diff --git a/advisories/unreviewed/2024/01/GHSA-2w8f-25gq-9g77/GHSA-2w8f-25gq-9g77.json b/advisories/unreviewed/2024/01/GHSA-2w8f-25gq-9g77/GHSA-2w8f-25gq-9g77.json index a0c8334de82..76365f51eee 100644 --- a/advisories/unreviewed/2024/01/GHSA-2w8f-25gq-9g77/GHSA-2w8f-25gq-9g77.json +++ b/advisories/unreviewed/2024/01/GHSA-2w8f-25gq-9g77/GHSA-2w8f-25gq-9g77.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2w8f-25gq-9g77", - "modified": "2024-02-03T03:30:27Z", + "modified": "2025-06-09T21:30:36Z", "published": "2024-01-29T15:30:29Z", "aliases": [ "CVE-2023-5956" diff --git a/advisories/unreviewed/2024/01/GHSA-xh95-48w4-456m/GHSA-xh95-48w4-456m.json b/advisories/unreviewed/2024/01/GHSA-xh95-48w4-456m/GHSA-xh95-48w4-456m.json index 6ece4e723a8..3a0dcc8b24b 100644 --- a/advisories/unreviewed/2024/01/GHSA-xh95-48w4-456m/GHSA-xh95-48w4-456m.json +++ b/advisories/unreviewed/2024/01/GHSA-xh95-48w4-456m/GHSA-xh95-48w4-456m.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-xh95-48w4-456m", - "modified": "2024-02-03T00:31:34Z", + "modified": "2025-06-09T21:30:37Z", "published": "2024-01-31T15:30:19Z", "aliases": [ "CVE-2024-0589" ], - "details": "Cross-site scripting (XSS) vulnerability in the entry overview tab in Devolutions Remote Desktop Manager 2023.3.36 and earlier on Windows allows an attacker with access to a data source to inject a malicious script via a specially crafted input in an entry.\n\n\n\n\n\n", + "details": "Cross-site scripting (XSS) vulnerability in the entry overview tab in Devolutions Remote Desktop Manager 2023.3.36 and earlier on Windows allows an attacker with access to a data source to inject a malicious script via a specially crafted input in an entry.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/06/GHSA-2frj-77vm-453x/GHSA-2frj-77vm-453x.json b/advisories/unreviewed/2024/06/GHSA-2frj-77vm-453x/GHSA-2frj-77vm-453x.json index a81ef992c4a..2bde5e7a219 100644 --- a/advisories/unreviewed/2024/06/GHSA-2frj-77vm-453x/GHSA-2frj-77vm-453x.json +++ b/advisories/unreviewed/2024/06/GHSA-2frj-77vm-453x/GHSA-2frj-77vm-453x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2frj-77vm-453x", - "modified": "2024-06-19T12:31:21Z", + "modified": "2025-06-09T21:30:38Z", "published": "2024-06-19T12:31:21Z", "aliases": [ "CVE-2024-35765" diff --git a/advisories/unreviewed/2024/08/GHSA-r2cp-jr96-fmw7/GHSA-r2cp-jr96-fmw7.json b/advisories/unreviewed/2024/08/GHSA-r2cp-jr96-fmw7/GHSA-r2cp-jr96-fmw7.json index 63d33dd4164..95a46e6106e 100644 --- a/advisories/unreviewed/2024/08/GHSA-r2cp-jr96-fmw7/GHSA-r2cp-jr96-fmw7.json +++ b/advisories/unreviewed/2024/08/GHSA-r2cp-jr96-fmw7/GHSA-r2cp-jr96-fmw7.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/08/GHSA-xr9f-3r4j-v7r6/GHSA-xr9f-3r4j-v7r6.json b/advisories/unreviewed/2024/08/GHSA-xr9f-3r4j-v7r6/GHSA-xr9f-3r4j-v7r6.json index c456c44457a..e674ef3e7af 100644 --- a/advisories/unreviewed/2024/08/GHSA-xr9f-3r4j-v7r6/GHSA-xr9f-3r4j-v7r6.json +++ b/advisories/unreviewed/2024/08/GHSA-xr9f-3r4j-v7r6/GHSA-xr9f-3r4j-v7r6.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/10/GHSA-h3fm-h666-8g3f/GHSA-h3fm-h666-8g3f.json b/advisories/unreviewed/2024/10/GHSA-h3fm-h666-8g3f/GHSA-h3fm-h666-8g3f.json index 0aeb1304906..e0d639f3de5 100644 --- a/advisories/unreviewed/2024/10/GHSA-h3fm-h666-8g3f/GHSA-h3fm-h666-8g3f.json +++ b/advisories/unreviewed/2024/10/GHSA-h3fm-h666-8g3f/GHSA-h3fm-h666-8g3f.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-65f9-48qm-g2v2/GHSA-65f9-48qm-g2v2.json b/advisories/unreviewed/2025/01/GHSA-65f9-48qm-g2v2/GHSA-65f9-48qm-g2v2.json index f2a878e7e3d..ca88a84fbf0 100644 --- a/advisories/unreviewed/2025/01/GHSA-65f9-48qm-g2v2/GHSA-65f9-48qm-g2v2.json +++ b/advisories/unreviewed/2025/01/GHSA-65f9-48qm-g2v2/GHSA-65f9-48qm-g2v2.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-g359-p277-83p3/GHSA-g359-p277-83p3.json b/advisories/unreviewed/2025/01/GHSA-g359-p277-83p3/GHSA-g359-p277-83p3.json index 42d45f24d16..4f431bcf644 100644 --- a/advisories/unreviewed/2025/01/GHSA-g359-p277-83p3/GHSA-g359-p277-83p3.json +++ b/advisories/unreviewed/2025/01/GHSA-g359-p277-83p3/GHSA-g359-p277-83p3.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-75" + "CWE-75", + "CWE-77" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-ggj6-66q9-rcw5/GHSA-ggj6-66q9-rcw5.json b/advisories/unreviewed/2025/01/GHSA-ggj6-66q9-rcw5/GHSA-ggj6-66q9-rcw5.json index 4de28ad6c75..458c5c8f5a5 100644 --- a/advisories/unreviewed/2025/01/GHSA-ggj6-66q9-rcw5/GHSA-ggj6-66q9-rcw5.json +++ b/advisories/unreviewed/2025/01/GHSA-ggj6-66q9-rcw5/GHSA-ggj6-66q9-rcw5.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-706", "CWE-98" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/01/GHSA-xr4j-2qp3-r4xc/GHSA-xr4j-2qp3-r4xc.json b/advisories/unreviewed/2025/01/GHSA-xr4j-2qp3-r4xc/GHSA-xr4j-2qp3-r4xc.json index a119fa3ec19..0e4b6efe019 100644 --- a/advisories/unreviewed/2025/01/GHSA-xr4j-2qp3-r4xc/GHSA-xr4j-2qp3-r4xc.json +++ b/advisories/unreviewed/2025/01/GHSA-xr4j-2qp3-r4xc/GHSA-xr4j-2qp3-r4xc.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-2377-3h83-ch9w/GHSA-2377-3h83-ch9w.json b/advisories/unreviewed/2025/05/GHSA-2377-3h83-ch9w/GHSA-2377-3h83-ch9w.json index 7fbe508dec5..150487e86d7 100644 --- a/advisories/unreviewed/2025/05/GHSA-2377-3h83-ch9w/GHSA-2377-3h83-ch9w.json +++ b/advisories/unreviewed/2025/05/GHSA-2377-3h83-ch9w/GHSA-2377-3h83-ch9w.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-2g6g-hhqw-63q5/GHSA-2g6g-hhqw-63q5.json b/advisories/unreviewed/2025/05/GHSA-2g6g-hhqw-63q5/GHSA-2g6g-hhqw-63q5.json index 6e980566cbb..4d1be335845 100644 --- a/advisories/unreviewed/2025/05/GHSA-2g6g-hhqw-63q5/GHSA-2g6g-hhqw-63q5.json +++ b/advisories/unreviewed/2025/05/GHSA-2g6g-hhqw-63q5/GHSA-2g6g-hhqw-63q5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2g6g-hhqw-63q5", - "modified": "2025-05-20T21:30:33Z", + "modified": "2025-06-09T21:30:42Z", "published": "2025-05-15T21:31:29Z", "aliases": [ "CVE-2024-12282" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-32jx-cx53-vp3r/GHSA-32jx-cx53-vp3r.json b/advisories/unreviewed/2025/05/GHSA-32jx-cx53-vp3r/GHSA-32jx-cx53-vp3r.json index a4ee98a8412..9717391a066 100644 --- a/advisories/unreviewed/2025/05/GHSA-32jx-cx53-vp3r/GHSA-32jx-cx53-vp3r.json +++ b/advisories/unreviewed/2025/05/GHSA-32jx-cx53-vp3r/GHSA-32jx-cx53-vp3r.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-3vx5-jr5m-gpmq/GHSA-3vx5-jr5m-gpmq.json b/advisories/unreviewed/2025/05/GHSA-3vx5-jr5m-gpmq/GHSA-3vx5-jr5m-gpmq.json index c60480d4d37..5fe023faf22 100644 --- a/advisories/unreviewed/2025/05/GHSA-3vx5-jr5m-gpmq/GHSA-3vx5-jr5m-gpmq.json +++ b/advisories/unreviewed/2025/05/GHSA-3vx5-jr5m-gpmq/GHSA-3vx5-jr5m-gpmq.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-4777-jjjg-6mxh/GHSA-4777-jjjg-6mxh.json b/advisories/unreviewed/2025/05/GHSA-4777-jjjg-6mxh/GHSA-4777-jjjg-6mxh.json index aa8f5cde18f..f70a63c6aea 100644 --- a/advisories/unreviewed/2025/05/GHSA-4777-jjjg-6mxh/GHSA-4777-jjjg-6mxh.json +++ b/advisories/unreviewed/2025/05/GHSA-4777-jjjg-6mxh/GHSA-4777-jjjg-6mxh.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-256" + "CWE-256", + "CWE-522" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-4x2h-w98x-4p25/GHSA-4x2h-w98x-4p25.json b/advisories/unreviewed/2025/05/GHSA-4x2h-w98x-4p25/GHSA-4x2h-w98x-4p25.json index d55d37891f2..e8f9909604c 100644 --- a/advisories/unreviewed/2025/05/GHSA-4x2h-w98x-4p25/GHSA-4x2h-w98x-4p25.json +++ b/advisories/unreviewed/2025/05/GHSA-4x2h-w98x-4p25/GHSA-4x2h-w98x-4p25.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-5x56-8gp2-c78j/GHSA-5x56-8gp2-c78j.json b/advisories/unreviewed/2025/05/GHSA-5x56-8gp2-c78j/GHSA-5x56-8gp2-c78j.json index 81648451790..7fd4989e9fb 100644 --- a/advisories/unreviewed/2025/05/GHSA-5x56-8gp2-c78j/GHSA-5x56-8gp2-c78j.json +++ b/advisories/unreviewed/2025/05/GHSA-5x56-8gp2-c78j/GHSA-5x56-8gp2-c78j.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-62xj-j866-fwp8/GHSA-62xj-j866-fwp8.json b/advisories/unreviewed/2025/05/GHSA-62xj-j866-fwp8/GHSA-62xj-j866-fwp8.json index 9c4ff4139b5..8826309838f 100644 --- a/advisories/unreviewed/2025/05/GHSA-62xj-j866-fwp8/GHSA-62xj-j866-fwp8.json +++ b/advisories/unreviewed/2025/05/GHSA-62xj-j866-fwp8/GHSA-62xj-j866-fwp8.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-6r2v-xpcr-fqcv/GHSA-6r2v-xpcr-fqcv.json b/advisories/unreviewed/2025/05/GHSA-6r2v-xpcr-fqcv/GHSA-6r2v-xpcr-fqcv.json index a8c59f7cce0..5dd93f894fd 100644 --- a/advisories/unreviewed/2025/05/GHSA-6r2v-xpcr-fqcv/GHSA-6r2v-xpcr-fqcv.json +++ b/advisories/unreviewed/2025/05/GHSA-6r2v-xpcr-fqcv/GHSA-6r2v-xpcr-fqcv.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-7gvw-8492-45cx/GHSA-7gvw-8492-45cx.json b/advisories/unreviewed/2025/05/GHSA-7gvw-8492-45cx/GHSA-7gvw-8492-45cx.json index 05910539c17..4294eb99258 100644 --- a/advisories/unreviewed/2025/05/GHSA-7gvw-8492-45cx/GHSA-7gvw-8492-45cx.json +++ b/advisories/unreviewed/2025/05/GHSA-7gvw-8492-45cx/GHSA-7gvw-8492-45cx.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-7xpv-834v-x9rj/GHSA-7xpv-834v-x9rj.json b/advisories/unreviewed/2025/05/GHSA-7xpv-834v-x9rj/GHSA-7xpv-834v-x9rj.json index 78d00278093..fb6cb2e8031 100644 --- a/advisories/unreviewed/2025/05/GHSA-7xpv-834v-x9rj/GHSA-7xpv-834v-x9rj.json +++ b/advisories/unreviewed/2025/05/GHSA-7xpv-834v-x9rj/GHSA-7xpv-834v-x9rj.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-326", "CWE-328" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/05/GHSA-8gp3-q997-wcjx/GHSA-8gp3-q997-wcjx.json b/advisories/unreviewed/2025/05/GHSA-8gp3-q997-wcjx/GHSA-8gp3-q997-wcjx.json index 10c8730b6c7..ecc756eeb69 100644 --- a/advisories/unreviewed/2025/05/GHSA-8gp3-q997-wcjx/GHSA-8gp3-q997-wcjx.json +++ b/advisories/unreviewed/2025/05/GHSA-8gp3-q997-wcjx/GHSA-8gp3-q997-wcjx.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-8w6q-4mh2-p2gh/GHSA-8w6q-4mh2-p2gh.json b/advisories/unreviewed/2025/05/GHSA-8w6q-4mh2-p2gh/GHSA-8w6q-4mh2-p2gh.json index 5695fe0895f..928b85c8e6c 100644 --- a/advisories/unreviewed/2025/05/GHSA-8w6q-4mh2-p2gh/GHSA-8w6q-4mh2-p2gh.json +++ b/advisories/unreviewed/2025/05/GHSA-8w6q-4mh2-p2gh/GHSA-8w6q-4mh2-p2gh.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-f5w7-cjpw-qq45/GHSA-f5w7-cjpw-qq45.json b/advisories/unreviewed/2025/05/GHSA-f5w7-cjpw-qq45/GHSA-f5w7-cjpw-qq45.json index 6f6b5651fbf..e08b46ccba9 100644 --- a/advisories/unreviewed/2025/05/GHSA-f5w7-cjpw-qq45/GHSA-f5w7-cjpw-qq45.json +++ b/advisories/unreviewed/2025/05/GHSA-f5w7-cjpw-qq45/GHSA-f5w7-cjpw-qq45.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f5w7-cjpw-qq45", - "modified": "2025-05-28T15:34:34Z", + "modified": "2025-06-09T21:30:44Z", "published": "2025-05-28T15:34:34Z", "aliases": [ "CVE-2025-3357" @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-1285" + "CWE-1285", + "CWE-129" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-h9vp-frfm-hwvq/GHSA-h9vp-frfm-hwvq.json b/advisories/unreviewed/2025/05/GHSA-h9vp-frfm-hwvq/GHSA-h9vp-frfm-hwvq.json index b3635d97520..76640f5c1d0 100644 --- a/advisories/unreviewed/2025/05/GHSA-h9vp-frfm-hwvq/GHSA-h9vp-frfm-hwvq.json +++ b/advisories/unreviewed/2025/05/GHSA-h9vp-frfm-hwvq/GHSA-h9vp-frfm-hwvq.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-j2r4-h64j-ggm9/GHSA-j2r4-h64j-ggm9.json b/advisories/unreviewed/2025/05/GHSA-j2r4-h64j-ggm9/GHSA-j2r4-h64j-ggm9.json index d17b3829a2e..ff9ecd21a56 100644 --- a/advisories/unreviewed/2025/05/GHSA-j2r4-h64j-ggm9/GHSA-j2r4-h64j-ggm9.json +++ b/advisories/unreviewed/2025/05/GHSA-j2r4-h64j-ggm9/GHSA-j2r4-h64j-ggm9.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-jp64-jgv4-9vfq/GHSA-jp64-jgv4-9vfq.json b/advisories/unreviewed/2025/05/GHSA-jp64-jgv4-9vfq/GHSA-jp64-jgv4-9vfq.json index e4f6645c335..fbaa39f8be9 100644 --- a/advisories/unreviewed/2025/05/GHSA-jp64-jgv4-9vfq/GHSA-jp64-jgv4-9vfq.json +++ b/advisories/unreviewed/2025/05/GHSA-jp64-jgv4-9vfq/GHSA-jp64-jgv4-9vfq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jp64-jgv4-9vfq", - "modified": "2025-05-28T00:30:35Z", + "modified": "2025-06-09T21:30:44Z", "published": "2025-05-28T00:30:35Z", "aliases": [ "CVE-2024-45094" diff --git a/advisories/unreviewed/2025/05/GHSA-m9fv-fh52-9c95/GHSA-m9fv-fh52-9c95.json b/advisories/unreviewed/2025/05/GHSA-m9fv-fh52-9c95/GHSA-m9fv-fh52-9c95.json index e22fddfca62..4e46ade326d 100644 --- a/advisories/unreviewed/2025/05/GHSA-m9fv-fh52-9c95/GHSA-m9fv-fh52-9c95.json +++ b/advisories/unreviewed/2025/05/GHSA-m9fv-fh52-9c95/GHSA-m9fv-fh52-9c95.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-p629-9pvp-h6f9/GHSA-p629-9pvp-h6f9.json b/advisories/unreviewed/2025/05/GHSA-p629-9pvp-h6f9/GHSA-p629-9pvp-h6f9.json index 2a18b25e4bc..ae96a91b379 100644 --- a/advisories/unreviewed/2025/05/GHSA-p629-9pvp-h6f9/GHSA-p629-9pvp-h6f9.json +++ b/advisories/unreviewed/2025/05/GHSA-p629-9pvp-h6f9/GHSA-p629-9pvp-h6f9.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-pcjq-4m2m-9fw8/GHSA-pcjq-4m2m-9fw8.json b/advisories/unreviewed/2025/05/GHSA-pcjq-4m2m-9fw8/GHSA-pcjq-4m2m-9fw8.json index cd8a2dba6aa..3b802b36026 100644 --- a/advisories/unreviewed/2025/05/GHSA-pcjq-4m2m-9fw8/GHSA-pcjq-4m2m-9fw8.json +++ b/advisories/unreviewed/2025/05/GHSA-pcjq-4m2m-9fw8/GHSA-pcjq-4m2m-9fw8.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-q2mh-5gjr-6m57/GHSA-q2mh-5gjr-6m57.json b/advisories/unreviewed/2025/05/GHSA-q2mh-5gjr-6m57/GHSA-q2mh-5gjr-6m57.json index b748f7866a2..4a0e500e5a6 100644 --- a/advisories/unreviewed/2025/05/GHSA-q2mh-5gjr-6m57/GHSA-q2mh-5gjr-6m57.json +++ b/advisories/unreviewed/2025/05/GHSA-q2mh-5gjr-6m57/GHSA-q2mh-5gjr-6m57.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-rm8v-7m88-ppxf/GHSA-rm8v-7m88-ppxf.json b/advisories/unreviewed/2025/05/GHSA-rm8v-7m88-ppxf/GHSA-rm8v-7m88-ppxf.json index 8e33b08e240..f675a1c5d81 100644 --- a/advisories/unreviewed/2025/05/GHSA-rm8v-7m88-ppxf/GHSA-rm8v-7m88-ppxf.json +++ b/advisories/unreviewed/2025/05/GHSA-rm8v-7m88-ppxf/GHSA-rm8v-7m88-ppxf.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-rrc7-p8g9-c7vg/GHSA-rrc7-p8g9-c7vg.json b/advisories/unreviewed/2025/05/GHSA-rrc7-p8g9-c7vg/GHSA-rrc7-p8g9-c7vg.json index cdce1a319f1..1435004593b 100644 --- a/advisories/unreviewed/2025/05/GHSA-rrc7-p8g9-c7vg/GHSA-rrc7-p8g9-c7vg.json +++ b/advisories/unreviewed/2025/05/GHSA-rrc7-p8g9-c7vg/GHSA-rrc7-p8g9-c7vg.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-v364-qrc6-2qj4/GHSA-v364-qrc6-2qj4.json b/advisories/unreviewed/2025/05/GHSA-v364-qrc6-2qj4/GHSA-v364-qrc6-2qj4.json index ba6ca12d488..89e067e5229 100644 --- a/advisories/unreviewed/2025/05/GHSA-v364-qrc6-2qj4/GHSA-v364-qrc6-2qj4.json +++ b/advisories/unreviewed/2025/05/GHSA-v364-qrc6-2qj4/GHSA-v364-qrc6-2qj4.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-vppg-gg96-53c9/GHSA-vppg-gg96-53c9.json b/advisories/unreviewed/2025/05/GHSA-vppg-gg96-53c9/GHSA-vppg-gg96-53c9.json index 8eedf492a71..807ffa4729f 100644 --- a/advisories/unreviewed/2025/05/GHSA-vppg-gg96-53c9/GHSA-vppg-gg96-53c9.json +++ b/advisories/unreviewed/2025/05/GHSA-vppg-gg96-53c9/GHSA-vppg-gg96-53c9.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-x8qc-qf2g-j5w3/GHSA-x8qc-qf2g-j5w3.json b/advisories/unreviewed/2025/05/GHSA-x8qc-qf2g-j5w3/GHSA-x8qc-qf2g-j5w3.json index fb367f5a04d..c4dab93bd4c 100644 --- a/advisories/unreviewed/2025/05/GHSA-x8qc-qf2g-j5w3/GHSA-x8qc-qf2g-j5w3.json +++ b/advisories/unreviewed/2025/05/GHSA-x8qc-qf2g-j5w3/GHSA-x8qc-qf2g-j5w3.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/06/GHSA-29vm-vjqm-q2mx/GHSA-29vm-vjqm-q2mx.json b/advisories/unreviewed/2025/06/GHSA-29vm-vjqm-q2mx/GHSA-29vm-vjqm-q2mx.json new file mode 100644 index 00000000000..c6af1fd4b6a --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-29vm-vjqm-q2mx/GHSA-29vm-vjqm-q2mx.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-29vm-vjqm-q2mx", + "modified": "2025-06-09T21:30:52Z", + "published": "2025-06-09T21:30:52Z", + "aliases": [ + "CVE-2025-5917" + ], + "details": "A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes for file names. This can lead to a 1-byte write overflow. While seemingly small, such an overflow can corrupt adjacent memory, leading to unpredictable program behavior, crashes, or in specific circumstances, could be leveraged as a building block for more sophisticated exploitation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5917" + }, + { + "type": "WEB", + "url": "https://github.com/libarchive/libarchive/pull/2588" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-5917" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370874" + }, + { + "type": "WEB", + "url": "https://github.com/libarchive/libarchive/releases/tag/v3.8.0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T20:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-2gwh-2hvc-7qgh/GHSA-2gwh-2hvc-7qgh.json b/advisories/unreviewed/2025/06/GHSA-2gwh-2hvc-7qgh/GHSA-2gwh-2hvc-7qgh.json new file mode 100644 index 00000000000..7850861d96d --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-2gwh-2hvc-7qgh/GHSA-2gwh-2hvc-7qgh.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2gwh-2hvc-7qgh", + "modified": "2025-06-09T21:30:51Z", + "published": "2025-06-09T21:30:51Z", + "aliases": [ + "CVE-2025-5890" + ], + "details": "A vulnerability classified as problematic has been found in actions toolkit 0.5.0. This affects the function globEscape of the file toolkit/packages/glob/src/internal-pattern.ts of the component glob. The manipulation leads to inefficient regular expression complexity. It is possible to initiate the attack remotely.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5890" + }, + { + "type": "WEB", + "url": "https://github.com/actions/toolkit/pull/2057" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311661" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311661" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.585727" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T19:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-2jrq-xcm6-56wv/GHSA-2jrq-xcm6-56wv.json b/advisories/unreviewed/2025/06/GHSA-2jrq-xcm6-56wv/GHSA-2jrq-xcm6-56wv.json index e0d6d61b354..9b94207ffdd 100644 --- a/advisories/unreviewed/2025/06/GHSA-2jrq-xcm6-56wv/GHSA-2jrq-xcm6-56wv.json +++ b/advisories/unreviewed/2025/06/GHSA-2jrq-xcm6-56wv/GHSA-2jrq-xcm6-56wv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2jrq-xcm6-56wv", - "modified": "2025-06-04T21:31:15Z", + "modified": "2025-06-09T21:30:47Z", "published": "2025-06-04T21:31:15Z", "aliases": [ "CVE-2025-46011" @@ -19,9 +19,25 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46011" }, + { + "type": "WEB", + "url": "https://github.com/knadh/listmonk/issues/2412" + }, + { + "type": "WEB", + "url": "https://github.com/knadh/listmonk/commit/4b805f885b9f5a20126ec06f8b59dc448c4af33b" + }, { "type": "WEB", "url": "https://github.com/kevinroleke/security/tree/main/CVE-2025-46011" + }, + { + "type": "WEB", + "url": "https://github.com/knadh/listmonk/releases/tag/v4.1.0" + }, + { + "type": "WEB", + "url": "https://github.com/knadh/listmonk/releases/tag/v5.0.0" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/06/GHSA-2jv4-g2j5-gcgx/GHSA-2jv4-g2j5-gcgx.json b/advisories/unreviewed/2025/06/GHSA-2jv4-g2j5-gcgx/GHSA-2jv4-g2j5-gcgx.json index db2dd04005a..a2f2ba41fa7 100644 --- a/advisories/unreviewed/2025/06/GHSA-2jv4-g2j5-gcgx/GHSA-2jv4-g2j5-gcgx.json +++ b/advisories/unreviewed/2025/06/GHSA-2jv4-g2j5-gcgx/GHSA-2jv4-g2j5-gcgx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2jv4-g2j5-gcgx", - "modified": "2025-06-08T12:30:33Z", + "modified": "2025-06-09T21:30:47Z", "published": "2025-06-08T12:30:33Z", "aliases": [ "CVE-2025-27131" diff --git a/advisories/unreviewed/2025/06/GHSA-3frr-hc3j-3mrr/GHSA-3frr-hc3j-3mrr.json b/advisories/unreviewed/2025/06/GHSA-3frr-hc3j-3mrr/GHSA-3frr-hc3j-3mrr.json index 747eab4c94e..8c507c1b545 100644 --- a/advisories/unreviewed/2025/06/GHSA-3frr-hc3j-3mrr/GHSA-3frr-hc3j-3mrr.json +++ b/advisories/unreviewed/2025/06/GHSA-3frr-hc3j-3mrr/GHSA-3frr-hc3j-3mrr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3frr-hc3j-3mrr", - "modified": "2025-06-09T18:32:16Z", + "modified": "2025-06-09T21:30:50Z", "published": "2025-06-09T18:32:16Z", "aliases": [ "CVE-2024-46452" ], "details": "A Host Header injection vulnerability in the password reset function of VigyBag Open Source Online Shop commit 3f0e21b allows attackers to redirect victim users to a malicious site via a crafted URL.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-09T17:15:28Z" diff --git a/advisories/unreviewed/2025/06/GHSA-3hqh-8h99-q2cf/GHSA-3hqh-8h99-q2cf.json b/advisories/unreviewed/2025/06/GHSA-3hqh-8h99-q2cf/GHSA-3hqh-8h99-q2cf.json new file mode 100644 index 00000000000..df22286ee80 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-3hqh-8h99-q2cf/GHSA-3hqh-8h99-q2cf.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3hqh-8h99-q2cf", + "modified": "2025-06-09T21:30:52Z", + "published": "2025-06-09T21:30:52Z", + "aliases": [ + "CVE-2025-5918" + ], + "details": "A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5918" + }, + { + "type": "WEB", + "url": "https://github.com/libarchive/libarchive/pull/2584" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-5918" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370877" + }, + { + "type": "WEB", + "url": "https://github.com/libarchive/libarchive/releases/tag/v3.8.0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T20:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-3xgx-5fr5-rcrq/GHSA-3xgx-5fr5-rcrq.json b/advisories/unreviewed/2025/06/GHSA-3xgx-5fr5-rcrq/GHSA-3xgx-5fr5-rcrq.json index cdc20344722..0a351f68593 100644 --- a/advisories/unreviewed/2025/06/GHSA-3xgx-5fr5-rcrq/GHSA-3xgx-5fr5-rcrq.json +++ b/advisories/unreviewed/2025/06/GHSA-3xgx-5fr5-rcrq/GHSA-3xgx-5fr5-rcrq.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/06/GHSA-4377-g9q2-3wh5/GHSA-4377-g9q2-3wh5.json b/advisories/unreviewed/2025/06/GHSA-4377-g9q2-3wh5/GHSA-4377-g9q2-3wh5.json index f8e609995bb..49df31824a7 100644 --- a/advisories/unreviewed/2025/06/GHSA-4377-g9q2-3wh5/GHSA-4377-g9q2-3wh5.json +++ b/advisories/unreviewed/2025/06/GHSA-4377-g9q2-3wh5/GHSA-4377-g9q2-3wh5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4377-g9q2-3wh5", - "modified": "2025-06-09T18:32:13Z", + "modified": "2025-06-09T21:30:50Z", "published": "2025-06-09T18:32:13Z", "aliases": [ "CVE-2025-45055" ], "details": "Silverpeas 6.4.2 contains a stored cross-site scripting (XSS) vulnerability in the event management module. An authenticated user can upload a malicious SVG file as an event attachment, which, when viewed by an administrator, executes embedded JavaScript in the admin's session. This allows attackers to escalate privileges by creating a new administrator account. The vulnerability arises from insufficient sanitization of SVG files and weak CSRF protections.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-09T16:15:40Z" diff --git a/advisories/unreviewed/2025/06/GHSA-6vfc-8w2v-vx36/GHSA-6vfc-8w2v-vx36.json b/advisories/unreviewed/2025/06/GHSA-6vfc-8w2v-vx36/GHSA-6vfc-8w2v-vx36.json index 32fce534718..6cece2b7eb7 100644 --- a/advisories/unreviewed/2025/06/GHSA-6vfc-8w2v-vx36/GHSA-6vfc-8w2v-vx36.json +++ b/advisories/unreviewed/2025/06/GHSA-6vfc-8w2v-vx36/GHSA-6vfc-8w2v-vx36.json @@ -50,7 +50,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/06/GHSA-7376-x4rm-3v8x/GHSA-7376-x4rm-3v8x.json b/advisories/unreviewed/2025/06/GHSA-7376-x4rm-3v8x/GHSA-7376-x4rm-3v8x.json new file mode 100644 index 00000000000..d9425946541 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-7376-x4rm-3v8x/GHSA-7376-x4rm-3v8x.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7376-x4rm-3v8x", + "modified": "2025-06-09T21:30:52Z", + "published": "2025-06-09T21:30:52Z", + "aliases": [ + "CVE-2025-5914" + ], + "details": "A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free vulnerability can result in memory corruption, enabling an attacker to execute arbitrary code or cause a denial-of-service condition.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5914" + }, + { + "type": "WEB", + "url": "https://github.com/libarchive/libarchive/pull/2598" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-5914" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370861" + }, + { + "type": "WEB", + "url": "https://github.com/libarchive/libarchive/releases/tag/v3.8.0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-415" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T20:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-79vf-hf9f-j9q8/GHSA-79vf-hf9f-j9q8.json b/advisories/unreviewed/2025/06/GHSA-79vf-hf9f-j9q8/GHSA-79vf-hf9f-j9q8.json new file mode 100644 index 00000000000..eceaf0bd0bf --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-79vf-hf9f-j9q8/GHSA-79vf-hf9f-j9q8.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-79vf-hf9f-j9q8", + "modified": "2025-06-09T21:30:52Z", + "published": "2025-06-09T21:30:52Z", + "aliases": [ + "CVE-2025-5897" + ], + "details": "A vulnerability was found in vuejs vue-cli up to 5.0.8. It has been rated as problematic. This issue affects the function HtmlPwaPlugin of the file packages/@vue/cli-plugin-pwa/lib/HtmlPwaPlugin.js of the component Markdown Code Handler. The manipulation leads to inefficient regular expression complexity. The attack may be initiated remotely.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5897" + }, + { + "type": "WEB", + "url": "https://github.com/vuejs/vue-cli/pull/7478" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311669" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311669" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.585798" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T21:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-8388-575x-9wmq/GHSA-8388-575x-9wmq.json b/advisories/unreviewed/2025/06/GHSA-8388-575x-9wmq/GHSA-8388-575x-9wmq.json index 91382b8cea8..a3bf27871c2 100644 --- a/advisories/unreviewed/2025/06/GHSA-8388-575x-9wmq/GHSA-8388-575x-9wmq.json +++ b/advisories/unreviewed/2025/06/GHSA-8388-575x-9wmq/GHSA-8388-575x-9wmq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8388-575x-9wmq", - "modified": "2025-06-06T06:30:26Z", + "modified": "2025-06-09T21:30:46Z", "published": "2025-06-06T06:30:26Z", "aliases": [ "CVE-2023-2921" ], "details": "The Short URL WordPress plugin through 1.6.8 does not properly sanitise and escape a parameter before using it in SQL statement, leading to a SQL injection exploitable by users with relatively low privilege on the site, like subscribers.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-06T06:15:30Z" diff --git a/advisories/unreviewed/2025/06/GHSA-8j85-hmc5-39qq/GHSA-8j85-hmc5-39qq.json b/advisories/unreviewed/2025/06/GHSA-8j85-hmc5-39qq/GHSA-8j85-hmc5-39qq.json index 002f743e88f..2bc9667eb48 100644 --- a/advisories/unreviewed/2025/06/GHSA-8j85-hmc5-39qq/GHSA-8j85-hmc5-39qq.json +++ b/advisories/unreviewed/2025/06/GHSA-8j85-hmc5-39qq/GHSA-8j85-hmc5-39qq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8j85-hmc5-39qq", - "modified": "2025-06-09T18:32:16Z", + "modified": "2025-06-09T21:30:50Z", "published": "2025-06-09T18:32:16Z", "aliases": [ "CVE-2025-29627" ], "details": "An issue in KeeperChat IOS Application v.5.8.8 allows a physically proximate attacker to escalate privileges via the Biometric Authentication Module", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-09T17:15:28Z" diff --git a/advisories/unreviewed/2025/06/GHSA-94cm-j3mf-q873/GHSA-94cm-j3mf-q873.json b/advisories/unreviewed/2025/06/GHSA-94cm-j3mf-q873/GHSA-94cm-j3mf-q873.json new file mode 100644 index 00000000000..f745c3de647 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-94cm-j3mf-q873/GHSA-94cm-j3mf-q873.json @@ -0,0 +1,60 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-94cm-j3mf-q873", + "modified": "2025-06-09T21:30:51Z", + "published": "2025-06-09T21:30:51Z", + "aliases": [ + "CVE-2025-5895" + ], + "details": "A vulnerability was found in Metabase 54.10. It has been classified as problematic. This affects the function parseDataUri of the file frontend/src/metabase/lib/dom.js. The manipulation leads to inefficient regular expression complexity. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The patch is named 4454ebbdc7719016bf80ca0f34859ce5cee9f6b0. It is recommended to apply a patch to fix this issue.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5895" + }, + { + "type": "WEB", + "url": "https://github.com/metabase/metabase/pull/57011" + }, + { + "type": "WEB", + "url": "https://github.com/metabase/metabase/pull/57011#pullrequestreview-2792664135" + }, + { + "type": "WEB", + "url": "https://github.com/metabase/metabase/commit/4454ebbdc7719016bf80ca0f34859ce5cee9f6b0" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311667" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311667" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.585795" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T20:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-cc44-4fcv-cqh7/GHSA-cc44-4fcv-cqh7.json b/advisories/unreviewed/2025/06/GHSA-cc44-4fcv-cqh7/GHSA-cc44-4fcv-cqh7.json index fbc937411b3..9cf2db84fad 100644 --- a/advisories/unreviewed/2025/06/GHSA-cc44-4fcv-cqh7/GHSA-cc44-4fcv-cqh7.json +++ b/advisories/unreviewed/2025/06/GHSA-cc44-4fcv-cqh7/GHSA-cc44-4fcv-cqh7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cc44-4fcv-cqh7", - "modified": "2025-06-09T18:32:17Z", + "modified": "2025-06-09T21:30:50Z", "published": "2025-06-09T18:32:16Z", "aliases": [ "CVE-2025-46041" ], "details": "A stored cross-site scripting (XSS) vulnerability in Anchor CMS v0.12.7 allows attackers to inject malicious JavaScript via the page description field in the page creation interface (/admin/pages/add).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-09T17:15:29Z" diff --git a/advisories/unreviewed/2025/06/GHSA-cwjc-83cr-56p7/GHSA-cwjc-83cr-56p7.json b/advisories/unreviewed/2025/06/GHSA-cwjc-83cr-56p7/GHSA-cwjc-83cr-56p7.json index 7d07af37079..ba0eb6e69e3 100644 --- a/advisories/unreviewed/2025/06/GHSA-cwjc-83cr-56p7/GHSA-cwjc-83cr-56p7.json +++ b/advisories/unreviewed/2025/06/GHSA-cwjc-83cr-56p7/GHSA-cwjc-83cr-56p7.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/06/GHSA-f5xg-cfpj-2mw6/GHSA-f5xg-cfpj-2mw6.json b/advisories/unreviewed/2025/06/GHSA-f5xg-cfpj-2mw6/GHSA-f5xg-cfpj-2mw6.json new file mode 100644 index 00000000000..d146aa70e8c --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-f5xg-cfpj-2mw6/GHSA-f5xg-cfpj-2mw6.json @@ -0,0 +1,60 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f5xg-cfpj-2mw6", + "modified": "2025-06-09T21:30:52Z", + "published": "2025-06-09T21:30:52Z", + "aliases": [ + "CVE-2025-5896" + ], + "details": "A vulnerability was found in tarojs taro up to 4.1.1. It has been declared as problematic. This vulnerability affects unknown code of the file taro/packages/css-to-react-native/src/index.js. The manipulation leads to inefficient regular expression complexity. The attack can be initiated remotely. Upgrading to version 4.1.2 is able to address this issue. The name of the patch is c2e321a8b6fc873427c466c69f41ed0b5e8814bf. It is recommended to upgrade the affected component.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5896" + }, + { + "type": "WEB", + "url": "https://github.com/NervJS/taro/pull/17619" + }, + { + "type": "WEB", + "url": "https://github.com/NervJS/taro/commit/c2e321a8b6fc873427c466c69f41ed0b5e8814bf" + }, + { + "type": "WEB", + "url": "https://github.com/NervJS/taro/releases/tag/v4.1.2" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311668" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311668" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.585796" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T21:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-fg6q-2hc3-4h9c/GHSA-fg6q-2hc3-4h9c.json b/advisories/unreviewed/2025/06/GHSA-fg6q-2hc3-4h9c/GHSA-fg6q-2hc3-4h9c.json new file mode 100644 index 00000000000..a76e39329a5 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-fg6q-2hc3-4h9c/GHSA-fg6q-2hc3-4h9c.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fg6q-2hc3-4h9c", + "modified": "2025-06-09T21:30:52Z", + "published": "2025-06-09T21:30:51Z", + "aliases": [ + "CVE-2025-5916" + ], + "details": "A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content bytes. An attacker could craft a malicious WARC archive to induce this overflow, potentially leading to unpredictable program behavior, memory corruption, or a denial-of-service condition within applications that process such archives using libarchive.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5916" + }, + { + "type": "WEB", + "url": "https://github.com/libarchive/libarchive/pull/2568" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-5916" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370872" + }, + { + "type": "WEB", + "url": "https://github.com/libarchive/libarchive/releases/tag/v3.8.0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T20:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-fj44-h6xw-896g/GHSA-fj44-h6xw-896g.json b/advisories/unreviewed/2025/06/GHSA-fj44-h6xw-896g/GHSA-fj44-h6xw-896g.json index 9dae85d94ea..2e3ff3daf21 100644 --- a/advisories/unreviewed/2025/06/GHSA-fj44-h6xw-896g/GHSA-fj44-h6xw-896g.json +++ b/advisories/unreviewed/2025/06/GHSA-fj44-h6xw-896g/GHSA-fj44-h6xw-896g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fj44-h6xw-896g", - "modified": "2025-06-09T18:32:17Z", + "modified": "2025-06-09T21:30:50Z", "published": "2025-06-09T18:32:16Z", "aliases": [ "CVE-2025-45001" ], "details": "react-native-keys 0.7.11 is vulnerable to sensitive information disclosure (remote) as encryption cipher and Base64 chunks are stored as plaintext in the compiled native binary. Attackers can extract these secrets using basic static analysis tools.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-312" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-09T17:15:29Z" diff --git a/advisories/unreviewed/2025/06/GHSA-gx3m-44w2-wmgh/GHSA-gx3m-44w2-wmgh.json b/advisories/unreviewed/2025/06/GHSA-gx3m-44w2-wmgh/GHSA-gx3m-44w2-wmgh.json index 870b2a8a240..0334a61eb3b 100644 --- a/advisories/unreviewed/2025/06/GHSA-gx3m-44w2-wmgh/GHSA-gx3m-44w2-wmgh.json +++ b/advisories/unreviewed/2025/06/GHSA-gx3m-44w2-wmgh/GHSA-gx3m-44w2-wmgh.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/06/GHSA-j8p7-wwq4-9gm4/GHSA-j8p7-wwq4-9gm4.json b/advisories/unreviewed/2025/06/GHSA-j8p7-wwq4-9gm4/GHSA-j8p7-wwq4-9gm4.json index 7359a04c969..82d83763075 100644 --- a/advisories/unreviewed/2025/06/GHSA-j8p7-wwq4-9gm4/GHSA-j8p7-wwq4-9gm4.json +++ b/advisories/unreviewed/2025/06/GHSA-j8p7-wwq4-9gm4/GHSA-j8p7-wwq4-9gm4.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/06/GHSA-prxp-75xx-3cxw/GHSA-prxp-75xx-3cxw.json b/advisories/unreviewed/2025/06/GHSA-prxp-75xx-3cxw/GHSA-prxp-75xx-3cxw.json new file mode 100644 index 00000000000..f34b59df64b --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-prxp-75xx-3cxw/GHSA-prxp-75xx-3cxw.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-prxp-75xx-3cxw", + "modified": "2025-06-09T21:30:51Z", + "published": "2025-06-09T21:30:51Z", + "aliases": [ + "CVE-2025-5892" + ], + "details": "A vulnerability, which was classified as problematic, has been found in RocketChat up to 7.6.1. This issue affects the function parseMessage of the file /apps/meteor/app/irc/server/servers/RFC2813/parseMessage.js. The manipulation of the argument line leads to inefficient regular expression complexity. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5892" + }, + { + "type": "WEB", + "url": "https://github.com/RocketChat/Rocket.Chat/pull/35711" + }, + { + "type": "WEB", + "url": "https://gist.github.com/mmmsssttt404/0fcda3b3e85edafc4eaa6816aa252deb" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311663" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311663" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.585751" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T20:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-rfq2-xjgr-h957/GHSA-rfq2-xjgr-h957.json b/advisories/unreviewed/2025/06/GHSA-rfq2-xjgr-h957/GHSA-rfq2-xjgr-h957.json new file mode 100644 index 00000000000..eda5b6c7833 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-rfq2-xjgr-h957/GHSA-rfq2-xjgr-h957.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rfq2-xjgr-h957", + "modified": "2025-06-09T21:30:52Z", + "published": "2025-06-09T21:30:51Z", + "aliases": [ + "CVE-2025-5915" + ], + "details": "A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may attempt to read beyond the allocated memory buffer, which can result in unpredictable program behavior, crashes (denial of service), or the disclosure of sensitive information from adjacent memory regions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5915" + }, + { + "type": "WEB", + "url": "https://github.com/libarchive/libarchive/pull/2599" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-5915" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370865" + }, + { + "type": "WEB", + "url": "https://github.com/libarchive/libarchive/releases/tag/v3.8.0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T20:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-rw8p-95qv-rmgj/GHSA-rw8p-95qv-rmgj.json b/advisories/unreviewed/2025/06/GHSA-rw8p-95qv-rmgj/GHSA-rw8p-95qv-rmgj.json index 83ab92beb9d..f71205c0de2 100644 --- a/advisories/unreviewed/2025/06/GHSA-rw8p-95qv-rmgj/GHSA-rw8p-95qv-rmgj.json +++ b/advisories/unreviewed/2025/06/GHSA-rw8p-95qv-rmgj/GHSA-rw8p-95qv-rmgj.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/06/GHSA-v57j-pmmv-88c8/GHSA-v57j-pmmv-88c8.json b/advisories/unreviewed/2025/06/GHSA-v57j-pmmv-88c8/GHSA-v57j-pmmv-88c8.json index fd3208b2292..af82bb173da 100644 --- a/advisories/unreviewed/2025/06/GHSA-v57j-pmmv-88c8/GHSA-v57j-pmmv-88c8.json +++ b/advisories/unreviewed/2025/06/GHSA-v57j-pmmv-88c8/GHSA-v57j-pmmv-88c8.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/06/GHSA-v6h2-p8h4-qcjw/GHSA-v6h2-p8h4-qcjw.json b/advisories/unreviewed/2025/06/GHSA-v6h2-p8h4-qcjw/GHSA-v6h2-p8h4-qcjw.json new file mode 100644 index 00000000000..3a5766c1368 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-v6h2-p8h4-qcjw/GHSA-v6h2-p8h4-qcjw.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v6h2-p8h4-qcjw", + "modified": "2025-06-09T21:30:51Z", + "published": "2025-06-09T21:30:51Z", + "aliases": [ + "CVE-2025-5889" + ], + "details": "A vulnerability was found in juliangruber brace-expansion up to 1.1.11. It has been rated as problematic. Affected by this issue is the function expand of the file index.js. The manipulation leads to inefficient regular expression complexity. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is a5b98a4f30d7813266b221435e1eaaf25a1b0ac5. It is recommended to apply a patch to fix this issue.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5889" + }, + { + "type": "WEB", + "url": "https://github.com/juliangruber/brace-expansion/pull/65/commits/a5b98a4f30d7813266b221435e1eaaf25a1b0ac5" + }, + { + "type": "WEB", + "url": "https://gist.github.com/mmmsssttt404/37a40ce7d6e5ca604858fe30814d9466" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311660" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311660" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.585717" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T19:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-v8mm-64rg-m2wg/GHSA-v8mm-64rg-m2wg.json b/advisories/unreviewed/2025/06/GHSA-v8mm-64rg-m2wg/GHSA-v8mm-64rg-m2wg.json index bedcd9c2730..9fbad5c4afd 100644 --- a/advisories/unreviewed/2025/06/GHSA-v8mm-64rg-m2wg/GHSA-v8mm-64rg-m2wg.json +++ b/advisories/unreviewed/2025/06/GHSA-v8mm-64rg-m2wg/GHSA-v8mm-64rg-m2wg.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/06/GHSA-vc7q-fmv2-m8g3/GHSA-vc7q-fmv2-m8g3.json b/advisories/unreviewed/2025/06/GHSA-vc7q-fmv2-m8g3/GHSA-vc7q-fmv2-m8g3.json index a1b9d0d7330..b462f413980 100644 --- a/advisories/unreviewed/2025/06/GHSA-vc7q-fmv2-m8g3/GHSA-vc7q-fmv2-m8g3.json +++ b/advisories/unreviewed/2025/06/GHSA-vc7q-fmv2-m8g3/GHSA-vc7q-fmv2-m8g3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vc7q-fmv2-m8g3", - "modified": "2025-06-09T18:32:16Z", + "modified": "2025-06-09T21:30:50Z", "published": "2025-06-09T18:32:16Z", "aliases": [ "CVE-2025-45002" ], "details": "Vigybag v1.0 and before is vulnerable to Cross Site Scripting (XSS) via the upload profile picture function under my profile.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-09T17:15:29Z" diff --git a/advisories/unreviewed/2025/06/GHSA-vm64-xcc6-8fhj/GHSA-vm64-xcc6-8fhj.json b/advisories/unreviewed/2025/06/GHSA-vm64-xcc6-8fhj/GHSA-vm64-xcc6-8fhj.json index 320daa6ab17..ad2cd7bc48b 100644 --- a/advisories/unreviewed/2025/06/GHSA-vm64-xcc6-8fhj/GHSA-vm64-xcc6-8fhj.json +++ b/advisories/unreviewed/2025/06/GHSA-vm64-xcc6-8fhj/GHSA-vm64-xcc6-8fhj.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/06/GHSA-w6g8-vwvh-5j95/GHSA-w6g8-vwvh-5j95.json b/advisories/unreviewed/2025/06/GHSA-w6g8-vwvh-5j95/GHSA-w6g8-vwvh-5j95.json index 9e7abc81c6c..ebe71369ff5 100644 --- a/advisories/unreviewed/2025/06/GHSA-w6g8-vwvh-5j95/GHSA-w6g8-vwvh-5j95.json +++ b/advisories/unreviewed/2025/06/GHSA-w6g8-vwvh-5j95/GHSA-w6g8-vwvh-5j95.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/06/GHSA-w866-3fpp-r6c4/GHSA-w866-3fpp-r6c4.json b/advisories/unreviewed/2025/06/GHSA-w866-3fpp-r6c4/GHSA-w866-3fpp-r6c4.json index b85c01eedd7..9cb757f06db 100644 --- a/advisories/unreviewed/2025/06/GHSA-w866-3fpp-r6c4/GHSA-w866-3fpp-r6c4.json +++ b/advisories/unreviewed/2025/06/GHSA-w866-3fpp-r6c4/GHSA-w866-3fpp-r6c4.json @@ -50,7 +50,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/06/GHSA-x5gf-qvw8-r2rm/GHSA-x5gf-qvw8-r2rm.json b/advisories/unreviewed/2025/06/GHSA-x5gf-qvw8-r2rm/GHSA-x5gf-qvw8-r2rm.json new file mode 100644 index 00000000000..ab2439ad272 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-x5gf-qvw8-r2rm/GHSA-x5gf-qvw8-r2rm.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x5gf-qvw8-r2rm", + "modified": "2025-06-09T21:30:51Z", + "published": "2025-06-09T21:30:51Z", + "aliases": [ + "CVE-2025-5891" + ], + "details": "A vulnerability classified as problematic was found in Unitech pm2 up to 6.0.6. This vulnerability affects unknown code of the file /lib/tools/Config.js. The manipulation leads to inefficient regular expression complexity. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5891" + }, + { + "type": "WEB", + "url": "https://github.com/Unitech/pm2/pull/5971" + }, + { + "type": "WEB", + "url": "https://gist.github.com/mmmsssttt404/407e2ffe3e0eaa393ad923a86316a385" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311662" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311662" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.585750" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T19:15:25Z" + } +} \ No newline at end of file