From bb6e36d392625746b67e4744518a379d0d1d8efc Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 28 May 2025 18:35:10 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-349w-cgp3-287r.json | 17 ++++++- .../GHSA-4mf4-j3m9-h786.json | 3 +- .../GHSA-5993-g4g9-vmxq.json | 4 +- .../GHSA-5vfq-rv44-c5ff.json | 17 ++++++- .../GHSA-63xv-5555-rrjh.json | 4 +- .../GHSA-7qp8-gff7-3q94.json | 4 +- .../GHSA-9g62-7rj3-h7w2.json | 3 +- .../GHSA-9p8r-gmq2-69cr.json | 4 +- .../GHSA-9vhf-78v4-49cq.json | 3 +- .../GHSA-f2cm-pc3v-mjrg.json | 4 +- .../GHSA-frxw-cc6c-jg2m.json | 4 +- .../GHSA-jfpq-w2g4-wcpm.json | 2 +- .../GHSA-jp9x-px2h-j57p.json | 4 +- .../GHSA-m2rw-gwp5-6wqw.json | 6 ++- .../GHSA-q925-4hvg-j5pg.json | 4 +- .../GHSA-qgj3-jh2x-36gf.json | 4 +- .../GHSA-qrm9-295f-xg65.json | 6 ++- .../GHSA-x92w-hx54-ffh8.json | 4 +- .../GHSA-4f2h-j443-g993.json | 2 +- .../GHSA-7mp8-w7v3-999f.json | 4 +- .../GHSA-8cxm-wrjw-f6qw.json | 6 ++- .../GHSA-hj36-mw8h-wwjc.json | 4 +- .../GHSA-wj8f-78wg-52vw.json | 6 ++- .../GHSA-f74m-5p64-49qj.json | 3 +- .../GHSA-2f98-4x2w-23pw.json | 3 +- .../GHSA-76vw-8gm2-pwmh.json | 3 +- .../GHSA-76x3-9rqr-2g63.json | 3 +- .../GHSA-qxwf-xj2v-qm83.json | 3 +- .../GHSA-rrc2-m8v6-jh7q.json | 3 +- .../GHSA-vr2r-rp8h-3j86.json | 3 +- .../GHSA-w9wx-xm8x-jhqq.json | 3 +- .../GHSA-8c9q-c5r4-q67m.json | 3 +- .../GHSA-995j-2jcg-pg6h.json | 3 +- .../GHSA-9cp2-r8w6-r4vm.json | 4 +- .../GHSA-ffc2-m4f8-5m2g.json | 4 +- .../GHSA-h4g8-pvpv-p57j.json | 3 +- .../GHSA-hq28-6c72-q4fg.json | 2 +- .../GHSA-jvjx-8r65-mrp9.json | 3 +- .../GHSA-p6jq-9gcc-mcvx.json | 4 +- .../GHSA-p9vw-vmhm-c984.json | 3 +- .../GHSA-r37f-v2p6-x6cx.json | 3 +- .../GHSA-2954-4rrv-2pfp.json | 4 +- .../GHSA-2fcj-g7j8-pg57.json | 36 +++++++++++++++ .../GHSA-2jfq-9qf9-jmjj.json | 44 +++++++++++++++++++ .../GHSA-2qrm-36rr-ffj3.json | 4 +- .../GHSA-2v5h-r74h-52p7.json | 6 ++- .../GHSA-33cx-2vvq-mf52.json | 10 ++++- .../GHSA-3p76-4rrp-wwv9.json | 25 +++++++++++ .../GHSA-45pv-3wg3-68gv.json | 25 +++++++++++ .../GHSA-4hwf-mgvq-g226.json | 25 +++++++++++ .../GHSA-54mq-99qq-7hr5.json | 36 +++++++++++++++ .../GHSA-5wx3-hjmf-qcgx.json | 36 +++++++++++++++ .../GHSA-7374-5865-cjhh.json | 25 +++++++++++ .../GHSA-764c-3vwj-x87m.json | 4 +- .../GHSA-76w2-jhhw-cjjj.json | 40 +++++++++++++++++ .../GHSA-7xpv-834v-x9rj.json | 36 +++++++++++++++ .../GHSA-89wf-mr2w-22xh.json | 4 +- .../GHSA-8mq9-3232-xxrj.json | 25 +++++++++++ .../GHSA-8q85-7q4r-xhgc.json | 44 +++++++++++++++++++ .../GHSA-8r5j-5vhh-wr82.json | 3 +- .../GHSA-9j47-qv65-j87p.json | 40 +++++++++++++++++ .../GHSA-9qww-jrc3-jf78.json | 25 +++++++++++ .../GHSA-cg63-5mwv-w273.json | 25 +++++++++++ .../GHSA-cv2r-m5ph-vgj6.json | 25 +++++++++++ .../GHSA-f2c5-m7v5-93g5.json | 25 +++++++++++ .../GHSA-fg72-v8xw-hm7h.json | 33 ++++++++++++++ .../GHSA-frcx-58px-56g2.json | 25 +++++++++++ .../GHSA-g7m2-hjxw-27h7.json | 36 +++++++++++++++ .../GHSA-hc7m-j4w7-pv6w.json | 29 ++++++++++++ .../GHSA-hv8v-455m-2grc.json | 36 +++++++++++++++ .../GHSA-j54f-6g32-3jwj.json | 4 +- .../GHSA-j95r-8c72-m59j.json | 4 +- .../GHSA-jxv9-h32m-39xj.json | 25 +++++++++++ .../GHSA-mcfv-326r-vxp8.json | 25 +++++++++++ .../GHSA-mjrc-8w22-4fpj.json | 25 +++++++++++ .../GHSA-p2p2-xpg4-rpvh.json | 25 +++++++++++ .../GHSA-p3p9-wgx4-mq3v.json | 3 +- .../GHSA-p694-pgrr-cmpq.json | 4 +- .../GHSA-pmfj-hrgr-wvm5.json | 25 +++++++++++ .../GHSA-pr6c-x44x-mpwc.json | 4 +- .../GHSA-prj7-2jhj-62fj.json | 36 +++++++++++++++ .../GHSA-pw38-3jfp-fw32.json | 36 +++++++++++++++ .../GHSA-qm8c-9qvf-wv68.json | 25 +++++++++++ .../GHSA-qq2r-6j4w-49qc.json | 33 ++++++++++++++ .../GHSA-rxgj-95gj-27xq.json | 25 +++++++++++ .../GHSA-v4hr-6g26-8757.json | 36 +++++++++++++++ .../GHSA-v6cp-qj97-x87h.json | 3 +- .../GHSA-v7c5-rprq-jfcf.json | 25 +++++++++++ .../GHSA-vg38-3h8m-863x.json | 4 +- .../GHSA-vg5q-95gg-rqfg.json | 36 +++++++++++++++ .../GHSA-vprv-ph4x-pqgj.json | 36 +++++++++++++++ .../GHSA-vr74-xqq8-6564.json | 25 +++++++++++ .../GHSA-vr9v-xw27-65fc.json | 40 +++++++++++++++++ .../GHSA-vvqh-pjh9-jh35.json | 40 +++++++++++++++++ .../GHSA-vwc9-wh34-hrfm.json | 36 +++++++++++++++ .../GHSA-w2h3-r7p6-vm66.json | 25 +++++++++++ .../GHSA-w3pc-9cp7-x9xr.json | 25 +++++++++++ .../GHSA-w3vc-hpm9-2h9q.json | 29 ++++++++++++ .../GHSA-w95r-6gjg-73xh.json | 25 +++++++++++ .../GHSA-wcwc-445x-wf23.json | 3 +- .../GHSA-wxg6-4cwm-4rjf.json | 29 ++++++++++++ .../GHSA-x298-29qf-2vcx.json | 25 +++++++++++ .../GHSA-x6fc-488r-qh93.json | 33 ++++++++++++++ .../GHSA-xh67-8c9c-jwgx.json | 36 +++++++++++++++ .../GHSA-xv8q-37rr-6369.json | 25 +++++++++++ 105 files changed, 1681 insertions(+), 60 deletions(-) create mode 100644 advisories/unreviewed/2025/05/GHSA-2fcj-g7j8-pg57/GHSA-2fcj-g7j8-pg57.json create mode 100644 advisories/unreviewed/2025/05/GHSA-2jfq-9qf9-jmjj/GHSA-2jfq-9qf9-jmjj.json create mode 100644 advisories/unreviewed/2025/05/GHSA-3p76-4rrp-wwv9/GHSA-3p76-4rrp-wwv9.json create mode 100644 advisories/unreviewed/2025/05/GHSA-45pv-3wg3-68gv/GHSA-45pv-3wg3-68gv.json create mode 100644 advisories/unreviewed/2025/05/GHSA-4hwf-mgvq-g226/GHSA-4hwf-mgvq-g226.json create mode 100644 advisories/unreviewed/2025/05/GHSA-54mq-99qq-7hr5/GHSA-54mq-99qq-7hr5.json create mode 100644 advisories/unreviewed/2025/05/GHSA-5wx3-hjmf-qcgx/GHSA-5wx3-hjmf-qcgx.json create mode 100644 advisories/unreviewed/2025/05/GHSA-7374-5865-cjhh/GHSA-7374-5865-cjhh.json create mode 100644 advisories/unreviewed/2025/05/GHSA-76w2-jhhw-cjjj/GHSA-76w2-jhhw-cjjj.json create mode 100644 advisories/unreviewed/2025/05/GHSA-7xpv-834v-x9rj/GHSA-7xpv-834v-x9rj.json create mode 100644 advisories/unreviewed/2025/05/GHSA-8mq9-3232-xxrj/GHSA-8mq9-3232-xxrj.json create mode 100644 advisories/unreviewed/2025/05/GHSA-8q85-7q4r-xhgc/GHSA-8q85-7q4r-xhgc.json create mode 100644 advisories/unreviewed/2025/05/GHSA-9j47-qv65-j87p/GHSA-9j47-qv65-j87p.json create mode 100644 advisories/unreviewed/2025/05/GHSA-9qww-jrc3-jf78/GHSA-9qww-jrc3-jf78.json create mode 100644 advisories/unreviewed/2025/05/GHSA-cg63-5mwv-w273/GHSA-cg63-5mwv-w273.json create mode 100644 advisories/unreviewed/2025/05/GHSA-cv2r-m5ph-vgj6/GHSA-cv2r-m5ph-vgj6.json create mode 100644 advisories/unreviewed/2025/05/GHSA-f2c5-m7v5-93g5/GHSA-f2c5-m7v5-93g5.json create mode 100644 advisories/unreviewed/2025/05/GHSA-fg72-v8xw-hm7h/GHSA-fg72-v8xw-hm7h.json create mode 100644 advisories/unreviewed/2025/05/GHSA-frcx-58px-56g2/GHSA-frcx-58px-56g2.json create mode 100644 advisories/unreviewed/2025/05/GHSA-g7m2-hjxw-27h7/GHSA-g7m2-hjxw-27h7.json create mode 100644 advisories/unreviewed/2025/05/GHSA-hc7m-j4w7-pv6w/GHSA-hc7m-j4w7-pv6w.json create mode 100644 advisories/unreviewed/2025/05/GHSA-hv8v-455m-2grc/GHSA-hv8v-455m-2grc.json create mode 100644 advisories/unreviewed/2025/05/GHSA-jxv9-h32m-39xj/GHSA-jxv9-h32m-39xj.json create mode 100644 advisories/unreviewed/2025/05/GHSA-mcfv-326r-vxp8/GHSA-mcfv-326r-vxp8.json create mode 100644 advisories/unreviewed/2025/05/GHSA-mjrc-8w22-4fpj/GHSA-mjrc-8w22-4fpj.json create mode 100644 advisories/unreviewed/2025/05/GHSA-p2p2-xpg4-rpvh/GHSA-p2p2-xpg4-rpvh.json create mode 100644 advisories/unreviewed/2025/05/GHSA-pmfj-hrgr-wvm5/GHSA-pmfj-hrgr-wvm5.json create mode 100644 advisories/unreviewed/2025/05/GHSA-prj7-2jhj-62fj/GHSA-prj7-2jhj-62fj.json create mode 100644 advisories/unreviewed/2025/05/GHSA-pw38-3jfp-fw32/GHSA-pw38-3jfp-fw32.json create mode 100644 advisories/unreviewed/2025/05/GHSA-qm8c-9qvf-wv68/GHSA-qm8c-9qvf-wv68.json create mode 100644 advisories/unreviewed/2025/05/GHSA-qq2r-6j4w-49qc/GHSA-qq2r-6j4w-49qc.json create mode 100644 advisories/unreviewed/2025/05/GHSA-rxgj-95gj-27xq/GHSA-rxgj-95gj-27xq.json create mode 100644 advisories/unreviewed/2025/05/GHSA-v4hr-6g26-8757/GHSA-v4hr-6g26-8757.json create mode 100644 advisories/unreviewed/2025/05/GHSA-v7c5-rprq-jfcf/GHSA-v7c5-rprq-jfcf.json create mode 100644 advisories/unreviewed/2025/05/GHSA-vg5q-95gg-rqfg/GHSA-vg5q-95gg-rqfg.json create mode 100644 advisories/unreviewed/2025/05/GHSA-vprv-ph4x-pqgj/GHSA-vprv-ph4x-pqgj.json create mode 100644 advisories/unreviewed/2025/05/GHSA-vr74-xqq8-6564/GHSA-vr74-xqq8-6564.json create mode 100644 advisories/unreviewed/2025/05/GHSA-vr9v-xw27-65fc/GHSA-vr9v-xw27-65fc.json create mode 100644 advisories/unreviewed/2025/05/GHSA-vvqh-pjh9-jh35/GHSA-vvqh-pjh9-jh35.json create mode 100644 advisories/unreviewed/2025/05/GHSA-vwc9-wh34-hrfm/GHSA-vwc9-wh34-hrfm.json create mode 100644 advisories/unreviewed/2025/05/GHSA-w2h3-r7p6-vm66/GHSA-w2h3-r7p6-vm66.json create mode 100644 advisories/unreviewed/2025/05/GHSA-w3pc-9cp7-x9xr/GHSA-w3pc-9cp7-x9xr.json create mode 100644 advisories/unreviewed/2025/05/GHSA-w3vc-hpm9-2h9q/GHSA-w3vc-hpm9-2h9q.json create mode 100644 advisories/unreviewed/2025/05/GHSA-w95r-6gjg-73xh/GHSA-w95r-6gjg-73xh.json create mode 100644 advisories/unreviewed/2025/05/GHSA-wxg6-4cwm-4rjf/GHSA-wxg6-4cwm-4rjf.json create mode 100644 advisories/unreviewed/2025/05/GHSA-x298-29qf-2vcx/GHSA-x298-29qf-2vcx.json create mode 100644 advisories/unreviewed/2025/05/GHSA-x6fc-488r-qh93/GHSA-x6fc-488r-qh93.json create mode 100644 advisories/unreviewed/2025/05/GHSA-xh67-8c9c-jwgx/GHSA-xh67-8c9c-jwgx.json create mode 100644 advisories/unreviewed/2025/05/GHSA-xv8q-37rr-6369/GHSA-xv8q-37rr-6369.json diff --git a/advisories/unreviewed/2022/09/GHSA-349w-cgp3-287r/GHSA-349w-cgp3-287r.json b/advisories/unreviewed/2022/09/GHSA-349w-cgp3-287r/GHSA-349w-cgp3-287r.json index 696a3d4249b..2c0637c4e14 100644 --- a/advisories/unreviewed/2022/09/GHSA-349w-cgp3-287r/GHSA-349w-cgp3-287r.json +++ b/advisories/unreviewed/2022/09/GHSA-349w-cgp3-287r/GHSA-349w-cgp3-287r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-349w-cgp3-287r", - "modified": "2022-09-25T00:00:20Z", + "modified": "2025-05-28T18:33:05Z", "published": "2022-09-22T00:00:32Z", "aliases": [ "CVE-2022-38178" @@ -27,6 +27,18 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2022/10/msg00007.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CV4GQWBPF7Y52J2FA24U6UMHQAOXZEF7" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MRHB6J4Z7BKH4HPEKG5D35QGRD6ANNMT" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YZJQNUASODNVAWZV6STKG5SD6XIJ446S" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CV4GQWBPF7Y52J2FA24U6UMHQAOXZEF7" @@ -58,7 +70,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-347" + "CWE-347", + "CWE-401" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/09/GHSA-4mf4-j3m9-h786/GHSA-4mf4-j3m9-h786.json b/advisories/unreviewed/2022/09/GHSA-4mf4-j3m9-h786/GHSA-4mf4-j3m9-h786.json index 912530db830..1b0037bceea 100644 --- a/advisories/unreviewed/2022/09/GHSA-4mf4-j3m9-h786/GHSA-4mf4-j3m9-h786.json +++ b/advisories/unreviewed/2022/09/GHSA-4mf4-j3m9-h786/GHSA-4mf4-j3m9-h786.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/09/GHSA-5993-g4g9-vmxq/GHSA-5993-g4g9-vmxq.json b/advisories/unreviewed/2022/09/GHSA-5993-g4g9-vmxq/GHSA-5993-g4g9-vmxq.json index b87692fcac1..9d2f89082d8 100644 --- a/advisories/unreviewed/2022/09/GHSA-5993-g4g9-vmxq/GHSA-5993-g4g9-vmxq.json +++ b/advisories/unreviewed/2022/09/GHSA-5993-g4g9-vmxq/GHSA-5993-g4g9-vmxq.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-294" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-5vfq-rv44-c5ff/GHSA-5vfq-rv44-c5ff.json b/advisories/unreviewed/2022/09/GHSA-5vfq-rv44-c5ff/GHSA-5vfq-rv44-c5ff.json index 8ff42281c50..6b38acdde20 100644 --- a/advisories/unreviewed/2022/09/GHSA-5vfq-rv44-c5ff/GHSA-5vfq-rv44-c5ff.json +++ b/advisories/unreviewed/2022/09/GHSA-5vfq-rv44-c5ff/GHSA-5vfq-rv44-c5ff.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5vfq-rv44-c5ff", - "modified": "2022-09-25T00:00:20Z", + "modified": "2025-05-28T18:33:05Z", "published": "2022-09-22T00:00:32Z", "aliases": [ "CVE-2022-38177" @@ -27,6 +27,18 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2022/10/msg00007.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CV4GQWBPF7Y52J2FA24U6UMHQAOXZEF7" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MRHB6J4Z7BKH4HPEKG5D35QGRD6ANNMT" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YZJQNUASODNVAWZV6STKG5SD6XIJ446S" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CV4GQWBPF7Y52J2FA24U6UMHQAOXZEF7" @@ -58,7 +70,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-347" + "CWE-347", + "CWE-401" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/09/GHSA-63xv-5555-rrjh/GHSA-63xv-5555-rrjh.json b/advisories/unreviewed/2022/09/GHSA-63xv-5555-rrjh/GHSA-63xv-5555-rrjh.json index 4081b02c369..87b7b18116c 100644 --- a/advisories/unreviewed/2022/09/GHSA-63xv-5555-rrjh/GHSA-63xv-5555-rrjh.json +++ b/advisories/unreviewed/2022/09/GHSA-63xv-5555-rrjh/GHSA-63xv-5555-rrjh.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-693" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-7qp8-gff7-3q94/GHSA-7qp8-gff7-3q94.json b/advisories/unreviewed/2022/09/GHSA-7qp8-gff7-3q94/GHSA-7qp8-gff7-3q94.json index 98f22267323..67944a05cba 100644 --- a/advisories/unreviewed/2022/09/GHSA-7qp8-gff7-3q94/GHSA-7qp8-gff7-3q94.json +++ b/advisories/unreviewed/2022/09/GHSA-7qp8-gff7-3q94/GHSA-7qp8-gff7-3q94.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-9g62-7rj3-h7w2/GHSA-9g62-7rj3-h7w2.json b/advisories/unreviewed/2022/09/GHSA-9g62-7rj3-h7w2/GHSA-9g62-7rj3-h7w2.json index aabb71197cb..19319261e59 100644 --- a/advisories/unreviewed/2022/09/GHSA-9g62-7rj3-h7w2/GHSA-9g62-7rj3-h7w2.json +++ b/advisories/unreviewed/2022/09/GHSA-9g62-7rj3-h7w2/GHSA-9g62-7rj3-h7w2.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-125" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/09/GHSA-9p8r-gmq2-69cr/GHSA-9p8r-gmq2-69cr.json b/advisories/unreviewed/2022/09/GHSA-9p8r-gmq2-69cr/GHSA-9p8r-gmq2-69cr.json index 10e1fd4fafc..6ece485a1f9 100644 --- a/advisories/unreviewed/2022/09/GHSA-9p8r-gmq2-69cr/GHSA-9p8r-gmq2-69cr.json +++ b/advisories/unreviewed/2022/09/GHSA-9p8r-gmq2-69cr/GHSA-9p8r-gmq2-69cr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-78" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-9vhf-78v4-49cq/GHSA-9vhf-78v4-49cq.json b/advisories/unreviewed/2022/09/GHSA-9vhf-78v4-49cq/GHSA-9vhf-78v4-49cq.json index 591b88013e9..b24ab34d809 100644 --- a/advisories/unreviewed/2022/09/GHSA-9vhf-78v4-49cq/GHSA-9vhf-78v4-49cq.json +++ b/advisories/unreviewed/2022/09/GHSA-9vhf-78v4-49cq/GHSA-9vhf-78v4-49cq.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/09/GHSA-f2cm-pc3v-mjrg/GHSA-f2cm-pc3v-mjrg.json b/advisories/unreviewed/2022/09/GHSA-f2cm-pc3v-mjrg/GHSA-f2cm-pc3v-mjrg.json index 9d1d30ae4d3..e79790ba411 100644 --- a/advisories/unreviewed/2022/09/GHSA-f2cm-pc3v-mjrg/GHSA-f2cm-pc3v-mjrg.json +++ b/advisories/unreviewed/2022/09/GHSA-f2cm-pc3v-mjrg/GHSA-f2cm-pc3v-mjrg.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-693" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-frxw-cc6c-jg2m/GHSA-frxw-cc6c-jg2m.json b/advisories/unreviewed/2022/09/GHSA-frxw-cc6c-jg2m/GHSA-frxw-cc6c-jg2m.json index e93359e5322..58db8dbbb1d 100644 --- a/advisories/unreviewed/2022/09/GHSA-frxw-cc6c-jg2m/GHSA-frxw-cc6c-jg2m.json +++ b/advisories/unreviewed/2022/09/GHSA-frxw-cc6c-jg2m/GHSA-frxw-cc6c-jg2m.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-77" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-jfpq-w2g4-wcpm/GHSA-jfpq-w2g4-wcpm.json b/advisories/unreviewed/2022/09/GHSA-jfpq-w2g4-wcpm/GHSA-jfpq-w2g4-wcpm.json index ac732cc79f3..534e7d04212 100644 --- a/advisories/unreviewed/2022/09/GHSA-jfpq-w2g4-wcpm/GHSA-jfpq-w2g4-wcpm.json +++ b/advisories/unreviewed/2022/09/GHSA-jfpq-w2g4-wcpm/GHSA-jfpq-w2g4-wcpm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jfpq-w2g4-wcpm", - "modified": "2022-09-23T00:00:35Z", + "modified": "2025-05-28T18:33:05Z", "published": "2022-09-22T00:00:32Z", "aliases": [ "CVE-2022-41222" diff --git a/advisories/unreviewed/2022/09/GHSA-jp9x-px2h-j57p/GHSA-jp9x-px2h-j57p.json b/advisories/unreviewed/2022/09/GHSA-jp9x-px2h-j57p/GHSA-jp9x-px2h-j57p.json index 1a3922ee342..cf134e3852e 100644 --- a/advisories/unreviewed/2022/09/GHSA-jp9x-px2h-j57p/GHSA-jp9x-px2h-j57p.json +++ b/advisories/unreviewed/2022/09/GHSA-jp9x-px2h-j57p/GHSA-jp9x-px2h-j57p.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-m2rw-gwp5-6wqw/GHSA-m2rw-gwp5-6wqw.json b/advisories/unreviewed/2022/09/GHSA-m2rw-gwp5-6wqw/GHSA-m2rw-gwp5-6wqw.json index 0593ac0defd..a3b80d21c1e 100644 --- a/advisories/unreviewed/2022/09/GHSA-m2rw-gwp5-6wqw/GHSA-m2rw-gwp5-6wqw.json +++ b/advisories/unreviewed/2022/09/GHSA-m2rw-gwp5-6wqw/GHSA-m2rw-gwp5-6wqw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m2rw-gwp5-6wqw", - "modified": "2022-09-23T00:00:41Z", + "modified": "2025-05-28T18:32:59Z", "published": "2022-09-21T00:00:38Z", "aliases": [ "CVE-2022-38955" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-38955" }, + { + "type": "WEB", + "url": "https://hackmd.io/%40eupX2KdkT6iNpqJUWk9p4A/SyAnOSd1s" + }, { "type": "WEB", "url": "https://hackmd.io/@eupX2KdkT6iNpqJUWk9p4A/SyAnOSd1s" diff --git a/advisories/unreviewed/2022/09/GHSA-q925-4hvg-j5pg/GHSA-q925-4hvg-j5pg.json b/advisories/unreviewed/2022/09/GHSA-q925-4hvg-j5pg/GHSA-q925-4hvg-j5pg.json index 92900077d72..3fd11dbfff7 100644 --- a/advisories/unreviewed/2022/09/GHSA-q925-4hvg-j5pg/GHSA-q925-4hvg-j5pg.json +++ b/advisories/unreviewed/2022/09/GHSA-q925-4hvg-j5pg/GHSA-q925-4hvg-j5pg.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-77" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-qgj3-jh2x-36gf/GHSA-qgj3-jh2x-36gf.json b/advisories/unreviewed/2022/09/GHSA-qgj3-jh2x-36gf/GHSA-qgj3-jh2x-36gf.json index 3ae478cd1fe..54161bc407e 100644 --- a/advisories/unreviewed/2022/09/GHSA-qgj3-jh2x-36gf/GHSA-qgj3-jh2x-36gf.json +++ b/advisories/unreviewed/2022/09/GHSA-qgj3-jh2x-36gf/GHSA-qgj3-jh2x-36gf.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-78" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-qrm9-295f-xg65/GHSA-qrm9-295f-xg65.json b/advisories/unreviewed/2022/09/GHSA-qrm9-295f-xg65/GHSA-qrm9-295f-xg65.json index cfbf07a0bed..c8fb6e93814 100644 --- a/advisories/unreviewed/2022/09/GHSA-qrm9-295f-xg65/GHSA-qrm9-295f-xg65.json +++ b/advisories/unreviewed/2022/09/GHSA-qrm9-295f-xg65/GHSA-qrm9-295f-xg65.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qrm9-295f-xg65", - "modified": "2022-09-23T00:00:41Z", + "modified": "2025-05-28T18:32:59Z", "published": "2022-09-21T00:00:38Z", "aliases": [ "CVE-2022-38956" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-38956" }, + { + "type": "WEB", + "url": "https://hackmd.io/%40eupX2KdkT6iNpqJUWk9p4A/SyAnOSd1s" + }, { "type": "WEB", "url": "https://hackmd.io/@eupX2KdkT6iNpqJUWk9p4A/SyAnOSd1s" diff --git a/advisories/unreviewed/2022/09/GHSA-x92w-hx54-ffh8/GHSA-x92w-hx54-ffh8.json b/advisories/unreviewed/2022/09/GHSA-x92w-hx54-ffh8/GHSA-x92w-hx54-ffh8.json index 1ef1d7f107c..e89309554fd 100644 --- a/advisories/unreviewed/2022/09/GHSA-x92w-hx54-ffh8/GHSA-x92w-hx54-ffh8.json +++ b/advisories/unreviewed/2022/09/GHSA-x92w-hx54-ffh8/GHSA-x92w-hx54-ffh8.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/12/GHSA-4f2h-j443-g993/GHSA-4f2h-j443-g993.json b/advisories/unreviewed/2023/12/GHSA-4f2h-j443-g993/GHSA-4f2h-j443-g993.json index bf1b47218a5..9507f9af03f 100644 --- a/advisories/unreviewed/2023/12/GHSA-4f2h-j443-g993/GHSA-4f2h-j443-g993.json +++ b/advisories/unreviewed/2023/12/GHSA-4f2h-j443-g993/GHSA-4f2h-j443-g993.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4f2h-j443-g993", - "modified": "2023-12-09T06:30:20Z", + "modified": "2025-05-28T18:33:06Z", "published": "2023-12-07T09:30:44Z", "aliases": [ "CVE-2023-48834" diff --git a/advisories/unreviewed/2023/12/GHSA-7mp8-w7v3-999f/GHSA-7mp8-w7v3-999f.json b/advisories/unreviewed/2023/12/GHSA-7mp8-w7v3-999f/GHSA-7mp8-w7v3-999f.json index aaaaafc3ad5..591ef0a3ffe 100644 --- a/advisories/unreviewed/2023/12/GHSA-7mp8-w7v3-999f/GHSA-7mp8-w7v3-999f.json +++ b/advisories/unreviewed/2023/12/GHSA-7mp8-w7v3-999f/GHSA-7mp8-w7v3-999f.json @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-838" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/12/GHSA-8cxm-wrjw-f6qw/GHSA-8cxm-wrjw-f6qw.json b/advisories/unreviewed/2023/12/GHSA-8cxm-wrjw-f6qw/GHSA-8cxm-wrjw-f6qw.json index 5276ad0f4cd..2d0c05fba38 100644 --- a/advisories/unreviewed/2023/12/GHSA-8cxm-wrjw-f6qw/GHSA-8cxm-wrjw-f6qw.json +++ b/advisories/unreviewed/2023/12/GHSA-8cxm-wrjw-f6qw/GHSA-8cxm-wrjw-f6qw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8cxm-wrjw-f6qw", - "modified": "2023-12-12T18:31:31Z", + "modified": "2025-05-28T18:33:05Z", "published": "2023-12-06T09:30:17Z", "aliases": [ "CVE-2023-49246" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/12/GHSA-hj36-mw8h-wwjc/GHSA-hj36-mw8h-wwjc.json b/advisories/unreviewed/2023/12/GHSA-hj36-mw8h-wwjc/GHSA-hj36-mw8h-wwjc.json index 1711306bc70..069f9e86d05 100644 --- a/advisories/unreviewed/2023/12/GHSA-hj36-mw8h-wwjc/GHSA-hj36-mw8h-wwjc.json +++ b/advisories/unreviewed/2023/12/GHSA-hj36-mw8h-wwjc/GHSA-hj36-mw8h-wwjc.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-290" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/12/GHSA-wj8f-78wg-52vw/GHSA-wj8f-78wg-52vw.json b/advisories/unreviewed/2023/12/GHSA-wj8f-78wg-52vw/GHSA-wj8f-78wg-52vw.json index 2e396a227e2..45cb51ffbcb 100644 --- a/advisories/unreviewed/2023/12/GHSA-wj8f-78wg-52vw/GHSA-wj8f-78wg-52vw.json +++ b/advisories/unreviewed/2023/12/GHSA-wj8f-78wg-52vw/GHSA-wj8f-78wg-52vw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wj8f-78wg-52vw", - "modified": "2023-12-11T18:30:31Z", + "modified": "2025-05-28T18:33:05Z", "published": "2023-12-06T09:30:17Z", "aliases": [ "CVE-2023-45210" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-f74m-5p64-49qj/GHSA-f74m-5p64-49qj.json b/advisories/unreviewed/2025/01/GHSA-f74m-5p64-49qj/GHSA-f74m-5p64-49qj.json index 6cafbc0f027..21f94ae930e 100644 --- a/advisories/unreviewed/2025/01/GHSA-f74m-5p64-49qj/GHSA-f74m-5p64-49qj.json +++ b/advisories/unreviewed/2025/01/GHSA-f74m-5p64-49qj/GHSA-f74m-5p64-49qj.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-2f98-4x2w-23pw/GHSA-2f98-4x2w-23pw.json b/advisories/unreviewed/2025/03/GHSA-2f98-4x2w-23pw/GHSA-2f98-4x2w-23pw.json index 3c6767f17b1..3b1cfa9e5b1 100644 --- a/advisories/unreviewed/2025/03/GHSA-2f98-4x2w-23pw/GHSA-2f98-4x2w-23pw.json +++ b/advisories/unreviewed/2025/03/GHSA-2f98-4x2w-23pw/GHSA-2f98-4x2w-23pw.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-77" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-76vw-8gm2-pwmh/GHSA-76vw-8gm2-pwmh.json b/advisories/unreviewed/2025/03/GHSA-76vw-8gm2-pwmh/GHSA-76vw-8gm2-pwmh.json index 4460f9d53b6..76b2925a48f 100644 --- a/advisories/unreviewed/2025/03/GHSA-76vw-8gm2-pwmh/GHSA-76vw-8gm2-pwmh.json +++ b/advisories/unreviewed/2025/03/GHSA-76vw-8gm2-pwmh/GHSA-76vw-8gm2-pwmh.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-76x3-9rqr-2g63/GHSA-76x3-9rqr-2g63.json b/advisories/unreviewed/2025/03/GHSA-76x3-9rqr-2g63/GHSA-76x3-9rqr-2g63.json index cece2ddddb6..e73931ae804 100644 --- a/advisories/unreviewed/2025/03/GHSA-76x3-9rqr-2g63/GHSA-76x3-9rqr-2g63.json +++ b/advisories/unreviewed/2025/03/GHSA-76x3-9rqr-2g63/GHSA-76x3-9rqr-2g63.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-qxwf-xj2v-qm83/GHSA-qxwf-xj2v-qm83.json b/advisories/unreviewed/2025/03/GHSA-qxwf-xj2v-qm83/GHSA-qxwf-xj2v-qm83.json index 790f013d833..f4d8759ccce 100644 --- a/advisories/unreviewed/2025/03/GHSA-qxwf-xj2v-qm83/GHSA-qxwf-xj2v-qm83.json +++ b/advisories/unreviewed/2025/03/GHSA-qxwf-xj2v-qm83/GHSA-qxwf-xj2v-qm83.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-rrc2-m8v6-jh7q/GHSA-rrc2-m8v6-jh7q.json b/advisories/unreviewed/2025/03/GHSA-rrc2-m8v6-jh7q/GHSA-rrc2-m8v6-jh7q.json index c06a80ced58..90cd78254a0 100644 --- a/advisories/unreviewed/2025/03/GHSA-rrc2-m8v6-jh7q/GHSA-rrc2-m8v6-jh7q.json +++ b/advisories/unreviewed/2025/03/GHSA-rrc2-m8v6-jh7q/GHSA-rrc2-m8v6-jh7q.json @@ -50,7 +50,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-vr2r-rp8h-3j86/GHSA-vr2r-rp8h-3j86.json b/advisories/unreviewed/2025/03/GHSA-vr2r-rp8h-3j86/GHSA-vr2r-rp8h-3j86.json index 9a390178076..8411b182fd7 100644 --- a/advisories/unreviewed/2025/03/GHSA-vr2r-rp8h-3j86/GHSA-vr2r-rp8h-3j86.json +++ b/advisories/unreviewed/2025/03/GHSA-vr2r-rp8h-3j86/GHSA-vr2r-rp8h-3j86.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-w9wx-xm8x-jhqq/GHSA-w9wx-xm8x-jhqq.json b/advisories/unreviewed/2025/03/GHSA-w9wx-xm8x-jhqq/GHSA-w9wx-xm8x-jhqq.json index d4105b8e06a..65afa00e196 100644 --- a/advisories/unreviewed/2025/03/GHSA-w9wx-xm8x-jhqq/GHSA-w9wx-xm8x-jhqq.json +++ b/advisories/unreviewed/2025/03/GHSA-w9wx-xm8x-jhqq/GHSA-w9wx-xm8x-jhqq.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-8c9q-c5r4-q67m/GHSA-8c9q-c5r4-q67m.json b/advisories/unreviewed/2025/04/GHSA-8c9q-c5r4-q67m/GHSA-8c9q-c5r4-q67m.json index ab3d86631b9..17cc1179c1d 100644 --- a/advisories/unreviewed/2025/04/GHSA-8c9q-c5r4-q67m/GHSA-8c9q-c5r4-q67m.json +++ b/advisories/unreviewed/2025/04/GHSA-8c9q-c5r4-q67m/GHSA-8c9q-c5r4-q67m.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-995j-2jcg-pg6h/GHSA-995j-2jcg-pg6h.json b/advisories/unreviewed/2025/04/GHSA-995j-2jcg-pg6h/GHSA-995j-2jcg-pg6h.json index a07929a3acc..cb91625625a 100644 --- a/advisories/unreviewed/2025/04/GHSA-995j-2jcg-pg6h/GHSA-995j-2jcg-pg6h.json +++ b/advisories/unreviewed/2025/04/GHSA-995j-2jcg-pg6h/GHSA-995j-2jcg-pg6h.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-9cp2-r8w6-r4vm/GHSA-9cp2-r8w6-r4vm.json b/advisories/unreviewed/2025/04/GHSA-9cp2-r8w6-r4vm/GHSA-9cp2-r8w6-r4vm.json index 978b04c8cc9..cef08a08834 100644 --- a/advisories/unreviewed/2025/04/GHSA-9cp2-r8w6-r4vm/GHSA-9cp2-r8w6-r4vm.json +++ b/advisories/unreviewed/2025/04/GHSA-9cp2-r8w6-r4vm/GHSA-9cp2-r8w6-r4vm.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-ffc2-m4f8-5m2g/GHSA-ffc2-m4f8-5m2g.json b/advisories/unreviewed/2025/04/GHSA-ffc2-m4f8-5m2g/GHSA-ffc2-m4f8-5m2g.json index 90dd3d249b0..de2d096ed41 100644 --- a/advisories/unreviewed/2025/04/GHSA-ffc2-m4f8-5m2g/GHSA-ffc2-m4f8-5m2g.json +++ b/advisories/unreviewed/2025/04/GHSA-ffc2-m4f8-5m2g/GHSA-ffc2-m4f8-5m2g.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-h4g8-pvpv-p57j/GHSA-h4g8-pvpv-p57j.json b/advisories/unreviewed/2025/04/GHSA-h4g8-pvpv-p57j/GHSA-h4g8-pvpv-p57j.json index dba80a882ae..cd35b76b034 100644 --- a/advisories/unreviewed/2025/04/GHSA-h4g8-pvpv-p57j/GHSA-h4g8-pvpv-p57j.json +++ b/advisories/unreviewed/2025/04/GHSA-h4g8-pvpv-p57j/GHSA-h4g8-pvpv-p57j.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-hq28-6c72-q4fg/GHSA-hq28-6c72-q4fg.json b/advisories/unreviewed/2025/04/GHSA-hq28-6c72-q4fg/GHSA-hq28-6c72-q4fg.json index e5511b4ce46..b890392293b 100644 --- a/advisories/unreviewed/2025/04/GHSA-hq28-6c72-q4fg/GHSA-hq28-6c72-q4fg.json +++ b/advisories/unreviewed/2025/04/GHSA-hq28-6c72-q4fg/GHSA-hq28-6c72-q4fg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hq28-6c72-q4fg", - "modified": "2025-04-17T12:30:33Z", + "modified": "2025-05-28T18:33:16Z", "published": "2025-04-17T12:30:33Z", "aliases": [ "CVE-2025-3487" diff --git a/advisories/unreviewed/2025/04/GHSA-jvjx-8r65-mrp9/GHSA-jvjx-8r65-mrp9.json b/advisories/unreviewed/2025/04/GHSA-jvjx-8r65-mrp9/GHSA-jvjx-8r65-mrp9.json index 91ff449c46f..d11912f5a20 100644 --- a/advisories/unreviewed/2025/04/GHSA-jvjx-8r65-mrp9/GHSA-jvjx-8r65-mrp9.json +++ b/advisories/unreviewed/2025/04/GHSA-jvjx-8r65-mrp9/GHSA-jvjx-8r65-mrp9.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-p6jq-9gcc-mcvx/GHSA-p6jq-9gcc-mcvx.json b/advisories/unreviewed/2025/04/GHSA-p6jq-9gcc-mcvx/GHSA-p6jq-9gcc-mcvx.json index 8aabe49207c..d119abf7538 100644 --- a/advisories/unreviewed/2025/04/GHSA-p6jq-9gcc-mcvx/GHSA-p6jq-9gcc-mcvx.json +++ b/advisories/unreviewed/2025/04/GHSA-p6jq-9gcc-mcvx/GHSA-p6jq-9gcc-mcvx.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-1333" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-p9vw-vmhm-c984/GHSA-p9vw-vmhm-c984.json b/advisories/unreviewed/2025/04/GHSA-p9vw-vmhm-c984/GHSA-p9vw-vmhm-c984.json index c551a150d86..00e6b957d24 100644 --- a/advisories/unreviewed/2025/04/GHSA-p9vw-vmhm-c984/GHSA-p9vw-vmhm-c984.json +++ b/advisories/unreviewed/2025/04/GHSA-p9vw-vmhm-c984/GHSA-p9vw-vmhm-c984.json @@ -50,7 +50,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-434" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-r37f-v2p6-x6cx/GHSA-r37f-v2p6-x6cx.json b/advisories/unreviewed/2025/04/GHSA-r37f-v2p6-x6cx/GHSA-r37f-v2p6-x6cx.json index ea4d3904c4c..4ca79cae350 100644 --- a/advisories/unreviewed/2025/04/GHSA-r37f-v2p6-x6cx/GHSA-r37f-v2p6-x6cx.json +++ b/advisories/unreviewed/2025/04/GHSA-r37f-v2p6-x6cx/GHSA-r37f-v2p6-x6cx.json @@ -54,7 +54,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-2954-4rrv-2pfp/GHSA-2954-4rrv-2pfp.json b/advisories/unreviewed/2025/05/GHSA-2954-4rrv-2pfp/GHSA-2954-4rrv-2pfp.json index 915442f505f..de272659a19 100644 --- a/advisories/unreviewed/2025/05/GHSA-2954-4rrv-2pfp/GHSA-2954-4rrv-2pfp.json +++ b/advisories/unreviewed/2025/05/GHSA-2954-4rrv-2pfp/GHSA-2954-4rrv-2pfp.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-2fcj-g7j8-pg57/GHSA-2fcj-g7j8-pg57.json b/advisories/unreviewed/2025/05/GHSA-2fcj-g7j8-pg57/GHSA-2fcj-g7j8-pg57.json new file mode 100644 index 00000000000..5edc710e68f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2fcj-g7j8-pg57/GHSA-2fcj-g7j8-pg57.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2fcj-g7j8-pg57", + "modified": "2025-05-28T18:33:27Z", + "published": "2025-05-28T18:33:27Z", + "aliases": [ + "CVE-2024-51453" + ], + "details": "IBM Sterling Secure Proxy 6.2.0.0 through 6.2.0.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing \"dot dot\" sequences (/../) to view arbitrary files on the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51453" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7234887" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T16:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2jfq-9qf9-jmjj/GHSA-2jfq-9qf9-jmjj.json b/advisories/unreviewed/2025/05/GHSA-2jfq-9qf9-jmjj/GHSA-2jfq-9qf9-jmjj.json new file mode 100644 index 00000000000..7f0b7ddfff7 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2jfq-9qf9-jmjj/GHSA-2jfq-9qf9-jmjj.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2jfq-9qf9-jmjj", + "modified": "2025-05-28T18:33:29Z", + "published": "2025-05-28T18:33:29Z", + "aliases": [ + "CVE-2025-30087" + ], + "details": "Best Practical RT (Request Tracker) 4.4 through 4.4.7 and 5.0 through 5.0.7 allows XSS via injection of crafted parameters in a search URL.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30087" + }, + { + "type": "WEB", + "url": "https://docs.bestpractical.com/release-notes/rt/4.4.8" + }, + { + "type": "WEB", + "url": "https://docs.bestpractical.com/release-notes/rt/5.0.8" + }, + { + "type": "WEB", + "url": "https://docs.bestpractical.com/release-notes/rt/index.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T18:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2qrm-36rr-ffj3/GHSA-2qrm-36rr-ffj3.json b/advisories/unreviewed/2025/05/GHSA-2qrm-36rr-ffj3/GHSA-2qrm-36rr-ffj3.json index 4aa90bdf0ca..49a3850e2ed 100644 --- a/advisories/unreviewed/2025/05/GHSA-2qrm-36rr-ffj3/GHSA-2qrm-36rr-ffj3.json +++ b/advisories/unreviewed/2025/05/GHSA-2qrm-36rr-ffj3/GHSA-2qrm-36rr-ffj3.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-2v5h-r74h-52p7/GHSA-2v5h-r74h-52p7.json b/advisories/unreviewed/2025/05/GHSA-2v5h-r74h-52p7/GHSA-2v5h-r74h-52p7.json index 518897babd5..b8df0561b1d 100644 --- a/advisories/unreviewed/2025/05/GHSA-2v5h-r74h-52p7/GHSA-2v5h-r74h-52p7.json +++ b/advisories/unreviewed/2025/05/GHSA-2v5h-r74h-52p7/GHSA-2v5h-r74h-52p7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2v5h-r74h-52p7", - "modified": "2025-05-26T21:30:31Z", + "modified": "2025-05-28T18:33:27Z", "published": "2025-05-26T21:30:31Z", "aliases": [ "CVE-2025-5201" @@ -31,6 +31,10 @@ "type": "WEB", "url": "https://github.com/assimp/assimp/issues/6173" }, + { + "type": "WEB", + "url": "https://github.com/assimp/assimp/issues/6174" + }, { "type": "WEB", "url": "https://github.com/user-attachments/files/20209125/line-832-reproducer.zip" diff --git a/advisories/unreviewed/2025/05/GHSA-33cx-2vvq-mf52/GHSA-33cx-2vvq-mf52.json b/advisories/unreviewed/2025/05/GHSA-33cx-2vvq-mf52/GHSA-33cx-2vvq-mf52.json index ce42106cadc..3dbdbc879af 100644 --- a/advisories/unreviewed/2025/05/GHSA-33cx-2vvq-mf52/GHSA-33cx-2vvq-mf52.json +++ b/advisories/unreviewed/2025/05/GHSA-33cx-2vvq-mf52/GHSA-33cx-2vvq-mf52.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-33cx-2vvq-mf52", - "modified": "2025-05-05T12:30:34Z", + "modified": "2025-05-28T18:33:18Z", "published": "2025-05-05T12:30:34Z", "aliases": [ "CVE-2025-2545" @@ -19,6 +19,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2545" }, + { + "type": "WEB", + "url": "https://docs.bestpractical.com/release-notes/rt/4.4.8" + }, + { + "type": "WEB", + "url": "https://docs.bestpractical.com/release-notes/rt/5.0.8" + }, { "type": "WEB", "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/cryptographic-algorithm-not-recommended-request-tracker-best-practical" diff --git a/advisories/unreviewed/2025/05/GHSA-3p76-4rrp-wwv9/GHSA-3p76-4rrp-wwv9.json b/advisories/unreviewed/2025/05/GHSA-3p76-4rrp-wwv9/GHSA-3p76-4rrp-wwv9.json new file mode 100644 index 00000000000..a4bad9311fa --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3p76-4rrp-wwv9/GHSA-3p76-4rrp-wwv9.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3p76-4rrp-wwv9", + "modified": "2025-05-28T18:33:28Z", + "published": "2025-05-28T18:33:28Z", + "aliases": [ + "CVE-2022-27876" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-27876" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T18:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-45pv-3wg3-68gv/GHSA-45pv-3wg3-68gv.json b/advisories/unreviewed/2025/05/GHSA-45pv-3wg3-68gv/GHSA-45pv-3wg3-68gv.json new file mode 100644 index 00000000000..c1faa239e5e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-45pv-3wg3-68gv/GHSA-45pv-3wg3-68gv.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-45pv-3wg3-68gv", + "modified": "2025-05-28T18:33:29Z", + "published": "2025-05-28T18:33:29Z", + "aliases": [ + "CVE-2022-33893" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-33893" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T18:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4hwf-mgvq-g226/GHSA-4hwf-mgvq-g226.json b/advisories/unreviewed/2025/05/GHSA-4hwf-mgvq-g226/GHSA-4hwf-mgvq-g226.json new file mode 100644 index 00000000000..f63b4d43ff2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4hwf-mgvq-g226/GHSA-4hwf-mgvq-g226.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4hwf-mgvq-g226", + "modified": "2025-05-28T18:33:28Z", + "published": "2025-05-28T18:33:28Z", + "aliases": [ + "CVE-2022-29924" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-29924" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T18:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-54mq-99qq-7hr5/GHSA-54mq-99qq-7hr5.json b/advisories/unreviewed/2025/05/GHSA-54mq-99qq-7hr5/GHSA-54mq-99qq-7hr5.json new file mode 100644 index 00000000000..094ea199e40 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-54mq-99qq-7hr5/GHSA-54mq-99qq-7hr5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-54mq-99qq-7hr5", + "modified": "2025-05-28T18:33:28Z", + "published": "2025-05-28T18:33:28Z", + "aliases": [ + "CVE-2025-48928" + ], + "details": "The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a \"core dump\" in which a password previously sent over HTTP would be included in this dump, as exploited in the wild in May 2025.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48928" + }, + { + "type": "WEB", + "url": "https://www.wired.com/story/how-the-signal-knock-off-app-telemessage-got-hacked-in-20-minutes" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-528" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T17:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5wx3-hjmf-qcgx/GHSA-5wx3-hjmf-qcgx.json b/advisories/unreviewed/2025/05/GHSA-5wx3-hjmf-qcgx/GHSA-5wx3-hjmf-qcgx.json new file mode 100644 index 00000000000..964b276860c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5wx3-hjmf-qcgx/GHSA-5wx3-hjmf-qcgx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5wx3-hjmf-qcgx", + "modified": "2025-05-28T18:33:28Z", + "published": "2025-05-28T18:33:28Z", + "aliases": [ + "CVE-2025-48929" + ], + "details": "The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token with a short expiration time) that can be reused at a later date if discovered by an adversary, as exploited in the wild in May 2025.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48929" + }, + { + "type": "WEB", + "url": "https://www.wired.com/story/how-the-signal-knock-off-app-telemessage-got-hacked-in-20-minutes" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-922" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T17:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7374-5865-cjhh/GHSA-7374-5865-cjhh.json b/advisories/unreviewed/2025/05/GHSA-7374-5865-cjhh/GHSA-7374-5865-cjhh.json new file mode 100644 index 00000000000..071ecd44161 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7374-5865-cjhh/GHSA-7374-5865-cjhh.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7374-5865-cjhh", + "modified": "2025-05-28T18:33:29Z", + "published": "2025-05-28T18:33:29Z", + "aliases": [ + "CVE-2022-34860" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-34860" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T18:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-764c-3vwj-x87m/GHSA-764c-3vwj-x87m.json b/advisories/unreviewed/2025/05/GHSA-764c-3vwj-x87m/GHSA-764c-3vwj-x87m.json index 566be282812..e616090753a 100644 --- a/advisories/unreviewed/2025/05/GHSA-764c-3vwj-x87m/GHSA-764c-3vwj-x87m.json +++ b/advisories/unreviewed/2025/05/GHSA-764c-3vwj-x87m/GHSA-764c-3vwj-x87m.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-76w2-jhhw-cjjj/GHSA-76w2-jhhw-cjjj.json b/advisories/unreviewed/2025/05/GHSA-76w2-jhhw-cjjj/GHSA-76w2-jhhw-cjjj.json new file mode 100644 index 00000000000..baa839041c5 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-76w2-jhhw-cjjj/GHSA-76w2-jhhw-cjjj.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-76w2-jhhw-cjjj", + "modified": "2025-05-28T18:33:29Z", + "published": "2025-05-28T18:33:29Z", + "aliases": [ + "CVE-2025-31500" + ], + "details": "Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an Asset name.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31500" + }, + { + "type": "WEB", + "url": "https://docs.bestpractical.com/release-notes/rt/5.0.8" + }, + { + "type": "WEB", + "url": "https://docs.bestpractical.com/release-notes/rt/index.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T18:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7xpv-834v-x9rj/GHSA-7xpv-834v-x9rj.json b/advisories/unreviewed/2025/05/GHSA-7xpv-834v-x9rj/GHSA-7xpv-834v-x9rj.json new file mode 100644 index 00000000000..78d00278093 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7xpv-834v-x9rj/GHSA-7xpv-834v-x9rj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7xpv-834v-x9rj", + "modified": "2025-05-28T18:33:27Z", + "published": "2025-05-28T18:33:27Z", + "aliases": [ + "CVE-2024-38341" + ], + "details": "IBM Sterling Secure Proxy 6.0.0.0 through 6.0.3.1, 6.1.0.0 through 6.1.0.0, and 6.2.0.0 through 6.2.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38341" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7234888" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-328" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T16:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-89wf-mr2w-22xh/GHSA-89wf-mr2w-22xh.json b/advisories/unreviewed/2025/05/GHSA-89wf-mr2w-22xh/GHSA-89wf-mr2w-22xh.json index 4a111ad0797..a475d5e7c68 100644 --- a/advisories/unreviewed/2025/05/GHSA-89wf-mr2w-22xh/GHSA-89wf-mr2w-22xh.json +++ b/advisories/unreviewed/2025/05/GHSA-89wf-mr2w-22xh/GHSA-89wf-mr2w-22xh.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-8mq9-3232-xxrj/GHSA-8mq9-3232-xxrj.json b/advisories/unreviewed/2025/05/GHSA-8mq9-3232-xxrj/GHSA-8mq9-3232-xxrj.json new file mode 100644 index 00000000000..fe79cc489b0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8mq9-3232-xxrj/GHSA-8mq9-3232-xxrj.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8mq9-3232-xxrj", + "modified": "2025-05-28T18:33:29Z", + "published": "2025-05-28T18:33:29Z", + "aliases": [ + "CVE-2022-43502" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43502" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T18:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8q85-7q4r-xhgc/GHSA-8q85-7q4r-xhgc.json b/advisories/unreviewed/2025/05/GHSA-8q85-7q4r-xhgc/GHSA-8q85-7q4r-xhgc.json new file mode 100644 index 00000000000..1c97451a117 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8q85-7q4r-xhgc/GHSA-8q85-7q4r-xhgc.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8q85-7q4r-xhgc", + "modified": "2025-05-28T18:33:27Z", + "published": "2025-05-28T18:33:27Z", + "aliases": [ + "CVE-2025-45343" + ], + "details": "An issue in Tenda W18E v.2.0 v.16.01.0.11 allows an attacker to execute arbitrary code via the editing functionality of the account module in the goform/setmodules route.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45343" + }, + { + "type": "WEB", + "url": "https://gist.github.com/isstabber/b363d47966965e5c0a8ec26d445e090b" + }, + { + "type": "WEB", + "url": "https://www.tenda.com.cn" + }, + { + "type": "WEB", + "url": "http://w18e.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T16:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8r5j-5vhh-wr82/GHSA-8r5j-5vhh-wr82.json b/advisories/unreviewed/2025/05/GHSA-8r5j-5vhh-wr82/GHSA-8r5j-5vhh-wr82.json index d70a52ef4f6..367e1c51778 100644 --- a/advisories/unreviewed/2025/05/GHSA-8r5j-5vhh-wr82/GHSA-8r5j-5vhh-wr82.json +++ b/advisories/unreviewed/2025/05/GHSA-8r5j-5vhh-wr82/GHSA-8r5j-5vhh-wr82.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-9j47-qv65-j87p/GHSA-9j47-qv65-j87p.json b/advisories/unreviewed/2025/05/GHSA-9j47-qv65-j87p/GHSA-9j47-qv65-j87p.json new file mode 100644 index 00000000000..5b7a3f4a0c5 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9j47-qv65-j87p/GHSA-9j47-qv65-j87p.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9j47-qv65-j87p", + "modified": "2025-05-28T18:33:30Z", + "published": "2025-05-28T18:33:29Z", + "aliases": [ + "CVE-2025-31501" + ], + "details": "Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an RT permalink.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31501" + }, + { + "type": "WEB", + "url": "https://docs.bestpractical.com/release-notes/rt/5.0.8" + }, + { + "type": "WEB", + "url": "https://docs.bestpractical.com/release-notes/rt/index.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T18:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9qww-jrc3-jf78/GHSA-9qww-jrc3-jf78.json b/advisories/unreviewed/2025/05/GHSA-9qww-jrc3-jf78/GHSA-9qww-jrc3-jf78.json new file mode 100644 index 00000000000..bd47e16693d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9qww-jrc3-jf78/GHSA-9qww-jrc3-jf78.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qww-jrc3-jf78", + "modified": "2025-05-28T18:33:29Z", + "published": "2025-05-28T18:33:29Z", + "aliases": [ + "CVE-2022-40970" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40970" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T18:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-cg63-5mwv-w273/GHSA-cg63-5mwv-w273.json b/advisories/unreviewed/2025/05/GHSA-cg63-5mwv-w273/GHSA-cg63-5mwv-w273.json new file mode 100644 index 00000000000..55baf5d3e68 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-cg63-5mwv-w273/GHSA-cg63-5mwv-w273.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cg63-5mwv-w273", + "modified": "2025-05-28T18:33:28Z", + "published": "2025-05-28T18:33:28Z", + "aliases": [ + "CVE-2022-26056" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-26056" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T17:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-cv2r-m5ph-vgj6/GHSA-cv2r-m5ph-vgj6.json b/advisories/unreviewed/2025/05/GHSA-cv2r-m5ph-vgj6/GHSA-cv2r-m5ph-vgj6.json new file mode 100644 index 00000000000..0d09b3421fb --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-cv2r-m5ph-vgj6/GHSA-cv2r-m5ph-vgj6.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cv2r-m5ph-vgj6", + "modified": "2025-05-28T18:33:28Z", + "published": "2025-05-28T18:33:28Z", + "aliases": [ + "CVE-2022-32233" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-32233" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T18:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-f2c5-m7v5-93g5/GHSA-f2c5-m7v5-93g5.json b/advisories/unreviewed/2025/05/GHSA-f2c5-m7v5-93g5/GHSA-f2c5-m7v5-93g5.json new file mode 100644 index 00000000000..e2697adecf6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-f2c5-m7v5-93g5/GHSA-f2c5-m7v5-93g5.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f2c5-m7v5-93g5", + "modified": "2025-05-28T18:33:29Z", + "published": "2025-05-28T18:33:29Z", + "aliases": [ + "CVE-2022-36406" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36406" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T18:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fg72-v8xw-hm7h/GHSA-fg72-v8xw-hm7h.json b/advisories/unreviewed/2025/05/GHSA-fg72-v8xw-hm7h/GHSA-fg72-v8xw-hm7h.json new file mode 100644 index 00000000000..d85d277eaa9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fg72-v8xw-hm7h/GHSA-fg72-v8xw-hm7h.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fg72-v8xw-hm7h", + "modified": "2025-05-28T18:33:28Z", + "published": "2025-05-28T18:33:28Z", + "aliases": [ + "CVE-2025-48746" + ], + "details": "Netwrix Directory Manager (formerly Imanami GroupID) v.11.0.0.0 and before, as well as after v.11.1.25134.03 lacks Authentication for a Critical Function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48746" + }, + { + "type": "WEB", + "url": "https://community.netwrix.com/t/adv-2025-014-critical-vulnerabilities-in-netwrix-directory-manager-formerly-imanami-groupid-v11/13951" + }, + { + "type": "WEB", + "url": "https://netwrix.com" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T17:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-frcx-58px-56g2/GHSA-frcx-58px-56g2.json b/advisories/unreviewed/2025/05/GHSA-frcx-58px-56g2/GHSA-frcx-58px-56g2.json new file mode 100644 index 00000000000..660009e24e4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-frcx-58px-56g2/GHSA-frcx-58px-56g2.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-frcx-58px-56g2", + "modified": "2025-05-28T18:33:28Z", + "published": "2025-05-28T18:33:27Z", + "aliases": [ + "CVE-2022-25909" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-25909" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T17:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g7m2-hjxw-27h7/GHSA-g7m2-hjxw-27h7.json b/advisories/unreviewed/2025/05/GHSA-g7m2-hjxw-27h7/GHSA-g7m2-hjxw-27h7.json new file mode 100644 index 00000000000..6054daccbac --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g7m2-hjxw-27h7/GHSA-g7m2-hjxw-27h7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g7m2-hjxw-27h7", + "modified": "2025-05-28T18:33:28Z", + "published": "2025-05-28T18:33:28Z", + "aliases": [ + "CVE-2025-48925" + ], + "details": "The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash as the authentication credential, as exploited in the wild in May 2025.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48925" + }, + { + "type": "WEB", + "url": "https://www.wired.com/story/how-the-signal-knock-off-app-telemessage-got-hacked-in-20-minutes" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-836" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T17:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hc7m-j4w7-pv6w/GHSA-hc7m-j4w7-pv6w.json b/advisories/unreviewed/2025/05/GHSA-hc7m-j4w7-pv6w/GHSA-hc7m-j4w7-pv6w.json new file mode 100644 index 00000000000..451e8f18939 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hc7m-j4w7-pv6w/GHSA-hc7m-j4w7-pv6w.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hc7m-j4w7-pv6w", + "modified": "2025-05-28T18:33:29Z", + "published": "2025-05-28T18:33:29Z", + "aliases": [ + "CVE-2024-57336" + ], + "details": "Incorrect access control in M2Soft CROWNIX Report & ERS affected v7.x to v7.4.3.599 and v8.x to v8.0.3.79 allows unauthorized attackers to obtain Administrator account access.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57336" + }, + { + "type": "WEB", + "url": "https://www.m2soft.co.kr/sub/board/news.asp?mode=view&idx=2411" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hv8v-455m-2grc/GHSA-hv8v-455m-2grc.json b/advisories/unreviewed/2025/05/GHSA-hv8v-455m-2grc/GHSA-hv8v-455m-2grc.json new file mode 100644 index 00000000000..489cd29db87 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hv8v-455m-2grc/GHSA-hv8v-455m-2grc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hv8v-455m-2grc", + "modified": "2025-05-28T18:33:28Z", + "published": "2025-05-28T18:33:28Z", + "aliases": [ + "CVE-2025-32801" + ], + "details": "Kea configuration and API directives can be used to load a malicious hook library. Many common configurations run Kea as root, leave the API entry points unsecured by default, and/or place the control sockets in insecure paths.\nThis issue affects Kea versions 2.4.0 through 2.4.1, 2.6.0 through 2.6.2, and 2.7.0 through 2.7.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32801" + }, + { + "type": "WEB", + "url": "https://kb.isc.org/docs/cve-2025-32801" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T17:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-j54f-6g32-3jwj/GHSA-j54f-6g32-3jwj.json b/advisories/unreviewed/2025/05/GHSA-j54f-6g32-3jwj/GHSA-j54f-6g32-3jwj.json index 9870264ed99..99f79f66090 100644 --- a/advisories/unreviewed/2025/05/GHSA-j54f-6g32-3jwj/GHSA-j54f-6g32-3jwj.json +++ b/advisories/unreviewed/2025/05/GHSA-j54f-6g32-3jwj/GHSA-j54f-6g32-3jwj.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-j95r-8c72-m59j/GHSA-j95r-8c72-m59j.json b/advisories/unreviewed/2025/05/GHSA-j95r-8c72-m59j/GHSA-j95r-8c72-m59j.json index 14b77fa17ac..a24f17f1dbc 100644 --- a/advisories/unreviewed/2025/05/GHSA-j95r-8c72-m59j/GHSA-j95r-8c72-m59j.json +++ b/advisories/unreviewed/2025/05/GHSA-j95r-8c72-m59j/GHSA-j95r-8c72-m59j.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-jxv9-h32m-39xj/GHSA-jxv9-h32m-39xj.json b/advisories/unreviewed/2025/05/GHSA-jxv9-h32m-39xj/GHSA-jxv9-h32m-39xj.json new file mode 100644 index 00000000000..ebaec310e59 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jxv9-h32m-39xj/GHSA-jxv9-h32m-39xj.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jxv9-h32m-39xj", + "modified": "2025-05-28T18:33:29Z", + "published": "2025-05-28T18:33:29Z", + "aliases": [ + "CVE-2022-38092" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-38092" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T18:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mcfv-326r-vxp8/GHSA-mcfv-326r-vxp8.json b/advisories/unreviewed/2025/05/GHSA-mcfv-326r-vxp8/GHSA-mcfv-326r-vxp8.json new file mode 100644 index 00000000000..4947a417a32 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mcfv-326r-vxp8/GHSA-mcfv-326r-vxp8.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mcfv-326r-vxp8", + "modified": "2025-05-28T18:33:28Z", + "published": "2025-05-28T18:33:28Z", + "aliases": [ + "CVE-2022-26304" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-26304" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T17:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mjrc-8w22-4fpj/GHSA-mjrc-8w22-4fpj.json b/advisories/unreviewed/2025/05/GHSA-mjrc-8w22-4fpj/GHSA-mjrc-8w22-4fpj.json new file mode 100644 index 00000000000..416b304b901 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mjrc-8w22-4fpj/GHSA-mjrc-8w22-4fpj.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mjrc-8w22-4fpj", + "modified": "2025-05-28T18:33:28Z", + "published": "2025-05-28T18:33:28Z", + "aliases": [ + "CVE-2022-26037" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-26037" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T17:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p2p2-xpg4-rpvh/GHSA-p2p2-xpg4-rpvh.json b/advisories/unreviewed/2025/05/GHSA-p2p2-xpg4-rpvh/GHSA-p2p2-xpg4-rpvh.json new file mode 100644 index 00000000000..be7155070d7 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p2p2-xpg4-rpvh/GHSA-p2p2-xpg4-rpvh.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p2p2-xpg4-rpvh", + "modified": "2025-05-28T18:33:28Z", + "published": "2025-05-28T18:33:28Z", + "aliases": [ + "CVE-2022-26424" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-26424" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T17:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p3p9-wgx4-mq3v/GHSA-p3p9-wgx4-mq3v.json b/advisories/unreviewed/2025/05/GHSA-p3p9-wgx4-mq3v/GHSA-p3p9-wgx4-mq3v.json index bf785b3135d..4a8620479df 100644 --- a/advisories/unreviewed/2025/05/GHSA-p3p9-wgx4-mq3v/GHSA-p3p9-wgx4-mq3v.json +++ b/advisories/unreviewed/2025/05/GHSA-p3p9-wgx4-mq3v/GHSA-p3p9-wgx4-mq3v.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-p694-pgrr-cmpq/GHSA-p694-pgrr-cmpq.json b/advisories/unreviewed/2025/05/GHSA-p694-pgrr-cmpq/GHSA-p694-pgrr-cmpq.json index 5ac75ee71c3..ecebe32d8df 100644 --- a/advisories/unreviewed/2025/05/GHSA-p694-pgrr-cmpq/GHSA-p694-pgrr-cmpq.json +++ b/advisories/unreviewed/2025/05/GHSA-p694-pgrr-cmpq/GHSA-p694-pgrr-cmpq.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-pmfj-hrgr-wvm5/GHSA-pmfj-hrgr-wvm5.json b/advisories/unreviewed/2025/05/GHSA-pmfj-hrgr-wvm5/GHSA-pmfj-hrgr-wvm5.json new file mode 100644 index 00000000000..ccdca32969c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pmfj-hrgr-wvm5/GHSA-pmfj-hrgr-wvm5.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pmfj-hrgr-wvm5", + "modified": "2025-05-28T18:33:27Z", + "published": "2025-05-28T18:33:27Z", + "aliases": [ + "CVE-2022-24067" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-24067" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T17:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-pr6c-x44x-mpwc/GHSA-pr6c-x44x-mpwc.json b/advisories/unreviewed/2025/05/GHSA-pr6c-x44x-mpwc/GHSA-pr6c-x44x-mpwc.json index 80b062da9bf..8c7730970c5 100644 --- a/advisories/unreviewed/2025/05/GHSA-pr6c-x44x-mpwc/GHSA-pr6c-x44x-mpwc.json +++ b/advisories/unreviewed/2025/05/GHSA-pr6c-x44x-mpwc/GHSA-pr6c-x44x-mpwc.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-prj7-2jhj-62fj/GHSA-prj7-2jhj-62fj.json b/advisories/unreviewed/2025/05/GHSA-prj7-2jhj-62fj/GHSA-prj7-2jhj-62fj.json new file mode 100644 index 00000000000..edf3dd075e7 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-prj7-2jhj-62fj/GHSA-prj7-2jhj-62fj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-prj7-2jhj-62fj", + "modified": "2025-05-28T18:33:29Z", + "published": "2025-05-28T18:33:29Z", + "aliases": [ + "CVE-2025-32803" + ], + "details": "In some cases, Kea log files or lease files may be world-readable.\nThis issue affects Kea versions 2.4.0 through 2.4.1, 2.6.0 through 2.6.2, and 2.7.0 through 2.7.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32803" + }, + { + "type": "WEB", + "url": "https://kb.isc.org/docs/cve-2025-32803" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T18:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-pw38-3jfp-fw32/GHSA-pw38-3jfp-fw32.json b/advisories/unreviewed/2025/05/GHSA-pw38-3jfp-fw32/GHSA-pw38-3jfp-fw32.json new file mode 100644 index 00000000000..f0b10b97690 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pw38-3jfp-fw32/GHSA-pw38-3jfp-fw32.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pw38-3jfp-fw32", + "modified": "2025-05-28T18:33:28Z", + "published": "2025-05-28T18:33:28Z", + "aliases": [ + "CVE-2025-48931" + ], + "details": "The TeleMessage service through 2025-05-05 relies on MD5 for password hashing, which opens up various attack possibilities (including rainbow tables) with low computational effort.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48931" + }, + { + "type": "WEB", + "url": "https://www.wired.com/story/how-the-signal-knock-off-app-telemessage-got-hacked-in-20-minutes" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-328" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T17:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qm8c-9qvf-wv68/GHSA-qm8c-9qvf-wv68.json b/advisories/unreviewed/2025/05/GHSA-qm8c-9qvf-wv68/GHSA-qm8c-9qvf-wv68.json new file mode 100644 index 00000000000..5627011ccc3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qm8c-9qvf-wv68/GHSA-qm8c-9qvf-wv68.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qm8c-9qvf-wv68", + "modified": "2025-05-28T18:33:28Z", + "published": "2025-05-28T18:33:28Z", + "aliases": [ + "CVE-2022-26038" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-26038" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T18:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qq2r-6j4w-49qc/GHSA-qq2r-6j4w-49qc.json b/advisories/unreviewed/2025/05/GHSA-qq2r-6j4w-49qc/GHSA-qq2r-6j4w-49qc.json new file mode 100644 index 00000000000..e20f1008b3a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qq2r-6j4w-49qc/GHSA-qq2r-6j4w-49qc.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qq2r-6j4w-49qc", + "modified": "2025-05-28T18:33:29Z", + "published": "2025-05-28T18:33:29Z", + "aliases": [ + "CVE-2025-48749" + ], + "details": "Netwrix Directory Manager (formerly Imanami GroupID) v11.0.0.0 and before & after v.11.1.25134.03 inserts Sensitive Information into Sent Data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48749" + }, + { + "type": "WEB", + "url": "https://community.netwrix.com/t/adv-2025-014-critical-vulnerabilities-in-netwrix-directory-manager-formerly-imanami-groupid-v11/13951" + }, + { + "type": "WEB", + "url": "https://netwrix.com" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T18:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rxgj-95gj-27xq/GHSA-rxgj-95gj-27xq.json b/advisories/unreviewed/2025/05/GHSA-rxgj-95gj-27xq/GHSA-rxgj-95gj-27xq.json new file mode 100644 index 00000000000..38651287eda --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rxgj-95gj-27xq/GHSA-rxgj-95gj-27xq.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rxgj-95gj-27xq", + "modified": "2025-05-28T18:33:28Z", + "published": "2025-05-28T18:33:28Z", + "aliases": [ + "CVE-2022-26072" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-26072" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T17:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v4hr-6g26-8757/GHSA-v4hr-6g26-8757.json b/advisories/unreviewed/2025/05/GHSA-v4hr-6g26-8757/GHSA-v4hr-6g26-8757.json new file mode 100644 index 00000000000..5143e5d4198 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v4hr-6g26-8757/GHSA-v4hr-6g26-8757.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v4hr-6g26-8757", + "modified": "2025-05-28T18:33:28Z", + "published": "2025-05-28T18:33:28Z", + "aliases": [ + "CVE-2025-48930" + ], + "details": "The TeleMessage service through 2025-05-05 stores certain cleartext information in memory, even though memory content may be accessible to an adversary through various avenues, as exploited in the wild in May 2025.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48930" + }, + { + "type": "WEB", + "url": "https://www.wired.com/story/how-the-signal-knock-off-app-telemessage-got-hacked-in-20-minutes" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-316" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T17:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v6cp-qj97-x87h/GHSA-v6cp-qj97-x87h.json b/advisories/unreviewed/2025/05/GHSA-v6cp-qj97-x87h/GHSA-v6cp-qj97-x87h.json index ade80c83db4..e714371c82c 100644 --- a/advisories/unreviewed/2025/05/GHSA-v6cp-qj97-x87h/GHSA-v6cp-qj97-x87h.json +++ b/advisories/unreviewed/2025/05/GHSA-v6cp-qj97-x87h/GHSA-v6cp-qj97-x87h.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-v7c5-rprq-jfcf/GHSA-v7c5-rprq-jfcf.json b/advisories/unreviewed/2025/05/GHSA-v7c5-rprq-jfcf/GHSA-v7c5-rprq-jfcf.json new file mode 100644 index 00000000000..ed0bbd7f5a2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v7c5-rprq-jfcf/GHSA-v7c5-rprq-jfcf.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v7c5-rprq-jfcf", + "modified": "2025-05-28T18:33:29Z", + "published": "2025-05-28T18:33:29Z", + "aliases": [ + "CVE-2022-43493" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43493" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T18:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vg38-3h8m-863x/GHSA-vg38-3h8m-863x.json b/advisories/unreviewed/2025/05/GHSA-vg38-3h8m-863x/GHSA-vg38-3h8m-863x.json index 6b652e54155..74376e4234a 100644 --- a/advisories/unreviewed/2025/05/GHSA-vg38-3h8m-863x/GHSA-vg38-3h8m-863x.json +++ b/advisories/unreviewed/2025/05/GHSA-vg38-3h8m-863x/GHSA-vg38-3h8m-863x.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-vg5q-95gg-rqfg/GHSA-vg5q-95gg-rqfg.json b/advisories/unreviewed/2025/05/GHSA-vg5q-95gg-rqfg/GHSA-vg5q-95gg-rqfg.json new file mode 100644 index 00000000000..9191bbc06ef --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vg5q-95gg-rqfg/GHSA-vg5q-95gg-rqfg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vg5q-95gg-rqfg", + "modified": "2025-05-28T18:33:28Z", + "published": "2025-05-28T18:33:28Z", + "aliases": [ + "CVE-2025-48927" + ], + "details": "The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploited in the wild in May 2025.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48927" + }, + { + "type": "WEB", + "url": "https://www.wired.com/story/how-the-signal-knock-off-app-telemessage-got-hacked-in-20-minutes" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1188" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T17:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vprv-ph4x-pqgj/GHSA-vprv-ph4x-pqgj.json b/advisories/unreviewed/2025/05/GHSA-vprv-ph4x-pqgj/GHSA-vprv-ph4x-pqgj.json new file mode 100644 index 00000000000..86573d40b8d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vprv-ph4x-pqgj/GHSA-vprv-ph4x-pqgj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vprv-ph4x-pqgj", + "modified": "2025-05-28T18:33:28Z", + "published": "2025-05-28T18:33:28Z", + "aliases": [ + "CVE-2025-48926" + ], + "details": "The admin panel in the TeleMessage service through 2025-05-05 allows attackers to discover usernames, e-mail addresses, passwords, and telephone numbers, as exploited in the wild in May 2025.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48926" + }, + { + "type": "WEB", + "url": "https://www.wired.com/story/how-the-signal-knock-off-app-telemessage-got-hacked-in-20-minutes" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T17:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vr74-xqq8-6564/GHSA-vr74-xqq8-6564.json b/advisories/unreviewed/2025/05/GHSA-vr74-xqq8-6564/GHSA-vr74-xqq8-6564.json new file mode 100644 index 00000000000..0d78923452a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vr74-xqq8-6564/GHSA-vr74-xqq8-6564.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vr74-xqq8-6564", + "modified": "2025-05-28T18:33:29Z", + "published": "2025-05-28T18:33:29Z", + "aliases": [ + "CVE-2022-34859" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-34859" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T18:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vr9v-xw27-65fc/GHSA-vr9v-xw27-65fc.json b/advisories/unreviewed/2025/05/GHSA-vr9v-xw27-65fc/GHSA-vr9v-xw27-65fc.json new file mode 100644 index 00000000000..e01d381dcb8 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vr9v-xw27-65fc/GHSA-vr9v-xw27-65fc.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vr9v-xw27-65fc", + "modified": "2025-05-28T18:33:29Z", + "published": "2025-05-28T18:33:29Z", + "aliases": [ + "CVE-2025-1461" + ], + "details": "Improper neutralization of the value of the 'eventMoreText' property of the 'VCalendar' component in Vuetify allows unsanitized HTML to be inserted into the page. This can lead to a  Cross-Site Scripting (XSS) https://owasp.org/www-community/attacks/xss  attack. The vulnerability occurs because the default Vuetify translator will return the translation key as the translation, if it can't find an actual translation.\n\nThis issue affects Vuetify versions greater than or equal to 2.0.0 and less than 3.0.0.\n\nNote:\nVersion 2.x of Vuetify is End-of-Life and will not receive any updates to address this issue. For more information see here https://v2.vuetifyjs.com/en/about/eol/ .", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1461" + }, + { + "type": "WEB", + "url": "https://github.com/neverendingsupport/nes-vuetify-cve-2025-1461" + }, + { + "type": "WEB", + "url": "https://www.herodevs.com/vulnerability-directory/cve-2025-1461" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vvqh-pjh9-jh35/GHSA-vvqh-pjh9-jh35.json b/advisories/unreviewed/2025/05/GHSA-vvqh-pjh9-jh35/GHSA-vvqh-pjh9-jh35.json new file mode 100644 index 00000000000..bf558b983dd --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vvqh-pjh9-jh35/GHSA-vvqh-pjh9-jh35.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vvqh-pjh9-jh35", + "modified": "2025-05-28T18:33:29Z", + "published": "2025-05-28T18:33:29Z", + "aliases": [ + "CVE-2025-48747" + ], + "details": "Netwrix Directory Manager (formerly Imanami GroupID) before and including v.11.0.0.0 and after v.11.1.25134.03 has Incorrect Permission Assignment for a Critical Resource.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48747" + }, + { + "type": "WEB", + "url": "https://community.netwrix.com/t/adv-2025-014-critical-vulnerabilities-in-netwrix-directory-manager-formerly-imanami-groupid-v11/13951" + }, + { + "type": "WEB", + "url": "https://netwrix.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T18:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vwc9-wh34-hrfm/GHSA-vwc9-wh34-hrfm.json b/advisories/unreviewed/2025/05/GHSA-vwc9-wh34-hrfm/GHSA-vwc9-wh34-hrfm.json new file mode 100644 index 00000000000..76e1b7ec34d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vwc9-wh34-hrfm/GHSA-vwc9-wh34-hrfm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vwc9-wh34-hrfm", + "modified": "2025-05-28T18:33:28Z", + "published": "2025-05-28T18:33:28Z", + "aliases": [ + "CVE-2025-32802" + ], + "details": "Kea configuration and API directives can be used to overwrite arbitrary files, subject to permissions granted to Kea. Many common configurations run Kea as root, leave the API entry points unsecured by default, and/or place the control sockets in insecure paths.\nThis issue affects Kea versions 2.4.0 through 2.4.1, 2.6.0 through 2.6.2, and 2.7.0 through 2.7.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32802" + }, + { + "type": "WEB", + "url": "https://kb.isc.org/docs/cve-2025-32802" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-73" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T17:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w2h3-r7p6-vm66/GHSA-w2h3-r7p6-vm66.json b/advisories/unreviewed/2025/05/GHSA-w2h3-r7p6-vm66/GHSA-w2h3-r7p6-vm66.json new file mode 100644 index 00000000000..a10354ca84d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w2h3-r7p6-vm66/GHSA-w2h3-r7p6-vm66.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w2h3-r7p6-vm66", + "modified": "2025-05-28T18:33:29Z", + "published": "2025-05-28T18:33:29Z", + "aliases": [ + "CVE-2022-43496" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43496" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T18:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w3pc-9cp7-x9xr/GHSA-w3pc-9cp7-x9xr.json b/advisories/unreviewed/2025/05/GHSA-w3pc-9cp7-x9xr/GHSA-w3pc-9cp7-x9xr.json new file mode 100644 index 00000000000..965b0b92adc --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w3pc-9cp7-x9xr/GHSA-w3pc-9cp7-x9xr.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w3pc-9cp7-x9xr", + "modified": "2025-05-28T18:33:27Z", + "published": "2025-05-28T18:33:27Z", + "aliases": [ + "CVE-2022-25870" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-25870" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T17:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w3vc-hpm9-2h9q/GHSA-w3vc-hpm9-2h9q.json b/advisories/unreviewed/2025/05/GHSA-w3vc-hpm9-2h9q/GHSA-w3vc-hpm9-2h9q.json new file mode 100644 index 00000000000..5859d099d41 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w3vc-hpm9-2h9q/GHSA-w3vc-hpm9-2h9q.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w3vc-hpm9-2h9q", + "modified": "2025-05-28T18:33:29Z", + "published": "2025-05-28T18:33:29Z", + "aliases": [ + "CVE-2024-57338" + ], + "details": "An arbitrary file upload vulnerability in M2Soft CROWNIX Report & ERS v5.x to v5.5.14.1070, v7.x to v7.4.3.960, and v8.x to v8.2.0.345 allows attackers to execute arbitrary code via supplying a crafted file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57338" + }, + { + "type": "WEB", + "url": "https://www.m2soft.co.kr/sub/board/news.asp?mode=view&idx=2411" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w95r-6gjg-73xh/GHSA-w95r-6gjg-73xh.json b/advisories/unreviewed/2025/05/GHSA-w95r-6gjg-73xh/GHSA-w95r-6gjg-73xh.json new file mode 100644 index 00000000000..e803cd75c75 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w95r-6gjg-73xh/GHSA-w95r-6gjg-73xh.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w95r-6gjg-73xh", + "modified": "2025-05-28T18:33:27Z", + "published": "2025-05-28T18:33:27Z", + "aliases": [ + "CVE-2022-25868" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-25868" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T17:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wcwc-445x-wf23/GHSA-wcwc-445x-wf23.json b/advisories/unreviewed/2025/05/GHSA-wcwc-445x-wf23/GHSA-wcwc-445x-wf23.json index fcf886b8338..649844b489e 100644 --- a/advisories/unreviewed/2025/05/GHSA-wcwc-445x-wf23/GHSA-wcwc-445x-wf23.json +++ b/advisories/unreviewed/2025/05/GHSA-wcwc-445x-wf23/GHSA-wcwc-445x-wf23.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-wxg6-4cwm-4rjf/GHSA-wxg6-4cwm-4rjf.json b/advisories/unreviewed/2025/05/GHSA-wxg6-4cwm-4rjf/GHSA-wxg6-4cwm-4rjf.json new file mode 100644 index 00000000000..e5355232c76 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wxg6-4cwm-4rjf/GHSA-wxg6-4cwm-4rjf.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wxg6-4cwm-4rjf", + "modified": "2025-05-28T18:33:29Z", + "published": "2025-05-28T18:33:29Z", + "aliases": [ + "CVE-2024-57337" + ], + "details": "An arbitrary file upload vulnerability in the opcode 500 functionality of M2Soft CROWNIX Report & ERS v5.x to v5.5.14.1070, v7.x to v7.4.3.960, and v8.x to v8.2.0.345 allows attackers to execute arbitrary code via supplying a crafted file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57337" + }, + { + "type": "WEB", + "url": "https://www.m2soft.co.kr/sub/board/news.asp?mode=view&idx=2411" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-x298-29qf-2vcx/GHSA-x298-29qf-2vcx.json b/advisories/unreviewed/2025/05/GHSA-x298-29qf-2vcx/GHSA-x298-29qf-2vcx.json new file mode 100644 index 00000000000..5c3ff741303 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-x298-29qf-2vcx/GHSA-x298-29qf-2vcx.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x298-29qf-2vcx", + "modified": "2025-05-28T18:33:28Z", + "published": "2025-05-28T18:33:28Z", + "aliases": [ + "CVE-2022-27877" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-27877" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T18:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-x6fc-488r-qh93/GHSA-x6fc-488r-qh93.json b/advisories/unreviewed/2025/05/GHSA-x6fc-488r-qh93/GHSA-x6fc-488r-qh93.json new file mode 100644 index 00000000000..691d8c9343c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-x6fc-488r-qh93/GHSA-x6fc-488r-qh93.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x6fc-488r-qh93", + "modified": "2025-05-28T18:33:29Z", + "published": "2025-05-28T18:33:29Z", + "aliases": [ + "CVE-2025-47748" + ], + "details": "Netwrix Directory Manager v.11.0.0.0 and before & after v.11.1.25134.03 contains a hardcoded password.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47748" + }, + { + "type": "WEB", + "url": "https://community.netwrix.com/t/adv-2025-014-critical-vulnerabilities-in-netwrix-directory-manager-formerly-imanami-groupid-v11/13951" + }, + { + "type": "WEB", + "url": "https://netwrix.com" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T18:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xh67-8c9c-jwgx/GHSA-xh67-8c9c-jwgx.json b/advisories/unreviewed/2025/05/GHSA-xh67-8c9c-jwgx/GHSA-xh67-8c9c-jwgx.json new file mode 100644 index 00000000000..662d8bc24ea --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xh67-8c9c-jwgx/GHSA-xh67-8c9c-jwgx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xh67-8c9c-jwgx", + "modified": "2025-05-28T18:33:28Z", + "published": "2025-05-28T18:33:28Z", + "aliases": [ + "CVE-2025-36572" + ], + "details": "Dell PowerStore, version(s) 4.0.0.0, contain(s) an Use of Hard-coded Credentials vulnerability in the PowerStore image file. A low privileged attacker with remote access, with the knowledge of the hard-coded credentials, could potentially exploit this vulnerability to gain unauthorized access based on the hardcoded account's privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-36572" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000325205/dsa-2025-223-dell-powerstore-t-security-update-for-multiple-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-798" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T17:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xv8q-37rr-6369/GHSA-xv8q-37rr-6369.json b/advisories/unreviewed/2025/05/GHSA-xv8q-37rr-6369/GHSA-xv8q-37rr-6369.json new file mode 100644 index 00000000000..515345599c1 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xv8q-37rr-6369/GHSA-xv8q-37rr-6369.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xv8q-37rr-6369", + "modified": "2025-05-28T18:33:29Z", + "published": "2025-05-28T18:33:29Z", + "aliases": [ + "CVE-2022-36298" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36298" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T18:15:23Z" + } +} \ No newline at end of file