From bf9ba22d67e2e812ebea8de9585beeb6599db261 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 14 May 2025 15:32:47 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-32f7-x79r-fq9w.json | 2 +- .../GHSA-47r6-x4q8-pv4h.json | 2 +- .../GHSA-4r2p-352m-7q6g.json | 2 +- .../GHSA-6xc3-9629-w8h2.json | 6 +- .../GHSA-9xwc-9mfx-fvvq.json | 4 +- .../GHSA-m7f3-552r-pf23.json | 1 + .../GHSA-m8qv-r68j-xjrq.json | 6 +- .../GHSA-pf3v-gc23-99hq.json | 2 +- .../GHSA-pghj-qv6p-rgx5.json | 2 +- .../GHSA-qjvr-7h9f-927v.json | 2 +- .../GHSA-qr89-xx7m-9qx6.json | 6 +- .../GHSA-w789-m2hg-5x2h.json | 2 +- .../GHSA-w7mc-j82q-7jh2.json | 2 +- .../GHSA-g3gr-qpxc-qc6c.json | 6 +- .../GHSA-32wh-2cq7-f29f.json | 3 +- .../GHSA-5jw5-2rj7-x547.json | 4 +- .../GHSA-7jjg-gm2c-94v7.json | 4 +- .../GHSA-929x-9cm9-h83r.json | 4 +- .../GHSA-m7mh-v3gj-99xr.json | 4 +- .../GHSA-pjm4-fjw9-x2fh.json | 4 +- .../GHSA-24m8-vx7p-q7mf.json | 4 +- .../GHSA-2jv4-86qg-m23h.json | 4 +- .../GHSA-7mxj-3f68-p2v6.json | 4 +- .../GHSA-c797-jx9v-f674.json | 4 +- .../GHSA-ppp4-p6wj-8gp8.json | 4 +- .../GHSA-h7hv-3j2q-qw9g.json | 4 +- .../GHSA-rgpp-94g2-9xpm.json | 3 +- .../GHSA-43qr-pjmr-cgfv.json | 40 +++++++++++++ .../GHSA-535q-vmc8-386p.json | 15 +++-- .../GHSA-53jv-fmw5-42vr.json | 15 +++-- .../GHSA-5cw9-h2jj-8927.json | 15 +++-- .../GHSA-6442-5647-jqwc.json | 25 ++++++++ .../GHSA-69gm-vfv3-578x.json | 36 ++++++++++++ .../GHSA-6v8w-jmjm-w8cq.json | 36 ++++++++++++ .../GHSA-7gp9-jx5j-42cf.json | 57 +++++++++++++++++++ .../GHSA-8g7p-xh7p-947j.json | 36 ++++++++++++ .../GHSA-98m8-9qp9-q867.json | 15 +++-- .../GHSA-c46v-w72p-r2mx.json | 15 +++-- .../GHSA-cp2m-j67p-96qc.json | 15 +++-- .../GHSA-cxpp-jwcw-w84c.json | 15 +++-- .../GHSA-f4rq-f4j9-f6rm.json | 15 +++-- .../GHSA-fx6v-jrpq-f762.json | 40 +++++++++++++ .../GHSA-g47c-fvq8-4266.json | 15 +++-- .../GHSA-gphm-c4cj-h98g.json | 15 +++-- .../GHSA-gv5r-9gxr-v74w.json | 15 +++-- .../GHSA-h347-278r-gx23.json | 15 +++-- .../GHSA-h527-m3cp-9hm7.json | 44 ++++++++++++++ .../GHSA-jgxh-h9f6-9wh2.json | 15 +++-- .../GHSA-m3hm-6gqp-pf9f.json | 6 +- .../GHSA-m49r-wcx2-5jg3.json | 15 +++-- .../GHSA-mv5r-fm5f-wm4v.json | 15 +++-- .../GHSA-q3wm-48q6-668m.json | 15 +++-- .../GHSA-qqcr-9jfc-35c4.json | 15 +++-- .../GHSA-qqq6-x3jw-9c7x.json | 15 +++-- .../GHSA-rcw6-7x98-m9g9.json | 15 +++-- .../GHSA-rvh4-h7j5-46g3.json | 2 +- .../GHSA-v2qw-mwg5-px4g.json | 15 +++-- .../GHSA-v5vr-7qc6-xw56.json | 40 +++++++++++++ .../GHSA-v7m3-xggw-4h6v.json | 15 +++-- .../GHSA-vghf-926w-cc55.json | 15 +++-- .../GHSA-xf4q-c7gc-gpgr.json | 15 +++-- 61 files changed, 679 insertions(+), 123 deletions(-) create mode 100644 advisories/unreviewed/2025/05/GHSA-43qr-pjmr-cgfv/GHSA-43qr-pjmr-cgfv.json create mode 100644 advisories/unreviewed/2025/05/GHSA-6442-5647-jqwc/GHSA-6442-5647-jqwc.json create mode 100644 advisories/unreviewed/2025/05/GHSA-69gm-vfv3-578x/GHSA-69gm-vfv3-578x.json create mode 100644 advisories/unreviewed/2025/05/GHSA-6v8w-jmjm-w8cq/GHSA-6v8w-jmjm-w8cq.json create mode 100644 advisories/unreviewed/2025/05/GHSA-7gp9-jx5j-42cf/GHSA-7gp9-jx5j-42cf.json create mode 100644 advisories/unreviewed/2025/05/GHSA-8g7p-xh7p-947j/GHSA-8g7p-xh7p-947j.json create mode 100644 advisories/unreviewed/2025/05/GHSA-fx6v-jrpq-f762/GHSA-fx6v-jrpq-f762.json create mode 100644 advisories/unreviewed/2025/05/GHSA-h527-m3cp-9hm7/GHSA-h527-m3cp-9hm7.json create mode 100644 advisories/unreviewed/2025/05/GHSA-v5vr-7qc6-xw56/GHSA-v5vr-7qc6-xw56.json diff --git a/advisories/unreviewed/2022/10/GHSA-32f7-x79r-fq9w/GHSA-32f7-x79r-fq9w.json b/advisories/unreviewed/2022/10/GHSA-32f7-x79r-fq9w/GHSA-32f7-x79r-fq9w.json index 039ad608832..699213b1e8d 100644 --- a/advisories/unreviewed/2022/10/GHSA-32f7-x79r-fq9w/GHSA-32f7-x79r-fq9w.json +++ b/advisories/unreviewed/2022/10/GHSA-32f7-x79r-fq9w/GHSA-32f7-x79r-fq9w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-32f7-x79r-fq9w", - "modified": "2022-10-18T19:00:32Z", + "modified": "2025-05-14T15:31:30Z", "published": "2022-10-14T19:00:39Z", "aliases": [ "CVE-2022-41583" diff --git a/advisories/unreviewed/2022/10/GHSA-47r6-x4q8-pv4h/GHSA-47r6-x4q8-pv4h.json b/advisories/unreviewed/2022/10/GHSA-47r6-x4q8-pv4h/GHSA-47r6-x4q8-pv4h.json index a9374ee915d..7bdbebe3f5e 100644 --- a/advisories/unreviewed/2022/10/GHSA-47r6-x4q8-pv4h/GHSA-47r6-x4q8-pv4h.json +++ b/advisories/unreviewed/2022/10/GHSA-47r6-x4q8-pv4h/GHSA-47r6-x4q8-pv4h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-47r6-x4q8-pv4h", - "modified": "2022-10-15T12:00:55Z", + "modified": "2025-05-14T15:31:31Z", "published": "2022-10-14T19:00:39Z", "aliases": [ "CVE-2022-41600" diff --git a/advisories/unreviewed/2022/10/GHSA-4r2p-352m-7q6g/GHSA-4r2p-352m-7q6g.json b/advisories/unreviewed/2022/10/GHSA-4r2p-352m-7q6g/GHSA-4r2p-352m-7q6g.json index bc238ba9d21..dfb6aa2df0f 100644 --- a/advisories/unreviewed/2022/10/GHSA-4r2p-352m-7q6g/GHSA-4r2p-352m-7q6g.json +++ b/advisories/unreviewed/2022/10/GHSA-4r2p-352m-7q6g/GHSA-4r2p-352m-7q6g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4r2p-352m-7q6g", - "modified": "2022-10-15T12:00:55Z", + "modified": "2025-05-14T15:31:30Z", "published": "2022-10-14T19:00:39Z", "aliases": [ "CVE-2022-41577" diff --git a/advisories/unreviewed/2022/10/GHSA-6xc3-9629-w8h2/GHSA-6xc3-9629-w8h2.json b/advisories/unreviewed/2022/10/GHSA-6xc3-9629-w8h2/GHSA-6xc3-9629-w8h2.json index be61a470642..7ec8fc7734d 100644 --- a/advisories/unreviewed/2022/10/GHSA-6xc3-9629-w8h2/GHSA-6xc3-9629-w8h2.json +++ b/advisories/unreviewed/2022/10/GHSA-6xc3-9629-w8h2/GHSA-6xc3-9629-w8h2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6xc3-9629-w8h2", - "modified": "2022-10-18T19:00:31Z", + "modified": "2025-05-14T15:31:30Z", "published": "2022-10-14T19:00:39Z", "aliases": [ "CVE-2022-41582" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-15" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-9xwc-9mfx-fvvq/GHSA-9xwc-9mfx-fvvq.json b/advisories/unreviewed/2022/10/GHSA-9xwc-9mfx-fvvq/GHSA-9xwc-9mfx-fvvq.json index 9a9297ff75b..1f1b8595fd6 100644 --- a/advisories/unreviewed/2022/10/GHSA-9xwc-9mfx-fvvq/GHSA-9xwc-9mfx-fvvq.json +++ b/advisories/unreviewed/2022/10/GHSA-9xwc-9mfx-fvvq/GHSA-9xwc-9mfx-fvvq.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-285" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-m7f3-552r-pf23/GHSA-m7f3-552r-pf23.json b/advisories/unreviewed/2022/10/GHSA-m7f3-552r-pf23/GHSA-m7f3-552r-pf23.json index 60a2d234d6b..76844956369 100644 --- a/advisories/unreviewed/2022/10/GHSA-m7f3-552r-pf23/GHSA-m7f3-552r-pf23.json +++ b/advisories/unreviewed/2022/10/GHSA-m7f3-552r-pf23/GHSA-m7f3-552r-pf23.json @@ -38,6 +38,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-74", "CWE-77" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/10/GHSA-m8qv-r68j-xjrq/GHSA-m8qv-r68j-xjrq.json b/advisories/unreviewed/2022/10/GHSA-m8qv-r68j-xjrq/GHSA-m8qv-r68j-xjrq.json index 99437364675..30875c16407 100644 --- a/advisories/unreviewed/2022/10/GHSA-m8qv-r68j-xjrq/GHSA-m8qv-r68j-xjrq.json +++ b/advisories/unreviewed/2022/10/GHSA-m8qv-r68j-xjrq/GHSA-m8qv-r68j-xjrq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m8qv-r68j-xjrq", - "modified": "2022-10-18T19:00:31Z", + "modified": "2025-05-14T15:31:30Z", "published": "2022-10-14T19:00:39Z", "aliases": [ "CVE-2022-41581" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-125" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-pf3v-gc23-99hq/GHSA-pf3v-gc23-99hq.json b/advisories/unreviewed/2022/10/GHSA-pf3v-gc23-99hq/GHSA-pf3v-gc23-99hq.json index 31399ef6ae8..2381e847bed 100644 --- a/advisories/unreviewed/2022/10/GHSA-pf3v-gc23-99hq/GHSA-pf3v-gc23-99hq.json +++ b/advisories/unreviewed/2022/10/GHSA-pf3v-gc23-99hq/GHSA-pf3v-gc23-99hq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pf3v-gc23-99hq", - "modified": "2022-10-15T12:00:55Z", + "modified": "2025-05-14T15:31:31Z", "published": "2022-10-14T19:00:39Z", "aliases": [ "CVE-2022-41601" diff --git a/advisories/unreviewed/2022/10/GHSA-pghj-qv6p-rgx5/GHSA-pghj-qv6p-rgx5.json b/advisories/unreviewed/2022/10/GHSA-pghj-qv6p-rgx5/GHSA-pghj-qv6p-rgx5.json index 9ea28e54f36..694e7f7a692 100644 --- a/advisories/unreviewed/2022/10/GHSA-pghj-qv6p-rgx5/GHSA-pghj-qv6p-rgx5.json +++ b/advisories/unreviewed/2022/10/GHSA-pghj-qv6p-rgx5/GHSA-pghj-qv6p-rgx5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pghj-qv6p-rgx5", - "modified": "2022-10-15T12:00:55Z", + "modified": "2025-05-14T15:31:31Z", "published": "2022-10-14T19:00:39Z", "aliases": [ "CVE-2022-41603" diff --git a/advisories/unreviewed/2022/10/GHSA-qjvr-7h9f-927v/GHSA-qjvr-7h9f-927v.json b/advisories/unreviewed/2022/10/GHSA-qjvr-7h9f-927v/GHSA-qjvr-7h9f-927v.json index fb55b20927b..6e297b70705 100644 --- a/advisories/unreviewed/2022/10/GHSA-qjvr-7h9f-927v/GHSA-qjvr-7h9f-927v.json +++ b/advisories/unreviewed/2022/10/GHSA-qjvr-7h9f-927v/GHSA-qjvr-7h9f-927v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qjvr-7h9f-927v", - "modified": "2022-10-20T19:00:36Z", + "modified": "2025-05-14T15:31:31Z", "published": "2022-10-15T12:00:54Z", "aliases": [ "CVE-2017-20149" diff --git a/advisories/unreviewed/2022/10/GHSA-qr89-xx7m-9qx6/GHSA-qr89-xx7m-9qx6.json b/advisories/unreviewed/2022/10/GHSA-qr89-xx7m-9qx6/GHSA-qr89-xx7m-9qx6.json index 0786e5f92cc..2c31814bcf7 100644 --- a/advisories/unreviewed/2022/10/GHSA-qr89-xx7m-9qx6/GHSA-qr89-xx7m-9qx6.json +++ b/advisories/unreviewed/2022/10/GHSA-qr89-xx7m-9qx6/GHSA-qr89-xx7m-9qx6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qr89-xx7m-9qx6", - "modified": "2022-10-15T12:00:55Z", + "modified": "2025-05-14T15:31:30Z", "published": "2022-10-14T19:00:39Z", "aliases": [ "CVE-2022-41576" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-w789-m2hg-5x2h/GHSA-w789-m2hg-5x2h.json b/advisories/unreviewed/2022/10/GHSA-w789-m2hg-5x2h/GHSA-w789-m2hg-5x2h.json index 8cfe5cdec31..5abf1997883 100644 --- a/advisories/unreviewed/2022/10/GHSA-w789-m2hg-5x2h/GHSA-w789-m2hg-5x2h.json +++ b/advisories/unreviewed/2022/10/GHSA-w789-m2hg-5x2h/GHSA-w789-m2hg-5x2h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w789-m2hg-5x2h", - "modified": "2022-10-18T19:00:32Z", + "modified": "2025-05-14T15:31:30Z", "published": "2022-10-14T19:00:39Z", "aliases": [ "CVE-2022-41584" diff --git a/advisories/unreviewed/2022/10/GHSA-w7mc-j82q-7jh2/GHSA-w7mc-j82q-7jh2.json b/advisories/unreviewed/2022/10/GHSA-w7mc-j82q-7jh2/GHSA-w7mc-j82q-7jh2.json index 49e3045f321..d77aeb7b171 100644 --- a/advisories/unreviewed/2022/10/GHSA-w7mc-j82q-7jh2/GHSA-w7mc-j82q-7jh2.json +++ b/advisories/unreviewed/2022/10/GHSA-w7mc-j82q-7jh2/GHSA-w7mc-j82q-7jh2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w7mc-j82q-7jh2", - "modified": "2022-10-18T19:00:32Z", + "modified": "2025-05-14T15:31:31Z", "published": "2022-10-14T19:00:39Z", "aliases": [ "CVE-2022-41585" diff --git a/advisories/unreviewed/2024/07/GHSA-g3gr-qpxc-qc6c/GHSA-g3gr-qpxc-qc6c.json b/advisories/unreviewed/2024/07/GHSA-g3gr-qpxc-qc6c/GHSA-g3gr-qpxc-qc6c.json index 81e01092e08..38e55420db5 100644 --- a/advisories/unreviewed/2024/07/GHSA-g3gr-qpxc-qc6c/GHSA-g3gr-qpxc-qc6c.json +++ b/advisories/unreviewed/2024/07/GHSA-g3gr-qpxc-qc6c/GHSA-g3gr-qpxc-qc6c.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g3gr-qpxc-qc6c", - "modified": "2024-07-11T15:30:48Z", + "modified": "2025-05-14T15:31:33Z", "published": "2024-07-10T21:30:38Z", "aliases": [ "CVE-2024-6235" ], "details": "Sensitive information disclosure in NetScaler Console", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/12/GHSA-32wh-2cq7-f29f/GHSA-32wh-2cq7-f29f.json b/advisories/unreviewed/2024/12/GHSA-32wh-2cq7-f29f/GHSA-32wh-2cq7-f29f.json index bb105a61276..d0bc3df36a1 100644 --- a/advisories/unreviewed/2024/12/GHSA-32wh-2cq7-f29f/GHSA-32wh-2cq7-f29f.json +++ b/advisories/unreviewed/2024/12/GHSA-32wh-2cq7-f29f/GHSA-32wh-2cq7-f29f.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-5jw5-2rj7-x547/GHSA-5jw5-2rj7-x547.json b/advisories/unreviewed/2024/12/GHSA-5jw5-2rj7-x547/GHSA-5jw5-2rj7-x547.json index 39470d6caa5..93efa830ab6 100644 --- a/advisories/unreviewed/2024/12/GHSA-5jw5-2rj7-x547/GHSA-5jw5-2rj7-x547.json +++ b/advisories/unreviewed/2024/12/GHSA-5jw5-2rj7-x547/GHSA-5jw5-2rj7-x547.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-7jjg-gm2c-94v7/GHSA-7jjg-gm2c-94v7.json b/advisories/unreviewed/2024/12/GHSA-7jjg-gm2c-94v7/GHSA-7jjg-gm2c-94v7.json index a8903a41027..a7a259a2672 100644 --- a/advisories/unreviewed/2024/12/GHSA-7jjg-gm2c-94v7/GHSA-7jjg-gm2c-94v7.json +++ b/advisories/unreviewed/2024/12/GHSA-7jjg-gm2c-94v7/GHSA-7jjg-gm2c-94v7.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-918" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-929x-9cm9-h83r/GHSA-929x-9cm9-h83r.json b/advisories/unreviewed/2024/12/GHSA-929x-9cm9-h83r/GHSA-929x-9cm9-h83r.json index 84cbf864c06..c900947d596 100644 --- a/advisories/unreviewed/2024/12/GHSA-929x-9cm9-h83r/GHSA-929x-9cm9-h83r.json +++ b/advisories/unreviewed/2024/12/GHSA-929x-9cm9-h83r/GHSA-929x-9cm9-h83r.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-m7mh-v3gj-99xr/GHSA-m7mh-v3gj-99xr.json b/advisories/unreviewed/2024/12/GHSA-m7mh-v3gj-99xr/GHSA-m7mh-v3gj-99xr.json index bc8d784be2d..f70148b0d57 100644 --- a/advisories/unreviewed/2024/12/GHSA-m7mh-v3gj-99xr/GHSA-m7mh-v3gj-99xr.json +++ b/advisories/unreviewed/2024/12/GHSA-m7mh-v3gj-99xr/GHSA-m7mh-v3gj-99xr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-pjm4-fjw9-x2fh/GHSA-pjm4-fjw9-x2fh.json b/advisories/unreviewed/2024/12/GHSA-pjm4-fjw9-x2fh/GHSA-pjm4-fjw9-x2fh.json index 02f2312d3b0..b4387d1bf0e 100644 --- a/advisories/unreviewed/2024/12/GHSA-pjm4-fjw9-x2fh/GHSA-pjm4-fjw9-x2fh.json +++ b/advisories/unreviewed/2024/12/GHSA-pjm4-fjw9-x2fh/GHSA-pjm4-fjw9-x2fh.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-24m8-vx7p-q7mf/GHSA-24m8-vx7p-q7mf.json b/advisories/unreviewed/2025/01/GHSA-24m8-vx7p-q7mf/GHSA-24m8-vx7p-q7mf.json index 04881894b07..d43c2affee6 100644 --- a/advisories/unreviewed/2025/01/GHSA-24m8-vx7p-q7mf/GHSA-24m8-vx7p-q7mf.json +++ b/advisories/unreviewed/2025/01/GHSA-24m8-vx7p-q7mf/GHSA-24m8-vx7p-q7mf.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-2jv4-86qg-m23h/GHSA-2jv4-86qg-m23h.json b/advisories/unreviewed/2025/01/GHSA-2jv4-86qg-m23h/GHSA-2jv4-86qg-m23h.json index e7eb3d4206d..37edafa82cf 100644 --- a/advisories/unreviewed/2025/01/GHSA-2jv4-86qg-m23h/GHSA-2jv4-86qg-m23h.json +++ b/advisories/unreviewed/2025/01/GHSA-2jv4-86qg-m23h/GHSA-2jv4-86qg-m23h.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-7mxj-3f68-p2v6/GHSA-7mxj-3f68-p2v6.json b/advisories/unreviewed/2025/01/GHSA-7mxj-3f68-p2v6/GHSA-7mxj-3f68-p2v6.json index 5ed899aa283..7005ebba5f1 100644 --- a/advisories/unreviewed/2025/01/GHSA-7mxj-3f68-p2v6/GHSA-7mxj-3f68-p2v6.json +++ b/advisories/unreviewed/2025/01/GHSA-7mxj-3f68-p2v6/GHSA-7mxj-3f68-p2v6.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-c797-jx9v-f674/GHSA-c797-jx9v-f674.json b/advisories/unreviewed/2025/01/GHSA-c797-jx9v-f674/GHSA-c797-jx9v-f674.json index 71656ef7ac4..2b61b16d47c 100644 --- a/advisories/unreviewed/2025/01/GHSA-c797-jx9v-f674/GHSA-c797-jx9v-f674.json +++ b/advisories/unreviewed/2025/01/GHSA-c797-jx9v-f674/GHSA-c797-jx9v-f674.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-ppp4-p6wj-8gp8/GHSA-ppp4-p6wj-8gp8.json b/advisories/unreviewed/2025/03/GHSA-ppp4-p6wj-8gp8/GHSA-ppp4-p6wj-8gp8.json index 8fd0579bcd1..8b909705c97 100644 --- a/advisories/unreviewed/2025/03/GHSA-ppp4-p6wj-8gp8/GHSA-ppp4-p6wj-8gp8.json +++ b/advisories/unreviewed/2025/03/GHSA-ppp4-p6wj-8gp8/GHSA-ppp4-p6wj-8gp8.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-290" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-h7hv-3j2q-qw9g/GHSA-h7hv-3j2q-qw9g.json b/advisories/unreviewed/2025/04/GHSA-h7hv-3j2q-qw9g/GHSA-h7hv-3j2q-qw9g.json index e0e58d71f50..9b53a49f5e1 100644 --- a/advisories/unreviewed/2025/04/GHSA-h7hv-3j2q-qw9g/GHSA-h7hv-3j2q-qw9g.json +++ b/advisories/unreviewed/2025/04/GHSA-h7hv-3j2q-qw9g/GHSA-h7hv-3j2q-qw9g.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-798" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-rgpp-94g2-9xpm/GHSA-rgpp-94g2-9xpm.json b/advisories/unreviewed/2025/04/GHSA-rgpp-94g2-9xpm/GHSA-rgpp-94g2-9xpm.json index fb3b1997008..c795f287a51 100644 --- a/advisories/unreviewed/2025/04/GHSA-rgpp-94g2-9xpm/GHSA-rgpp-94g2-9xpm.json +++ b/advisories/unreviewed/2025/04/GHSA-rgpp-94g2-9xpm/GHSA-rgpp-94g2-9xpm.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-43qr-pjmr-cgfv/GHSA-43qr-pjmr-cgfv.json b/advisories/unreviewed/2025/05/GHSA-43qr-pjmr-cgfv/GHSA-43qr-pjmr-cgfv.json new file mode 100644 index 00000000000..ebf46925d48 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-43qr-pjmr-cgfv/GHSA-43qr-pjmr-cgfv.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-43qr-pjmr-cgfv", + "modified": "2025-05-14T15:31:37Z", + "published": "2025-05-14T15:31:37Z", + "aliases": [ + "CVE-2024-54779" + ], + "details": "Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross Site Scripting (XSS) in widgets/log.widget.php.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54779" + }, + { + "type": "WEB", + "url": "https://blog.brillantit.com/exploiting-pfsense-xss-command-injection-cloud-hijack" + }, + { + "type": "WEB", + "url": "http://netgate.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T14:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-535q-vmc8-386p/GHSA-535q-vmc8-386p.json b/advisories/unreviewed/2025/05/GHSA-535q-vmc8-386p/GHSA-535q-vmc8-386p.json index c9451151450..8b4317db133 100644 --- a/advisories/unreviewed/2025/05/GHSA-535q-vmc8-386p/GHSA-535q-vmc8-386p.json +++ b/advisories/unreviewed/2025/05/GHSA-535q-vmc8-386p/GHSA-535q-vmc8-386p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-535q-vmc8-386p", - "modified": "2025-05-13T18:30:52Z", + "modified": "2025-05-14T15:31:37Z", "published": "2025-05-13T18:30:52Z", "aliases": [ "CVE-2025-28055" ], "details": "upset-gal-web v7.1.0 /api/music/v1/cover.ts contains an arbitrary file read vulnerabilit", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-13T16:15:28Z" diff --git a/advisories/unreviewed/2025/05/GHSA-53jv-fmw5-42vr/GHSA-53jv-fmw5-42vr.json b/advisories/unreviewed/2025/05/GHSA-53jv-fmw5-42vr/GHSA-53jv-fmw5-42vr.json index 9c1a2acd6f4..88357ed79d9 100644 --- a/advisories/unreviewed/2025/05/GHSA-53jv-fmw5-42vr/GHSA-53jv-fmw5-42vr.json +++ b/advisories/unreviewed/2025/05/GHSA-53jv-fmw5-42vr/GHSA-53jv-fmw5-42vr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-53jv-fmw5-42vr", - "modified": "2025-05-13T00:31:15Z", + "modified": "2025-05-14T15:31:36Z", "published": "2025-05-13T00:31:15Z", "aliases": [ "CVE-2025-31250" ], "details": "An information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.5. An app may be able to access sensitive user data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:25Z" diff --git a/advisories/unreviewed/2025/05/GHSA-5cw9-h2jj-8927/GHSA-5cw9-h2jj-8927.json b/advisories/unreviewed/2025/05/GHSA-5cw9-h2jj-8927/GHSA-5cw9-h2jj-8927.json index 263127ba55b..c0819ecfdca 100644 --- a/advisories/unreviewed/2025/05/GHSA-5cw9-h2jj-8927/GHSA-5cw9-h2jj-8927.json +++ b/advisories/unreviewed/2025/05/GHSA-5cw9-h2jj-8927/GHSA-5cw9-h2jj-8927.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5cw9-h2jj-8927", - "modified": "2025-05-13T21:30:53Z", + "modified": "2025-05-14T15:31:37Z", "published": "2025-05-13T21:30:53Z", "aliases": [ "CVE-2025-45863" ], "details": "TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the macstr parameter in the formMapDelDevice interface.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-13T20:15:29Z" diff --git a/advisories/unreviewed/2025/05/GHSA-6442-5647-jqwc/GHSA-6442-5647-jqwc.json b/advisories/unreviewed/2025/05/GHSA-6442-5647-jqwc/GHSA-6442-5647-jqwc.json new file mode 100644 index 00000000000..6759e010fac --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6442-5647-jqwc/GHSA-6442-5647-jqwc.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6442-5647-jqwc", + "modified": "2025-05-14T15:31:38Z", + "published": "2025-05-14T15:31:38Z", + "aliases": [ + "CVE-2025-22756" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22756" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T14:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-69gm-vfv3-578x/GHSA-69gm-vfv3-578x.json b/advisories/unreviewed/2025/05/GHSA-69gm-vfv3-578x/GHSA-69gm-vfv3-578x.json new file mode 100644 index 00000000000..7008aa77e3a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-69gm-vfv3-578x/GHSA-69gm-vfv3-578x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-69gm-vfv3-578x", + "modified": "2025-05-14T15:31:38Z", + "published": "2025-05-14T15:31:38Z", + "aliases": [ + "CVE-2024-10864" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OpenText Advance Authentication. This issue affects Advance Authentication versions before 6.5", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Green" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10864" + }, + { + "type": "WEB", + "url": "https://www.netiq.com/documentation/advanced-authentication-65/advanced-authentication-releasenotes-6.5/data/advanced-authentication-releasenotes-6.5.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T15:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6v8w-jmjm-w8cq/GHSA-6v8w-jmjm-w8cq.json b/advisories/unreviewed/2025/05/GHSA-6v8w-jmjm-w8cq/GHSA-6v8w-jmjm-w8cq.json new file mode 100644 index 00000000000..a00a9630128 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6v8w-jmjm-w8cq/GHSA-6v8w-jmjm-w8cq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6v8w-jmjm-w8cq", + "modified": "2025-05-14T15:31:38Z", + "published": "2025-05-14T15:31:38Z", + "aliases": [ + "CVE-2024-10865" + ], + "details": "Improper Input validation leads to XSS or Cross-site Scripting vulnerability in OpenText Advance Authentication. This issue affects Advance Authentication version before 6.5.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:X/V:X/RE:X/U:Amber" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10865" + }, + { + "type": "WEB", + "url": "https://www.netiq.com/documentation/advanced-authentication-65/advanced-authentication-releasenotes-6.5/data/advanced-authentication-releasenotes-6.5.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T15:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7gp9-jx5j-42cf/GHSA-7gp9-jx5j-42cf.json b/advisories/unreviewed/2025/05/GHSA-7gp9-jx5j-42cf/GHSA-7gp9-jx5j-42cf.json new file mode 100644 index 00000000000..973a7fa4ecc --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7gp9-jx5j-42cf/GHSA-7gp9-jx5j-42cf.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7gp9-jx5j-42cf", + "modified": "2025-05-14T15:31:37Z", + "published": "2025-05-14T15:31:37Z", + "aliases": [ + "CVE-2023-53146" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: dw2102: Fix null-ptr-deref in dw2102_i2c_transfer()\n\nIn dw2102_i2c_transfer, msg is controlled by user. When msg[i].buf\nis null and msg[i].len is zero, former checks on msg[i].buf would be\npassed. Malicious data finally reach dw2102_i2c_transfer. If accessing\nmsg[i].buf[0] without sanity check, null ptr deref would happen.\nWe add check on msg[i].len to prevent crash.\n\nSimilar commit:\ncommit 950e252cb469\n(\"[media] dw2102: limit messages to buffer size\")", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-53146" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/08dfcbd03b2b7f918c4f87c6ff637054e510df74" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5ae544d94abc8ff77b1b9bf8774def3fa5689b5b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/77cbd42d29de9ffc93d5529bab8813cde53af14c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/903566208ae6bb9c0e7e54355ce75bf6cf72485d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/97fdbdb750342cbc204befde976872fedb406ee6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/beb9550494e7349f92b9eaa283256a5ad9b1c9be" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ecbe6d011b95c7da59f014f8d26cb7245ed1e11e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fb28afab113a82b89ffec48c8155ec05b4f8cb5e" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T13:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8g7p-xh7p-947j/GHSA-8g7p-xh7p-947j.json b/advisories/unreviewed/2025/05/GHSA-8g7p-xh7p-947j/GHSA-8g7p-xh7p-947j.json new file mode 100644 index 00000000000..27a0d24b1d5 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8g7p-xh7p-947j/GHSA-8g7p-xh7p-947j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8g7p-xh7p-947j", + "modified": "2025-05-14T15:31:38Z", + "published": "2025-05-14T15:31:38Z", + "aliases": [ + "CVE-2025-3600" + ], + "details": "In Progress® Telerik® UI for AJAX, versions 2011.2.712 to 2025.1.218, an unsafe reflection vulnerability exists that may lead to an unhandled exception resulting in a crash of the hosting process and denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3600" + }, + { + "type": "WEB", + "url": "https://www.telerik.com/products/aspnet-ajax/documentation/knowledge-base/kb-security-unsafe-reflection-cve-2025-3600" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T14:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-98m8-9qp9-q867/GHSA-98m8-9qp9-q867.json b/advisories/unreviewed/2025/05/GHSA-98m8-9qp9-q867/GHSA-98m8-9qp9-q867.json index 1366d42cd3f..4c5a55eb4ad 100644 --- a/advisories/unreviewed/2025/05/GHSA-98m8-9qp9-q867/GHSA-98m8-9qp9-q867.json +++ b/advisories/unreviewed/2025/05/GHSA-98m8-9qp9-q867/GHSA-98m8-9qp9-q867.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-98m8-9qp9-q867", - "modified": "2025-05-13T00:31:14Z", + "modified": "2025-05-14T15:31:36Z", "published": "2025-05-13T00:31:14Z", "aliases": [ "CVE-2025-31226" ], "details": "A logic issue was addressed with improved checks. This issue is fixed in watchOS 11.5, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5. Processing a maliciously crafted image may lead to a denial-of-service.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:23Z" diff --git a/advisories/unreviewed/2025/05/GHSA-c46v-w72p-r2mx/GHSA-c46v-w72p-r2mx.json b/advisories/unreviewed/2025/05/GHSA-c46v-w72p-r2mx/GHSA-c46v-w72p-r2mx.json index 764773e187f..2cee2617c38 100644 --- a/advisories/unreviewed/2025/05/GHSA-c46v-w72p-r2mx/GHSA-c46v-w72p-r2mx.json +++ b/advisories/unreviewed/2025/05/GHSA-c46v-w72p-r2mx/GHSA-c46v-w72p-r2mx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c46v-w72p-r2mx", - "modified": "2025-05-13T00:31:15Z", + "modified": "2025-05-14T15:31:36Z", "published": "2025-05-13T00:31:15Z", "aliases": [ "CVE-2025-31251" ], "details": "The issue was addressed with improved input sanitization. This issue is fixed in watchOS 11.5, macOS Sonoma 14.7.6, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, macOS Ventura 13.7.6. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:25Z" diff --git a/advisories/unreviewed/2025/05/GHSA-cp2m-j67p-96qc/GHSA-cp2m-j67p-96qc.json b/advisories/unreviewed/2025/05/GHSA-cp2m-j67p-96qc/GHSA-cp2m-j67p-96qc.json index 6affa499ef1..cc995d88ca7 100644 --- a/advisories/unreviewed/2025/05/GHSA-cp2m-j67p-96qc/GHSA-cp2m-j67p-96qc.json +++ b/advisories/unreviewed/2025/05/GHSA-cp2m-j67p-96qc/GHSA-cp2m-j67p-96qc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cp2m-j67p-96qc", - "modified": "2025-05-13T00:31:13Z", + "modified": "2025-05-14T15:31:36Z", "published": "2025-05-13T00:31:13Z", "aliases": [ "CVE-2025-30440" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. An app may be able to bypass ASLR.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:21Z" diff --git a/advisories/unreviewed/2025/05/GHSA-cxpp-jwcw-w84c/GHSA-cxpp-jwcw-w84c.json b/advisories/unreviewed/2025/05/GHSA-cxpp-jwcw-w84c/GHSA-cxpp-jwcw-w84c.json index 91c13cc59aa..7c9e094ab33 100644 --- a/advisories/unreviewed/2025/05/GHSA-cxpp-jwcw-w84c/GHSA-cxpp-jwcw-w84c.json +++ b/advisories/unreviewed/2025/05/GHSA-cxpp-jwcw-w84c/GHSA-cxpp-jwcw-w84c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cxpp-jwcw-w84c", - "modified": "2025-05-13T21:30:54Z", + "modified": "2025-05-14T15:31:37Z", "published": "2025-05-13T21:30:53Z", "aliases": [ "CVE-2025-45861" ], "details": "TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the routername parameter in the formDnsv6 interface.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-13T19:15:51Z" diff --git a/advisories/unreviewed/2025/05/GHSA-f4rq-f4j9-f6rm/GHSA-f4rq-f4j9-f6rm.json b/advisories/unreviewed/2025/05/GHSA-f4rq-f4j9-f6rm/GHSA-f4rq-f4j9-f6rm.json index a3925c0bbe3..71b57e2204d 100644 --- a/advisories/unreviewed/2025/05/GHSA-f4rq-f4j9-f6rm/GHSA-f4rq-f4j9-f6rm.json +++ b/advisories/unreviewed/2025/05/GHSA-f4rq-f4j9-f6rm/GHSA-f4rq-f4j9-f6rm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f4rq-f4j9-f6rm", - "modified": "2025-05-14T12:31:11Z", + "modified": "2025-05-14T15:31:37Z", "published": "2025-05-14T12:31:11Z", "aliases": [ "CVE-2024-24780" ], "details": "Remote Code Execution with untrusted URI of UDF vulnerability in Apache IoTDB. The attacker who has privilege to create UDF can register malicious function from untrusted URI.\n\nThis issue affects Apache IoTDB: from 1.0.0 before 1.3.4.\n\nUsers are recommended to upgrade to version 1.3.4, which fixes the issue.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-14T11:15:47Z" diff --git a/advisories/unreviewed/2025/05/GHSA-fx6v-jrpq-f762/GHSA-fx6v-jrpq-f762.json b/advisories/unreviewed/2025/05/GHSA-fx6v-jrpq-f762/GHSA-fx6v-jrpq-f762.json new file mode 100644 index 00000000000..9614fddfb3e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fx6v-jrpq-f762/GHSA-fx6v-jrpq-f762.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fx6v-jrpq-f762", + "modified": "2025-05-14T15:31:38Z", + "published": "2025-05-14T15:31:37Z", + "aliases": [ + "CVE-2024-54780" + ], + "details": "Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget due to improper sanitization of user-supplied input to the OpenVPN management interface. An authenticated attacker can exploit this vulnerability by injecting arbitrary OpenVPN management commands via the remipp parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54780" + }, + { + "type": "WEB", + "url": "https://blog.brillantit.com/exploiting-pfsense-xss-command-injection-cloud-hijack" + }, + { + "type": "WEB", + "url": "http://netgate.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T14:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g47c-fvq8-4266/GHSA-g47c-fvq8-4266.json b/advisories/unreviewed/2025/05/GHSA-g47c-fvq8-4266/GHSA-g47c-fvq8-4266.json index 36b44e7904a..259b4dfcdc3 100644 --- a/advisories/unreviewed/2025/05/GHSA-g47c-fvq8-4266/GHSA-g47c-fvq8-4266.json +++ b/advisories/unreviewed/2025/05/GHSA-g47c-fvq8-4266/GHSA-g47c-fvq8-4266.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g47c-fvq8-4266", - "modified": "2025-05-13T00:31:12Z", + "modified": "2025-05-14T15:31:35Z", "published": "2025-05-13T00:31:12Z", "aliases": [ "CVE-2025-24155" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3, macOS Ventura 13.7.6, macOS Sonoma 14.7.6. An app may be able to disclose kernel memory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:19Z" diff --git a/advisories/unreviewed/2025/05/GHSA-gphm-c4cj-h98g/GHSA-gphm-c4cj-h98g.json b/advisories/unreviewed/2025/05/GHSA-gphm-c4cj-h98g/GHSA-gphm-c4cj-h98g.json index 1a4a82b18fc..b6a47ce7a1d 100644 --- a/advisories/unreviewed/2025/05/GHSA-gphm-c4cj-h98g/GHSA-gphm-c4cj-h98g.json +++ b/advisories/unreviewed/2025/05/GHSA-gphm-c4cj-h98g/GHSA-gphm-c4cj-h98g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gphm-c4cj-h98g", - "modified": "2025-05-13T00:31:14Z", + "modified": "2025-05-14T15:31:36Z", "published": "2025-05-13T00:31:14Z", "aliases": [ "CVE-2025-31227" ], "details": "A logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5. An attacker with physical access to a device may be able to access a deleted call recording.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:23Z" diff --git a/advisories/unreviewed/2025/05/GHSA-gv5r-9gxr-v74w/GHSA-gv5r-9gxr-v74w.json b/advisories/unreviewed/2025/05/GHSA-gv5r-9gxr-v74w/GHSA-gv5r-9gxr-v74w.json index cb56226f213..e7eca9a661c 100644 --- a/advisories/unreviewed/2025/05/GHSA-gv5r-9gxr-v74w/GHSA-gv5r-9gxr-v74w.json +++ b/advisories/unreviewed/2025/05/GHSA-gv5r-9gxr-v74w/GHSA-gv5r-9gxr-v74w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gv5r-9gxr-v74w", - "modified": "2025-05-13T18:30:53Z", + "modified": "2025-05-14T15:31:37Z", "published": "2025-05-13T18:30:53Z", "aliases": [ "CVE-2025-47204" ], "details": "An issue was discovered in post.php in bootstrap-multiselect (aka Bootstrap Multiselect) 1.1.2. A PHP script in the source code echoes arbitrary POST data. If a developer adopts this structure wholesale in a live application, it could create a Reflective Cross-Site Scripting (XSS) vulnerability exploitable through Cross-Site Request Forgery (CSRF).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-13T16:15:31Z" diff --git a/advisories/unreviewed/2025/05/GHSA-h347-278r-gx23/GHSA-h347-278r-gx23.json b/advisories/unreviewed/2025/05/GHSA-h347-278r-gx23/GHSA-h347-278r-gx23.json index b90a2c49fad..dab0eae8e8a 100644 --- a/advisories/unreviewed/2025/05/GHSA-h347-278r-gx23/GHSA-h347-278r-gx23.json +++ b/advisories/unreviewed/2025/05/GHSA-h347-278r-gx23/GHSA-h347-278r-gx23.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h347-278r-gx23", - "modified": "2025-05-13T00:31:12Z", + "modified": "2025-05-14T15:31:36Z", "published": "2025-05-13T00:31:12Z", "aliases": [ "CVE-2025-24225" ], "details": "An injection issue was addressed with improved input validation. This issue is fixed in iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5. Processing an email may lead to user interface spoofing.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:20Z" diff --git a/advisories/unreviewed/2025/05/GHSA-h527-m3cp-9hm7/GHSA-h527-m3cp-9hm7.json b/advisories/unreviewed/2025/05/GHSA-h527-m3cp-9hm7/GHSA-h527-m3cp-9hm7.json new file mode 100644 index 00000000000..267d5728f18 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h527-m3cp-9hm7/GHSA-h527-m3cp-9hm7.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h527-m3cp-9hm7", + "modified": "2025-05-14T15:31:38Z", + "published": "2025-05-14T15:31:38Z", + "aliases": [ + "CVE-2025-47436" + ], + "details": "Heap-based Buffer Overflow vulnerability in Apache ORC.\n\nA vulnerability has been identified in the ORC C++ LZO decompression logic, where specially crafted malformed ORC files can cause the decompressor to allocate a 250-byte buffer but then attempts to copy 295 bytes into it. It causes memory corruption.\n\nThis issue affects Apache ORC C++ library: through 1.8.8, from 1.9.0 through 1.9.5, from 2.0.0 through 2.0.4, from 2.1.0 through 2.1.1.\n\nUsers are recommended to upgrade to version 1.8.9, 1.9.6, 2.0.5, and 2.1.2, which fix the issue.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:X/R:X/V:X/RE:M/U:Amber" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47436" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/kd6tlv8fs5jybmsgxr4vrkdxyc866wrn" + }, + { + "type": "WEB", + "url": "https://orc.apache.org/security/CVE-2025-47436" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/05/13/4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T14:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jgxh-h9f6-9wh2/GHSA-jgxh-h9f6-9wh2.json b/advisories/unreviewed/2025/05/GHSA-jgxh-h9f6-9wh2/GHSA-jgxh-h9f6-9wh2.json index e9bf7d7758d..ff51587d7a2 100644 --- a/advisories/unreviewed/2025/05/GHSA-jgxh-h9f6-9wh2/GHSA-jgxh-h9f6-9wh2.json +++ b/advisories/unreviewed/2025/05/GHSA-jgxh-h9f6-9wh2/GHSA-jgxh-h9f6-9wh2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jgxh-h9f6-9wh2", - "modified": "2025-05-13T00:31:15Z", + "modified": "2025-05-14T15:31:36Z", "published": "2025-05-13T00:31:15Z", "aliases": [ "CVE-2025-31238" ], "details": "The issue was addressed with improved checks. This issue is fixed in watchOS 11.5, tvOS 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, Safari 18.5. Processing maliciously crafted web content may lead to memory corruption.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:24Z" diff --git a/advisories/unreviewed/2025/05/GHSA-m3hm-6gqp-pf9f/GHSA-m3hm-6gqp-pf9f.json b/advisories/unreviewed/2025/05/GHSA-m3hm-6gqp-pf9f/GHSA-m3hm-6gqp-pf9f.json index 09ae1e725af..050f899efd8 100644 --- a/advisories/unreviewed/2025/05/GHSA-m3hm-6gqp-pf9f/GHSA-m3hm-6gqp-pf9f.json +++ b/advisories/unreviewed/2025/05/GHSA-m3hm-6gqp-pf9f/GHSA-m3hm-6gqp-pf9f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m3hm-6gqp-pf9f", - "modified": "2025-05-13T21:30:54Z", + "modified": "2025-05-14T15:31:37Z", "published": "2025-05-13T21:30:54Z", "aliases": [ "CVE-2024-45332" @@ -23,6 +23,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45332" }, + { + "type": "WEB", + "url": "https://comsec.ethz.ch/research/microarch/branch-privilege-injection" + }, { "type": "WEB", "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01247.html" diff --git a/advisories/unreviewed/2025/05/GHSA-m49r-wcx2-5jg3/GHSA-m49r-wcx2-5jg3.json b/advisories/unreviewed/2025/05/GHSA-m49r-wcx2-5jg3/GHSA-m49r-wcx2-5jg3.json index df0a611f501..0faa3269471 100644 --- a/advisories/unreviewed/2025/05/GHSA-m49r-wcx2-5jg3/GHSA-m49r-wcx2-5jg3.json +++ b/advisories/unreviewed/2025/05/GHSA-m49r-wcx2-5jg3/GHSA-m49r-wcx2-5jg3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m49r-wcx2-5jg3", - "modified": "2025-05-13T18:30:52Z", + "modified": "2025-05-14T15:31:37Z", "published": "2025-05-13T18:30:52Z", "aliases": [ "CVE-2025-28056" ], "details": "rebuild v3.9.0 through v3.9.3 has a SQL injection vulnerability in /admin/admin-cli/exec component.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-13T16:15:29Z" diff --git a/advisories/unreviewed/2025/05/GHSA-mv5r-fm5f-wm4v/GHSA-mv5r-fm5f-wm4v.json b/advisories/unreviewed/2025/05/GHSA-mv5r-fm5f-wm4v/GHSA-mv5r-fm5f-wm4v.json index 227bf83c817..dd1b6bace29 100644 --- a/advisories/unreviewed/2025/05/GHSA-mv5r-fm5f-wm4v/GHSA-mv5r-fm5f-wm4v.json +++ b/advisories/unreviewed/2025/05/GHSA-mv5r-fm5f-wm4v/GHSA-mv5r-fm5f-wm4v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mv5r-fm5f-wm4v", - "modified": "2025-05-13T00:31:13Z", + "modified": "2025-05-14T15:31:36Z", "published": "2025-05-13T00:31:13Z", "aliases": [ "CVE-2025-31195" ], "details": "The issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.4. An app may be able to break out of its sandbox.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:21Z" diff --git a/advisories/unreviewed/2025/05/GHSA-q3wm-48q6-668m/GHSA-q3wm-48q6-668m.json b/advisories/unreviewed/2025/05/GHSA-q3wm-48q6-668m/GHSA-q3wm-48q6-668m.json index cb581aae508..3ea10c4a7ce 100644 --- a/advisories/unreviewed/2025/05/GHSA-q3wm-48q6-668m/GHSA-q3wm-48q6-668m.json +++ b/advisories/unreviewed/2025/05/GHSA-q3wm-48q6-668m/GHSA-q3wm-48q6-668m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q3wm-48q6-668m", - "modified": "2025-05-13T18:30:53Z", + "modified": "2025-05-14T15:31:37Z", "published": "2025-05-13T18:30:53Z", "aliases": [ "CVE-2025-45857" ], "details": "EDIMAX CV7428NS v1.20 was discovered to contain a remote code execution (RCE) vulnerability via the command parameter in the mp function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-13T16:15:30Z" diff --git a/advisories/unreviewed/2025/05/GHSA-qqcr-9jfc-35c4/GHSA-qqcr-9jfc-35c4.json b/advisories/unreviewed/2025/05/GHSA-qqcr-9jfc-35c4/GHSA-qqcr-9jfc-35c4.json index 33991f720f3..1522d3e40aa 100644 --- a/advisories/unreviewed/2025/05/GHSA-qqcr-9jfc-35c4/GHSA-qqcr-9jfc-35c4.json +++ b/advisories/unreviewed/2025/05/GHSA-qqcr-9jfc-35c4/GHSA-qqcr-9jfc-35c4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qqcr-9jfc-35c4", - "modified": "2025-05-13T18:30:52Z", + "modified": "2025-05-14T15:31:37Z", "published": "2025-05-13T18:30:52Z", "aliases": [ "CVE-2024-56526" ], "details": "An issue was discovered in OXID eShop before 7. CMS pages in combination with Smarty may display user information if a CMS page contains a Smarty syntax error.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-13T16:15:28Z" diff --git a/advisories/unreviewed/2025/05/GHSA-qqq6-x3jw-9c7x/GHSA-qqq6-x3jw-9c7x.json b/advisories/unreviewed/2025/05/GHSA-qqq6-x3jw-9c7x/GHSA-qqq6-x3jw-9c7x.json index a5e93f7b1ac..d28834521f7 100644 --- a/advisories/unreviewed/2025/05/GHSA-qqq6-x3jw-9c7x/GHSA-qqq6-x3jw-9c7x.json +++ b/advisories/unreviewed/2025/05/GHSA-qqq6-x3jw-9c7x/GHSA-qqq6-x3jw-9c7x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qqq6-x3jw-9c7x", - "modified": "2025-05-13T15:32:16Z", + "modified": "2025-05-14T15:31:37Z", "published": "2025-05-13T15:32:16Z", "aliases": [ "CVE-2025-28057" ], "details": "owl-admin v3.2.2~ to v4.10.2 is vulnerable to SQL Injection in /admin-api/system/admin_menus/save_order.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-13T15:15:55Z" diff --git a/advisories/unreviewed/2025/05/GHSA-rcw6-7x98-m9g9/GHSA-rcw6-7x98-m9g9.json b/advisories/unreviewed/2025/05/GHSA-rcw6-7x98-m9g9/GHSA-rcw6-7x98-m9g9.json index 3131e21888f..12a2e6512da 100644 --- a/advisories/unreviewed/2025/05/GHSA-rcw6-7x98-m9g9/GHSA-rcw6-7x98-m9g9.json +++ b/advisories/unreviewed/2025/05/GHSA-rcw6-7x98-m9g9/GHSA-rcw6-7x98-m9g9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rcw6-7x98-m9g9", - "modified": "2025-05-13T21:30:54Z", + "modified": "2025-05-14T15:31:37Z", "published": "2025-05-13T21:30:53Z", "aliases": [ "CVE-2025-45746" ], "details": "In ZKT ZKBio CVSecurity 6.4.1_R an unauthenticated attacker can craft JWT token using the hardcoded secret to authenticate to the service console.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-798" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-13T19:15:51Z" diff --git a/advisories/unreviewed/2025/05/GHSA-rvh4-h7j5-46g3/GHSA-rvh4-h7j5-46g3.json b/advisories/unreviewed/2025/05/GHSA-rvh4-h7j5-46g3/GHSA-rvh4-h7j5-46g3.json index 5abc78554e6..5a8e8458200 100644 --- a/advisories/unreviewed/2025/05/GHSA-rvh4-h7j5-46g3/GHSA-rvh4-h7j5-46g3.json +++ b/advisories/unreviewed/2025/05/GHSA-rvh4-h7j5-46g3/GHSA-rvh4-h7j5-46g3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rvh4-h7j5-46g3", - "modified": "2025-05-13T21:30:43Z", + "modified": "2025-05-14T15:31:37Z", "published": "2025-05-13T00:31:15Z", "aliases": [ "CVE-2025-31256" diff --git a/advisories/unreviewed/2025/05/GHSA-v2qw-mwg5-px4g/GHSA-v2qw-mwg5-px4g.json b/advisories/unreviewed/2025/05/GHSA-v2qw-mwg5-px4g/GHSA-v2qw-mwg5-px4g.json index 974746eb5f2..1937c242350 100644 --- a/advisories/unreviewed/2025/05/GHSA-v2qw-mwg5-px4g/GHSA-v2qw-mwg5-px4g.json +++ b/advisories/unreviewed/2025/05/GHSA-v2qw-mwg5-px4g/GHSA-v2qw-mwg5-px4g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v2qw-mwg5-px4g", - "modified": "2025-05-13T00:31:12Z", + "modified": "2025-05-14T15:31:35Z", "published": "2025-05-13T00:31:12Z", "aliases": [ "CVE-2025-24220" ], "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in iPadOS 17.7.7, iOS 18.4 and iPadOS 18.4. An app may be able to read a persistent device identifier.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:19Z" diff --git a/advisories/unreviewed/2025/05/GHSA-v5vr-7qc6-xw56/GHSA-v5vr-7qc6-xw56.json b/advisories/unreviewed/2025/05/GHSA-v5vr-7qc6-xw56/GHSA-v5vr-7qc6-xw56.json new file mode 100644 index 00000000000..eb56400fc3f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v5vr-7qc6-xw56/GHSA-v5vr-7qc6-xw56.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v5vr-7qc6-xw56", + "modified": "2025-05-14T15:31:38Z", + "published": "2025-05-14T15:31:38Z", + "aliases": [ + "CVE-2024-57273" + ], + "details": "Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross-site scripting (XSS) in the Automatic Configuration Backup (ACB) service, allowing remote attackers to execute arbitrary JavaScript, delete backups, or leak sensitive information via an unsanitized \"reason\" field and a derivable device key generated from the public SSH key.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57273" + }, + { + "type": "WEB", + "url": "https://blog.brillantit.com/exploiting-pfsense-xss-command-injection-cloud-hijack" + }, + { + "type": "WEB", + "url": "http://netgate.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T14:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v7m3-xggw-4h6v/GHSA-v7m3-xggw-4h6v.json b/advisories/unreviewed/2025/05/GHSA-v7m3-xggw-4h6v/GHSA-v7m3-xggw-4h6v.json index 7ce08f90ef8..c6a9902e117 100644 --- a/advisories/unreviewed/2025/05/GHSA-v7m3-xggw-4h6v/GHSA-v7m3-xggw-4h6v.json +++ b/advisories/unreviewed/2025/05/GHSA-v7m3-xggw-4h6v/GHSA-v7m3-xggw-4h6v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v7m3-xggw-4h6v", - "modified": "2025-05-13T21:30:53Z", + "modified": "2025-05-14T15:31:37Z", "published": "2025-05-13T21:30:53Z", "aliases": [ "CVE-2025-45865" ], "details": "TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the dnsaddr parameter in the formDhcpv6s interface.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-13T19:15:51Z" diff --git a/advisories/unreviewed/2025/05/GHSA-vghf-926w-cc55/GHSA-vghf-926w-cc55.json b/advisories/unreviewed/2025/05/GHSA-vghf-926w-cc55/GHSA-vghf-926w-cc55.json index 284fb748cfd..a4960d06bbc 100644 --- a/advisories/unreviewed/2025/05/GHSA-vghf-926w-cc55/GHSA-vghf-926w-cc55.json +++ b/advisories/unreviewed/2025/05/GHSA-vghf-926w-cc55/GHSA-vghf-926w-cc55.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vghf-926w-cc55", - "modified": "2025-05-13T15:32:17Z", + "modified": "2025-05-14T15:31:37Z", "published": "2025-05-13T15:32:17Z", "aliases": [ "CVE-2025-44831" ], "details": "EngineerCMS v1.02 through v2.0.5 has a SQL injection vulnerability in the /project/addproject interface.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-13T15:15:58Z" diff --git a/advisories/unreviewed/2025/05/GHSA-xf4q-c7gc-gpgr/GHSA-xf4q-c7gc-gpgr.json b/advisories/unreviewed/2025/05/GHSA-xf4q-c7gc-gpgr/GHSA-xf4q-c7gc-gpgr.json index 3ac483a17cc..ac3073af298 100644 --- a/advisories/unreviewed/2025/05/GHSA-xf4q-c7gc-gpgr/GHSA-xf4q-c7gc-gpgr.json +++ b/advisories/unreviewed/2025/05/GHSA-xf4q-c7gc-gpgr/GHSA-xf4q-c7gc-gpgr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xf4q-c7gc-gpgr", - "modified": "2025-05-13T00:31:15Z", + "modified": "2025-05-14T15:31:36Z", "published": "2025-05-13T00:31:15Z", "aliases": [ "CVE-2025-31242" ], "details": "A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iPadOS 17.7.7, macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. An app may be able to access sensitive user data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:24Z"