHSA-vfx3-xjmh-f34c.json create mode 100644 advisories/unreviewed/2025/05/GHSA-vh6g-f64r-5r5w/GHSA-vh6g-f64r-5r5w.json create mode 100644 advisories/unreviewed/2025/05/GHSA-vqxf-9gx2-9j34/GHSA-vqxf-9gx2-9j34.json create mode 100644 advisories/unreviewed/2025/05/GHSA-vqxg-8xhm-jf4p/GHSA-vqxg-8xhm-jf4p.json create mode 100644 advisories/unreviewed/2025/05/GHSA-wjv3-vv76-gqfj/GHSA-wjv3-vv76-gqfj.json create mode 100644 advisories/unreviewed/2025/05/GHSA-x47c-v779-7xcp/GHSA-x47c-v779-7xcp.json create mode 100644 advisories/unreviewed/2025/05/GHSA-x725-g7rw-pw6q/GHSA-x725-g7rw-pw6q.json create mode 100644 advisories/unreviewed/2025/05/GHSA-x8r2-wrm6-4v97/GHSA-x8r2-wrm6-4v97.json diff --git a/advisories/unreviewed/2023/08/GHSA-27mv-5vpc-8g53/GHSA-27mv-5vpc-8g53.json b/advisories/unreviewed/2023/08/GHSA-27mv-5vpc-8g53/GHSA-27mv-5vpc-8g53.json index 99a0bc82196..e65a2b8d945 100644 --- a/advisories/unreviewed/2023/08/GHSA-27mv-5vpc-8g53/GHSA-27mv-5vpc-8g53.json +++ b/advisories/unreviewed/2023/08/GHSA-27mv-5vpc-8g53/GHSA-27mv-5vpc-8g53.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-27mv-5vpc-8g53", - "modified": "2025-05-05T15:30:43Z", + "modified": "2025-05-19T18:30:34Z", "published": "2023-08-04T00:30:15Z", "aliases": [ "CVE-2023-38950" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://sploitus.com/exploit?id=PACKETSTORM:177859" }, + { + "type": "WEB", + "url": "https://www.fortinet.com/content/dam/fortinet/assets/reports/report-incident-response-middle-east.pdf" + }, { "type": "WEB", "url": "http://zkteco.com" diff --git a/advisories/unreviewed/2024/03/GHSA-rr36-3hq5-mqj8/GHSA-rr36-3hq5-mqj8.json b/advisories/unreviewed/2024/03/GHSA-rr36-3hq5-mqj8/GHSA-rr36-3hq5-mqj8.json index 3503e77c2d6..706b3aab5f7 100644 --- a/advisories/unreviewed/2024/03/GHSA-rr36-3hq5-mqj8/GHSA-rr36-3hq5-mqj8.json +++ b/advisories/unreviewed/2024/03/GHSA-rr36-3hq5-mqj8/GHSA-rr36-3hq5-mqj8.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-rr36-3hq5-mqj8", - "modified": "2024-03-01T00:30:28Z", + "modified": "2025-05-19T18:30:35Z", "published": "2024-03-01T00:30:28Z", "aliases": [ "CVE-2024-2045" ], - "details": "Session version 1.17.5 allows obtaining internal application files and public\n\nfiles from the user's device without the user's consent. This is possible\n\nbecause the application is vulnerable to Local File Read via chat attachments.\n\n\n\n\n", + "details": "Session version 1.17.5 allows obtaining internal application files and public\n\nfiles from the user's device without the user's consent. This is possible\n\nbecause the application is vulnerable to Local File Read via chat attachments.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/05/GHSA-4q9h-rhrc-98f3/GHSA-4q9h-rhrc-98f3.json b/advisories/unreviewed/2024/05/GHSA-4q9h-rhrc-98f3/GHSA-4q9h-rhrc-98f3.json index 32174ea759f..9acecbebe10 100644 --- a/advisories/unreviewed/2024/05/GHSA-4q9h-rhrc-98f3/GHSA-4q9h-rhrc-98f3.json +++ b/advisories/unreviewed/2024/05/GHSA-4q9h-rhrc-98f3/GHSA-4q9h-rhrc-98f3.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-qrvg-mg33-q843/GHSA-qrvg-mg33-q843.json b/advisories/unreviewed/2024/08/GHSA-qrvg-mg33-q843/GHSA-qrvg-mg33-q843.json index 6a66dc16f33..73332b465c3 100644 --- a/advisories/unreviewed/2024/08/GHSA-qrvg-mg33-q843/GHSA-qrvg-mg33-q843.json +++ b/advisories/unreviewed/2024/08/GHSA-qrvg-mg33-q843/GHSA-qrvg-mg33-q843.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qrvg-mg33-q843", - "modified": "2024-08-13T18:31:14Z", + "modified": "2025-05-19T18:30:36Z", "published": "2024-08-12T15:30:53Z", "aliases": [ "CVE-2024-27443" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P39#Security_Fixes" + }, + { + "type": "WEB", + "url": "https://www.welivesecurity.com/en/eset-research/operation-roundpress" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/05/GHSA-27mf-h76r-wrj9/GHSA-27mf-h76r-wrj9.json b/advisories/unreviewed/2025/05/GHSA-27mf-h76r-wrj9/GHSA-27mf-h76r-wrj9.json new file mode 100644 index 00000000000..acea93bb081 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-27mf-h76r-wrj9/GHSA-27mf-h76r-wrj9.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-27mf-h76r-wrj9", + "modified": "2025-05-19T18:30:46Z", + "published": "2025-05-19T18:30:46Z", + "aliases": [ + "CVE-2025-31262" + ], + "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. An app may be able to modify protected parts of the file system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31262" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122066" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122071" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122072" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122073" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T16:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-292v-wgjp-vm43/GHSA-292v-wgjp-vm43.json b/advisories/unreviewed/2025/05/GHSA-292v-wgjp-vm43/GHSA-292v-wgjp-vm43.json new file mode 100644 index 00000000000..9b90377944a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-292v-wgjp-vm43/GHSA-292v-wgjp-vm43.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-292v-wgjp-vm43", + "modified": "2025-05-19T18:30:48Z", + "published": "2025-05-19T18:30:47Z", + "aliases": [ + "CVE-2025-26892" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in dkszone Celestial Aura allows Using Malicious Files.This issue affects Celestial Aura: from n/a through 2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26892" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/celestial-aura/vulnerability/wordpress-celestial-aura-plugin-2-2-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T18:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2cr7-4mvv-cpm5/GHSA-2cr7-4mvv-cpm5.json b/advisories/unreviewed/2025/05/GHSA-2cr7-4mvv-cpm5/GHSA-2cr7-4mvv-cpm5.json index 2ddbb190d94..b42d6059f69 100644 --- a/advisories/unreviewed/2025/05/GHSA-2cr7-4mvv-cpm5/GHSA-2cr7-4mvv-cpm5.json +++ b/advisories/unreviewed/2025/05/GHSA-2cr7-4mvv-cpm5/GHSA-2cr7-4mvv-cpm5.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-2m98-w299-f59w/GHSA-2m98-w299-f59w.json b/advisories/unreviewed/2025/05/GHSA-2m98-w299-f59w/GHSA-2m98-w299-f59w.json new file mode 100644 index 00000000000..d57ceb9d114 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2m98-w299-f59w/GHSA-2m98-w299-f59w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2m98-w299-f59w", + "modified": "2025-05-19T18:30:47Z", + "published": "2025-05-19T18:30:47Z", + "aliases": [ + "CVE-2025-39353" + ], + "details": "Missing Authorization vulnerability in ThemeGoods Grand Restaurant WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Grand Restaurant WordPress: from n/a through 7.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39353" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/grandrestaurant/vulnerability/wordpress-grand-restaurant-wordpress-theme-7-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T17:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2qw9-5pj2-hf6h/GHSA-2qw9-5pj2-hf6h.json b/advisories/unreviewed/2025/05/GHSA-2qw9-5pj2-hf6h/GHSA-2qw9-5pj2-hf6h.json new file mode 100644 index 00000000000..32fe9f99366 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2qw9-5pj2-hf6h/GHSA-2qw9-5pj2-hf6h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2qw9-5pj2-hf6h", + "modified": "2025-05-19T18:30:48Z", + "published": "2025-05-19T18:30:48Z", + "aliases": [ + "CVE-2025-39412" + ], + "details": "Missing Authorization vulnerability in Averta Master Slider.This issue affects Master Slider: from n/a through 3.10.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39412" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/master-slider/vulnerability/wordpress-master-slider-plugin-3-10-7-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T18:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2r7h-jv72-f7xp/GHSA-2r7h-jv72-f7xp.json b/advisories/unreviewed/2025/05/GHSA-2r7h-jv72-f7xp/GHSA-2r7h-jv72-f7xp.json new file mode 100644 index 00000000000..3983df0b8ad --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2r7h-jv72-f7xp/GHSA-2r7h-jv72-f7xp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2r7h-jv72-f7xp", + "modified": "2025-05-19T18:30:47Z", + "published": "2025-05-19T18:30:47Z", + "aliases": [ + "CVE-2025-39394" + ], + "details": "Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Solid Plugins AnalyticsWP allows Retrieve Embedded Sensitive Data.This issue affects AnalyticsWP: from n/a through 2.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39394" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/analyticswp/vulnerability/wordpress-analyticswp-plugin-2-1-2-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T17:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3349-q488-4m7r/GHSA-3349-q488-4m7r.json b/advisories/unreviewed/2025/05/GHSA-3349-q488-4m7r/GHSA-3349-q488-4m7r.json new file mode 100644 index 00000000000..90bc96930d0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3349-q488-4m7r/GHSA-3349-q488-4m7r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3349-q488-4m7r", + "modified": "2025-05-19T18:30:46Z", + "published": "2025-05-19T18:30:46Z", + "aliases": [ + "CVE-2025-23979" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in duwasai Flashy allows Reflected XSS.This issue affects Flashy: from n/a through 1.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23979" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/flashy/vulnerability/wordpress-flashy-theme-1-2-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T16:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3533-x66r-qv4w/GHSA-3533-x66r-qv4w.json b/advisories/unreviewed/2025/05/GHSA-3533-x66r-qv4w/GHSA-3533-x66r-qv4w.json index 7de44939c9b..7dc0e199df7 100644 --- a/advisories/unreviewed/2025/05/GHSA-3533-x66r-qv4w/GHSA-3533-x66r-qv4w.json +++ b/advisories/unreviewed/2025/05/GHSA-3533-x66r-qv4w/GHSA-3533-x66r-qv4w.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-37xj-x86x-8h3f/GHSA-37xj-x86x-8h3f.json b/advisories/unreviewed/2025/05/GHSA-37xj-x86x-8h3f/GHSA-37xj-x86x-8h3f.json new file mode 100644 index 00000000000..83fb462c8c9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-37xj-x86x-8h3f/GHSA-37xj-x86x-8h3f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-37xj-x86x-8h3f", + "modified": "2025-05-19T18:30:48Z", + "published": "2025-05-19T18:30:48Z", + "aliases": [ + "CVE-2025-43834" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tox82 cookieBAR allows Stored XSS.This issue affects cookieBAR: from n/a through 1.7.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43834" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cookiebar/vulnerability/wordpress-cookiebar-plugin-1-7-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T18:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3f4g-72qh-pgc7/GHSA-3f4g-72qh-pgc7.json b/advisories/unreviewed/2025/05/GHSA-3f4g-72qh-pgc7/GHSA-3f4g-72qh-pgc7.json new file mode 100644 index 00000000000..b846137ced5 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3f4g-72qh-pgc7/GHSA-3f4g-72qh-pgc7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3f4g-72qh-pgc7", + "modified": "2025-05-19T18:30:47Z", + "published": "2025-05-19T18:30:47Z", + "aliases": [ + "CVE-2025-39376" + ], + "details": "Missing Authorization vulnerability in QuanticaLabs Car Park Booking System for WordPress.This issue affects Car Park Booking System for WordPress: from n/a through 2.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39376" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/car-park-booking-system-for-wordpress/vulnerability/wordpress-car-park-booking-system-for-wordpress-plugin-2-6-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T17:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3gx9-8889-ccm7/GHSA-3gx9-8889-ccm7.json b/advisories/unreviewed/2025/05/GHSA-3gx9-8889-ccm7/GHSA-3gx9-8889-ccm7.json index 3f1be88baa2..9fabad75fe0 100644 --- a/advisories/unreviewed/2025/05/GHSA-3gx9-8889-ccm7/GHSA-3gx9-8889-ccm7.json +++ b/advisories/unreviewed/2025/05/GHSA-3gx9-8889-ccm7/GHSA-3gx9-8889-ccm7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3gx9-8889-ccm7", - "modified": "2025-05-19T15:31:00Z", + "modified": "2025-05-19T18:30:45Z", "published": "2025-05-19T15:31:00Z", "aliases": [ "CVE-2025-30072" ], "details": "Tiiwee X1 Alarm System TWX1HAKV2 allows Authentication Bypass by Capture-replay, leading to physical Access to the protected facilities without triggering an alarm.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-294" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-19T15:15:23Z" diff --git a/advisories/unreviewed/2025/05/GHSA-3hhf-g967-wcf6/GHSA-3hhf-g967-wcf6.json b/advisories/unreviewed/2025/05/GHSA-3hhf-g967-wcf6/GHSA-3hhf-g967-wcf6.json new file mode 100644 index 00000000000..850854c2f13 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3hhf-g967-wcf6/GHSA-3hhf-g967-wcf6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3hhf-g967-wcf6", + "modified": "2025-05-19T18:30:47Z", + "published": "2025-05-19T18:30:46Z", + "aliases": [ + "CVE-2025-26867" + ], + "details": "Missing Authorization vulnerability in Themes4WP Bulk allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Bulk: from n/a through 1.0.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26867" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/bulk/vulnerability/wordpress-bulk-theme-1-0-11-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T17:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3vpx-xc92-826m/GHSA-3vpx-xc92-826m.json b/advisories/unreviewed/2025/05/GHSA-3vpx-xc92-826m/GHSA-3vpx-xc92-826m.json new file mode 100644 index 00000000000..c6506915bfc --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3vpx-xc92-826m/GHSA-3vpx-xc92-826m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3vpx-xc92-826m", + "modified": "2025-05-19T18:30:47Z", + "published": "2025-05-19T18:30:47Z", + "aliases": [ + "CVE-2025-39370" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cnilsson iCafe Library allows SQL Injection.This issue affects iCafe Library: from n/a through 1.8.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39370" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/icafe-library/vulnerability/wordpress-icafe-library-plugin-1-8-3-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T17:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-43hr-6fp9-6wgg/GHSA-43hr-6fp9-6wgg.json b/advisories/unreviewed/2025/05/GHSA-43hr-6fp9-6wgg/GHSA-43hr-6fp9-6wgg.json index 4d18e4bef0f..f26fb6ad3be 100644 --- a/advisories/unreviewed/2025/05/GHSA-43hr-6fp9-6wgg/GHSA-43hr-6fp9-6wgg.json +++ b/advisories/unreviewed/2025/05/GHSA-43hr-6fp9-6wgg/GHSA-43hr-6fp9-6wgg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-43hr-6fp9-6wgg", - "modified": "2025-05-19T15:31:00Z", + "modified": "2025-05-19T18:30:45Z", "published": "2025-05-19T15:31:00Z", "aliases": [ "CVE-2024-55063" ], "details": "Multiple Code Injection vulnerabilities in EasyVirt DC NetScope <= 8.7.0 allows remote authenticated attackers to execute arbitrary code via the (1) lang parameter to /international/keyboard/options; the (2) keyboard_layout or (3) keyboard_variant parameter to /international/settings/keyboard; the (4) timezone parameter to /international/settings/timezone.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-19T15:15:22Z" diff --git a/advisories/unreviewed/2025/05/GHSA-45rr-p56g-wc84/GHSA-45rr-p56g-wc84.json b/advisories/unreviewed/2025/05/GHSA-45rr-p56g-wc84/GHSA-45rr-p56g-wc84.json index 6ff001596c7..28af7a07fdf 100644 --- a/advisories/unreviewed/2025/05/GHSA-45rr-p56g-wc84/GHSA-45rr-p56g-wc84.json +++ b/advisories/unreviewed/2025/05/GHSA-45rr-p56g-wc84/GHSA-45rr-p56g-wc84.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-4ffv-mjwj-jpv4/GHSA-4ffv-mjwj-jpv4.json b/advisories/unreviewed/2025/05/GHSA-4ffv-mjwj-jpv4/GHSA-4ffv-mjwj-jpv4.json new file mode 100644 index 00000000000..9a100c1c48f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4ffv-mjwj-jpv4/GHSA-4ffv-mjwj-jpv4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4ffv-mjwj-jpv4", + "modified": "2025-05-19T18:30:48Z", + "published": "2025-05-19T18:30:48Z", + "aliases": [ + "CVE-2025-39460" + ], + "details": "Missing Authorization vulnerability in ThimPress Eduma allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Eduma: from n/a through 5.6.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39460" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/eduma/vulnerability/wordpress-eduma-theme-5-6-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T18:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4ggw-jqjj-86hc/GHSA-4ggw-jqjj-86hc.json b/advisories/unreviewed/2025/05/GHSA-4ggw-jqjj-86hc/GHSA-4ggw-jqjj-86hc.json new file mode 100644 index 00000000000..29b44f8ad7b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4ggw-jqjj-86hc/GHSA-4ggw-jqjj-86hc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4ggw-jqjj-86hc", + "modified": "2025-05-19T18:30:48Z", + "published": "2025-05-19T18:30:47Z", + "aliases": [ + "CVE-2025-47576" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Bringthepixel Bimber - Viral Magazine WordPress Theme.This issue affects Bimber - Viral Magazine WordPress Theme: from n/a through 9.2.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47576" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/bimber/vulnerability/wordpress-bimber-viral-magazine-wordpress-theme-theme-9-2-5-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T17:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4mvv-v35x-r8h9/GHSA-4mvv-v35x-r8h9.json b/advisories/unreviewed/2025/05/GHSA-4mvv-v35x-r8h9/GHSA-4mvv-v35x-r8h9.json new file mode 100644 index 00000000000..c2dcd9b5035 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4mvv-v35x-r8h9/GHSA-4mvv-v35x-r8h9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4mvv-v35x-r8h9", + "modified": "2025-05-19T18:30:48Z", + "published": "2025-05-19T18:30:48Z", + "aliases": [ + "CVE-2025-39454" + ], + "details": "Missing Authorization vulnerability in Jeroen Peters Name Directory.This issue affects Name Directory: from n/a through 1.30.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39454" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/name-directory/vulnerability/wordpress-name-directory-plugin-1-30-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T18:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4rxg-fmh7-xhh5/GHSA-4rxg-fmh7-xhh5.json b/advisories/unreviewed/2025/05/GHSA-4rxg-fmh7-xhh5/GHSA-4rxg-fmh7-xhh5.json index 717e423fe5c..b8d9ad1145a 100644 --- a/advisories/unreviewed/2025/05/GHSA-4rxg-fmh7-xhh5/GHSA-4rxg-fmh7-xhh5.json +++ b/advisories/unreviewed/2025/05/GHSA-4rxg-fmh7-xhh5/GHSA-4rxg-fmh7-xhh5.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-5c6q-hvvg-576r/GHSA-5c6q-hvvg-576r.json b/advisories/unreviewed/2025/05/GHSA-5c6q-hvvg-576r/GHSA-5c6q-hvvg-576r.json new file mode 100644 index 00000000000..256e7b69113 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5c6q-hvvg-576r/GHSA-5c6q-hvvg-576r.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5c6q-hvvg-576r", + "modified": "2025-05-19T18:30:46Z", + "published": "2025-05-19T18:30:46Z", + "aliases": [ + "CVE-2025-4948" + ], + "details": "A flaw was found in the soup_multipart_new_from_message() function of the libsoup HTTP library, which is commonly used by GNOME and other applications to handle web communications. The issue occurs when the library processes specially crafted multipart messages. Due to improper validation, an internal calculation can go wrong, leading to an integer underflow. This can cause the program to access invalid memory and crash. As a result, any application or server using libsoup could be forced to exit unexpectedly, creating a denial-of-service (DoS) risk.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4948" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-4948" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2367183" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-191" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5f94-w474-qm8f/GHSA-5f94-w474-qm8f.json b/advisories/unreviewed/2025/05/GHSA-5f94-w474-qm8f/GHSA-5f94-w474-qm8f.json new file mode 100644 index 00000000000..8122805c486 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5f94-w474-qm8f/GHSA-5f94-w474-qm8f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5f94-w474-qm8f", + "modified": "2025-05-19T18:30:48Z", + "published": "2025-05-19T18:30:48Z", + "aliases": [ + "CVE-2025-43841" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jamesdbruner WP Vegas allows Stored XSS.This issue affects WP Vegas: from n/a through 2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43841" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/vegas-fullscreen-background-slider/vulnerability/wordpress-wp-vegas-plugin-2-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T18:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5mh7-pwwr-gwf7/GHSA-5mh7-pwwr-gwf7.json b/advisories/unreviewed/2025/05/GHSA-5mh7-pwwr-gwf7/GHSA-5mh7-pwwr-gwf7.json new file mode 100644 index 00000000000..054c65355e3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5mh7-pwwr-gwf7/GHSA-5mh7-pwwr-gwf7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5mh7-pwwr-gwf7", + "modified": "2025-05-19T18:30:48Z", + "published": "2025-05-19T18:30:48Z", + "aliases": [ + "CVE-2025-39450" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetTabs allows DOM-Based XSS.This issue affects JetTabs: from n/a through 2.2.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39450" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/jet-tabs/vulnerability/wordpress-jettabs-plugin-2-2-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T18:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5p8g-r99q-6826/GHSA-5p8g-r99q-6826.json b/advisories/unreviewed/2025/05/GHSA-5p8g-r99q-6826/GHSA-5p8g-r99q-6826.json new file mode 100644 index 00000000000..3b092e2e4c0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5p8g-r99q-6826/GHSA-5p8g-r99q-6826.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5p8g-r99q-6826", + "modified": "2025-05-19T18:30:48Z", + "published": "2025-05-19T18:30:48Z", + "aliases": [ + "CVE-2025-46263" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lloyd Saunders Author Box After Posts allows Stored XSS.This issue affects Author Box After Posts: from n/a through 1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46263" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/author-box-after-posts/vulnerability/wordpress-author-box-after-posts-plugin-1-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T17:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5r36-pxhw-fw6j/GHSA-5r36-pxhw-fw6j.json b/advisories/unreviewed/2025/05/GHSA-5r36-pxhw-fw6j/GHSA-5r36-pxhw-fw6j.json index f2a805dd55e..2e03b163802 100644 --- a/advisories/unreviewed/2025/05/GHSA-5r36-pxhw-fw6j/GHSA-5r36-pxhw-fw6j.json +++ b/advisories/unreviewed/2025/05/GHSA-5r36-pxhw-fw6j/GHSA-5r36-pxhw-fw6j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5r36-pxhw-fw6j", - "modified": "2025-05-14T18:30:47Z", + "modified": "2025-05-19T18:30:40Z", "published": "2025-05-14T18:30:47Z", "aliases": [ "CVE-2025-26784" ], "details": "An issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. The lack of a length check leads to out-of-bounds writes.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-14T17:15:47Z" diff --git a/advisories/unreviewed/2025/05/GHSA-5xjr-6vjm-xc96/GHSA-5xjr-6vjm-xc96.json b/advisories/unreviewed/2025/05/GHSA-5xjr-6vjm-xc96/GHSA-5xjr-6vjm-xc96.json index 5947216af43..3551473bcd1 100644 --- a/advisories/unreviewed/2025/05/GHSA-5xjr-6vjm-xc96/GHSA-5xjr-6vjm-xc96.json +++ b/advisories/unreviewed/2025/05/GHSA-5xjr-6vjm-xc96/GHSA-5xjr-6vjm-xc96.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-6366-5cxc-p7vq/GHSA-6366-5cxc-p7vq.json b/advisories/unreviewed/2025/05/GHSA-6366-5cxc-p7vq/GHSA-6366-5cxc-p7vq.json new file mode 100644 index 00000000000..6ec96ea1c91 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6366-5cxc-p7vq/GHSA-6366-5cxc-p7vq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6366-5cxc-p7vq", + "modified": "2025-05-19T18:30:47Z", + "published": "2025-05-19T18:30:47Z", + "aliases": [ + "CVE-2025-39375" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Ashok G Easy Child Theme Creator allows Cross Site Request Forgery.This issue affects Easy Child Theme Creator: from n/a through 1.3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39375" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/easy-child-theme-creator/vulnerability/wordpress-easy-child-theme-creator-plugin-1-3-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T17:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-66q6-24vw-2g98/GHSA-66q6-24vw-2g98.json b/advisories/unreviewed/2025/05/GHSA-66q6-24vw-2g98/GHSA-66q6-24vw-2g98.json index c333a5e6b01..5f5f808e647 100644 --- a/advisories/unreviewed/2025/05/GHSA-66q6-24vw-2g98/GHSA-66q6-24vw-2g98.json +++ b/advisories/unreviewed/2025/05/GHSA-66q6-24vw-2g98/GHSA-66q6-24vw-2g98.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-66q6-24vw-2g98", - "modified": "2025-05-05T18:32:52Z", + "modified": "2025-05-19T18:30:37Z", "published": "2025-05-05T18:32:52Z", "aliases": [ "CVE-2025-27920" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27920" }, + { + "type": "WEB", + "url": "https://www.microsoft.com/en-us/security/blog/2025/05/12/marbled-dust-leverages-zero-day-in-output-messenger-for-regional-espionage" + }, { "type": "WEB", "url": "https://www.outputmessenger.com/cve-2025-27920" diff --git a/advisories/unreviewed/2025/05/GHSA-67wj-6mjf-7pcq/GHSA-67wj-6mjf-7pcq.json b/advisories/unreviewed/2025/05/GHSA-67wj-6mjf-7pcq/GHSA-67wj-6mjf-7pcq.json new file mode 100644 index 00000000000..52925c030e9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-67wj-6mjf-7pcq/GHSA-67wj-6mjf-7pcq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67wj-6mjf-7pcq", + "modified": "2025-05-19T18:30:48Z", + "published": "2025-05-19T18:30:48Z", + "aliases": [ + "CVE-2025-39396" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Crocoblock JetReviews allows PHP Local File Inclusion.This issue affects JetReviews: from n/a through 2.3.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39396" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/jet-reviews/vulnerability/wordpress-jetreviews-plugin-2-3-6-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T18:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6m6f-rwf2-ghvg/GHSA-6m6f-rwf2-ghvg.json b/advisories/unreviewed/2025/05/GHSA-6m6f-rwf2-ghvg/GHSA-6m6f-rwf2-ghvg.json index bf303713472..093295cd67f 100644 --- a/advisories/unreviewed/2025/05/GHSA-6m6f-rwf2-ghvg/GHSA-6m6f-rwf2-ghvg.json +++ b/advisories/unreviewed/2025/05/GHSA-6m6f-rwf2-ghvg/GHSA-6m6f-rwf2-ghvg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6m6f-rwf2-ghvg", - "modified": "2025-05-14T21:31:20Z", + "modified": "2025-05-19T18:30:41Z", "published": "2025-05-14T21:31:20Z", "aliases": [ "CVE-2024-56427" ], "details": "An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. The lack of a length check leads to out-of-bounds access via malformed RRC packets to the target.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-14T21:15:58Z" diff --git a/advisories/unreviewed/2025/05/GHSA-6wqv-328v-59px/GHSA-6wqv-328v-59px.json b/advisories/unreviewed/2025/05/GHSA-6wqv-328v-59px/GHSA-6wqv-328v-59px.json new file mode 100644 index 00000000000..7b5bae723d2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6wqv-328v-59px/GHSA-6wqv-328v-59px.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6wqv-328v-59px", + "modified": "2025-05-19T18:30:46Z", + "published": "2025-05-19T18:30:46Z", + "aliases": [ + "CVE-2025-22790" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in asmedia allows Reflected XSS.This issue affects moseter: from n/a through 1.3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22790" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/moseter/vulnerability/wordpress-moseter-theme-1-3-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7f8x-9x27-qrmg/GHSA-7f8x-9x27-qrmg.json b/advisories/unreviewed/2025/05/GHSA-7f8x-9x27-qrmg/GHSA-7f8x-9x27-qrmg.json new file mode 100644 index 00000000000..9b4c90c0623 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7f8x-9x27-qrmg/GHSA-7f8x-9x27-qrmg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7f8x-9x27-qrmg", + "modified": "2025-05-19T18:30:48Z", + "published": "2025-05-19T18:30:48Z", + "aliases": [ + "CVE-2025-43835" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in ktsvetkov allows Cross Site Request Forgery.This issue affects wp-cyr-cho: from n/a through 0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43835" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-cyr-cho/vulnerability/wordpress-wp-cyr-cho-plugin-0-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T18:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7rm6-cjw9-cf8v/GHSA-7rm6-cjw9-cf8v.json b/advisories/unreviewed/2025/05/GHSA-7rm6-cjw9-cf8v/GHSA-7rm6-cjw9-cf8v.json index 6f988c98404..575158ce4f4 100644 --- a/advisories/unreviewed/2025/05/GHSA-7rm6-cjw9-cf8v/GHSA-7rm6-cjw9-cf8v.json +++ b/advisories/unreviewed/2025/05/GHSA-7rm6-cjw9-cf8v/GHSA-7rm6-cjw9-cf8v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7rm6-cjw9-cf8v", - "modified": "2025-05-17T06:30:28Z", + "modified": "2025-05-19T18:30:41Z", "published": "2025-05-17T06:30:28Z", "aliases": [ "CVE-2025-4190" ], "details": "The CSV Mass Importer WordPress plugin through 1.2 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-17T06:15:18Z" diff --git a/advisories/unreviewed/2025/05/GHSA-7xmm-8q26-r88f/GHSA-7xmm-8q26-r88f.json b/advisories/unreviewed/2025/05/GHSA-7xmm-8q26-r88f/GHSA-7xmm-8q26-r88f.json new file mode 100644 index 00000000000..eae7fb65960 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7xmm-8q26-r88f/GHSA-7xmm-8q26-r88f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7xmm-8q26-r88f", + "modified": "2025-05-19T18:30:47Z", + "published": "2025-05-19T18:30:46Z", + "aliases": [ + "CVE-2025-39351" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Restaurant WordPress allows Cross Site Request Forgery.This issue affects Grand Restaurant WordPress: from n/a through 7.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39351" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/grandrestaurant/vulnerability/wordpress-grand-restaurant-wordpress-theme-7-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T17:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7xxp-38mj-pgpw/GHSA-7xxp-38mj-pgpw.json b/advisories/unreviewed/2025/05/GHSA-7xxp-38mj-pgpw/GHSA-7xxp-38mj-pgpw.json new file mode 100644 index 00000000000..f4ee961b53b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7xxp-38mj-pgpw/GHSA-7xxp-38mj-pgpw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7xxp-38mj-pgpw", + "modified": "2025-05-19T18:30:48Z", + "published": "2025-05-19T18:30:48Z", + "aliases": [ + "CVE-2025-39448" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetElements For Elementor allows Stored XSS.This issue affects JetElements For Elementor: from n/a through 2.7.4.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39448" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/jet-elements/vulnerability/wordpress-jetelements-for-elementor-plugin-2-7-4-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T18:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8f4v-pgv9-r6f5/GHSA-8f4v-pgv9-r6f5.json b/advisories/unreviewed/2025/05/GHSA-8f4v-pgv9-r6f5/GHSA-8f4v-pgv9-r6f5.json new file mode 100644 index 00000000000..c1a5eff5202 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8f4v-pgv9-r6f5/GHSA-8f4v-pgv9-r6f5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8f4v-pgv9-r6f5", + "modified": "2025-05-19T18:30:47Z", + "published": "2025-05-19T18:30:47Z", + "aliases": [ + "CVE-2025-39369" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sihibbs Posts for Page allows DOM-Based XSS.This issue affects Posts for Page: from n/a through 2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39369" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/posts-for-page/vulnerability/wordpress-posts-for-page-plugin-2-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T17:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8h35-v7xf-x336/GHSA-8h35-v7xf-x336.json b/advisories/unreviewed/2025/05/GHSA-8h35-v7xf-x336/GHSA-8h35-v7xf-x336.json new file mode 100644 index 00000000000..82121a0eda9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8h35-v7xf-x336/GHSA-8h35-v7xf-x336.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8h35-v7xf-x336", + "modified": "2025-05-19T18:30:47Z", + "published": "2025-05-19T18:30:47Z", + "aliases": [ + "CVE-2025-39368" + ], + "details": "Missing Authorization vulnerability in ed4becky Rootspersona allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rootspersona: from n/a through 3.7.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39368" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/rootspersona/vulnerability/wordpress-rootspersona-plugin-3-7-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T17:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8p9j-879p-799j/GHSA-8p9j-879p-799j.json b/advisories/unreviewed/2025/05/GHSA-8p9j-879p-799j/GHSA-8p9j-879p-799j.json index ff6a107efb3..b1c39593b22 100644 --- a/advisories/unreviewed/2025/05/GHSA-8p9j-879p-799j/GHSA-8p9j-879p-799j.json +++ b/advisories/unreviewed/2025/05/GHSA-8p9j-879p-799j/GHSA-8p9j-879p-799j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8p9j-879p-799j", - "modified": "2025-05-19T15:30:59Z", + "modified": "2025-05-19T18:30:45Z", "published": "2025-05-19T15:30:59Z", "aliases": [ "CVE-2025-28371" ], "details": "EnGenius ENH500 AP 2T2R V3.0 FW3.7.22 is vulnerable to Incorrect Access Control via the password change function. The device fails to validate the current password, allowing an attacker to submit a password change request with an invalid current password and set a new password.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-19T14:15:23Z" diff --git a/advisories/unreviewed/2025/05/GHSA-8qm7-2hp6-h7jr/GHSA-8qm7-2hp6-h7jr.json b/advisories/unreviewed/2025/05/GHSA-8qm7-2hp6-h7jr/GHSA-8qm7-2hp6-h7jr.json new file mode 100644 index 00000000000..8ae91112709 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8qm7-2hp6-h7jr/GHSA-8qm7-2hp6-h7jr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8qm7-2hp6-h7jr", + "modified": "2025-05-19T18:30:48Z", + "published": "2025-05-19T18:30:48Z", + "aliases": [ + "CVE-2025-47582" + ], + "details": "Deserialization of Untrusted Data vulnerability in QuantumCloud WPBot Pro Wordpress Chatbot allows Object Injection.This issue affects WPBot Pro Wordpress Chatbot: from n/a through 12.7.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47582" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpbot-pro/vulnerability/wordpress-wpbot-pro-wordpress-chatbot-12-7-0-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T18:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9397-457v-6qhp/GHSA-9397-457v-6qhp.json b/advisories/unreviewed/2025/05/GHSA-9397-457v-6qhp/GHSA-9397-457v-6qhp.json new file mode 100644 index 00000000000..9c1706da08d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9397-457v-6qhp/GHSA-9397-457v-6qhp.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9397-457v-6qhp", + "modified": "2025-05-19T18:30:47Z", + "published": "2025-05-19T18:30:47Z", + "aliases": [ + "CVE-2025-4939" + ], + "details": "A vulnerability classified as problematic was found in PHPGurukul Credit Card Application Management System 1.0. This vulnerability affects unknown code of the file /admin/new-ccapplication.php. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4939" + }, + { + "type": "WEB", + "url": "https://github.com/GIRISH05/credit-card-application-management-system-using-php-and-mysql/blob/main/Stored%20Cross-Site%20Scripting%20(XSS).md" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309502" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309502" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.580119" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9p4p-6vvc-6mcp/GHSA-9p4p-6vvc-6mcp.json b/advisories/unreviewed/2025/05/GHSA-9p4p-6vvc-6mcp/GHSA-9p4p-6vvc-6mcp.json new file mode 100644 index 00000000000..0f10873636a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9p4p-6vvc-6mcp/GHSA-9p4p-6vvc-6mcp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9p4p-6vvc-6mcp", + "modified": "2025-05-19T18:30:47Z", + "published": "2025-05-19T18:30:47Z", + "aliases": [ + "CVE-2025-39364" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PluginEver Product Category Slider for WooCommerce allows PHP Local File Inclusion.This issue affects Product Category Slider for WooCommerce: from n/a through 4.3.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39364" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woo-category-slider-by-pluginever/vulnerability/wordpress-product-category-slider-for-woocommerce-plugin-4-3-4-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T17:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c2j9-c6rw-g8g7/GHSA-c2j9-c6rw-g8g7.json b/advisories/unreviewed/2025/05/GHSA-c2j9-c6rw-g8g7/GHSA-c2j9-c6rw-g8g7.json new file mode 100644 index 00000000000..5775f86e69f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c2j9-c6rw-g8g7/GHSA-c2j9-c6rw-g8g7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2j9-c6rw-g8g7", + "modified": "2025-05-19T18:30:47Z", + "published": "2025-05-19T18:30:47Z", + "aliases": [ + "CVE-2025-26735" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Candid themes Grip.This issue affects Grip: from n/a through 1.0.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26735" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/grip/vulnerability/wordpress-grip-theme-1-0-9-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T18:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c6gj-2jr9-8cjp/GHSA-c6gj-2jr9-8cjp.json b/advisories/unreviewed/2025/05/GHSA-c6gj-2jr9-8cjp/GHSA-c6gj-2jr9-8cjp.json new file mode 100644 index 00000000000..5a6ae73951d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c6gj-2jr9-8cjp/GHSA-c6gj-2jr9-8cjp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c6gj-2jr9-8cjp", + "modified": "2025-05-19T18:30:47Z", + "published": "2025-05-19T18:30:47Z", + "aliases": [ + "CVE-2025-39371" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Sanjeev Mohindra Author Box Plugin With Different Description allows Cross Site Request Forgery.This issue affects Author Box Plugin With Different Description: from n/a through 1.3.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39371" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/author-box-with-different-description/vulnerability/wordpress-author-box-plugin-with-different-description-plugin-1-3-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T17:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c9gm-698m-cjr7/GHSA-c9gm-698m-cjr7.json b/advisories/unreviewed/2025/05/GHSA-c9gm-698m-cjr7/GHSA-c9gm-698m-cjr7.json new file mode 100644 index 00000000000..fe076a1355a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c9gm-698m-cjr7/GHSA-c9gm-698m-cjr7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c9gm-698m-cjr7", + "modified": "2025-05-19T18:30:48Z", + "published": "2025-05-19T18:30:48Z", + "aliases": [ + "CVE-2025-39398" + ], + "details": "Missing Authorization vulnerability in Themovation Hotel + Bed and Breakfast Booking Calendar Theme | Bellevue.This issue affects Hotel + Bed and Breakfast Booking Calendar Theme | Bellevue: from n/a through 4.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39398" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/bellevuex/vulnerability/wordpress-hotel-bed-and-breakfast-booking-calendar-theme-bellevue-theme-4-2-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T18:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-cq8m-2x25-mgg8/GHSA-cq8m-2x25-mgg8.json b/advisories/unreviewed/2025/05/GHSA-cq8m-2x25-mgg8/GHSA-cq8m-2x25-mgg8.json index a54735f9406..793e805aa33 100644 --- a/advisories/unreviewed/2025/05/GHSA-cq8m-2x25-mgg8/GHSA-cq8m-2x25-mgg8.json +++ b/advisories/unreviewed/2025/05/GHSA-cq8m-2x25-mgg8/GHSA-cq8m-2x25-mgg8.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-345", "CWE-349" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/05/GHSA-cr74-88qf-5463/GHSA-cr74-88qf-5463.json b/advisories/unreviewed/2025/05/GHSA-cr74-88qf-5463/GHSA-cr74-88qf-5463.json new file mode 100644 index 00000000000..03109dd775c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-cr74-88qf-5463/GHSA-cr74-88qf-5463.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cr74-88qf-5463", + "modified": "2025-05-19T18:30:47Z", + "published": "2025-05-19T18:30:47Z", + "aliases": [ + "CVE-2025-39388" + ], + "details": "Missing Authorization vulnerability in Solid Plugins AnalyticsWP allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects AnalyticsWP: from n/a through 2.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39388" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/analyticswp/vulnerability/wordpress-analyticswp-plugin-2-0-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T17:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-cv2q-598m-m7h2/GHSA-cv2q-598m-m7h2.json b/advisories/unreviewed/2025/05/GHSA-cv2q-598m-m7h2/GHSA-cv2q-598m-m7h2.json index 2fc2bb32d54..fc45fdebf2a 100644 --- a/advisories/unreviewed/2025/05/GHSA-cv2q-598m-m7h2/GHSA-cv2q-598m-m7h2.json +++ b/advisories/unreviewed/2025/05/GHSA-cv2q-598m-m7h2/GHSA-cv2q-598m-m7h2.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-f2q5-wfpv-jc4m/GHSA-f2q5-wfpv-jc4m.json b/advisories/unreviewed/2025/05/GHSA-f2q5-wfpv-jc4m/GHSA-f2q5-wfpv-jc4m.json new file mode 100644 index 00000000000..968f8979167 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-f2q5-wfpv-jc4m/GHSA-f2q5-wfpv-jc4m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f2q5-wfpv-jc4m", + "modified": "2025-05-19T18:30:46Z", + "published": "2025-05-19T18:30:46Z", + "aliases": [ + "CVE-2025-22687" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Asmedia Tuaug4 allows Reflected XSS.This issue affects Tuaug4: from n/a through 1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22687" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/tuaug4/vulnerability/wordpress-tuaug4-theme-1-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-f333-vhwv-jvmx/GHSA-f333-vhwv-jvmx.json b/advisories/unreviewed/2025/05/GHSA-f333-vhwv-jvmx/GHSA-f333-vhwv-jvmx.json index 6f43e45e7bb..e7dcecd4a85 100644 --- a/advisories/unreviewed/2025/05/GHSA-f333-vhwv-jvmx/GHSA-f333-vhwv-jvmx.json +++ b/advisories/unreviewed/2025/05/GHSA-f333-vhwv-jvmx/GHSA-f333-vhwv-jvmx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f333-vhwv-jvmx", - "modified": "2025-05-18T21:30:20Z", + "modified": "2025-05-19T18:30:41Z", "published": "2025-05-18T00:30:27Z", "aliases": [ "CVE-2025-4919" ], "details": "An attacker was able to perform an out-of-bounds read or write on a JavaScript object by confusing array index sizes. This vulnerability affects Firefox ESR < 115.23.1.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-17T22:15:19Z" diff --git a/advisories/unreviewed/2025/05/GHSA-f6vc-5hqq-c3x2/GHSA-f6vc-5hqq-c3x2.json b/advisories/unreviewed/2025/05/GHSA-f6vc-5hqq-c3x2/GHSA-f6vc-5hqq-c3x2.json new file mode 100644 index 00000000000..86a340ab693 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-f6vc-5hqq-c3x2/GHSA-f6vc-5hqq-c3x2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f6vc-5hqq-c3x2", + "modified": "2025-05-19T18:30:48Z", + "published": "2025-05-19T18:30:48Z", + "aliases": [ + "CVE-2025-43840" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Ref CheckBot allows Stored XSS.This issue affects CheckBot: from n/a through 1.05.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43840" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/checkbot/vulnerability/wordpress-checkbot-plugin-1-05-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T18:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fhx6-jcrh-354h/GHSA-fhx6-jcrh-354h.json b/advisories/unreviewed/2025/05/GHSA-fhx6-jcrh-354h/GHSA-fhx6-jcrh-354h.json new file mode 100644 index 00000000000..26c94fe3633 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fhx6-jcrh-354h/GHSA-fhx6-jcrh-354h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fhx6-jcrh-354h", + "modified": "2025-05-19T18:30:46Z", + "published": "2025-05-19T18:30:46Z", + "aliases": [ + "CVE-2025-23988" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bruno Cavalcante Ghostwriter allows Reflected XSS.This issue affects Ghostwriter: from n/a through 1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23988" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/ghostwriter/vulnerability/wordpress-ghostwriter-theme-1-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T16:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fp2g-4h6f-28h2/GHSA-fp2g-4h6f-28h2.json b/advisories/unreviewed/2025/05/GHSA-fp2g-4h6f-28h2/GHSA-fp2g-4h6f-28h2.json index 32544d4ca2a..36b747e1be3 100644 --- a/advisories/unreviewed/2025/05/GHSA-fp2g-4h6f-28h2/GHSA-fp2g-4h6f-28h2.json +++ b/advisories/unreviewed/2025/05/GHSA-fp2g-4h6f-28h2/GHSA-fp2g-4h6f-28h2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fp2g-4h6f-28h2", - "modified": "2025-05-19T15:31:00Z", + "modified": "2025-05-19T18:30:45Z", "published": "2025-05-19T15:31:00Z", "aliases": [ "CVE-2025-3908" ], "details": "The configuration initialization tool in OpenVPN 3 Linux v20 through v24 on Linux allows a local attacker to use symlinks pointing at an arbitrary directory which will change the ownership and permissions of that destination directory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-59" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-19T15:15:23Z" diff --git a/advisories/unreviewed/2025/05/GHSA-frr9-jr53-8x43/GHSA-frr9-jr53-8x43.json b/advisories/unreviewed/2025/05/GHSA-frr9-jr53-8x43/GHSA-frr9-jr53-8x43.json new file mode 100644 index 00000000000..c3b5594133e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-frr9-jr53-8x43/GHSA-frr9-jr53-8x43.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-frr9-jr53-8x43", + "modified": "2025-05-19T18:30:48Z", + "published": "2025-05-19T18:30:48Z", + "aliases": [ + "CVE-2025-26997" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in validas Wireless Butler allows Reflected XSS.This issue affects Wireless Butler: from n/a through 1.0.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26997" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/wireless-butler/vulnerability/wordpress-wireless-butler-plugin-1-0-11-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T18:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fxh5-h665-pxfj/GHSA-fxh5-h665-pxfj.json b/advisories/unreviewed/2025/05/GHSA-fxh5-h665-pxfj/GHSA-fxh5-h665-pxfj.json index 93c9f869999..280c4cbedfb 100644 --- a/advisories/unreviewed/2025/05/GHSA-fxh5-h665-pxfj/GHSA-fxh5-h665-pxfj.json +++ b/advisories/unreviewed/2025/05/GHSA-fxh5-h665-pxfj/GHSA-fxh5-h665-pxfj.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-362" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-ggh3-rx92-gffh/GHSA-ggh3-rx92-gffh.json b/advisories/unreviewed/2025/05/GHSA-ggh3-rx92-gffh/GHSA-ggh3-rx92-gffh.json index bbb9c2f8ad9..1a87296f58f 100644 --- a/advisories/unreviewed/2025/05/GHSA-ggh3-rx92-gffh/GHSA-ggh3-rx92-gffh.json +++ b/advisories/unreviewed/2025/05/GHSA-ggh3-rx92-gffh/GHSA-ggh3-rx92-gffh.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/05/GHSA-grxh-3m7g-g4pc/GHSA-grxh-3m7g-g4pc.json b/advisories/unreviewed/2025/05/GHSA-grxh-3m7g-g4pc/GHSA-grxh-3m7g-g4pc.json new file mode 100644 index 00000000000..6e128c16f5d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-grxh-3m7g-g4pc/GHSA-grxh-3m7g-g4pc.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-grxh-3m7g-g4pc", + "modified": "2025-05-19T18:30:46Z", + "published": "2025-05-19T18:30:46Z", + "aliases": [ + "CVE-2025-24184" + ], + "details": "The issue was addressed with improved memory handling. This issue is fixed in visionOS 2.3, iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. An app may be able to cause unexpected system termination.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24184" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122066" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122067" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122071" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122072" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122073" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h4v2-mpxm-7h3w/GHSA-h4v2-mpxm-7h3w.json b/advisories/unreviewed/2025/05/GHSA-h4v2-mpxm-7h3w/GHSA-h4v2-mpxm-7h3w.json new file mode 100644 index 00000000000..cb94b8b653b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h4v2-mpxm-7h3w/GHSA-h4v2-mpxm-7h3w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h4v2-mpxm-7h3w", + "modified": "2025-05-19T18:30:46Z", + "published": "2025-05-19T18:30:46Z", + "aliases": [ + "CVE-2025-22791" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in twh offset writing allows Reflected XSS.This issue affects offset writing: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22791" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/offset-writing/vulnerability/wordpress-offset-writing-theme-1-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T16:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hcg6-8qj3-r5xc/GHSA-hcg6-8qj3-r5xc.json b/advisories/unreviewed/2025/05/GHSA-hcg6-8qj3-r5xc/GHSA-hcg6-8qj3-r5xc.json new file mode 100644 index 00000000000..f9777472d2d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hcg6-8qj3-r5xc/GHSA-hcg6-8qj3-r5xc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hcg6-8qj3-r5xc", + "modified": "2025-05-19T18:30:46Z", + "published": "2025-05-19T18:30:46Z", + "aliases": [ + "CVE-2025-32920" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TemplateInvaders TI WooCommerce Wishlist allows Stored XSS.This issue affects TI WooCommerce Wishlist: from n/a through 2.9.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32920" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ti-woocommerce-wishlist/vulnerability/wordpress-ti-woocommerce-wishlist-plugin-2-9-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T16:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hchw-qwx7-4w4c/GHSA-hchw-qwx7-4w4c.json b/advisories/unreviewed/2025/05/GHSA-hchw-qwx7-4w4c/GHSA-hchw-qwx7-4w4c.json index 9d0a08bb70d..0849cc8d32a 100644 --- a/advisories/unreviewed/2025/05/GHSA-hchw-qwx7-4w4c/GHSA-hchw-qwx7-4w4c.json +++ b/advisories/unreviewed/2025/05/GHSA-hchw-qwx7-4w4c/GHSA-hchw-qwx7-4w4c.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-444" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-hqf6-65hw-qq68/GHSA-hqf6-65hw-qq68.json b/advisories/unreviewed/2025/05/GHSA-hqf6-65hw-qq68/GHSA-hqf6-65hw-qq68.json new file mode 100644 index 00000000000..3358116bfd4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hqf6-65hw-qq68/GHSA-hqf6-65hw-qq68.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hqf6-65hw-qq68", + "modified": "2025-05-19T18:30:47Z", + "published": "2025-05-19T18:30:47Z", + "aliases": [ + "CVE-2025-46262" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zack Katz Mad Mimi for WordPress allows Stored XSS.This issue affects Mad Mimi for WordPress: from n/a through 1.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46262" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mad-mimi/vulnerability/wordpress-mad-mimi-for-wordpress-plugin-1-5-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T17:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hw3m-mgfc-g5r4/GHSA-hw3m-mgfc-g5r4.json b/advisories/unreviewed/2025/05/GHSA-hw3m-mgfc-g5r4/GHSA-hw3m-mgfc-g5r4.json new file mode 100644 index 00000000000..cc99f752bdc --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hw3m-mgfc-g5r4/GHSA-hw3m-mgfc-g5r4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hw3m-mgfc-g5r4", + "modified": "2025-05-19T18:30:46Z", + "published": "2025-05-19T18:30:46Z", + "aliases": [ + "CVE-2025-22789" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fyrewurks polka dots allows Reflected XSS.This issue affects polka dots: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22789" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/polka-dots/vulnerability/wordpress-polka-dots-theme-1-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hwpp-r7c7-mx9g/GHSA-hwpp-r7c7-mx9g.json b/advisories/unreviewed/2025/05/GHSA-hwpp-r7c7-mx9g/GHSA-hwpp-r7c7-mx9g.json new file mode 100644 index 00000000000..745277c9d91 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hwpp-r7c7-mx9g/GHSA-hwpp-r7c7-mx9g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwpp-r7c7-mx9g", + "modified": "2025-05-19T18:30:47Z", + "published": "2025-05-19T18:30:47Z", + "aliases": [ + "CVE-2025-26872" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in dkszone Eximius allows Using Malicious Files.This issue affects Eximius: from n/a through 2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26872" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/eximius/vulnerability/wordpress-eximius-theme-2-2-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T18:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jwxw-jqxj-962v/GHSA-jwxw-jqxj-962v.json b/advisories/unreviewed/2025/05/GHSA-jwxw-jqxj-962v/GHSA-jwxw-jqxj-962v.json new file mode 100644 index 00000000000..f1302c6513d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jwxw-jqxj-962v/GHSA-jwxw-jqxj-962v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jwxw-jqxj-962v", + "modified": "2025-05-19T18:30:46Z", + "published": "2025-05-19T18:30:46Z", + "aliases": [ + "CVE-2025-23981" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Takimi Themes CarZine allows Reflected XSS.This issue affects CarZine: from n/a through 1.4.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23981" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/carzine/vulnerability/wordpress-carzine-theme-1-4-6-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T16:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-m4gj-q4fx-v26f/GHSA-m4gj-q4fx-v26f.json b/advisories/unreviewed/2025/05/GHSA-m4gj-q4fx-v26f/GHSA-m4gj-q4fx-v26f.json new file mode 100644 index 00000000000..a95ad4166c9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-m4gj-q4fx-v26f/GHSA-m4gj-q4fx-v26f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m4gj-q4fx-v26f", + "modified": "2025-05-19T18:30:47Z", + "published": "2025-05-19T18:30:47Z", + "aliases": [ + "CVE-2025-39374" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in aseem1234 Best Posts Summary allows Stored XSS.This issue affects Best Posts Summary: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39374" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/best-posts-summary/vulnerability/wordpress-best-posts-summary-plugin-1-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T17:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-m4w4-6mfj-fqh8/GHSA-m4w4-6mfj-fqh8.json b/advisories/unreviewed/2025/05/GHSA-m4w4-6mfj-fqh8/GHSA-m4w4-6mfj-fqh8.json new file mode 100644 index 00000000000..330adc58040 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-m4w4-6mfj-fqh8/GHSA-m4w4-6mfj-fqh8.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m4w4-6mfj-fqh8", + "modified": "2025-05-19T18:30:48Z", + "published": "2025-05-19T18:30:48Z", + "aliases": [ + "CVE-2025-4940" + ], + "details": "A vulnerability, which was classified as critical, has been found in 1000 Projects Daily College Class Work Report Book 1.0. This issue affects some unknown processing of the file /admin_info.php. The manipulation of the argument batch leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4940" + }, + { + "type": "WEB", + "url": "https://github.com/ubfbuz3/cve/issues/15" + }, + { + "type": "WEB", + "url": "https://1000projects.org" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309503" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309503" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.580161" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T17:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mhg9-c8wr-hm8x/GHSA-mhg9-c8wr-hm8x.json b/advisories/unreviewed/2025/05/GHSA-mhg9-c8wr-hm8x/GHSA-mhg9-c8wr-hm8x.json new file mode 100644 index 00000000000..b3646eae4f7 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mhg9-c8wr-hm8x/GHSA-mhg9-c8wr-hm8x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mhg9-c8wr-hm8x", + "modified": "2025-05-19T18:30:48Z", + "published": "2025-05-19T18:30:48Z", + "aliases": [ + "CVE-2025-43833" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Amir Helzer Absolute Links allows Blind SQL Injection.This issue affects Absolute Links: from n/a through 1.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43833" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/absolute-links/vulnerability/wordpress-absolute-links-plugin-1-1-1-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T18:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mjqj-43pc-37r9/GHSA-mjqj-43pc-37r9.json b/advisories/unreviewed/2025/05/GHSA-mjqj-43pc-37r9/GHSA-mjqj-43pc-37r9.json index b5dfe642d7f..dcd4339e53b 100644 --- a/advisories/unreviewed/2025/05/GHSA-mjqj-43pc-37r9/GHSA-mjqj-43pc-37r9.json +++ b/advisories/unreviewed/2025/05/GHSA-mjqj-43pc-37r9/GHSA-mjqj-43pc-37r9.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/05/GHSA-mr4j-xfv9-w967/GHSA-mr4j-xfv9-w967.json b/advisories/unreviewed/2025/05/GHSA-mr4j-xfv9-w967/GHSA-mr4j-xfv9-w967.json index 813f78d04dc..18ffa488b3d 100644 --- a/advisories/unreviewed/2025/05/GHSA-mr4j-xfv9-w967/GHSA-mr4j-xfv9-w967.json +++ b/advisories/unreviewed/2025/05/GHSA-mr4j-xfv9-w967/GHSA-mr4j-xfv9-w967.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-761" + "CWE-761", + "CWE-763" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-mwcf-jv2p-mmpx/GHSA-mwcf-jv2p-mmpx.json b/advisories/unreviewed/2025/05/GHSA-mwcf-jv2p-mmpx/GHSA-mwcf-jv2p-mmpx.json new file mode 100644 index 00000000000..d864feeb3f9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mwcf-jv2p-mmpx/GHSA-mwcf-jv2p-mmpx.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mwcf-jv2p-mmpx", + "modified": "2025-05-19T18:30:47Z", + "published": "2025-05-19T18:30:47Z", + "aliases": [ + "CVE-2025-4945" + ], + "details": "A flaw was found in the cookie parsing logic of the libsoup HTTP library, used in GNOME applications and other software. The vulnerability arises when processing the expiration date of cookies, where a specially crafted value can trigger an integer overflow. This may result in undefined behavior, allowing an attacker to bypass cookie expiration logic, causing persistent or unintended cookie behavior. The issue stems from improper validation of large integer inputs during date arithmetic operations within the cookie parsing routines.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4945" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-4945" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2367175" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T17:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p9jx-jr54-2xq2/GHSA-p9jx-jr54-2xq2.json b/advisories/unreviewed/2025/05/GHSA-p9jx-jr54-2xq2/GHSA-p9jx-jr54-2xq2.json index cbd2a42d356..76fd0519c70 100644 --- a/advisories/unreviewed/2025/05/GHSA-p9jx-jr54-2xq2/GHSA-p9jx-jr54-2xq2.json +++ b/advisories/unreviewed/2025/05/GHSA-p9jx-jr54-2xq2/GHSA-p9jx-jr54-2xq2.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-770" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-pc32-32fx-wxh7/GHSA-pc32-32fx-wxh7.json b/advisories/unreviewed/2025/05/GHSA-pc32-32fx-wxh7/GHSA-pc32-32fx-wxh7.json new file mode 100644 index 00000000000..694c5c68057 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pc32-32fx-wxh7/GHSA-pc32-32fx-wxh7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pc32-32fx-wxh7", + "modified": "2025-05-19T18:30:48Z", + "published": "2025-05-19T18:30:47Z", + "aliases": [ + "CVE-2025-22287" + ], + "details": "Missing Authorization vulnerability in Eniture Technology LTL Freight Quotes – FreightQuote Edition allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LTL Freight Quotes – FreightQuote Edition: from n/a through 2.3.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22287" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ltl-freight-quotes-freightquote-edition/vulnerability/wordpress-ltl-freight-quotes-freightquote-edition-plugin-2-3-11-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T18:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-pjx5-26hx-4cj5/GHSA-pjx5-26hx-4cj5.json b/advisories/unreviewed/2025/05/GHSA-pjx5-26hx-4cj5/GHSA-pjx5-26hx-4cj5.json new file mode 100644 index 00000000000..4e89ad985c2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pjx5-26hx-4cj5/GHSA-pjx5-26hx-4cj5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pjx5-26hx-4cj5", + "modified": "2025-05-19T18:30:48Z", + "published": "2025-05-19T18:30:48Z", + "aliases": [ + "CVE-2025-27010" + ], + "details": "Path Traversal: '.../...//' vulnerability in bslthemes Tastyc allows PHP Local File Inclusion.This issue affects Tastyc: from n/a before 2.5.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27010" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/tastyc/vulnerability/wordpress-tastyc-2-5-2-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-35" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T18:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-pp7f-fm4q-phg7/GHSA-pp7f-fm4q-phg7.json b/advisories/unreviewed/2025/05/GHSA-pp7f-fm4q-phg7/GHSA-pp7f-fm4q-phg7.json new file mode 100644 index 00000000000..6056615bd35 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pp7f-fm4q-phg7/GHSA-pp7f-fm4q-phg7.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pp7f-fm4q-phg7", + "modified": "2025-05-19T18:30:46Z", + "published": "2025-05-19T18:30:46Z", + "aliases": [ + "CVE-2025-31185" + ], + "details": "A logic issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3. Photos in the Hidden Photos Album may be viewed without authentication.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31185" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122066" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T16:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-prf9-gx8m-9cfq/GHSA-prf9-gx8m-9cfq.json b/advisories/unreviewed/2025/05/GHSA-prf9-gx8m-9cfq/GHSA-prf9-gx8m-9cfq.json new file mode 100644 index 00000000000..ebcc782bec0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-prf9-gx8m-9cfq/GHSA-prf9-gx8m-9cfq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-prf9-gx8m-9cfq", + "modified": "2025-05-19T18:30:46Z", + "published": "2025-05-19T18:30:46Z", + "aliases": [ + "CVE-2025-4876" + ], + "details": "ConnectWise-Password-Encryption-Utility.exe in ConnectWise Risk Assessment allows an attacker to extract a hardcoded AES decryption key via reverse engineering. This key is embedded in plaintext within the binary and used in cryptographic operations without dynamic key management. Once obtained the key can be used to decrypt CSV input files used for authenticated network scanning.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4876" + }, + { + "type": "WEB", + "url": "https://github.com/packetlabs/vulnerability-advisory/blob/main/Disclosures/PL-2025-11315/README.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-798" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T16:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q2pv-8f62-27p3/GHSA-q2pv-8f62-27p3.json b/advisories/unreviewed/2025/05/GHSA-q2pv-8f62-27p3/GHSA-q2pv-8f62-27p3.json new file mode 100644 index 00000000000..c12159d785e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q2pv-8f62-27p3/GHSA-q2pv-8f62-27p3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q2pv-8f62-27p3", + "modified": "2025-05-19T18:30:46Z", + "published": "2025-05-19T18:30:46Z", + "aliases": [ + "CVE-2025-23986" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fyrewurks Tiki Time allows Reflected XSS.This issue affects Tiki Time: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23986" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/tiki-time/vulnerability/wordpress-tiki-time-theme-1-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T16:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q7qq-47m5-qqj6/GHSA-q7qq-47m5-qqj6.json b/advisories/unreviewed/2025/05/GHSA-q7qq-47m5-qqj6/GHSA-q7qq-47m5-qqj6.json index bd9c388a851..1a670678fac 100644 --- a/advisories/unreviewed/2025/05/GHSA-q7qq-47m5-qqj6/GHSA-q7qq-47m5-qqj6.json +++ b/advisories/unreviewed/2025/05/GHSA-q7qq-47m5-qqj6/GHSA-q7qq-47m5-qqj6.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-qwwx-f8r3-v9pc/GHSA-qwwx-f8r3-v9pc.json b/advisories/unreviewed/2025/05/GHSA-qwwx-f8r3-v9pc/GHSA-qwwx-f8r3-v9pc.json new file mode 100644 index 00000000000..60a4bba9f79 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qwwx-f8r3-v9pc/GHSA-qwwx-f8r3-v9pc.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qwwx-f8r3-v9pc", + "modified": "2025-05-19T18:30:47Z", + "published": "2025-05-19T18:30:47Z", + "aliases": [ + "CVE-2025-4941" + ], + "details": "A vulnerability, which was classified as critical, was found in PHPGurukul Credit Card Application Management System 1.0. Affected is an unknown function of the file /admin/index.php. The manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4941" + }, + { + "type": "WEB", + "url": "https://github.com/GIRISH05/Credit-card-application-management-system/blob/main/SQL-Injection.md" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309504" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309504" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.580167" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T17:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-r2q8-3rg5-p5rg/GHSA-r2q8-3rg5-p5rg.json b/advisories/unreviewed/2025/05/GHSA-r2q8-3rg5-p5rg/GHSA-r2q8-3rg5-p5rg.json index 0fb8efb0e95..9fd2ef6bbcb 100644 --- a/advisories/unreviewed/2025/05/GHSA-r2q8-3rg5-p5rg/GHSA-r2q8-3rg5-p5rg.json +++ b/advisories/unreviewed/2025/05/GHSA-r2q8-3rg5-p5rg/GHSA-r2q8-3rg5-p5rg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r2q8-3rg5-p5rg", - "modified": "2025-05-14T18:30:47Z", + "modified": "2025-05-19T18:30:40Z", "published": "2025-05-14T18:30:47Z", "aliases": [ "CVE-2025-26785" ], "details": "An issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. The lack of a length check leads to out-of-bounds writes.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-14T17:15:47Z" diff --git a/advisories/unreviewed/2025/05/GHSA-r3v9-92q2-pvmf/GHSA-r3v9-92q2-pvmf.json b/advisories/unreviewed/2025/05/GHSA-r3v9-92q2-pvmf/GHSA-r3v9-92q2-pvmf.json index 2f7a00df1af..ad3f3e81a57 100644 --- a/advisories/unreviewed/2025/05/GHSA-r3v9-92q2-pvmf/GHSA-r3v9-92q2-pvmf.json +++ b/advisories/unreviewed/2025/05/GHSA-r3v9-92q2-pvmf/GHSA-r3v9-92q2-pvmf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r3v9-92q2-pvmf", - "modified": "2025-05-14T18:30:48Z", + "modified": "2025-05-19T18:30:41Z", "published": "2025-05-14T18:30:48Z", "aliases": [ "CVE-2025-44186" ], "details": "SourceCodester Best Employee Management System 1.0 is vulnerable to Cross Site Request Forgery (CSRF) in /admin/Operation/User.php page.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-14T17:15:49Z" diff --git a/advisories/unreviewed/2025/05/GHSA-r53g-69jj-xq7x/GHSA-r53g-69jj-xq7x.json b/advisories/unreviewed/2025/05/GHSA-r53g-69jj-xq7x/GHSA-r53g-69jj-xq7x.json new file mode 100644 index 00000000000..f5e557eab6f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-r53g-69jj-xq7x/GHSA-r53g-69jj-xq7x.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r53g-69jj-xq7x", + "modified": "2025-05-19T18:30:46Z", + "published": "2025-05-19T18:30:46Z", + "aliases": [ + "CVE-2025-4938" + ], + "details": "A vulnerability was found in PHPGurukul Employee Record Management System 1.3. It has been rated as critical. Affected by this issue is some unknown functionality of the file /registererms.php. The manipulation of the argument Email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4938" + }, + { + "type": "WEB", + "url": "https://github.com/WuYanneko/CVE/issues/2" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309500" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309500" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.579848" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-r593-5693-qv6x/GHSA-r593-5693-qv6x.json b/advisories/unreviewed/2025/05/GHSA-r593-5693-qv6x/GHSA-r593-5693-qv6x.json new file mode 100644 index 00000000000..53abf4bb4f3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-r593-5693-qv6x/GHSA-r593-5693-qv6x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r593-5693-qv6x", + "modified": "2025-05-19T18:30:47Z", + "published": "2025-05-19T18:30:47Z", + "aliases": [ + "CVE-2025-39373" + ], + "details": "Missing Authorization vulnerability in jegtheme JNews.This issue affects JNews: from n/a through 11.6.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39373" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/jnews/vulnerability/wordpress-jnews-theme-11-6-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T17:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rf2f-phpv-m2gx/GHSA-rf2f-phpv-m2gx.json b/advisories/unreviewed/2025/05/GHSA-rf2f-phpv-m2gx/GHSA-rf2f-phpv-m2gx.json index 66610ce5e23..7fa9c7a092e 100644 --- a/advisories/unreviewed/2025/05/GHSA-rf2f-phpv-m2gx/GHSA-rf2f-phpv-m2gx.json +++ b/advisories/unreviewed/2025/05/GHSA-rf2f-phpv-m2gx/GHSA-rf2f-phpv-m2gx.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-rgrg-qwpp-28j8/GHSA-rgrg-qwpp-28j8.json b/advisories/unreviewed/2025/05/GHSA-rgrg-qwpp-28j8/GHSA-rgrg-qwpp-28j8.json index bbe29f22c21..f46c358c1af 100644 --- a/advisories/unreviewed/2025/05/GHSA-rgrg-qwpp-28j8/GHSA-rgrg-qwpp-28j8.json +++ b/advisories/unreviewed/2025/05/GHSA-rgrg-qwpp-28j8/GHSA-rgrg-qwpp-28j8.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-770" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-rrcx-vcp9-h6c7/GHSA-rrcx-vcp9-h6c7.json b/advisories/unreviewed/2025/05/GHSA-rrcx-vcp9-h6c7/GHSA-rrcx-vcp9-h6c7.json index 03e7b7a4cc8..bc2b95c5e34 100644 --- a/advisories/unreviewed/2025/05/GHSA-rrcx-vcp9-h6c7/GHSA-rrcx-vcp9-h6c7.json +++ b/advisories/unreviewed/2025/05/GHSA-rrcx-vcp9-h6c7/GHSA-rrcx-vcp9-h6c7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rrcx-vcp9-h6c7", - "modified": "2025-05-19T15:31:00Z", + "modified": "2025-05-19T18:30:45Z", "published": "2025-05-19T15:31:00Z", "aliases": [ "CVE-2025-43714" ], "details": "The ChatGPT system through 2025-03-30 performs inline rendering of SVG documents (instead of, for example, rendering them as text inside a code block), which enables HTML injection within most modern graphical web browsers.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-19T15:15:23Z" diff --git a/advisories/unreviewed/2025/05/GHSA-rw3p-877j-xxwm/GHSA-rw3p-877j-xxwm.json b/advisories/unreviewed/2025/05/GHSA-rw3p-877j-xxwm/GHSA-rw3p-877j-xxwm.json new file mode 100644 index 00000000000..a4fcf1d27ba --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rw3p-877j-xxwm/GHSA-rw3p-877j-xxwm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rw3p-877j-xxwm", + "modified": "2025-05-19T18:30:46Z", + "published": "2025-05-19T18:30:46Z", + "aliases": [ + "CVE-2025-22678" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mythemes my white allows Reflected XSS.This issue affects my white: from n/a through 2.0.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22678" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/my-white/vulnerability/wordpress-my-white-theme-2-0-8-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v5vr-7qc6-xw56/GHSA-v5vr-7qc6-xw56.json b/advisories/unreviewed/2025/05/GHSA-v5vr-7qc6-xw56/GHSA-v5vr-7qc6-xw56.json index eb56400fc3f..8118c60885e 100644 --- a/advisories/unreviewed/2025/05/GHSA-v5vr-7qc6-xw56/GHSA-v5vr-7qc6-xw56.json +++ b/advisories/unreviewed/2025/05/GHSA-v5vr-7qc6-xw56/GHSA-v5vr-7qc6-xw56.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v5vr-7qc6-xw56", - "modified": "2025-05-14T15:31:38Z", + "modified": "2025-05-19T18:30:40Z", "published": "2025-05-14T15:31:38Z", "aliases": [ "CVE-2024-57273" @@ -23,6 +23,14 @@ "type": "WEB", "url": "https://blog.brillantit.com/exploiting-pfsense-xss-command-injection-cloud-hijack" }, + { + "type": "WEB", + "url": "https://docs.netgate.com/downloads/pfSense-SA-25_03.webgui.asc" + }, + { + "type": "WEB", + "url": "https://www.netgate.com/blog/important-security-updates-for-pfsense-plus-24.11-and-ce-2.7.2" + }, { "type": "WEB", "url": "http://netgate.com" diff --git a/advisories/unreviewed/2025/05/GHSA-vfg9-gh45-wrq2/GHSA-vfg9-gh45-wrq2.json b/advisories/unreviewed/2025/05/GHSA-vfg9-gh45-wrq2/GHSA-vfg9-gh45-wrq2.json index 3bcf6bca90f..3ad702fd6c0 100644 --- a/advisories/unreviewed/2025/05/GHSA-vfg9-gh45-wrq2/GHSA-vfg9-gh45-wrq2.json +++ b/advisories/unreviewed/2025/05/GHSA-vfg9-gh45-wrq2/GHSA-vfg9-gh45-wrq2.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-770" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-vfx3-xjmh-f34c/GHSA-vfx3-xjmh-f34c.json b/advisories/unreviewed/2025/05/GHSA-vfx3-xjmh-f34c/GHSA-vfx3-xjmh-f34c.json new file mode 100644 index 00000000000..2d2e98e6bce --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vfx3-xjmh-f34c/GHSA-vfx3-xjmh-f34c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vfx3-xjmh-f34c", + "modified": "2025-05-19T18:30:46Z", + "published": "2025-05-19T18:30:45Z", + "aliases": [ + "CVE-2024-33939" + ], + "details": "Authentication Bypass Using an Alternate Path or Channel vulnerability in Masteriyo Masteriyo - LMS. Unauth access to course progress.This issue affects Masteriyo - LMS: from n/a through 1.7.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33939" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/learning-management-system/vulnerability/wordpress-lms-by-masteriyo-plugin-1-7-3-broken-authentication-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vgrj-mg42-7vqg/GHSA-vgrj-mg42-7vqg.json b/advisories/unreviewed/2025/05/GHSA-vgrj-mg42-7vqg/GHSA-vgrj-mg42-7vqg.json index 616c0d137a8..102a66843ec 100644 --- a/advisories/unreviewed/2025/05/GHSA-vgrj-mg42-7vqg/GHSA-vgrj-mg42-7vqg.json +++ b/advisories/unreviewed/2025/05/GHSA-vgrj-mg42-7vqg/GHSA-vgrj-mg42-7vqg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vgrj-mg42-7vqg", - "modified": "2025-05-19T15:31:00Z", + "modified": "2025-05-19T18:30:45Z", "published": "2025-05-19T15:30:59Z", "aliases": [ "CVE-2024-51106" ], "details": "A cross-site scripting (XSS) vulnerability in the component mcgs/admin/aboutus.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the pagetitle parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-19T15:15:22Z" diff --git a/advisories/unreviewed/2025/05/GHSA-vh6g-f64r-5r5w/GHSA-vh6g-f64r-5r5w.json b/advisories/unreviewed/2025/05/GHSA-vh6g-f64r-5r5w/GHSA-vh6g-f64r-5r5w.json new file mode 100644 index 00000000000..544b8d018cf --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vh6g-f64r-5r5w/GHSA-vh6g-f64r-5r5w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vh6g-f64r-5r5w", + "modified": "2025-05-19T18:30:47Z", + "published": "2025-05-19T18:30:47Z", + "aliases": [ + "CVE-2025-47583" + ], + "details": "Unauthenticated Cross Site Request Forgery (CSRF) in Salon booking system <= 10.16 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47583" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/salon-booking-system/vulnerability/wordpress-salon-booking-system-plugin-10-16-csrf-to-arbitrary-content-deletion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T17:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vqxf-9gx2-9j34/GHSA-vqxf-9gx2-9j34.json b/advisories/unreviewed/2025/05/GHSA-vqxf-9gx2-9j34/GHSA-vqxf-9gx2-9j34.json new file mode 100644 index 00000000000..d1026ec63ef --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vqxf-9gx2-9j34/GHSA-vqxf-9gx2-9j34.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vqxf-9gx2-9j34", + "modified": "2025-05-19T18:30:47Z", + "published": "2025-05-19T18:30:47Z", + "aliases": [ + "CVE-2025-46543" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Charly Leetham Enhanced Paypal Shortcodes allows Stored XSS.This issue affects Enhanced Paypal Shortcodes: from n/a through 0.5a.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46543" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/enhanced-paypal-shortcodes/vulnerability/wordpress-enhanced-paypal-shortcodes-plugin-0-5a-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T17:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vqxg-8xhm-jf4p/GHSA-vqxg-8xhm-jf4p.json b/advisories/unreviewed/2025/05/GHSA-vqxg-8xhm-jf4p/GHSA-vqxg-8xhm-jf4p.json new file mode 100644 index 00000000000..859770f33ca --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vqxg-8xhm-jf4p/GHSA-vqxg-8xhm-jf4p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vqxg-8xhm-jf4p", + "modified": "2025-05-19T18:30:47Z", + "published": "2025-05-19T18:30:46Z", + "aliases": [ + "CVE-2025-26920" + ], + "details": "Missing Authorization vulnerability in PressMaximum Customify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Customify: from n/a through 0.4.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26920" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/customify-theme/vulnerability/wordpress-customify-theme-0-4-8-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T17:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w2cm-pc9j-3m28/GHSA-w2cm-pc9j-3m28.json b/advisories/unreviewed/2025/05/GHSA-w2cm-pc9j-3m28/GHSA-w2cm-pc9j-3m28.json index 9b9969d8695..d4cba2f0ec2 100644 --- a/advisories/unreviewed/2025/05/GHSA-w2cm-pc9j-3m28/GHSA-w2cm-pc9j-3m28.json +++ b/advisories/unreviewed/2025/05/GHSA-w2cm-pc9j-3m28/GHSA-w2cm-pc9j-3m28.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-280" + "CWE-280", + "CWE-755" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-wjv3-vv76-gqfj/GHSA-wjv3-vv76-gqfj.json b/advisories/unreviewed/2025/05/GHSA-wjv3-vv76-gqfj/GHSA-wjv3-vv76-gqfj.json new file mode 100644 index 00000000000..dfb39cc1392 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wjv3-vv76-gqfj/GHSA-wjv3-vv76-gqfj.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wjv3-vv76-gqfj", + "modified": "2025-05-19T18:30:46Z", + "published": "2025-05-19T18:30:46Z", + "aliases": [ + "CVE-2025-24189" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in Safari 18.3, visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. Processing maliciously crafted web content may lead to memory corruption.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24189" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122066" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122071" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122072" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122073" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122074" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wr46-685x-rcr2/GHSA-wr46-685x-rcr2.json b/advisories/unreviewed/2025/05/GHSA-wr46-685x-rcr2/GHSA-wr46-685x-rcr2.json index 47fdbf63d4c..9b95cca9f3f 100644 --- a/advisories/unreviewed/2025/05/GHSA-wr46-685x-rcr2/GHSA-wr46-685x-rcr2.json +++ b/advisories/unreviewed/2025/05/GHSA-wr46-685x-rcr2/GHSA-wr46-685x-rcr2.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-x47c-v779-7xcp/GHSA-x47c-v779-7xcp.json b/advisories/unreviewed/2025/05/GHSA-x47c-v779-7xcp/GHSA-x47c-v779-7xcp.json new file mode 100644 index 00000000000..662a6de1758 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-x47c-v779-7xcp/GHSA-x47c-v779-7xcp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x47c-v779-7xcp", + "modified": "2025-05-19T18:30:46Z", + "published": "2025-05-19T18:30:46Z", + "aliases": [ + "CVE-2025-22792" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jinwen Js O3 Lite allows Reflected XSS.This issue affects Js O3 Lite: from n/a through 1.5.8.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22792" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/js-o3-lite/vulnerability/wordpress-js-o3-lite-theme-1-5-8-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T16:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-x725-g7rw-pw6q/GHSA-x725-g7rw-pw6q.json b/advisories/unreviewed/2025/05/GHSA-x725-g7rw-pw6q/GHSA-x725-g7rw-pw6q.json new file mode 100644 index 00000000000..a4011d8938f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-x725-g7rw-pw6q/GHSA-x725-g7rw-pw6q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x725-g7rw-pw6q", + "modified": "2025-05-19T18:30:46Z", + "published": "2025-05-19T18:30:46Z", + "aliases": [ + "CVE-2025-23983" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tijaji allows Reflected XSS.This issue affects Tijaji: from n/a through 1.43.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23983" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/tijaji/vulnerability/wordpress-tijaji-theme-1-43-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T16:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-x8r2-wrm6-4v97/GHSA-x8r2-wrm6-4v97.json b/advisories/unreviewed/2025/05/GHSA-x8r2-wrm6-4v97/GHSA-x8r2-wrm6-4v97.json new file mode 100644 index 00000000000..0fddf88c076 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-x8r2-wrm6-4v97/GHSA-x8r2-wrm6-4v97.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x8r2-wrm6-4v97", + "modified": "2025-05-19T18:30:46Z", + "published": "2025-05-19T18:30:46Z", + "aliases": [ + "CVE-2025-24183" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. A local user may be able to modify protected parts of the file system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24183" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122069" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122070" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xh92-vqm9-v66r/GHSA-xh92-vqm9-v66r.json b/advisories/unreviewed/2025/05/GHSA-xh92-vqm9-v66r/GHSA-xh92-vqm9-v66r.json index 244458fdd5f..b5df9addbfe 100644 --- a/advisories/unreviewed/2025/05/GHSA-xh92-vqm9-v66r/GHSA-xh92-vqm9-v66r.json +++ b/advisories/unreviewed/2025/05/GHSA-xh92-vqm9-v66r/GHSA-xh92-vqm9-v66r.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-xrjq-mmx8-72h6/GHSA-xrjq-mmx8-72h6.json b/advisories/unreviewed/2025/05/GHSA-xrjq-mmx8-72h6/GHSA-xrjq-mmx8-72h6.json index 5f3c80c7fba..9d78cfdf7d4 100644 --- a/advisories/unreviewed/2025/05/GHSA-xrjq-mmx8-72h6/GHSA-xrjq-mmx8-72h6.json +++ b/advisories/unreviewed/2025/05/GHSA-xrjq-mmx8-72h6/GHSA-xrjq-mmx8-72h6.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-610", "CWE-73" ], "severity": "MODERATE",