From be637da4ce5cfaabfee9c8e6da3cff3be88fbaaf Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 2 Jun 2025 18:32:03 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-6m5p-5ccp-c8p3.json | 6 ++- .../GHSA-279h-8hwx-39m5.json | 2 +- .../GHSA-449w-g66x-h54j.json | 2 +- .../GHSA-4g99-5gw9-42hv.json | 2 +- .../GHSA-5g8x-4pjj-p6fm.json | 2 +- .../GHSA-6xr5-p6cj-8mrm.json | 2 +- .../GHSA-8rfj-2m76-7x2p.json | 2 +- .../GHSA-9mj4-2jjf-889w.json | 2 +- .../GHSA-cj4r-8g68-rx5f.json | 2 +- .../GHSA-f6fq-4q55-rg2f.json | 2 +- .../GHSA-grw9-xhr2-wcp3.json | 2 +- .../GHSA-h3w7-w9rh-w829.json | 2 +- .../GHSA-jg3h-w3vp-mwf6.json | 2 +- .../GHSA-pcmh-49qc-2rx3.json | 2 +- .../GHSA-vrp7-hqrc-f29q.json | 2 +- .../GHSA-vv37-8w95-rgj3.json | 2 +- .../GHSA-x93g-3xq3-cp8q.json | 2 +- .../GHSA-2h3c-3h32-6j65.json | 15 +++++-- .../GHSA-mhvp-2g8x-v832.json | 6 ++- .../GHSA-26pq-6hf6-mh32.json | 11 +++-- .../GHSA-277h-8wc5-7qfc.json | 6 ++- .../GHSA-2x4q-h3hx-hhh6.json | 6 ++- .../GHSA-3353-8xh7-8f2x.json | 11 +++-- .../GHSA-33vg-fjg5-6p64.json | 6 ++- .../GHSA-3h3m-9w6m-92hw.json | 33 +++++++++++++++ .../GHSA-3r93-v644-8g5h.json | 36 +++++++++++++++++ .../GHSA-4q83-43xw-q63j.json | 36 +++++++++++++++++ .../GHSA-77h2-x83m-w6w9.json | 36 +++++++++++++++++ .../GHSA-7c63-xmgg-xrx5.json | 36 +++++++++++++++++ .../GHSA-7f34-p2r4-j656.json | 36 +++++++++++++++++ .../GHSA-7wp3-36m3-58j5.json | 37 +++++++++++++++++ .../GHSA-8ghf-hrfq-8q3j.json | 40 +++++++++++++++++++ .../GHSA-8j8w-wwqc-x596.json | 6 ++- .../GHSA-cp5v-2hmc-3vjx.json | 36 +++++++++++++++++ .../GHSA-cwjc-83cr-56p7.json | 11 +++-- .../GHSA-f2rq-qhqv-93pg.json | 29 ++++++++++++++ .../GHSA-fg83-j4cx-5cww.json | 33 +++++++++++++++ .../GHSA-fxp8-rw49-cf65.json | 11 +++-- .../GHSA-g9qh-c549-gj4x.json | 6 ++- .../GHSA-gvwx-c268-xr4p.json | 29 ++++++++++++++ .../GHSA-h628-q67p-f6w4.json | 6 ++- .../GHSA-hh39-985p-g37g.json | 33 +++++++++++++++ .../GHSA-hw75-9xrf-7fg8.json | 11 +++-- .../GHSA-j3qf-mq3f-rgcf.json | 33 +++++++++++++++ .../GHSA-jqw7-hgh5-2ppr.json | 33 +++++++++++++++ .../GHSA-jvhv-7727-rf3v.json | 40 +++++++++++++++++++ .../GHSA-jwc3-6wrj-fj5w.json | 29 ++++++++++++++ .../GHSA-mc52-7658-v986.json | 37 +++++++++++++++++ .../GHSA-mxj6-x52w-4g7m.json | 11 +++-- .../GHSA-pf22-rv2m-7xj7.json | 6 ++- .../GHSA-qj64-gvr6-h7qx.json | 6 ++- .../GHSA-qw96-3vm7-2xqg.json | 4 +- .../GHSA-qxm6-r385-gmwp.json | 4 +- .../GHSA-rhfv-c52c-x747.json | 36 +++++++++++++++++ .../GHSA-v8mm-64rg-m2wg.json | 11 +++-- .../GHSA-vpgx-c322-qgw5.json | 6 ++- .../GHSA-x223-vrgf-8f8m.json | 36 +++++++++++++++++ .../GHSA-xpxp-r8hf-wgf6.json | 36 +++++++++++++++++ 58 files changed, 870 insertions(+), 58 deletions(-) create mode 100644 advisories/unreviewed/2025/06/GHSA-3h3m-9w6m-92hw/GHSA-3h3m-9w6m-92hw.json create mode 100644 advisories/unreviewed/2025/06/GHSA-3r93-v644-8g5h/GHSA-3r93-v644-8g5h.json create mode 100644 advisories/unreviewed/2025/06/GHSA-4q83-43xw-q63j/GHSA-4q83-43xw-q63j.json create mode 100644 advisories/unreviewed/2025/06/GHSA-77h2-x83m-w6w9/GHSA-77h2-x83m-w6w9.json create mode 100644 advisories/unreviewed/2025/06/GHSA-7c63-xmgg-xrx5/GHSA-7c63-xmgg-xrx5.json create mode 100644 advisories/unreviewed/2025/06/GHSA-7f34-p2r4-j656/GHSA-7f34-p2r4-j656.json create mode 100644 advisories/unreviewed/2025/06/GHSA-7wp3-36m3-58j5/GHSA-7wp3-36m3-58j5.json create mode 100644 advisories/unreviewed/2025/06/GHSA-8ghf-hrfq-8q3j/GHSA-8ghf-hrfq-8q3j.json create mode 100644 advisories/unreviewed/2025/06/GHSA-cp5v-2hmc-3vjx/GHSA-cp5v-2hmc-3vjx.json create mode 100644 advisories/unreviewed/2025/06/GHSA-f2rq-qhqv-93pg/GHSA-f2rq-qhqv-93pg.json create mode 100644 advisories/unreviewed/2025/06/GHSA-fg83-j4cx-5cww/GHSA-fg83-j4cx-5cww.json create mode 100644 advisories/unreviewed/2025/06/GHSA-gvwx-c268-xr4p/GHSA-gvwx-c268-xr4p.json create mode 100644 advisories/unreviewed/2025/06/GHSA-hh39-985p-g37g/GHSA-hh39-985p-g37g.json create mode 100644 advisories/unreviewed/2025/06/GHSA-j3qf-mq3f-rgcf/GHSA-j3qf-mq3f-rgcf.json create mode 100644 advisories/unreviewed/2025/06/GHSA-jqw7-hgh5-2ppr/GHSA-jqw7-hgh5-2ppr.json create mode 100644 advisories/unreviewed/2025/06/GHSA-jvhv-7727-rf3v/GHSA-jvhv-7727-rf3v.json create mode 100644 advisories/unreviewed/2025/06/GHSA-jwc3-6wrj-fj5w/GHSA-jwc3-6wrj-fj5w.json create mode 100644 advisories/unreviewed/2025/06/GHSA-mc52-7658-v986/GHSA-mc52-7658-v986.json create mode 100644 advisories/unreviewed/2025/06/GHSA-rhfv-c52c-x747/GHSA-rhfv-c52c-x747.json create mode 100644 advisories/unreviewed/2025/06/GHSA-x223-vrgf-8f8m/GHSA-x223-vrgf-8f8m.json create mode 100644 advisories/unreviewed/2025/06/GHSA-xpxp-r8hf-wgf6/GHSA-xpxp-r8hf-wgf6.json diff --git a/advisories/unreviewed/2023/09/GHSA-6m5p-5ccp-c8p3/GHSA-6m5p-5ccp-c8p3.json b/advisories/unreviewed/2023/09/GHSA-6m5p-5ccp-c8p3/GHSA-6m5p-5ccp-c8p3.json index 1f14df1c23c..454703c3e61 100644 --- a/advisories/unreviewed/2023/09/GHSA-6m5p-5ccp-c8p3/GHSA-6m5p-5ccp-c8p3.json +++ b/advisories/unreviewed/2023/09/GHSA-6m5p-5ccp-c8p3/GHSA-6m5p-5ccp-c8p3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6m5p-5ccp-c8p3", - "modified": "2024-04-04T07:35:55Z", + "modified": "2025-06-02T18:30:25Z", "published": "2023-09-11T21:30:16Z", "aliases": [ "CVE-2023-39780" @@ -42,6 +42,10 @@ { "type": "WEB", "url": "https://github.com/D2y6p/CVE/blob/main/asus/CVE-2023-39780/6/EN.md" + }, + { + "type": "WEB", + "url": "https://www.greynoise.io/blog/stealthy-backdoor-campaign-affecting-asus-routers" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-279h-8hwx-39m5/GHSA-279h-8hwx-39m5.json b/advisories/unreviewed/2024/01/GHSA-279h-8hwx-39m5/GHSA-279h-8hwx-39m5.json index ed02d8b5406..271ae06da77 100644 --- a/advisories/unreviewed/2024/01/GHSA-279h-8hwx-39m5/GHSA-279h-8hwx-39m5.json +++ b/advisories/unreviewed/2024/01/GHSA-279h-8hwx-39m5/GHSA-279h-8hwx-39m5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-279h-8hwx-39m5", - "modified": "2024-01-24T18:31:00Z", + "modified": "2025-06-02T18:30:26Z", "published": "2024-01-16T18:31:09Z", "aliases": [ "CVE-2022-3899" diff --git a/advisories/unreviewed/2024/01/GHSA-449w-g66x-h54j/GHSA-449w-g66x-h54j.json b/advisories/unreviewed/2024/01/GHSA-449w-g66x-h54j/GHSA-449w-g66x-h54j.json index 6af566c1155..10eae8ac082 100644 --- a/advisories/unreviewed/2024/01/GHSA-449w-g66x-h54j/GHSA-449w-g66x-h54j.json +++ b/advisories/unreviewed/2024/01/GHSA-449w-g66x-h54j/GHSA-449w-g66x-h54j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-449w-g66x-h54j", - "modified": "2024-01-19T21:30:34Z", + "modified": "2025-06-02T18:30:25Z", "published": "2024-01-16T12:30:25Z", "aliases": [ "CVE-2023-52100" diff --git a/advisories/unreviewed/2024/01/GHSA-4g99-5gw9-42hv/GHSA-4g99-5gw9-42hv.json b/advisories/unreviewed/2024/01/GHSA-4g99-5gw9-42hv/GHSA-4g99-5gw9-42hv.json index f766b9cc509..d3108489c55 100644 --- a/advisories/unreviewed/2024/01/GHSA-4g99-5gw9-42hv/GHSA-4g99-5gw9-42hv.json +++ b/advisories/unreviewed/2024/01/GHSA-4g99-5gw9-42hv/GHSA-4g99-5gw9-42hv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4g99-5gw9-42hv", - "modified": "2024-01-22T21:31:07Z", + "modified": "2025-06-02T18:30:26Z", "published": "2024-01-16T18:31:09Z", "aliases": [ "CVE-2022-1609" diff --git a/advisories/unreviewed/2024/01/GHSA-5g8x-4pjj-p6fm/GHSA-5g8x-4pjj-p6fm.json b/advisories/unreviewed/2024/01/GHSA-5g8x-4pjj-p6fm/GHSA-5g8x-4pjj-p6fm.json index e2ddfc6b582..0bb0a41e3fe 100644 --- a/advisories/unreviewed/2024/01/GHSA-5g8x-4pjj-p6fm/GHSA-5g8x-4pjj-p6fm.json +++ b/advisories/unreviewed/2024/01/GHSA-5g8x-4pjj-p6fm/GHSA-5g8x-4pjj-p6fm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5g8x-4pjj-p6fm", - "modified": "2024-01-24T18:31:00Z", + "modified": "2025-06-02T18:30:26Z", "published": "2024-01-16T18:31:09Z", "aliases": [ "CVE-2022-3194" diff --git a/advisories/unreviewed/2024/01/GHSA-6xr5-p6cj-8mrm/GHSA-6xr5-p6cj-8mrm.json b/advisories/unreviewed/2024/01/GHSA-6xr5-p6cj-8mrm/GHSA-6xr5-p6cj-8mrm.json index ebc7aacb71e..79b5ae5900f 100644 --- a/advisories/unreviewed/2024/01/GHSA-6xr5-p6cj-8mrm/GHSA-6xr5-p6cj-8mrm.json +++ b/advisories/unreviewed/2024/01/GHSA-6xr5-p6cj-8mrm/GHSA-6xr5-p6cj-8mrm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6xr5-p6cj-8mrm", - "modified": "2024-01-19T21:30:34Z", + "modified": "2025-06-02T18:30:26Z", "published": "2024-01-16T12:30:26Z", "aliases": [ "CVE-2023-52104" diff --git a/advisories/unreviewed/2024/01/GHSA-8rfj-2m76-7x2p/GHSA-8rfj-2m76-7x2p.json b/advisories/unreviewed/2024/01/GHSA-8rfj-2m76-7x2p/GHSA-8rfj-2m76-7x2p.json index 74f0147231d..538a5191c11 100644 --- a/advisories/unreviewed/2024/01/GHSA-8rfj-2m76-7x2p/GHSA-8rfj-2m76-7x2p.json +++ b/advisories/unreviewed/2024/01/GHSA-8rfj-2m76-7x2p/GHSA-8rfj-2m76-7x2p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8rfj-2m76-7x2p", - "modified": "2024-01-23T15:30:57Z", + "modified": "2025-06-02T18:30:26Z", "published": "2024-01-16T18:31:09Z", "aliases": [ "CVE-2023-2655" diff --git a/advisories/unreviewed/2024/01/GHSA-9mj4-2jjf-889w/GHSA-9mj4-2jjf-889w.json b/advisories/unreviewed/2024/01/GHSA-9mj4-2jjf-889w/GHSA-9mj4-2jjf-889w.json index 176ec91f8c1..3128b9c9782 100644 --- a/advisories/unreviewed/2024/01/GHSA-9mj4-2jjf-889w/GHSA-9mj4-2jjf-889w.json +++ b/advisories/unreviewed/2024/01/GHSA-9mj4-2jjf-889w/GHSA-9mj4-2jjf-889w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9mj4-2jjf-889w", - "modified": "2024-01-19T15:30:19Z", + "modified": "2025-06-02T18:30:26Z", "published": "2024-01-16T18:31:08Z", "aliases": [ "CVE-2021-24869" diff --git a/advisories/unreviewed/2024/01/GHSA-cj4r-8g68-rx5f/GHSA-cj4r-8g68-rx5f.json b/advisories/unreviewed/2024/01/GHSA-cj4r-8g68-rx5f/GHSA-cj4r-8g68-rx5f.json index a07eff640aa..f14094b7cb1 100644 --- a/advisories/unreviewed/2024/01/GHSA-cj4r-8g68-rx5f/GHSA-cj4r-8g68-rx5f.json +++ b/advisories/unreviewed/2024/01/GHSA-cj4r-8g68-rx5f/GHSA-cj4r-8g68-rx5f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cj4r-8g68-rx5f", - "modified": "2024-01-19T21:30:34Z", + "modified": "2025-06-02T18:30:25Z", "published": "2024-01-16T09:30:19Z", "aliases": [ "CVE-2023-52108" diff --git a/advisories/unreviewed/2024/01/GHSA-f6fq-4q55-rg2f/GHSA-f6fq-4q55-rg2f.json b/advisories/unreviewed/2024/01/GHSA-f6fq-4q55-rg2f/GHSA-f6fq-4q55-rg2f.json index 711205064be..dbe51a313fd 100644 --- a/advisories/unreviewed/2024/01/GHSA-f6fq-4q55-rg2f/GHSA-f6fq-4q55-rg2f.json +++ b/advisories/unreviewed/2024/01/GHSA-f6fq-4q55-rg2f/GHSA-f6fq-4q55-rg2f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f6fq-4q55-rg2f", - "modified": "2024-01-23T21:30:19Z", + "modified": "2025-06-02T18:30:26Z", "published": "2024-01-16T18:31:08Z", "aliases": [ "CVE-2021-24433" diff --git a/advisories/unreviewed/2024/01/GHSA-grw9-xhr2-wcp3/GHSA-grw9-xhr2-wcp3.json b/advisories/unreviewed/2024/01/GHSA-grw9-xhr2-wcp3/GHSA-grw9-xhr2-wcp3.json index 0d86e4cfe8f..b7e6024947c 100644 --- a/advisories/unreviewed/2024/01/GHSA-grw9-xhr2-wcp3/GHSA-grw9-xhr2-wcp3.json +++ b/advisories/unreviewed/2024/01/GHSA-grw9-xhr2-wcp3/GHSA-grw9-xhr2-wcp3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-grw9-xhr2-wcp3", - "modified": "2024-01-23T18:31:11Z", + "modified": "2025-06-02T18:30:26Z", "published": "2024-01-16T18:31:09Z", "aliases": [ "CVE-2023-0079" diff --git a/advisories/unreviewed/2024/01/GHSA-h3w7-w9rh-w829/GHSA-h3w7-w9rh-w829.json b/advisories/unreviewed/2024/01/GHSA-h3w7-w9rh-w829/GHSA-h3w7-w9rh-w829.json index 49cd1fffb2f..b72403d2fb6 100644 --- a/advisories/unreviewed/2024/01/GHSA-h3w7-w9rh-w829/GHSA-h3w7-w9rh-w829.json +++ b/advisories/unreviewed/2024/01/GHSA-h3w7-w9rh-w829/GHSA-h3w7-w9rh-w829.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h3w7-w9rh-w829", - "modified": "2024-01-19T15:30:19Z", + "modified": "2025-06-02T18:30:26Z", "published": "2024-01-16T18:31:08Z", "aliases": [ "CVE-2021-4227" diff --git a/advisories/unreviewed/2024/01/GHSA-jg3h-w3vp-mwf6/GHSA-jg3h-w3vp-mwf6.json b/advisories/unreviewed/2024/01/GHSA-jg3h-w3vp-mwf6/GHSA-jg3h-w3vp-mwf6.json index c8dbe36e3d7..ae551561b78 100644 --- a/advisories/unreviewed/2024/01/GHSA-jg3h-w3vp-mwf6/GHSA-jg3h-w3vp-mwf6.json +++ b/advisories/unreviewed/2024/01/GHSA-jg3h-w3vp-mwf6/GHSA-jg3h-w3vp-mwf6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jg3h-w3vp-mwf6", - "modified": "2024-01-19T21:30:34Z", + "modified": "2025-06-02T18:30:26Z", "published": "2024-01-16T09:30:19Z", "aliases": [ "CVE-2023-52116" diff --git a/advisories/unreviewed/2024/01/GHSA-pcmh-49qc-2rx3/GHSA-pcmh-49qc-2rx3.json b/advisories/unreviewed/2024/01/GHSA-pcmh-49qc-2rx3/GHSA-pcmh-49qc-2rx3.json index 8f8815a8aac..09e1056c46f 100644 --- a/advisories/unreviewed/2024/01/GHSA-pcmh-49qc-2rx3/GHSA-pcmh-49qc-2rx3.json +++ b/advisories/unreviewed/2024/01/GHSA-pcmh-49qc-2rx3/GHSA-pcmh-49qc-2rx3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pcmh-49qc-2rx3", - "modified": "2024-01-22T15:30:22Z", + "modified": "2025-06-02T18:30:25Z", "published": "2024-01-16T06:30:31Z", "aliases": [ "CVE-2024-21672" diff --git a/advisories/unreviewed/2024/01/GHSA-vrp7-hqrc-f29q/GHSA-vrp7-hqrc-f29q.json b/advisories/unreviewed/2024/01/GHSA-vrp7-hqrc-f29q/GHSA-vrp7-hqrc-f29q.json index 14aa9dc52c9..58ac0426324 100644 --- a/advisories/unreviewed/2024/01/GHSA-vrp7-hqrc-f29q/GHSA-vrp7-hqrc-f29q.json +++ b/advisories/unreviewed/2024/01/GHSA-vrp7-hqrc-f29q/GHSA-vrp7-hqrc-f29q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vrp7-hqrc-f29q", - "modified": "2024-01-19T18:30:25Z", + "modified": "2025-06-02T18:30:25Z", "published": "2024-01-16T09:30:18Z", "aliases": [ "CVE-2023-52109" diff --git a/advisories/unreviewed/2024/01/GHSA-vv37-8w95-rgj3/GHSA-vv37-8w95-rgj3.json b/advisories/unreviewed/2024/01/GHSA-vv37-8w95-rgj3/GHSA-vv37-8w95-rgj3.json index 27d50920275..04c283bdf5d 100644 --- a/advisories/unreviewed/2024/01/GHSA-vv37-8w95-rgj3/GHSA-vv37-8w95-rgj3.json +++ b/advisories/unreviewed/2024/01/GHSA-vv37-8w95-rgj3/GHSA-vv37-8w95-rgj3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vv37-8w95-rgj3", - "modified": "2024-01-22T21:31:07Z", + "modified": "2025-06-02T18:30:26Z", "published": "2024-01-16T18:31:09Z", "aliases": [ "CVE-2023-3178" diff --git a/advisories/unreviewed/2024/01/GHSA-x93g-3xq3-cp8q/GHSA-x93g-3xq3-cp8q.json b/advisories/unreviewed/2024/01/GHSA-x93g-3xq3-cp8q/GHSA-x93g-3xq3-cp8q.json index 99a1eee7090..7ec72104b48 100644 --- a/advisories/unreviewed/2024/01/GHSA-x93g-3xq3-cp8q/GHSA-x93g-3xq3-cp8q.json +++ b/advisories/unreviewed/2024/01/GHSA-x93g-3xq3-cp8q/GHSA-x93g-3xq3-cp8q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x93g-3xq3-cp8q", - "modified": "2024-01-23T21:30:20Z", + "modified": "2025-06-02T18:30:26Z", "published": "2024-01-16T18:31:09Z", "aliases": [ "CVE-2022-1760" diff --git a/advisories/unreviewed/2025/05/GHSA-2h3c-3h32-6j65/GHSA-2h3c-3h32-6j65.json b/advisories/unreviewed/2025/05/GHSA-2h3c-3h32-6j65/GHSA-2h3c-3h32-6j65.json index 20649e4ef57..fc7c144b167 100644 --- a/advisories/unreviewed/2025/05/GHSA-2h3c-3h32-6j65/GHSA-2h3c-3h32-6j65.json +++ b/advisories/unreviewed/2025/05/GHSA-2h3c-3h32-6j65/GHSA-2h3c-3h32-6j65.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2h3c-3h32-6j65", - "modified": "2025-05-23T18:32:12Z", + "modified": "2025-06-02T18:30:32Z", "published": "2025-05-23T18:32:12Z", "aliases": [ "CVE-2024-48704" ], "details": "Phpgurukul Medical Card Generation System v1.0 is vulnerable to HTML Injection in admin/contactus.php via the parameter pagedes.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-23T16:15:24Z" diff --git a/advisories/unreviewed/2025/05/GHSA-mhvp-2g8x-v832/GHSA-mhvp-2g8x-v832.json b/advisories/unreviewed/2025/05/GHSA-mhvp-2g8x-v832/GHSA-mhvp-2g8x-v832.json index 0463f024878..a68f538d37c 100644 --- a/advisories/unreviewed/2025/05/GHSA-mhvp-2g8x-v832/GHSA-mhvp-2g8x-v832.json +++ b/advisories/unreviewed/2025/05/GHSA-mhvp-2g8x-v832/GHSA-mhvp-2g8x-v832.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mhvp-2g8x-v832", - "modified": "2025-05-27T18:30:51Z", + "modified": "2025-06-02T18:30:32Z", "published": "2025-05-27T18:30:51Z", "aliases": [ "CVE-2025-23247" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5643" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2151" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/06/GHSA-26pq-6hf6-mh32/GHSA-26pq-6hf6-mh32.json b/advisories/unreviewed/2025/06/GHSA-26pq-6hf6-mh32/GHSA-26pq-6hf6-mh32.json index f56a9172fc9..8c092c14def 100644 --- a/advisories/unreviewed/2025/06/GHSA-26pq-6hf6-mh32/GHSA-26pq-6hf6-mh32.json +++ b/advisories/unreviewed/2025/06/GHSA-26pq-6hf6-mh32/GHSA-26pq-6hf6-mh32.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-26pq-6hf6-mh32", - "modified": "2025-06-02T03:30:23Z", + "modified": "2025-06-02T18:30:42Z", "published": "2025-06-02T03:30:23Z", "aliases": [ "CVE-2025-20673" ], "details": "In wlan STA driver, there is a possible system crash due to an uncaught exception. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00413200; Issue ID: MSV-3304.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-02T03:15:24Z" diff --git a/advisories/unreviewed/2025/06/GHSA-277h-8wc5-7qfc/GHSA-277h-8wc5-7qfc.json b/advisories/unreviewed/2025/06/GHSA-277h-8wc5-7qfc/GHSA-277h-8wc5-7qfc.json index c72bb2f21d7..66094c78892 100644 --- a/advisories/unreviewed/2025/06/GHSA-277h-8wc5-7qfc/GHSA-277h-8wc5-7qfc.json +++ b/advisories/unreviewed/2025/06/GHSA-277h-8wc5-7qfc/GHSA-277h-8wc5-7qfc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-277h-8wc5-7qfc", - "modified": "2025-06-02T15:31:25Z", + "modified": "2025-06-02T18:30:51Z", "published": "2025-06-02T15:31:25Z", "aliases": [ "CVE-2025-20001" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2025-2157" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2157" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/06/GHSA-2x4q-h3hx-hhh6/GHSA-2x4q-h3hx-hhh6.json b/advisories/unreviewed/2025/06/GHSA-2x4q-h3hx-hhh6/GHSA-2x4q-h3hx-hhh6.json index da4d67d2a5e..2a77ef4cd6a 100644 --- a/advisories/unreviewed/2025/06/GHSA-2x4q-h3hx-hhh6/GHSA-2x4q-h3hx-hhh6.json +++ b/advisories/unreviewed/2025/06/GHSA-2x4q-h3hx-hhh6/GHSA-2x4q-h3hx-hhh6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2x4q-h3hx-hhh6", - "modified": "2025-06-02T15:31:25Z", + "modified": "2025-06-02T18:30:51Z", "published": "2025-06-02T15:31:25Z", "aliases": [ "CVE-2024-48877" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2128" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2128" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/06/GHSA-3353-8xh7-8f2x/GHSA-3353-8xh7-8f2x.json b/advisories/unreviewed/2025/06/GHSA-3353-8xh7-8f2x/GHSA-3353-8xh7-8f2x.json index df30a2a8a06..bb14947e252 100644 --- a/advisories/unreviewed/2025/06/GHSA-3353-8xh7-8f2x/GHSA-3353-8xh7-8f2x.json +++ b/advisories/unreviewed/2025/06/GHSA-3353-8xh7-8f2x/GHSA-3353-8xh7-8f2x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3353-8xh7-8f2x", - "modified": "2025-06-02T03:30:23Z", + "modified": "2025-06-02T18:30:42Z", "published": "2025-06-02T03:30:23Z", "aliases": [ "CVE-2025-20675" ], "details": "In wlan STA driver, there is a possible system crash due to an uncaught exception. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00413201; Issue ID: MSV-3302.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-02T03:15:24Z" diff --git a/advisories/unreviewed/2025/06/GHSA-33vg-fjg5-6p64/GHSA-33vg-fjg5-6p64.json b/advisories/unreviewed/2025/06/GHSA-33vg-fjg5-6p64/GHSA-33vg-fjg5-6p64.json index f23d98c887a..b78f5809b95 100644 --- a/advisories/unreviewed/2025/06/GHSA-33vg-fjg5-6p64/GHSA-33vg-fjg5-6p64.json +++ b/advisories/unreviewed/2025/06/GHSA-33vg-fjg5-6p64/GHSA-33vg-fjg5-6p64.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-33vg-fjg5-6p64", - "modified": "2025-06-02T15:31:25Z", + "modified": "2025-06-02T18:30:51Z", "published": "2025-06-02T15:31:25Z", "aliases": [ "CVE-2025-37095" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-22" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/06/GHSA-3h3m-9w6m-92hw/GHSA-3h3m-9w6m-92hw.json b/advisories/unreviewed/2025/06/GHSA-3h3m-9w6m-92hw/GHSA-3h3m-9w6m-92hw.json new file mode 100644 index 00000000000..f173ff873e4 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-3h3m-9w6m-92hw/GHSA-3h3m-9w6m-92hw.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3h3m-9w6m-92hw", + "modified": "2025-06-02T18:30:51Z", + "published": "2025-06-02T18:30:51Z", + "aliases": [ + "CVE-2024-40113" + ], + "details": "Sitecom WLX-2006 Wall Mount Range Extender N300 v.1.5 and before is vulnerable to Use of Default Credentials.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40113" + }, + { + "type": "WEB", + "url": "https://github.com/Emm448/vulnerability-research/tree/main/CVE-2024-40113" + }, + { + "type": "WEB", + "url": "http://www.sitecomlearningcentre.com/products/wlx-2006v1001/wi-fi-range-extender-n300/downloads" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-02T16:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-3r93-v644-8g5h/GHSA-3r93-v644-8g5h.json b/advisories/unreviewed/2025/06/GHSA-3r93-v644-8g5h/GHSA-3r93-v644-8g5h.json new file mode 100644 index 00000000000..5497d33f444 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-3r93-v644-8g5h/GHSA-3r93-v644-8g5h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3r93-v644-8g5h", + "modified": "2025-06-02T18:30:52Z", + "published": "2025-06-02T18:30:52Z", + "aliases": [ + "CVE-2025-20297" + ], + "details": "In Splunk Enterprise versions below 9.4.2, 9.3.4 and 9.2.6, and Splunk Cloud Platform versions below 9.3.2411.102, 9.3.2408.111 and 9.2.2406.118, a low-privileged user that does not hold the \"admin\" or \"power\" Splunk roles could craft a malicious payload through the pdfgen/render REST endpoint that could result in execution of unauthorized JavaScript code in the browser of a user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20297" + }, + { + "type": "WEB", + "url": "https://advisory.splunk.com/advisories/SVD-2025-0601" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-02T18:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-4q83-43xw-q63j/GHSA-4q83-43xw-q63j.json b/advisories/unreviewed/2025/06/GHSA-4q83-43xw-q63j/GHSA-4q83-43xw-q63j.json new file mode 100644 index 00000000000..46d4e5c2565 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-4q83-43xw-q63j/GHSA-4q83-43xw-q63j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4q83-43xw-q63j", + "modified": "2025-06-02T18:30:52Z", + "published": "2025-06-02T18:30:52Z", + "aliases": [ + "CVE-2025-20298" + ], + "details": "In Universal Forwarder for Windows versions below 9.4.2, 9.3.4, 9.2.6, and 9.1.9, a new installation of or an upgrade to an affected version can result in incorrect permissions assignment in the Universal Forwarder for Windows Installation directory (by default, C:\\Program Files\\SplunkUniversalForwarder). This lets non-administrator users on the machine access the directory and all its contents.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20298" + }, + { + "type": "WEB", + "url": "https://advisory.splunk.com/advisories/SVD-2025-0602" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-02T18:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-77h2-x83m-w6w9/GHSA-77h2-x83m-w6w9.json b/advisories/unreviewed/2025/06/GHSA-77h2-x83m-w6w9/GHSA-77h2-x83m-w6w9.json new file mode 100644 index 00000000000..ca3984169e9 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-77h2-x83m-w6w9/GHSA-77h2-x83m-w6w9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-77h2-x83m-w6w9", + "modified": "2025-06-02T18:30:52Z", + "published": "2025-06-02T18:30:52Z", + "aliases": [ + "CVE-2024-7073" + ], + "details": "A server-side request forgery (SSRF) vulnerability exists in multiple WSO2 products due to improper input validation in SOAP admin services. This flaw allows unauthenticated attackers to manipulate server-side requests, enabling access to internal and external resources available through the network or filesystem.\n\nExploitation of this vulnerability could lead to unauthorized access to sensitive data and systems, including resources within private networks, as long as they are reachable by the affected product.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7073" + }, + { + "type": "WEB", + "url": "https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2024-3562" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-02T17:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-7c63-xmgg-xrx5/GHSA-7c63-xmgg-xrx5.json b/advisories/unreviewed/2025/06/GHSA-7c63-xmgg-xrx5/GHSA-7c63-xmgg-xrx5.json new file mode 100644 index 00000000000..03f88f3ba69 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-7c63-xmgg-xrx5/GHSA-7c63-xmgg-xrx5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7c63-xmgg-xrx5", + "modified": "2025-06-02T18:30:53Z", + "published": "2025-06-02T18:30:53Z", + "aliases": [ + "CVE-2025-5086" + ], + "details": "A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could lead to a remote code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5086" + }, + { + "type": "WEB", + "url": "https://www.3ds.com/vulnerability/advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-02T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-7f34-p2r4-j656/GHSA-7f34-p2r4-j656.json b/advisories/unreviewed/2025/06/GHSA-7f34-p2r4-j656/GHSA-7f34-p2r4-j656.json new file mode 100644 index 00000000000..21fdab222f6 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-7f34-p2r4-j656/GHSA-7f34-p2r4-j656.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7f34-p2r4-j656", + "modified": "2025-06-02T18:30:52Z", + "published": "2025-06-02T18:30:52Z", + "aliases": [ + "CVE-2024-7074" + ], + "details": "An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user input in SOAP admin services. A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location on the server.\n\nBy leveraging this vulnerability, an attacker could upload a specially crafted payload, potentially achieving remote code execution (RCE) on the server. Exploitation requires valid admin credentials, limiting its impact to authorized but potentially malicious users.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7074" + }, + { + "type": "WEB", + "url": "https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2025/WSO2-2024-3566" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-02T17:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-7wp3-36m3-58j5/GHSA-7wp3-36m3-58j5.json b/advisories/unreviewed/2025/06/GHSA-7wp3-36m3-58j5/GHSA-7wp3-36m3-58j5.json new file mode 100644 index 00000000000..e744af42fe2 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-7wp3-36m3-58j5/GHSA-7wp3-36m3-58j5.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7wp3-36m3-58j5", + "modified": "2025-06-02T18:30:52Z", + "published": "2025-06-02T18:30:52Z", + "aliases": [ + "CVE-2025-44115" + ], + "details": "A vulnerability has been found in Cotonti Siena v0.9.25. Affected by this vulnerability is the file /admin.php?m=config&n=edit&o=core&p=title. The manipulation of the value of title leads to cross-site scripting.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44115" + }, + { + "type": "WEB", + "url": "https://github.com/Cotonti/Cotonti/issues/1650" + }, + { + "type": "WEB", + "url": "https://github.com/Cotonti/Cotonti/issues/1834" + }, + { + "type": "WEB", + "url": "https://gist.github.com/yA0-Z/9666b1a333607381ab8dfcc137f2b65c" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-02T16:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-8ghf-hrfq-8q3j/GHSA-8ghf-hrfq-8q3j.json b/advisories/unreviewed/2025/06/GHSA-8ghf-hrfq-8q3j/GHSA-8ghf-hrfq-8q3j.json new file mode 100644 index 00000000000..45dbfb141d7 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-8ghf-hrfq-8q3j/GHSA-8ghf-hrfq-8q3j.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8ghf-hrfq-8q3j", + "modified": "2025-06-02T18:30:52Z", + "published": "2025-06-02T18:30:52Z", + "aliases": [ + "CVE-2024-57459" + ], + "details": "A time-based SQL injection vulnerability exists in mydetailsstudent.php in the CloudClassroom PHP Project 1.0. The myds parameter does not properly validate user input, allowing an attacker to inject arbitrary SQL commands.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57459" + }, + { + "type": "WEB", + "url": "https://gist.github.com/b0mk35h/921cfa00f9ea1af66645574537d38587" + }, + { + "type": "WEB", + "url": "https://owasp.org/www-community/attacks/SQL_Injection" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-02T16:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-8j8w-wwqc-x596/GHSA-8j8w-wwqc-x596.json b/advisories/unreviewed/2025/06/GHSA-8j8w-wwqc-x596/GHSA-8j8w-wwqc-x596.json index c5f2caf5fa3..7a5e965d1ab 100644 --- a/advisories/unreviewed/2025/06/GHSA-8j8w-wwqc-x596/GHSA-8j8w-wwqc-x596.json +++ b/advisories/unreviewed/2025/06/GHSA-8j8w-wwqc-x596/GHSA-8j8w-wwqc-x596.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8j8w-wwqc-x596", - "modified": "2025-06-02T15:31:21Z", + "modified": "2025-06-02T18:30:43Z", "published": "2025-06-02T06:30:32Z", "aliases": [ "CVE-2025-49113" @@ -50,6 +50,10 @@ { "type": "WEB", "url": "https://roundcube.net/news/2025/06/01/security-updates-1.6.11-and-1.5.10" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/06/02/3" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/06/GHSA-cp5v-2hmc-3vjx/GHSA-cp5v-2hmc-3vjx.json b/advisories/unreviewed/2025/06/GHSA-cp5v-2hmc-3vjx/GHSA-cp5v-2hmc-3vjx.json new file mode 100644 index 00000000000..08069408340 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-cp5v-2hmc-3vjx/GHSA-cp5v-2hmc-3vjx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cp5v-2hmc-3vjx", + "modified": "2025-06-02T18:30:52Z", + "published": "2025-06-02T18:30:52Z", + "aliases": [ + "CVE-2024-1440" + ], + "details": "An open redirection vulnerability exists in multiple WSO2 products due to improper validation of the multi-option URL in the authentication endpoint when multi-option authentication is enabled. A malicious actor can craft a valid link that redirects users to an attacker-controlled site.\n\nBy exploiting this vulnerability, an attacker may trick users into visiting a malicious page, enabling phishing attacks to harvest sensitive information or perform other harmful actions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1440" + }, + { + "type": "WEB", + "url": "https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2024-3171" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-02T17:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-cwjc-83cr-56p7/GHSA-cwjc-83cr-56p7.json b/advisories/unreviewed/2025/06/GHSA-cwjc-83cr-56p7/GHSA-cwjc-83cr-56p7.json index d245682b2a0..7d07af37079 100644 --- a/advisories/unreviewed/2025/06/GHSA-cwjc-83cr-56p7/GHSA-cwjc-83cr-56p7.json +++ b/advisories/unreviewed/2025/06/GHSA-cwjc-83cr-56p7/GHSA-cwjc-83cr-56p7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cwjc-83cr-56p7", - "modified": "2025-06-02T06:30:32Z", + "modified": "2025-06-02T18:30:44Z", "published": "2025-06-02T06:30:32Z", "aliases": [ "CVE-2025-3951" ], "details": "The WP-Optimize WordPress plugin before 4.2.0 does not properly escape user input when checking image compression statuses, which could allow users with the administrator role to conduct SQL Injection attacks in the context of Multi-Site WordPress configurations.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-02T06:15:20Z" diff --git a/advisories/unreviewed/2025/06/GHSA-f2rq-qhqv-93pg/GHSA-f2rq-qhqv-93pg.json b/advisories/unreviewed/2025/06/GHSA-f2rq-qhqv-93pg/GHSA-f2rq-qhqv-93pg.json new file mode 100644 index 00000000000..39e9f44df67 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-f2rq-qhqv-93pg/GHSA-f2rq-qhqv-93pg.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f2rq-qhqv-93pg", + "modified": "2025-06-02T18:30:52Z", + "published": "2025-06-02T18:30:52Z", + "aliases": [ + "CVE-2025-27955" + ], + "details": "Clinical Collaboration Platform 12.2.1.5 has a weak logout system where the session token remains valid after logout and allows a remote attacker to obtain sensitive information and execute arbitrary code.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27955" + }, + { + "type": "WEB", + "url": "https://github.com/intruderlabs/cvex/tree/main/Carestream/session-token-in-url" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-02T18:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-fg83-j4cx-5cww/GHSA-fg83-j4cx-5cww.json b/advisories/unreviewed/2025/06/GHSA-fg83-j4cx-5cww/GHSA-fg83-j4cx-5cww.json new file mode 100644 index 00000000000..049ac915a38 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-fg83-j4cx-5cww/GHSA-fg83-j4cx-5cww.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fg83-j4cx-5cww", + "modified": "2025-06-02T18:30:52Z", + "published": "2025-06-02T18:30:52Z", + "aliases": [ + "CVE-2025-27954" + ], + "details": "An issue in Clinical Collaboration Platform 12.2.1.5 allows a remote attacker to obtain sensitive information and execute arbitrary code via the usertoken function of default.aspx.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27954" + }, + { + "type": "WEB", + "url": "https://github.com/intruderlabs/cvex/tree/main/Carestream/session-token-in-url" + }, + { + "type": "WEB", + "url": "https://portswigger.net/kb/issues/00500700_session-token-in-url" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-02T18:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-fxp8-rw49-cf65/GHSA-fxp8-rw49-cf65.json b/advisories/unreviewed/2025/06/GHSA-fxp8-rw49-cf65/GHSA-fxp8-rw49-cf65.json index ca1af8200b6..58c85f4d658 100644 --- a/advisories/unreviewed/2025/06/GHSA-fxp8-rw49-cf65/GHSA-fxp8-rw49-cf65.json +++ b/advisories/unreviewed/2025/06/GHSA-fxp8-rw49-cf65/GHSA-fxp8-rw49-cf65.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fxp8-rw49-cf65", - "modified": "2025-06-02T03:30:24Z", + "modified": "2025-06-02T18:30:42Z", "published": "2025-06-02T03:30:24Z", "aliases": [ "CVE-2025-20678" ], "details": "In ims service, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01394606; Issue ID: MSV-2739.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-674" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-02T03:15:25Z" diff --git a/advisories/unreviewed/2025/06/GHSA-g9qh-c549-gj4x/GHSA-g9qh-c549-gj4x.json b/advisories/unreviewed/2025/06/GHSA-g9qh-c549-gj4x/GHSA-g9qh-c549-gj4x.json index fed73acbda7..26127f22273 100644 --- a/advisories/unreviewed/2025/06/GHSA-g9qh-c549-gj4x/GHSA-g9qh-c549-gj4x.json +++ b/advisories/unreviewed/2025/06/GHSA-g9qh-c549-gj4x/GHSA-g9qh-c549-gj4x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g9qh-c549-gj4x", - "modified": "2025-06-02T15:31:24Z", + "modified": "2025-06-02T18:30:50Z", "published": "2025-06-02T15:31:24Z", "aliases": [ "CVE-2025-37093" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-287" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/06/GHSA-gvwx-c268-xr4p/GHSA-gvwx-c268-xr4p.json b/advisories/unreviewed/2025/06/GHSA-gvwx-c268-xr4p/GHSA-gvwx-c268-xr4p.json new file mode 100644 index 00000000000..c269b228025 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-gvwx-c268-xr4p/GHSA-gvwx-c268-xr4p.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gvwx-c268-xr4p", + "modified": "2025-06-02T18:30:52Z", + "published": "2025-06-02T18:30:52Z", + "aliases": [ + "CVE-2025-27953" + ], + "details": "An issue in Clinical Collaboration Platform 12.2.1.5 allows a remote attacker to obtain sensitive information and execute arbitrary code via the session management component.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27953" + }, + { + "type": "WEB", + "url": "https://github.com/intruderlabs/cvex/tree/main/Carestream/session-token-in-url" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-02T18:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-h628-q67p-f6w4/GHSA-h628-q67p-f6w4.json b/advisories/unreviewed/2025/06/GHSA-h628-q67p-f6w4/GHSA-h628-q67p-f6w4.json index 4f68859722c..b1545fc6edb 100644 --- a/advisories/unreviewed/2025/06/GHSA-h628-q67p-f6w4/GHSA-h628-q67p-f6w4.json +++ b/advisories/unreviewed/2025/06/GHSA-h628-q67p-f6w4/GHSA-h628-q67p-f6w4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h628-q67p-f6w4", - "modified": "2025-06-02T15:31:25Z", + "modified": "2025-06-02T18:30:51Z", "published": "2025-06-02T15:31:25Z", "aliases": [ "CVE-2024-54028" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2132" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2132" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/06/GHSA-hh39-985p-g37g/GHSA-hh39-985p-g37g.json b/advisories/unreviewed/2025/06/GHSA-hh39-985p-g37g/GHSA-hh39-985p-g37g.json new file mode 100644 index 00000000000..e6425321ec7 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-hh39-985p-g37g/GHSA-hh39-985p-g37g.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hh39-985p-g37g", + "modified": "2025-06-02T18:30:51Z", + "published": "2025-06-02T18:30:51Z", + "aliases": [ + "CVE-2024-40114" + ], + "details": "A Cross Site Scripting (XSS) vulnerability in Sitecom WLX-2006 Wall Mount Range Extender N300 v1.5 and before allows an attacker to manipulate the language cookie to inject malicious JavaScript code.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40114" + }, + { + "type": "WEB", + "url": "https://github.com/Emm448/vulnerability-research/tree/main/CVE-2024-40114" + }, + { + "type": "WEB", + "url": "http://www.sitecomlearningcentre.com/products/wlx-2006v1001/wi-fi-range-extender-n300/downloads" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-02T16:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-hw75-9xrf-7fg8/GHSA-hw75-9xrf-7fg8.json b/advisories/unreviewed/2025/06/GHSA-hw75-9xrf-7fg8/GHSA-hw75-9xrf-7fg8.json index a21a52b0d91..d1105705c42 100644 --- a/advisories/unreviewed/2025/06/GHSA-hw75-9xrf-7fg8/GHSA-hw75-9xrf-7fg8.json +++ b/advisories/unreviewed/2025/06/GHSA-hw75-9xrf-7fg8/GHSA-hw75-9xrf-7fg8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hw75-9xrf-7fg8", - "modified": "2025-06-02T03:30:23Z", + "modified": "2025-06-02T18:30:42Z", "published": "2025-06-02T03:30:23Z", "aliases": [ "CVE-2025-20672" ], "details": "In Bluetooth driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00412257; Issue ID: MSV-3292.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-122" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-02T03:15:24Z" diff --git a/advisories/unreviewed/2025/06/GHSA-j3qf-mq3f-rgcf/GHSA-j3qf-mq3f-rgcf.json b/advisories/unreviewed/2025/06/GHSA-j3qf-mq3f-rgcf/GHSA-j3qf-mq3f-rgcf.json new file mode 100644 index 00000000000..2c499cfcac5 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-j3qf-mq3f-rgcf/GHSA-j3qf-mq3f-rgcf.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j3qf-mq3f-rgcf", + "modified": "2025-06-02T18:30:51Z", + "published": "2025-06-02T18:30:51Z", + "aliases": [ + "CVE-2024-40112" + ], + "details": "A Local File Inclusion (LFI) vulnerability exists in Sitecom WLX-2006 Wall Mount Range Extender N300 v1.5 and before, which allows an attacker to manipulate the \"language\" cookie to include arbitrary files from the server. This vulnerability can be exploited to disclose sensitive information.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40112" + }, + { + "type": "WEB", + "url": "https://github.com/Emm448/vulnerability-research/tree/main/CVE-2024-40112" + }, + { + "type": "WEB", + "url": "http://www.sitecomlearningcentre.com/products/wlx-2006v1001/wi-fi-range-extender-n300/downloads" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-02T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-jqw7-hgh5-2ppr/GHSA-jqw7-hgh5-2ppr.json b/advisories/unreviewed/2025/06/GHSA-jqw7-hgh5-2ppr/GHSA-jqw7-hgh5-2ppr.json new file mode 100644 index 00000000000..ca82acc90d6 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-jqw7-hgh5-2ppr/GHSA-jqw7-hgh5-2ppr.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jqw7-hgh5-2ppr", + "modified": "2025-06-02T18:30:52Z", + "published": "2025-06-02T18:30:52Z", + "aliases": [ + "CVE-2025-23104" + ], + "details": "An issue was discovered in Samsung Mobile Processor Exynos 2200, 1480, and 2400. A Use-After-Free in the mobile processor leads to privilege escalation.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23104" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2025-23104" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-02T18:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-jvhv-7727-rf3v/GHSA-jvhv-7727-rf3v.json b/advisories/unreviewed/2025/06/GHSA-jvhv-7727-rf3v/GHSA-jvhv-7727-rf3v.json new file mode 100644 index 00000000000..8785f8103ff --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-jvhv-7727-rf3v/GHSA-jvhv-7727-rf3v.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jvhv-7727-rf3v", + "modified": "2025-06-02T18:30:52Z", + "published": "2025-06-02T18:30:52Z", + "aliases": [ + "CVE-2025-45542" + ], + "details": "SQL injection vulnerability in the registrationform endpoint of CloudClassroom-PHP-Project v1.0. The pass parameter is vulnerable due to improper input validation, allowing attackers to inject SQL queries.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45542" + }, + { + "type": "WEB", + "url": "https://github.com/mathurvishal/CloudClassroom-PHP-Project" + }, + { + "type": "WEB", + "url": "https://medium.com/@sanjay70023/cve-2025-45542-time-based-blind-sql-injection-in-cloudclassroom-php-project-v1-0-1fa0efc8a94a" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-02T16:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-jwc3-6wrj-fj5w/GHSA-jwc3-6wrj-fj5w.json b/advisories/unreviewed/2025/06/GHSA-jwc3-6wrj-fj5w/GHSA-jwc3-6wrj-fj5w.json new file mode 100644 index 00000000000..87e58f1ec1d --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-jwc3-6wrj-fj5w/GHSA-jwc3-6wrj-fj5w.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jwc3-6wrj-fj5w", + "modified": "2025-06-02T18:30:53Z", + "published": "2025-06-02T18:30:52Z", + "aliases": [ + "CVE-2025-27956" + ], + "details": "Directory Traversal vulnerability in WebLaudos 24.2 (04) allows a remote attacker to obtain sensitive information via the id parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27956" + }, + { + "type": "WEB", + "url": "https://github.com/intruderlabs/cvex/blob/main/Pixeon/WebLaudos/Directory-Traversal/README.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-02T18:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-mc52-7658-v986/GHSA-mc52-7658-v986.json b/advisories/unreviewed/2025/06/GHSA-mc52-7658-v986/GHSA-mc52-7658-v986.json new file mode 100644 index 00000000000..964e634d72a --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-mc52-7658-v986/GHSA-mc52-7658-v986.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mc52-7658-v986", + "modified": "2025-06-02T18:30:53Z", + "published": "2025-06-02T18:30:53Z", + "aliases": [ + "CVE-2025-45387" + ], + "details": "osTicket prior to v1.17.6 and v1.18.2 are vulnerable to Broken Access Control Vulnerability in /scp/ajax.php.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45387" + }, + { + "type": "WEB", + "url": "https://github.com/osTicket/osTicket/pull/6802/commits/ab6672faa0991de305d4b90a3faa2e3cebdd23c8" + }, + { + "type": "WEB", + "url": "https://github.com/UmerAdeemCheema/CVE-Security-Research/blob/main/OSTicket/Unauthorized%20Access%20to%20Ajax%20Functions.md" + }, + { + "type": "WEB", + "url": "https://github.com/osTicket/osTicket" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-02T18:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-mxj6-x52w-4g7m/GHSA-mxj6-x52w-4g7m.json b/advisories/unreviewed/2025/06/GHSA-mxj6-x52w-4g7m/GHSA-mxj6-x52w-4g7m.json index f0603567ef7..5f726c18f44 100644 --- a/advisories/unreviewed/2025/06/GHSA-mxj6-x52w-4g7m/GHSA-mxj6-x52w-4g7m.json +++ b/advisories/unreviewed/2025/06/GHSA-mxj6-x52w-4g7m/GHSA-mxj6-x52w-4g7m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mxj6-x52w-4g7m", - "modified": "2025-06-02T03:30:23Z", + "modified": "2025-06-02T18:30:42Z", "published": "2025-06-02T03:30:23Z", "aliases": [ "CVE-2025-20674" ], "details": "In wlan AP driver, there is a possible way to inject arbitrary packet due to a missing permission check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00413202; Issue ID: MSV-3303.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-863" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-02T03:15:24Z" diff --git a/advisories/unreviewed/2025/06/GHSA-pf22-rv2m-7xj7/GHSA-pf22-rv2m-7xj7.json b/advisories/unreviewed/2025/06/GHSA-pf22-rv2m-7xj7/GHSA-pf22-rv2m-7xj7.json index c2fb6c23862..fe510446750 100644 --- a/advisories/unreviewed/2025/06/GHSA-pf22-rv2m-7xj7/GHSA-pf22-rv2m-7xj7.json +++ b/advisories/unreviewed/2025/06/GHSA-pf22-rv2m-7xj7/GHSA-pf22-rv2m-7xj7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pf22-rv2m-7xj7", - "modified": "2025-06-02T15:31:24Z", + "modified": "2025-06-02T18:30:50Z", "published": "2025-06-02T15:31:24Z", "aliases": [ "CVE-2025-37094" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-22" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/06/GHSA-qj64-gvr6-h7qx/GHSA-qj64-gvr6-h7qx.json b/advisories/unreviewed/2025/06/GHSA-qj64-gvr6-h7qx/GHSA-qj64-gvr6-h7qx.json index e9f6a4c3fe2..457c6b1300b 100644 --- a/advisories/unreviewed/2025/06/GHSA-qj64-gvr6-h7qx/GHSA-qj64-gvr6-h7qx.json +++ b/advisories/unreviewed/2025/06/GHSA-qj64-gvr6-h7qx/GHSA-qj64-gvr6-h7qx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qj64-gvr6-h7qx", - "modified": "2025-06-02T15:31:24Z", + "modified": "2025-06-02T18:30:49Z", "published": "2025-06-02T15:31:24Z", "aliases": [ "CVE-2025-37090" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-918" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/06/GHSA-qw96-3vm7-2xqg/GHSA-qw96-3vm7-2xqg.json b/advisories/unreviewed/2025/06/GHSA-qw96-3vm7-2xqg/GHSA-qw96-3vm7-2xqg.json index 2a79c696782..445d0b2c251 100644 --- a/advisories/unreviewed/2025/06/GHSA-qw96-3vm7-2xqg/GHSA-qw96-3vm7-2xqg.json +++ b/advisories/unreviewed/2025/06/GHSA-qw96-3vm7-2xqg/GHSA-qw96-3vm7-2xqg.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-77" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/06/GHSA-qxm6-r385-gmwp/GHSA-qxm6-r385-gmwp.json b/advisories/unreviewed/2025/06/GHSA-qxm6-r385-gmwp/GHSA-qxm6-r385-gmwp.json index d5a260f00f7..37b0295b026 100644 --- a/advisories/unreviewed/2025/06/GHSA-qxm6-r385-gmwp/GHSA-qxm6-r385-gmwp.json +++ b/advisories/unreviewed/2025/06/GHSA-qxm6-r385-gmwp/GHSA-qxm6-r385-gmwp.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-77" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/06/GHSA-rhfv-c52c-x747/GHSA-rhfv-c52c-x747.json b/advisories/unreviewed/2025/06/GHSA-rhfv-c52c-x747/GHSA-rhfv-c52c-x747.json new file mode 100644 index 00000000000..c00b66b5ce3 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-rhfv-c52c-x747/GHSA-rhfv-c52c-x747.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rhfv-c52c-x747", + "modified": "2025-06-02T18:30:52Z", + "published": "2025-06-02T18:30:52Z", + "aliases": [ + "CVE-2025-5036" + ], + "details": "A maliciously crafted RFA file, when linked or imported into Autodesk Revit, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5036" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0009" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-02T17:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-v8mm-64rg-m2wg/GHSA-v8mm-64rg-m2wg.json b/advisories/unreviewed/2025/06/GHSA-v8mm-64rg-m2wg/GHSA-v8mm-64rg-m2wg.json index 271cb645d9f..bedcd9c2730 100644 --- a/advisories/unreviewed/2025/06/GHSA-v8mm-64rg-m2wg/GHSA-v8mm-64rg-m2wg.json +++ b/advisories/unreviewed/2025/06/GHSA-v8mm-64rg-m2wg/GHSA-v8mm-64rg-m2wg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v8mm-64rg-m2wg", - "modified": "2025-06-02T06:30:32Z", + "modified": "2025-06-02T18:30:43Z", "published": "2025-06-02T06:30:32Z", "aliases": [ "CVE-2025-1485" ], "details": "The Real Cookie Banner: GDPR & ePrivacy Cookie Consent WordPress plugin before 5.1.6, real-cookie-banner-pro WordPress plugin before 5.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-02T06:15:20Z" diff --git a/advisories/unreviewed/2025/06/GHSA-vpgx-c322-qgw5/GHSA-vpgx-c322-qgw5.json b/advisories/unreviewed/2025/06/GHSA-vpgx-c322-qgw5/GHSA-vpgx-c322-qgw5.json index 2198a9b475a..7b0aa943bc2 100644 --- a/advisories/unreviewed/2025/06/GHSA-vpgx-c322-qgw5/GHSA-vpgx-c322-qgw5.json +++ b/advisories/unreviewed/2025/06/GHSA-vpgx-c322-qgw5/GHSA-vpgx-c322-qgw5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vpgx-c322-qgw5", - "modified": "2025-06-02T15:31:25Z", + "modified": "2025-06-02T18:30:51Z", "published": "2025-06-02T15:31:25Z", "aliases": [ "CVE-2024-52035" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2131" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2131" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/06/GHSA-x223-vrgf-8f8m/GHSA-x223-vrgf-8f8m.json b/advisories/unreviewed/2025/06/GHSA-x223-vrgf-8f8m/GHSA-x223-vrgf-8f8m.json new file mode 100644 index 00000000000..f61e1514158 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-x223-vrgf-8f8m/GHSA-x223-vrgf-8f8m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x223-vrgf-8f8m", + "modified": "2025-06-02T18:30:52Z", + "published": "2025-06-02T18:30:52Z", + "aliases": [ + "CVE-2024-3509" + ], + "details": "A stored cross-site scripting (XSS) vulnerability exists in the Management Console of multiple WSO2 products due to insufficient input validation in the Rich Text Editor within the registry section.\nTo exploit this vulnerability, a malicious actor must have a valid user account with administrative access to the Management Console. If successful, the actor could inject persistent JavaScript payloads, enabling the theft of user data or execution of unauthorized actions on behalf of other users.\n\nWhile this issue enables persistent client-side script execution, session-related cookies remain protected with the httpOnly flag, preventing session hijacking.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3509" + }, + { + "type": "WEB", + "url": "https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2024-2701" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-02T17:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-xpxp-r8hf-wgf6/GHSA-xpxp-r8hf-wgf6.json b/advisories/unreviewed/2025/06/GHSA-xpxp-r8hf-wgf6/GHSA-xpxp-r8hf-wgf6.json new file mode 100644 index 00000000000..75c14b8bdd1 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-xpxp-r8hf-wgf6/GHSA-xpxp-r8hf-wgf6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xpxp-r8hf-wgf6", + "modified": "2025-06-02T18:30:52Z", + "published": "2025-06-02T18:30:52Z", + "aliases": [ + "CVE-2024-8008" + ], + "details": "A reflected cross-site scripting (XSS) vulnerability exists in multiple [Vendor Name] products due to insufficient output encoding in error messages generated by the JDBC user store connection validation request. A malicious actor can inject a specially crafted payload into the request, causing the browser to execute arbitrary JavaScript in the context of the vulnerable page.\n\nThis vulnerability may allow UI manipulation, redirection to malicious websites, or data exfiltration from the browser. However, since all session-related sensitive cookies are protected with the httpOnly flag, session hijacking is not possible.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8008" + }, + { + "type": "WEB", + "url": "https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2025/WSO2-2024-3178" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-02T17:15:36Z" + } +} \ No newline at end of file