diff --git a/advisories/unreviewed/2022/10/GHSA-3mw6-fgc8-7frc/GHSA-3mw6-fgc8-7frc.json b/advisories/unreviewed/2022/10/GHSA-3mw6-fgc8-7frc/GHSA-3mw6-fgc8-7frc.json index 0b34eee2c93..820e3df742d 100644 --- a/advisories/unreviewed/2022/10/GHSA-3mw6-fgc8-7frc/GHSA-3mw6-fgc8-7frc.json +++ b/advisories/unreviewed/2022/10/GHSA-3mw6-fgc8-7frc/GHSA-3mw6-fgc8-7frc.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-4q4h-g4fj-3qhw/GHSA-4q4h-g4fj-3qhw.json b/advisories/unreviewed/2022/10/GHSA-4q4h-g4fj-3qhw/GHSA-4q4h-g4fj-3qhw.json index 799bc6bd2ed..921185dad06 100644 --- a/advisories/unreviewed/2022/10/GHSA-4q4h-g4fj-3qhw/GHSA-4q4h-g4fj-3qhw.json +++ b/advisories/unreviewed/2022/10/GHSA-4q4h-g4fj-3qhw/GHSA-4q4h-g4fj-3qhw.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-5v74-qfg6-c824/GHSA-5v74-qfg6-c824.json b/advisories/unreviewed/2022/10/GHSA-5v74-qfg6-c824/GHSA-5v74-qfg6-c824.json index 0da5d1b9d2b..44847e7ad08 100644 --- a/advisories/unreviewed/2022/10/GHSA-5v74-qfg6-c824/GHSA-5v74-qfg6-c824.json +++ b/advisories/unreviewed/2022/10/GHSA-5v74-qfg6-c824/GHSA-5v74-qfg6-c824.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5v74-qfg6-c824", - "modified": "2022-10-24T19:00:21Z", + "modified": "2025-05-09T15:31:30Z", "published": "2022-10-19T12:00:18Z", "aliases": [ "CVE-2020-23648" diff --git a/advisories/unreviewed/2022/10/GHSA-5w9w-8mvw-9v74/GHSA-5w9w-8mvw-9v74.json b/advisories/unreviewed/2022/10/GHSA-5w9w-8mvw-9v74/GHSA-5w9w-8mvw-9v74.json index 6b6982c0ab0..e37ec33e284 100644 --- a/advisories/unreviewed/2022/10/GHSA-5w9w-8mvw-9v74/GHSA-5w9w-8mvw-9v74.json +++ b/advisories/unreviewed/2022/10/GHSA-5w9w-8mvw-9v74/GHSA-5w9w-8mvw-9v74.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5w9w-8mvw-9v74", - "modified": "2022-10-21T19:01:14Z", + "modified": "2025-05-09T15:31:36Z", "published": "2022-10-19T19:00:17Z", "aliases": [ "CVE-2022-23241" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-jf8h-prq4-w478/GHSA-jf8h-prq4-w478.json b/advisories/unreviewed/2022/10/GHSA-jf8h-prq4-w478/GHSA-jf8h-prq4-w478.json index fbacfc436ee..55b70b0fb7f 100644 --- a/advisories/unreviewed/2022/10/GHSA-jf8h-prq4-w478/GHSA-jf8h-prq4-w478.json +++ b/advisories/unreviewed/2022/10/GHSA-jf8h-prq4-w478/GHSA-jf8h-prq4-w478.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-252" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-p4xh-2j8v-rpq8/GHSA-p4xh-2j8v-rpq8.json b/advisories/unreviewed/2022/10/GHSA-p4xh-2j8v-rpq8/GHSA-p4xh-2j8v-rpq8.json index 38729561ee9..5a691f36912 100644 --- a/advisories/unreviewed/2022/10/GHSA-p4xh-2j8v-rpq8/GHSA-p4xh-2j8v-rpq8.json +++ b/advisories/unreviewed/2022/10/GHSA-p4xh-2j8v-rpq8/GHSA-p4xh-2j8v-rpq8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p4xh-2j8v-rpq8", - "modified": "2022-10-21T19:01:13Z", + "modified": "2025-05-09T15:31:30Z", "published": "2022-10-19T12:00:19Z", "aliases": [ "CVE-2016-20016" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-78" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-pjrg-447r-7rp9/GHSA-pjrg-447r-7rp9.json b/advisories/unreviewed/2022/10/GHSA-pjrg-447r-7rp9/GHSA-pjrg-447r-7rp9.json index 5cfb2f09ebc..2cdd3e0664d 100644 --- a/advisories/unreviewed/2022/10/GHSA-pjrg-447r-7rp9/GHSA-pjrg-447r-7rp9.json +++ b/advisories/unreviewed/2022/10/GHSA-pjrg-447r-7rp9/GHSA-pjrg-447r-7rp9.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-125" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-rcm9-3jwh-7pxx/GHSA-rcm9-3jwh-7pxx.json b/advisories/unreviewed/2022/10/GHSA-rcm9-3jwh-7pxx/GHSA-rcm9-3jwh-7pxx.json index e96c93e9307..c4942c9da58 100644 --- a/advisories/unreviewed/2022/10/GHSA-rcm9-3jwh-7pxx/GHSA-rcm9-3jwh-7pxx.json +++ b/advisories/unreviewed/2022/10/GHSA-rcm9-3jwh-7pxx/GHSA-rcm9-3jwh-7pxx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rcm9-3jwh-7pxx", - "modified": "2022-10-21T12:00:21Z", + "modified": "2025-05-09T15:31:35Z", "published": "2022-10-19T19:00:24Z", "aliases": [ "CVE-2022-23734" @@ -19,6 +19,22 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-23734" }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server%403.2/admin/release-notes#3.2.16" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server%403.3/admin/release-notes#3.3.11" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server%403.4/admin/release-notes#3.4.6" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server%403.5/admin/release-notes#3.5.3" + }, { "type": "WEB", "url": "https://docs.github.com/en/enterprise-server@3.2/admin/release-notes#3.2.16" diff --git a/advisories/unreviewed/2022/10/GHSA-rf38-5cw8-grm4/GHSA-rf38-5cw8-grm4.json b/advisories/unreviewed/2022/10/GHSA-rf38-5cw8-grm4/GHSA-rf38-5cw8-grm4.json index 9154c258b9b..d7beed46567 100644 --- a/advisories/unreviewed/2022/10/GHSA-rf38-5cw8-grm4/GHSA-rf38-5cw8-grm4.json +++ b/advisories/unreviewed/2022/10/GHSA-rf38-5cw8-grm4/GHSA-rf38-5cw8-grm4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rf38-5cw8-grm4", - "modified": "2022-10-21T12:00:21Z", + "modified": "2025-05-09T15:31:30Z", "published": "2022-10-19T12:00:21Z", "aliases": [ "CVE-2022-33077" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-33077" }, + { + "type": "WEB", + "url": "https://medium.com/%40rohan_pagey/cve-2022-33077-idor-to-change-address-of-any-customer-via-parameter-pollution-in-nopcommerce-4-5-2fa4bc763cc6" + }, { "type": "WEB", "url": "https://medium.com/@rohan_pagey/cve-2022-33077-idor-to-change-address-of-any-customer-via-parameter-pollution-in-nopcommerce-4-5-2fa4bc763cc6" diff --git a/advisories/unreviewed/2024/03/GHSA-6c9c-w2p4-7rfx/GHSA-6c9c-w2p4-7rfx.json b/advisories/unreviewed/2024/03/GHSA-6c9c-w2p4-7rfx/GHSA-6c9c-w2p4-7rfx.json index 49e4b1edbc8..d1f4456e583 100644 --- a/advisories/unreviewed/2024/03/GHSA-6c9c-w2p4-7rfx/GHSA-6c9c-w2p4-7rfx.json +++ b/advisories/unreviewed/2024/03/GHSA-6c9c-w2p4-7rfx/GHSA-6c9c-w2p4-7rfx.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-6c9c-w2p4-7rfx", - "modified": "2024-03-19T15:30:34Z", + "modified": "2025-05-09T15:31:37Z", "published": "2024-03-19T15:30:34Z", "aliases": [ "CVE-2024-29109" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jan-Peter Lambeck & 3UU Shariff Wrapper allows Stored XSS.This issue affects Shariff Wrapper: from n/a through 4.6.10.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jan-Peter Lambeck & 3UU Shariff Wrapper allows Stored XSS.This issue affects Shariff Wrapper: from n/a through 4.6.10.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-93jv-fpc3-9m4w/GHSA-93jv-fpc3-9m4w.json b/advisories/unreviewed/2024/03/GHSA-93jv-fpc3-9m4w/GHSA-93jv-fpc3-9m4w.json index 4c3a5c9f262..edd1460cb4b 100644 --- a/advisories/unreviewed/2024/03/GHSA-93jv-fpc3-9m4w/GHSA-93jv-fpc3-9m4w.json +++ b/advisories/unreviewed/2024/03/GHSA-93jv-fpc3-9m4w/GHSA-93jv-fpc3-9m4w.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-9jr7-gg57-r7pf/GHSA-9jr7-gg57-r7pf.json b/advisories/unreviewed/2024/03/GHSA-9jr7-gg57-r7pf/GHSA-9jr7-gg57-r7pf.json index 5355a3ea37f..11a1125cf56 100644 --- a/advisories/unreviewed/2024/03/GHSA-9jr7-gg57-r7pf/GHSA-9jr7-gg57-r7pf.json +++ b/advisories/unreviewed/2024/03/GHSA-9jr7-gg57-r7pf/GHSA-9jr7-gg57-r7pf.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-fc5p-vfgp-xc5m/GHSA-fc5p-vfgp-xc5m.json b/advisories/unreviewed/2024/03/GHSA-fc5p-vfgp-xc5m/GHSA-fc5p-vfgp-xc5m.json index fc698bce471..426cd6d32a1 100644 --- a/advisories/unreviewed/2024/03/GHSA-fc5p-vfgp-xc5m/GHSA-fc5p-vfgp-xc5m.json +++ b/advisories/unreviewed/2024/03/GHSA-fc5p-vfgp-xc5m/GHSA-fc5p-vfgp-xc5m.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-qjj5-xfqc-jqqm/GHSA-qjj5-xfqc-jqqm.json b/advisories/unreviewed/2024/04/GHSA-qjj5-xfqc-jqqm/GHSA-qjj5-xfqc-jqqm.json index a47b5fdb6af..4c39075ddf9 100644 --- a/advisories/unreviewed/2024/04/GHSA-qjj5-xfqc-jqqm/GHSA-qjj5-xfqc-jqqm.json +++ b/advisories/unreviewed/2024/04/GHSA-qjj5-xfqc-jqqm/GHSA-qjj5-xfqc-jqqm.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-32q5-2wwg-3v4v/GHSA-32q5-2wwg-3v4v.json b/advisories/unreviewed/2024/06/GHSA-32q5-2wwg-3v4v/GHSA-32q5-2wwg-3v4v.json index df15f072a7a..f4b94b593d4 100644 --- a/advisories/unreviewed/2024/06/GHSA-32q5-2wwg-3v4v/GHSA-32q5-2wwg-3v4v.json +++ b/advisories/unreviewed/2024/06/GHSA-32q5-2wwg-3v4v/GHSA-32q5-2wwg-3v4v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-32q5-2wwg-3v4v", - "modified": "2024-06-20T09:30:59Z", + "modified": "2025-05-09T15:31:38Z", "published": "2024-06-20T09:30:59Z", "aliases": [ "CVE-2024-4098" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-552" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-99mv-9fmf-vmvq/GHSA-99mv-9fmf-vmvq.json b/advisories/unreviewed/2024/06/GHSA-99mv-9fmf-vmvq/GHSA-99mv-9fmf-vmvq.json index 14294e92e17..4d172b46b77 100644 --- a/advisories/unreviewed/2024/06/GHSA-99mv-9fmf-vmvq/GHSA-99mv-9fmf-vmvq.json +++ b/advisories/unreviewed/2024/06/GHSA-99mv-9fmf-vmvq/GHSA-99mv-9fmf-vmvq.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-9hcv-xw76-m4h6/GHSA-9hcv-xw76-m4h6.json b/advisories/unreviewed/2025/03/GHSA-9hcv-xw76-m4h6/GHSA-9hcv-xw76-m4h6.json index 8219d76eebd..94f1105fc4f 100644 --- a/advisories/unreviewed/2025/03/GHSA-9hcv-xw76-m4h6/GHSA-9hcv-xw76-m4h6.json +++ b/advisories/unreviewed/2025/03/GHSA-9hcv-xw76-m4h6/GHSA-9hcv-xw76-m4h6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9hcv-xw76-m4h6", - "modified": "2025-05-05T09:31:09Z", + "modified": "2025-05-09T15:31:40Z", "published": "2025-03-14T09:34:06Z", "aliases": [ "CVE-2024-8176" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://github.com/libexpat/libexpat/issues/893" }, + { + "type": "WEB", + "url": "https://www.kb.cert.org/vuls/id/760160" + }, { "type": "WEB", "url": "https://ubuntu.com/security/CVE-2024-8176" diff --git a/advisories/unreviewed/2025/04/GHSA-559r-938h-gh79/GHSA-559r-938h-gh79.json b/advisories/unreviewed/2025/04/GHSA-559r-938h-gh79/GHSA-559r-938h-gh79.json index d1108a4753a..e07788c63a9 100644 --- a/advisories/unreviewed/2025/04/GHSA-559r-938h-gh79/GHSA-559r-938h-gh79.json +++ b/advisories/unreviewed/2025/04/GHSA-559r-938h-gh79/GHSA-559r-938h-gh79.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-5wfx-74q9-f9jq/GHSA-5wfx-74q9-f9jq.json b/advisories/unreviewed/2025/04/GHSA-5wfx-74q9-f9jq/GHSA-5wfx-74q9-f9jq.json index cbe72ba9bb1..4a3f4ba6292 100644 --- a/advisories/unreviewed/2025/04/GHSA-5wfx-74q9-f9jq/GHSA-5wfx-74q9-f9jq.json +++ b/advisories/unreviewed/2025/04/GHSA-5wfx-74q9-f9jq/GHSA-5wfx-74q9-f9jq.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-8cvj-85rh-hgr2/GHSA-8cvj-85rh-hgr2.json b/advisories/unreviewed/2025/04/GHSA-8cvj-85rh-hgr2/GHSA-8cvj-85rh-hgr2.json index 3fe90e7cc34..1201a6a2110 100644 --- a/advisories/unreviewed/2025/04/GHSA-8cvj-85rh-hgr2/GHSA-8cvj-85rh-hgr2.json +++ b/advisories/unreviewed/2025/04/GHSA-8cvj-85rh-hgr2/GHSA-8cvj-85rh-hgr2.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-969p-47jr-q9pv/GHSA-969p-47jr-q9pv.json b/advisories/unreviewed/2025/04/GHSA-969p-47jr-q9pv/GHSA-969p-47jr-q9pv.json index a3327d41e83..973ac322bed 100644 --- a/advisories/unreviewed/2025/04/GHSA-969p-47jr-q9pv/GHSA-969p-47jr-q9pv.json +++ b/advisories/unreviewed/2025/04/GHSA-969p-47jr-q9pv/GHSA-969p-47jr-q9pv.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-vjq9-rqqq-vrgq/GHSA-vjq9-rqqq-vrgq.json b/advisories/unreviewed/2025/04/GHSA-vjq9-rqqq-vrgq/GHSA-vjq9-rqqq-vrgq.json index 31488cea8e7..3b0fb1e73ca 100644 --- a/advisories/unreviewed/2025/04/GHSA-vjq9-rqqq-vrgq/GHSA-vjq9-rqqq-vrgq.json +++ b/advisories/unreviewed/2025/04/GHSA-vjq9-rqqq-vrgq/GHSA-vjq9-rqqq-vrgq.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-4p79-vffr-6jm5/GHSA-4p79-vffr-6jm5.json b/advisories/unreviewed/2025/05/GHSA-4p79-vffr-6jm5/GHSA-4p79-vffr-6jm5.json index 4a99e4e1545..b9f52ea99bc 100644 --- a/advisories/unreviewed/2025/05/GHSA-4p79-vffr-6jm5/GHSA-4p79-vffr-6jm5.json +++ b/advisories/unreviewed/2025/05/GHSA-4p79-vffr-6jm5/GHSA-4p79-vffr-6jm5.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-5cfh-88x5-4pvc/GHSA-5cfh-88x5-4pvc.json b/advisories/unreviewed/2025/05/GHSA-5cfh-88x5-4pvc/GHSA-5cfh-88x5-4pvc.json index 3f069aa5b48..17be1c9961c 100644 --- a/advisories/unreviewed/2025/05/GHSA-5cfh-88x5-4pvc/GHSA-5cfh-88x5-4pvc.json +++ b/advisories/unreviewed/2025/05/GHSA-5cfh-88x5-4pvc/GHSA-5cfh-88x5-4pvc.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-8786-m528-576j/GHSA-8786-m528-576j.json b/advisories/unreviewed/2025/05/GHSA-8786-m528-576j/GHSA-8786-m528-576j.json index b49ad3cecf6..d88031e1462 100644 --- a/advisories/unreviewed/2025/05/GHSA-8786-m528-576j/GHSA-8786-m528-576j.json +++ b/advisories/unreviewed/2025/05/GHSA-8786-m528-576j/GHSA-8786-m528-576j.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-9cfh-cv85-rqx7/GHSA-9cfh-cv85-rqx7.json b/advisories/unreviewed/2025/05/GHSA-9cfh-cv85-rqx7/GHSA-9cfh-cv85-rqx7.json index a37c7355221..9f726d5af18 100644 --- a/advisories/unreviewed/2025/05/GHSA-9cfh-cv85-rqx7/GHSA-9cfh-cv85-rqx7.json +++ b/advisories/unreviewed/2025/05/GHSA-9cfh-cv85-rqx7/GHSA-9cfh-cv85-rqx7.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-c22c-jjc2-m9m6/GHSA-c22c-jjc2-m9m6.json b/advisories/unreviewed/2025/05/GHSA-c22c-jjc2-m9m6/GHSA-c22c-jjc2-m9m6.json index 99152f7c94d..80b89db0845 100644 --- a/advisories/unreviewed/2025/05/GHSA-c22c-jjc2-m9m6/GHSA-c22c-jjc2-m9m6.json +++ b/advisories/unreviewed/2025/05/GHSA-c22c-jjc2-m9m6/GHSA-c22c-jjc2-m9m6.json @@ -50,7 +50,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-cfhv-gvm8-4fxv/GHSA-cfhv-gvm8-4fxv.json b/advisories/unreviewed/2025/05/GHSA-cfhv-gvm8-4fxv/GHSA-cfhv-gvm8-4fxv.json new file mode 100644 index 00000000000..4ec451f07ea --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-cfhv-gvm8-4fxv/GHSA-cfhv-gvm8-4fxv.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cfhv-gvm8-4fxv", + "modified": "2025-05-09T15:31:43Z", + "published": "2025-05-09T15:31:43Z", + "aliases": [ + "CVE-2025-45885" + ], + "details": "PHPGURUKUL Vehicle Parking Management System v1.13 is vulnerable to SQL injection in the /vpms/users/login.php file. Attackers can inject malicious code from the parameter 'emailcont' and use it directly in SQL queries.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45885" + }, + { + "type": "WEB", + "url": "https://github.com/lintian31/vpm-system/blob/main/Vehicle%20parking%20Management%20System.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-09T14:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hgm9-29r5-x94q/GHSA-hgm9-29r5-x94q.json b/advisories/unreviewed/2025/05/GHSA-hgm9-29r5-x94q/GHSA-hgm9-29r5-x94q.json index 6942a406bef..662ebe940f7 100644 --- a/advisories/unreviewed/2025/05/GHSA-hgm9-29r5-x94q/GHSA-hgm9-29r5-x94q.json +++ b/advisories/unreviewed/2025/05/GHSA-hgm9-29r5-x94q/GHSA-hgm9-29r5-x94q.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-hp57-25gh-2gjp/GHSA-hp57-25gh-2gjp.json b/advisories/unreviewed/2025/05/GHSA-hp57-25gh-2gjp/GHSA-hp57-25gh-2gjp.json new file mode 100644 index 00000000000..ba893bf84b0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hp57-25gh-2gjp/GHSA-hp57-25gh-2gjp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hp57-25gh-2gjp", + "modified": "2025-05-09T15:31:43Z", + "published": "2025-05-09T15:31:43Z", + "aliases": [ + "CVE-2024-11861" + ], + "details": "EnerSys AMPA 22.09 and prior versions are vulnerable to command injection leading to privileged remote shell access.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11861" + }, + { + "type": "WEB", + "url": "https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2025/MNDT-2025-0001.md" + }, + { + "type": "WEB", + "url": "https://www.enersys.com/4996bf/globalassets/documents/corporate/cve/enersys_cve-2024-11861-final.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-09T14:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p2j9-hh6h-8mxx/GHSA-p2j9-hh6h-8mxx.json b/advisories/unreviewed/2025/05/GHSA-p2j9-hh6h-8mxx/GHSA-p2j9-hh6h-8mxx.json new file mode 100644 index 00000000000..71eabd68bd5 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p2j9-hh6h-8mxx/GHSA-p2j9-hh6h-8mxx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p2j9-hh6h-8mxx", + "modified": "2025-05-09T15:31:43Z", + "published": "2025-05-09T15:31:43Z", + "aliases": [ + "CVE-2024-12442" + ], + "details": "EnerSys AMPA versions 24.04 through 24.16, inclusive, are vulnerable to command injection leading to privileged remote shell access.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12442" + }, + { + "type": "WEB", + "url": "https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2025/MNDT-2025-0002.md" + }, + { + "type": "WEB", + "url": "https://www.enersys.com/4996df/globalassets/documents/corporate/cve/enersys_cve-2024-12442-final.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-09T14:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-px42-xr3h-wjv8/GHSA-px42-xr3h-wjv8.json b/advisories/unreviewed/2025/05/GHSA-px42-xr3h-wjv8/GHSA-px42-xr3h-wjv8.json new file mode 100644 index 00000000000..9b18d772b43 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-px42-xr3h-wjv8/GHSA-px42-xr3h-wjv8.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-px42-xr3h-wjv8", + "modified": "2025-05-09T15:31:43Z", + "published": "2025-05-09T15:31:43Z", + "aliases": [ + "CVE-2025-45887" + ], + "details": "Yifang CMS v2.0.2 is vulnerable to Server-Side Request Forgery (SSRF) in /api/file/getRemoteContent.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45887" + }, + { + "type": "WEB", + "url": "https://gitee.com/wanglongcn/yifang/issues/IBZVAG" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-09T15:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q787-4mx6-96qg/GHSA-q787-4mx6-96qg.json b/advisories/unreviewed/2025/05/GHSA-q787-4mx6-96qg/GHSA-q787-4mx6-96qg.json index 1520e580ab7..423cf690391 100644 --- a/advisories/unreviewed/2025/05/GHSA-q787-4mx6-96qg/GHSA-q787-4mx6-96qg.json +++ b/advisories/unreviewed/2025/05/GHSA-q787-4mx6-96qg/GHSA-q787-4mx6-96qg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q787-4mx6-96qg", - "modified": "2025-05-08T18:30:42Z", + "modified": "2025-05-09T15:31:43Z", "published": "2025-05-07T21:31:45Z", "aliases": [ "CVE-2025-45388" @@ -19,9 +19,25 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45388" }, + { + "type": "WEB", + "url": "https://github.com/wagtail/wagtail/pull/12672" + }, + { + "type": "WEB", + "url": "https://docs.wagtail.org/en/stable/deployment/under_the_hood.html#documents" + }, { "type": "WEB", "url": "https://github.com/echoBRT/Wagtail-CMS-XSS" + }, + { + "type": "WEB", + "url": "https://github.com/wagtail/wagtail/discussions/12617" + }, + { + "type": "WEB", + "url": "https://github.com/wagtail/wagtail/wiki/Security-team" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/05/GHSA-r3fm-hmmx-f2qh/GHSA-r3fm-hmmx-f2qh.json b/advisories/unreviewed/2025/05/GHSA-r3fm-hmmx-f2qh/GHSA-r3fm-hmmx-f2qh.json index 48c43a3d0d0..d170eeedbf0 100644 --- a/advisories/unreviewed/2025/05/GHSA-r3fm-hmmx-f2qh/GHSA-r3fm-hmmx-f2qh.json +++ b/advisories/unreviewed/2025/05/GHSA-r3fm-hmmx-f2qh/GHSA-r3fm-hmmx-f2qh.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-vx82-68wg-wxq4/GHSA-vx82-68wg-wxq4.json b/advisories/unreviewed/2025/05/GHSA-vx82-68wg-wxq4/GHSA-vx82-68wg-wxq4.json index 7166ccac4c2..2ced0d0212f 100644 --- a/advisories/unreviewed/2025/05/GHSA-vx82-68wg-wxq4/GHSA-vx82-68wg-wxq4.json +++ b/advisories/unreviewed/2025/05/GHSA-vx82-68wg-wxq4/GHSA-vx82-68wg-wxq4.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-x69c-67qv-fx4j/GHSA-x69c-67qv-fx4j.json b/advisories/unreviewed/2025/05/GHSA-x69c-67qv-fx4j/GHSA-x69c-67qv-fx4j.json index f068319e6fd..bf9455f8cc1 100644 --- a/advisories/unreviewed/2025/05/GHSA-x69c-67qv-fx4j/GHSA-x69c-67qv-fx4j.json +++ b/advisories/unreviewed/2025/05/GHSA-x69c-67qv-fx4j/GHSA-x69c-67qv-fx4j.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false,