diff --git a/advisories/unreviewed/2022/05/GHSA-262w-gwhq-grfq/GHSA-262w-gwhq-grfq.json b/advisories/unreviewed/2022/05/GHSA-262w-gwhq-grfq/GHSA-262w-gwhq-grfq.json index 984d0763c40..126019317f7 100644 --- a/advisories/unreviewed/2022/05/GHSA-262w-gwhq-grfq/GHSA-262w-gwhq-grfq.json +++ b/advisories/unreviewed/2022/05/GHSA-262w-gwhq-grfq/GHSA-262w-gwhq-grfq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-262w-gwhq-grfq", - "modified": "2022-05-24T17:15:10Z", + "modified": "2025-05-08T18:30:29Z", "published": "2022-05-24T17:15:10Z", "aliases": [ "CVE-2020-2920" ], "details": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). Supported versions that are affected are 9.3.3, 9.3.5 and 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Agile PLM, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Agile PLM accessible data as well as unauthorized read access to a subset of Oracle Agile PLM accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/10/GHSA-23mm-62vv-wv83/GHSA-23mm-62vv-wv83.json b/advisories/unreviewed/2022/10/GHSA-23mm-62vv-wv83/GHSA-23mm-62vv-wv83.json index 6b55ae53ac8..8d8410129f2 100644 --- a/advisories/unreviewed/2022/10/GHSA-23mm-62vv-wv83/GHSA-23mm-62vv-wv83.json +++ b/advisories/unreviewed/2022/10/GHSA-23mm-62vv-wv83/GHSA-23mm-62vv-wv83.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-23mm-62vv-wv83", - "modified": "2022-10-21T19:01:08Z", + "modified": "2025-05-08T18:30:30Z", "published": "2022-10-21T12:00:16Z", "aliases": [ "CVE-2022-38108" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-38108" }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/171567" + }, { "type": "WEB", "url": "https://www.solarwinds.com/trust-center/security-advisories/CVE-2022-38108" diff --git a/advisories/unreviewed/2022/10/GHSA-44g9-qrmg-2wvf/GHSA-44g9-qrmg-2wvf.json b/advisories/unreviewed/2022/10/GHSA-44g9-qrmg-2wvf/GHSA-44g9-qrmg-2wvf.json index 98405650762..7411b1b088e 100644 --- a/advisories/unreviewed/2022/10/GHSA-44g9-qrmg-2wvf/GHSA-44g9-qrmg-2wvf.json +++ b/advisories/unreviewed/2022/10/GHSA-44g9-qrmg-2wvf/GHSA-44g9-qrmg-2wvf.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-425" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/10/GHSA-8fqj-hqqp-j85q/GHSA-8fqj-hqqp-j85q.json b/advisories/unreviewed/2022/10/GHSA-8fqj-hqqp-j85q/GHSA-8fqj-hqqp-j85q.json index ebeede02772..07bb9d0d398 100644 --- a/advisories/unreviewed/2022/10/GHSA-8fqj-hqqp-j85q/GHSA-8fqj-hqqp-j85q.json +++ b/advisories/unreviewed/2022/10/GHSA-8fqj-hqqp-j85q/GHSA-8fqj-hqqp-j85q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8fqj-hqqp-j85q", - "modified": "2022-10-21T19:01:14Z", + "modified": "2025-05-08T18:30:29Z", "published": "2022-10-20T19:00:36Z", "aliases": [ "CVE-2022-31366" diff --git a/advisories/unreviewed/2022/10/GHSA-mh42-rqv8-hggx/GHSA-mh42-rqv8-hggx.json b/advisories/unreviewed/2022/10/GHSA-mh42-rqv8-hggx/GHSA-mh42-rqv8-hggx.json index d7b00eb33a2..c93b937493d 100644 --- a/advisories/unreviewed/2022/10/GHSA-mh42-rqv8-hggx/GHSA-mh42-rqv8-hggx.json +++ b/advisories/unreviewed/2022/10/GHSA-mh42-rqv8-hggx/GHSA-mh42-rqv8-hggx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mh42-rqv8-hggx", - "modified": "2022-10-21T19:01:09Z", + "modified": "2025-05-08T18:30:30Z", "published": "2022-10-20T19:00:29Z", "aliases": [ "CVE-2020-9285" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-1191" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-v477-cfqw-jjcg/GHSA-v477-cfqw-jjcg.json b/advisories/unreviewed/2022/10/GHSA-v477-cfqw-jjcg/GHSA-v477-cfqw-jjcg.json index 5c6ee08dfdc..acaacae2600 100644 --- a/advisories/unreviewed/2022/10/GHSA-v477-cfqw-jjcg/GHSA-v477-cfqw-jjcg.json +++ b/advisories/unreviewed/2022/10/GHSA-v477-cfqw-jjcg/GHSA-v477-cfqw-jjcg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v477-cfqw-jjcg", - "modified": "2022-10-22T12:00:24Z", + "modified": "2025-05-08T18:30:29Z", "published": "2022-10-20T12:00:16Z", "aliases": [ "CVE-2021-33231" diff --git a/advisories/unreviewed/2023/07/GHSA-jvqw-9mq6-23h9/GHSA-jvqw-9mq6-23h9.json b/advisories/unreviewed/2023/07/GHSA-jvqw-9mq6-23h9/GHSA-jvqw-9mq6-23h9.json index 49f433ab8da..0db7071116b 100644 --- a/advisories/unreviewed/2023/07/GHSA-jvqw-9mq6-23h9/GHSA-jvqw-9mq6-23h9.json +++ b/advisories/unreviewed/2023/07/GHSA-jvqw-9mq6-23h9/GHSA-jvqw-9mq6-23h9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jvqw-9mq6-23h9", - "modified": "2023-11-17T18:30:49Z", + "modified": "2025-05-08T18:30:30Z", "published": "2023-07-01T00:30:45Z", "aliases": [ "CVE-2023-30586" diff --git a/advisories/unreviewed/2023/08/GHSA-356r-x8g9-vh8c/GHSA-356r-x8g9-vh8c.json b/advisories/unreviewed/2023/08/GHSA-356r-x8g9-vh8c/GHSA-356r-x8g9-vh8c.json index 6318cd3a990..8bd208c5c58 100644 --- a/advisories/unreviewed/2023/08/GHSA-356r-x8g9-vh8c/GHSA-356r-x8g9-vh8c.json +++ b/advisories/unreviewed/2023/08/GHSA-356r-x8g9-vh8c/GHSA-356r-x8g9-vh8c.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-693" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/01/GHSA-5rrq-v3j5-cwgm/GHSA-5rrq-v3j5-cwgm.json b/advisories/unreviewed/2024/01/GHSA-5rrq-v3j5-cwgm/GHSA-5rrq-v3j5-cwgm.json index 68f713ba5c6..8b903a21b29 100644 --- a/advisories/unreviewed/2024/01/GHSA-5rrq-v3j5-cwgm/GHSA-5rrq-v3j5-cwgm.json +++ b/advisories/unreviewed/2024/01/GHSA-5rrq-v3j5-cwgm/GHSA-5rrq-v3j5-cwgm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5rrq-v3j5-cwgm", - "modified": "2024-02-05T21:30:31Z", + "modified": "2025-05-08T18:30:30Z", "published": "2024-01-31T00:30:18Z", "aliases": [ "CVE-2024-1059" diff --git a/advisories/unreviewed/2024/02/GHSA-cjc8-gmgf-qv2g/GHSA-cjc8-gmgf-qv2g.json b/advisories/unreviewed/2024/02/GHSA-cjc8-gmgf-qv2g/GHSA-cjc8-gmgf-qv2g.json index 66fdf6dc24d..25d59102dcf 100644 --- a/advisories/unreviewed/2024/02/GHSA-cjc8-gmgf-qv2g/GHSA-cjc8-gmgf-qv2g.json +++ b/advisories/unreviewed/2024/02/GHSA-cjc8-gmgf-qv2g/GHSA-cjc8-gmgf-qv2g.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-1188" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-j4jm-98r4-89rv/GHSA-j4jm-98r4-89rv.json b/advisories/unreviewed/2024/02/GHSA-j4jm-98r4-89rv/GHSA-j4jm-98r4-89rv.json index 436926b907f..b149bc12419 100644 --- a/advisories/unreviewed/2024/02/GHSA-j4jm-98r4-89rv/GHSA-j4jm-98r4-89rv.json +++ b/advisories/unreviewed/2024/02/GHSA-j4jm-98r4-89rv/GHSA-j4jm-98r4-89rv.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-j4jm-98r4-89rv", - "modified": "2024-02-26T18:30:31Z", + "modified": "2025-05-08T18:30:30Z", "published": "2024-02-26T18:30:31Z", "aliases": [ "CVE-2024-25925" ], - "details": "Unrestricted Upload of File with Dangerous Type vulnerability in SYSBASICS WooCommerce Easy Checkout Field Editor, Fees & Discounts.This issue affects WooCommerce Easy Checkout Field Editor, Fees & Discounts: from n/a through 3.5.12.\n\n", + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in SYSBASICS WooCommerce Easy Checkout Field Editor, Fees & Discounts.This issue affects WooCommerce Easy Checkout Field Editor, Fees & Discounts: from n/a through 3.5.12.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/02/GHSA-p85g-mx27-m79q/GHSA-p85g-mx27-m79q.json b/advisories/unreviewed/2024/02/GHSA-p85g-mx27-m79q/GHSA-p85g-mx27-m79q.json index 87ad9cafef4..a1e53b48e01 100644 --- a/advisories/unreviewed/2024/02/GHSA-p85g-mx27-m79q/GHSA-p85g-mx27-m79q.json +++ b/advisories/unreviewed/2024/02/GHSA-p85g-mx27-m79q/GHSA-p85g-mx27-m79q.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-p85g-mx27-m79q", - "modified": "2024-02-26T18:30:31Z", + "modified": "2025-05-08T18:30:30Z", "published": "2024-02-26T18:30:31Z", "aliases": [ "CVE-2024-25913" ], - "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a through 6.2.\n\n", + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a through 6.2.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-6fcx-56j8-8rrw/GHSA-6fcx-56j8-8rrw.json b/advisories/unreviewed/2024/04/GHSA-6fcx-56j8-8rrw/GHSA-6fcx-56j8-8rrw.json index c81d1139ed7..adffceb574a 100644 --- a/advisories/unreviewed/2024/04/GHSA-6fcx-56j8-8rrw/GHSA-6fcx-56j8-8rrw.json +++ b/advisories/unreviewed/2024/04/GHSA-6fcx-56j8-8rrw/GHSA-6fcx-56j8-8rrw.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-qg8g-vp27-m3p5/GHSA-qg8g-vp27-m3p5.json b/advisories/unreviewed/2024/04/GHSA-qg8g-vp27-m3p5/GHSA-qg8g-vp27-m3p5.json index a615ae66cf4..914bc11ff9a 100644 --- a/advisories/unreviewed/2024/04/GHSA-qg8g-vp27-m3p5/GHSA-qg8g-vp27-m3p5.json +++ b/advisories/unreviewed/2024/04/GHSA-qg8g-vp27-m3p5/GHSA-qg8g-vp27-m3p5.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-x3cc-r2hp-r6x7/GHSA-x3cc-r2hp-r6x7.json b/advisories/unreviewed/2024/04/GHSA-x3cc-r2hp-r6x7/GHSA-x3cc-r2hp-r6x7.json index d43de2a8610..59e77702a65 100644 --- a/advisories/unreviewed/2024/04/GHSA-x3cc-r2hp-r6x7/GHSA-x3cc-r2hp-r6x7.json +++ b/advisories/unreviewed/2024/04/GHSA-x3cc-r2hp-r6x7/GHSA-x3cc-r2hp-r6x7.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-fxmj-37cj-x4r5/GHSA-fxmj-37cj-x4r5.json b/advisories/unreviewed/2024/05/GHSA-fxmj-37cj-x4r5/GHSA-fxmj-37cj-x4r5.json index 8969b2345f3..eddf3d75452 100644 --- a/advisories/unreviewed/2024/05/GHSA-fxmj-37cj-x4r5/GHSA-fxmj-37cj-x4r5.json +++ b/advisories/unreviewed/2024/05/GHSA-fxmj-37cj-x4r5/GHSA-fxmj-37cj-x4r5.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-gwqx-m7rc-2c9p/GHSA-gwqx-m7rc-2c9p.json b/advisories/unreviewed/2024/05/GHSA-gwqx-m7rc-2c9p/GHSA-gwqx-m7rc-2c9p.json index 1f69e0b5f93..6bef2f135c3 100644 --- a/advisories/unreviewed/2024/05/GHSA-gwqx-m7rc-2c9p/GHSA-gwqx-m7rc-2c9p.json +++ b/advisories/unreviewed/2024/05/GHSA-gwqx-m7rc-2c9p/GHSA-gwqx-m7rc-2c9p.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-j9wj-h588-6g73/GHSA-j9wj-h588-6g73.json b/advisories/unreviewed/2024/05/GHSA-j9wj-h588-6g73/GHSA-j9wj-h588-6g73.json index f4f68048758..ada6f488488 100644 --- a/advisories/unreviewed/2024/05/GHSA-j9wj-h588-6g73/GHSA-j9wj-h588-6g73.json +++ b/advisories/unreviewed/2024/05/GHSA-j9wj-h588-6g73/GHSA-j9wj-h588-6g73.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-502" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-pvfc-97vc-2gh2/GHSA-pvfc-97vc-2gh2.json b/advisories/unreviewed/2024/05/GHSA-pvfc-97vc-2gh2/GHSA-pvfc-97vc-2gh2.json index 718a4011213..876c880938b 100644 --- a/advisories/unreviewed/2024/05/GHSA-pvfc-97vc-2gh2/GHSA-pvfc-97vc-2gh2.json +++ b/advisories/unreviewed/2024/05/GHSA-pvfc-97vc-2gh2/GHSA-pvfc-97vc-2gh2.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-w2rv-8vw7-735j/GHSA-w2rv-8vw7-735j.json b/advisories/unreviewed/2024/05/GHSA-w2rv-8vw7-735j/GHSA-w2rv-8vw7-735j.json index a4f1d9a9b65..2782c8691ce 100644 --- a/advisories/unreviewed/2024/05/GHSA-w2rv-8vw7-735j/GHSA-w2rv-8vw7-735j.json +++ b/advisories/unreviewed/2024/05/GHSA-w2rv-8vw7-735j/GHSA-w2rv-8vw7-735j.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-w2x6-9r88-x4c6/GHSA-w2x6-9r88-x4c6.json b/advisories/unreviewed/2024/05/GHSA-w2x6-9r88-x4c6/GHSA-w2x6-9r88-x4c6.json index fa729cf516e..1d72a72ec71 100644 --- a/advisories/unreviewed/2024/05/GHSA-w2x6-9r88-x4c6/GHSA-w2x6-9r88-x4c6.json +++ b/advisories/unreviewed/2024/05/GHSA-w2x6-9r88-x4c6/GHSA-w2x6-9r88-x4c6.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-wx86-7jg2-9256/GHSA-wx86-7jg2-9256.json b/advisories/unreviewed/2024/05/GHSA-wx86-7jg2-9256/GHSA-wx86-7jg2-9256.json index e9a6e04ad57..5eef257a10e 100644 --- a/advisories/unreviewed/2024/05/GHSA-wx86-7jg2-9256/GHSA-wx86-7jg2-9256.json +++ b/advisories/unreviewed/2024/05/GHSA-wx86-7jg2-9256/GHSA-wx86-7jg2-9256.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-xmjw-8f7c-p37x/GHSA-xmjw-8f7c-p37x.json b/advisories/unreviewed/2024/05/GHSA-xmjw-8f7c-p37x/GHSA-xmjw-8f7c-p37x.json index 9c688dfd99a..cb68a2adb4a 100644 --- a/advisories/unreviewed/2024/05/GHSA-xmjw-8f7c-p37x/GHSA-xmjw-8f7c-p37x.json +++ b/advisories/unreviewed/2024/05/GHSA-xmjw-8f7c-p37x/GHSA-xmjw-8f7c-p37x.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-6rh6-g778-wcww/GHSA-6rh6-g778-wcww.json b/advisories/unreviewed/2024/12/GHSA-6rh6-g778-wcww/GHSA-6rh6-g778-wcww.json index 0209ee909f9..b88e430de45 100644 --- a/advisories/unreviewed/2024/12/GHSA-6rh6-g778-wcww/GHSA-6rh6-g778-wcww.json +++ b/advisories/unreviewed/2024/12/GHSA-6rh6-g778-wcww/GHSA-6rh6-g778-wcww.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-hmwf-p83m-gr4q/GHSA-hmwf-p83m-gr4q.json b/advisories/unreviewed/2024/12/GHSA-hmwf-p83m-gr4q/GHSA-hmwf-p83m-gr4q.json index a95ae1b2552..90360bc8175 100644 --- a/advisories/unreviewed/2024/12/GHSA-hmwf-p83m-gr4q/GHSA-hmwf-p83m-gr4q.json +++ b/advisories/unreviewed/2024/12/GHSA-hmwf-p83m-gr4q/GHSA-hmwf-p83m-gr4q.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-hp9r-wcfh-72pr/GHSA-hp9r-wcfh-72pr.json b/advisories/unreviewed/2025/02/GHSA-hp9r-wcfh-72pr/GHSA-hp9r-wcfh-72pr.json index 459511fcf56..18eef13e9f6 100644 --- a/advisories/unreviewed/2025/02/GHSA-hp9r-wcfh-72pr/GHSA-hp9r-wcfh-72pr.json +++ b/advisories/unreviewed/2025/02/GHSA-hp9r-wcfh-72pr/GHSA-hp9r-wcfh-72pr.json @@ -74,7 +74,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-v685-v3qp-pgjp/GHSA-v685-v3qp-pgjp.json b/advisories/unreviewed/2025/02/GHSA-v685-v3qp-pgjp/GHSA-v685-v3qp-pgjp.json index 6a703f4ca08..534574f7e01 100644 --- a/advisories/unreviewed/2025/02/GHSA-v685-v3qp-pgjp/GHSA-v685-v3qp-pgjp.json +++ b/advisories/unreviewed/2025/02/GHSA-v685-v3qp-pgjp/GHSA-v685-v3qp-pgjp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v685-v3qp-pgjp", - "modified": "2025-02-20T18:31:22Z", + "modified": "2025-05-08T18:30:36Z", "published": "2025-02-19T21:31:38Z", "aliases": [ "CVE-2023-51293" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51293" }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/176495" + }, { "type": "WEB", "url": "https://www.phpjabbers.com/event-booking-calendar/#sectionDemo" diff --git a/advisories/unreviewed/2025/03/GHSA-3r8r-7qh7-3hh4/GHSA-3r8r-7qh7-3hh4.json b/advisories/unreviewed/2025/03/GHSA-3r8r-7qh7-3hh4/GHSA-3r8r-7qh7-3hh4.json index 3acc34ef94d..c7aded26832 100644 --- a/advisories/unreviewed/2025/03/GHSA-3r8r-7qh7-3hh4/GHSA-3r8r-7qh7-3hh4.json +++ b/advisories/unreviewed/2025/03/GHSA-3r8r-7qh7-3hh4/GHSA-3r8r-7qh7-3hh4.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-457" + "CWE-457", + "CWE-908" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-7w8w-85w5-f5qw/GHSA-7w8w-85w5-f5qw.json b/advisories/unreviewed/2025/03/GHSA-7w8w-85w5-f5qw/GHSA-7w8w-85w5-f5qw.json index 759381fd7b0..6babcf4a3be 100644 --- a/advisories/unreviewed/2025/03/GHSA-7w8w-85w5-f5qw/GHSA-7w8w-85w5-f5qw.json +++ b/advisories/unreviewed/2025/03/GHSA-7w8w-85w5-f5qw/GHSA-7w8w-85w5-f5qw.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-fx4p-gr2c-m33q/GHSA-fx4p-gr2c-m33q.json b/advisories/unreviewed/2025/03/GHSA-fx4p-gr2c-m33q/GHSA-fx4p-gr2c-m33q.json index 2d0092a86ba..86e77021178 100644 --- a/advisories/unreviewed/2025/03/GHSA-fx4p-gr2c-m33q/GHSA-fx4p-gr2c-m33q.json +++ b/advisories/unreviewed/2025/03/GHSA-fx4p-gr2c-m33q/GHSA-fx4p-gr2c-m33q.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-120", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-hgvp-m8qf-mg69/GHSA-hgvp-m8qf-mg69.json b/advisories/unreviewed/2025/03/GHSA-hgvp-m8qf-mg69/GHSA-hgvp-m8qf-mg69.json index 8b35757ff7d..a19fdaad89b 100644 --- a/advisories/unreviewed/2025/03/GHSA-hgvp-m8qf-mg69/GHSA-hgvp-m8qf-mg69.json +++ b/advisories/unreviewed/2025/03/GHSA-hgvp-m8qf-mg69/GHSA-hgvp-m8qf-mg69.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-wr75-c4vc-pmxm/GHSA-wr75-c4vc-pmxm.json b/advisories/unreviewed/2025/03/GHSA-wr75-c4vc-pmxm/GHSA-wr75-c4vc-pmxm.json index 0cad0afa5bf..9e31a8a9c1a 100644 --- a/advisories/unreviewed/2025/03/GHSA-wr75-c4vc-pmxm/GHSA-wr75-c4vc-pmxm.json +++ b/advisories/unreviewed/2025/03/GHSA-wr75-c4vc-pmxm/GHSA-wr75-c4vc-pmxm.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-457" + "CWE-457", + "CWE-908" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-xrm7-9mcw-9wr5/GHSA-xrm7-9mcw-9wr5.json b/advisories/unreviewed/2025/03/GHSA-xrm7-9mcw-9wr5/GHSA-xrm7-9mcw-9wr5.json index 5e5e82cd11f..5d67f10883c 100644 --- a/advisories/unreviewed/2025/03/GHSA-xrm7-9mcw-9wr5/GHSA-xrm7-9mcw-9wr5.json +++ b/advisories/unreviewed/2025/03/GHSA-xrm7-9mcw-9wr5/GHSA-xrm7-9mcw-9wr5.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-457" + "CWE-457", + "CWE-908" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-24h7-jwc9-7j8v/GHSA-24h7-jwc9-7j8v.json b/advisories/unreviewed/2025/04/GHSA-24h7-jwc9-7j8v/GHSA-24h7-jwc9-7j8v.json index 0bef8cc00a3..54a13a11b47 100644 --- a/advisories/unreviewed/2025/04/GHSA-24h7-jwc9-7j8v/GHSA-24h7-jwc9-7j8v.json +++ b/advisories/unreviewed/2025/04/GHSA-24h7-jwc9-7j8v/GHSA-24h7-jwc9-7j8v.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-120", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-2r37-g5q9-qrfc/GHSA-2r37-g5q9-qrfc.json b/advisories/unreviewed/2025/04/GHSA-2r37-g5q9-qrfc/GHSA-2r37-g5q9-qrfc.json index 0690fe62abc..62ea7c69946 100644 --- a/advisories/unreviewed/2025/04/GHSA-2r37-g5q9-qrfc/GHSA-2r37-g5q9-qrfc.json +++ b/advisories/unreviewed/2025/04/GHSA-2r37-g5q9-qrfc/GHSA-2r37-g5q9-qrfc.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-58f7-f9v5-xpf2/GHSA-58f7-f9v5-xpf2.json b/advisories/unreviewed/2025/04/GHSA-58f7-f9v5-xpf2/GHSA-58f7-f9v5-xpf2.json index 89e2da19a9c..f788ea2fe0e 100644 --- a/advisories/unreviewed/2025/04/GHSA-58f7-f9v5-xpf2/GHSA-58f7-f9v5-xpf2.json +++ b/advisories/unreviewed/2025/04/GHSA-58f7-f9v5-xpf2/GHSA-58f7-f9v5-xpf2.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-j3f2-qmpv-4939/GHSA-j3f2-qmpv-4939.json b/advisories/unreviewed/2025/04/GHSA-j3f2-qmpv-4939/GHSA-j3f2-qmpv-4939.json index ccb67284919..35b8bb660c2 100644 --- a/advisories/unreviewed/2025/04/GHSA-j3f2-qmpv-4939/GHSA-j3f2-qmpv-4939.json +++ b/advisories/unreviewed/2025/04/GHSA-j3f2-qmpv-4939/GHSA-j3f2-qmpv-4939.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-r94p-hcr3-3qp9/GHSA-r94p-hcr3-3qp9.json b/advisories/unreviewed/2025/04/GHSA-r94p-hcr3-3qp9/GHSA-r94p-hcr3-3qp9.json index 6ad781f5e09..d6e092f41b6 100644 --- a/advisories/unreviewed/2025/04/GHSA-r94p-hcr3-3qp9/GHSA-r94p-hcr3-3qp9.json +++ b/advisories/unreviewed/2025/04/GHSA-r94p-hcr3-3qp9/GHSA-r94p-hcr3-3qp9.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-120", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-vvqg-86qw-rhm8/GHSA-vvqg-86qw-rhm8.json b/advisories/unreviewed/2025/04/GHSA-vvqg-86qw-rhm8/GHSA-vvqg-86qw-rhm8.json index e797fee3335..7e1e5e00c3a 100644 --- a/advisories/unreviewed/2025/04/GHSA-vvqg-86qw-rhm8/GHSA-vvqg-86qw-rhm8.json +++ b/advisories/unreviewed/2025/04/GHSA-vvqg-86qw-rhm8/GHSA-vvqg-86qw-rhm8.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-4cwh-m6gc-c4p6/GHSA-4cwh-m6gc-c4p6.json b/advisories/unreviewed/2025/05/GHSA-4cwh-m6gc-c4p6/GHSA-4cwh-m6gc-c4p6.json new file mode 100644 index 00000000000..d58d460f00f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4cwh-m6gc-c4p6/GHSA-4cwh-m6gc-c4p6.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4cwh-m6gc-c4p6", + "modified": "2025-05-08T18:30:42Z", + "published": "2025-05-08T18:30:42Z", + "aliases": [ + "CVE-2025-45843" + ], + "details": "TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid parameter in the setWiFiGuestCfg function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45843" + }, + { + "type": "WEB", + "url": "https://github.com/regainer27/CVE-key/tree/main/bo2" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + }, + { + "type": "WEB", + "url": "https://www.totolink.net/home/menu/detail/menu_listtpl/download/id/225/ids/36.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-57v8-cg97-233x/GHSA-57v8-cg97-233x.json b/advisories/unreviewed/2025/05/GHSA-57v8-cg97-233x/GHSA-57v8-cg97-233x.json new file mode 100644 index 00000000000..dbd8f2e1153 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-57v8-cg97-233x/GHSA-57v8-cg97-233x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-57v8-cg97-233x", + "modified": "2025-05-08T18:30:43Z", + "published": "2025-05-08T18:30:43Z", + "aliases": [ + "CVE-2025-30102" + ], + "details": "Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.1.0, contains an out-of-bounds write vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30102" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000317419/dsa-2025-192-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T18:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5h2c-h5cv-642q/GHSA-5h2c-h5cv-642q.json b/advisories/unreviewed/2025/05/GHSA-5h2c-h5cv-642q/GHSA-5h2c-h5cv-642q.json new file mode 100644 index 00000000000..e42eca2c5da --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5h2c-h5cv-642q/GHSA-5h2c-h5cv-642q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5h2c-h5cv-642q", + "modified": "2025-05-08T18:30:42Z", + "published": "2025-05-08T18:30:42Z", + "aliases": [ + "CVE-2025-30101" + ], + "details": "Dell PowerScale OneFS, versions 9.8.0.0 through 9.10.1.0, contain a time-of-check time-of-use (TOCTOU) race condition vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to denial of service and information tampering.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30101" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000317419/dsa-2025-192-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T18:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6895-x6gp-m725/GHSA-6895-x6gp-m725.json b/advisories/unreviewed/2025/05/GHSA-6895-x6gp-m725/GHSA-6895-x6gp-m725.json new file mode 100644 index 00000000000..3a56309dbd7 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6895-x6gp-m725/GHSA-6895-x6gp-m725.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6895-x6gp-m725", + "modified": "2025-05-08T18:30:42Z", + "published": "2025-05-08T18:30:42Z", + "aliases": [ + "CVE-2023-51295" + ], + "details": "PHPJabbers Event Booking Calendar v4.0 is vulnerable to Multiple HTML Injection in the \"name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title\" parameters.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51295" + }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/176485" + }, + { + "type": "WEB", + "url": "https://www.phpjabbers.com/event-booking-calendar/#sectionDemo" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6mp7-r3w8-3vrm/GHSA-6mp7-r3w8-3vrm.json b/advisories/unreviewed/2025/05/GHSA-6mp7-r3w8-3vrm/GHSA-6mp7-r3w8-3vrm.json new file mode 100644 index 00000000000..8fd1287c3aa --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6mp7-r3w8-3vrm/GHSA-6mp7-r3w8-3vrm.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6mp7-r3w8-3vrm", + "modified": "2025-05-08T18:30:42Z", + "published": "2025-05-08T18:30:42Z", + "aliases": [ + "CVE-2025-43926" + ], + "details": "An issue was discovered in Znuny through 6.5.14 and 7.x through 7.1.6. Custom AJAX calls to the AgentPreferences UpdateAJAX subaction can be used to set user preferences with arbitrary keys. When fetching user data via GetUserData, these keys and values are retrieved and given as a whole to other function calls, which then might use these keys/values to affect permissions or other settings.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43926" + }, + { + "type": "WEB", + "url": "https://www.znuny.org/en/advisories/zsa-2025-07" + }, + { + "type": "WEB", + "url": "https://znuny.com" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-765g-9g68-wg84/GHSA-765g-9g68-wg84.json b/advisories/unreviewed/2025/05/GHSA-765g-9g68-wg84/GHSA-765g-9g68-wg84.json new file mode 100644 index 00000000000..9c9a64d78b0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-765g-9g68-wg84/GHSA-765g-9g68-wg84.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-765g-9g68-wg84", + "modified": "2025-05-08T18:30:42Z", + "published": "2025-05-08T18:30:42Z", + "aliases": [ + "CVE-2025-45846" + ], + "details": "ALFA AIP-W512 v3.2.2.2.3 was discovered to contain an authenticated stack overflow via the torrentsindex parameter in the formBTClinetSetting function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45846" + }, + { + "type": "WEB", + "url": "https://files.alfa.com.tw/?dir=%5B2%5D%20WiFi%20Home%20Router/AIP-W512" + }, + { + "type": "WEB", + "url": "https://github.com/regainer27/CVE-key/tree/main/ALFA/AIP%20W512/bo4" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7vx7-qjwv-wcrm/GHSA-7vx7-qjwv-wcrm.json b/advisories/unreviewed/2025/05/GHSA-7vx7-qjwv-wcrm/GHSA-7vx7-qjwv-wcrm.json new file mode 100644 index 00000000000..78e5051533a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7vx7-qjwv-wcrm/GHSA-7vx7-qjwv-wcrm.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7vx7-qjwv-wcrm", + "modified": "2025-05-08T18:30:43Z", + "published": "2025-05-08T18:30:42Z", + "aliases": [ + "CVE-2025-45841" + ], + "details": "TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the text parameter in the setSmsCfg function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45841" + }, + { + "type": "WEB", + "url": "https://github.com/regainer27/CVE-key/blob/main/bo1/README.md" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + }, + { + "type": "WEB", + "url": "https://www.totolink.net/home/menu/detail/menu_listtpl/download/id/225/ids/36.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-88m5-wrqh-4w9g/GHSA-88m5-wrqh-4w9g.json b/advisories/unreviewed/2025/05/GHSA-88m5-wrqh-4w9g/GHSA-88m5-wrqh-4w9g.json new file mode 100644 index 00000000000..9ba9afdac88 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-88m5-wrqh-4w9g/GHSA-88m5-wrqh-4w9g.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-88m5-wrqh-4w9g", + "modified": "2025-05-08T18:30:42Z", + "published": "2025-05-08T18:30:42Z", + "aliases": [ + "CVE-2025-45844" + ], + "details": "TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid parameter in the setWiFiBasicCfg function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45844" + }, + { + "type": "WEB", + "url": "https://github.com/regainer27/CVE-key/tree/main/bo6" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + }, + { + "type": "WEB", + "url": "https://www.totolink.net/home/menu/detail/menu_listtpl/download/id/225/ids/36.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8hx2-3q2m-9xxf/GHSA-8hx2-3q2m-9xxf.json b/advisories/unreviewed/2025/05/GHSA-8hx2-3q2m-9xxf/GHSA-8hx2-3q2m-9xxf.json new file mode 100644 index 00000000000..5d77cf2f3a0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8hx2-3q2m-9xxf/GHSA-8hx2-3q2m-9xxf.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8hx2-3q2m-9xxf", + "modified": "2025-05-08T18:30:43Z", + "published": "2025-05-08T18:30:42Z", + "aliases": [ + "CVE-2025-26845" + ], + "details": "An Eval Injection issue was discovered in Znuny through 7.1.3. A user with write access to the configuration file can use this to execute a command executed by the user running the backup.pl script.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26845" + }, + { + "type": "WEB", + "url": "https://www.znuny.com" + }, + { + "type": "WEB", + "url": "https://www.znuny.org/en/advisories/zsa-2025-03" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T17:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c2x5-mpj8-v9v9/GHSA-c2x5-mpj8-v9v9.json b/advisories/unreviewed/2025/05/GHSA-c2x5-mpj8-v9v9/GHSA-c2x5-mpj8-v9v9.json new file mode 100644 index 00000000000..35fa2115a7c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c2x5-mpj8-v9v9/GHSA-c2x5-mpj8-v9v9.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2x5-mpj8-v9v9", + "modified": "2025-05-08T18:30:42Z", + "published": "2025-05-08T18:30:42Z", + "aliases": [ + "CVE-2025-26842" + ], + "details": "An issue was discovered in Znuny through 7.1.3. If access to a ticket is not given, the content of S/MIME encrypted e-mail messages is visible to users with access to the CommunicationLog.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26842" + }, + { + "type": "WEB", + "url": "https://www.znuny.org/en/advisories/zsa-2025-01" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-crjm-f8jp-7pww/GHSA-crjm-f8jp-7pww.json b/advisories/unreviewed/2025/05/GHSA-crjm-f8jp-7pww/GHSA-crjm-f8jp-7pww.json new file mode 100644 index 00000000000..30f66e1cbac --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-crjm-f8jp-7pww/GHSA-crjm-f8jp-7pww.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crjm-f8jp-7pww", + "modified": "2025-05-08T18:30:42Z", + "published": "2025-05-08T18:30:42Z", + "aliases": [ + "CVE-2025-26847" + ], + "details": "An issue was discovered in Znuny before 7.1.5. When generating a support bundle, not all passwords are masked.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26847" + }, + { + "type": "WEB", + "url": "https://www.znuny.com" + }, + { + "type": "WEB", + "url": "https://www.znuny.org/en/advisories/zsa-2025-06" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T17:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fxvx-gfmr-5xfj/GHSA-fxvx-gfmr-5xfj.json b/advisories/unreviewed/2025/05/GHSA-fxvx-gfmr-5xfj/GHSA-fxvx-gfmr-5xfj.json index 5f155fce613..a6b8071e643 100644 --- a/advisories/unreviewed/2025/05/GHSA-fxvx-gfmr-5xfj/GHSA-fxvx-gfmr-5xfj.json +++ b/advisories/unreviewed/2025/05/GHSA-fxvx-gfmr-5xfj/GHSA-fxvx-gfmr-5xfj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fxvx-gfmr-5xfj", - "modified": "2025-05-07T21:31:45Z", + "modified": "2025-05-08T18:30:42Z", "published": "2025-05-07T21:31:45Z", "aliases": [ "CVE-2025-29746" ], "details": "Cross Site Scripting vulnerability in Koillection v.1.6.10 allows a remote attacker to escalate privileges via the collection, Wishlist and album components", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-07T19:16:07Z" diff --git a/advisories/unreviewed/2025/05/GHSA-hmxm-mp3w-5hrg/GHSA-hmxm-mp3w-5hrg.json b/advisories/unreviewed/2025/05/GHSA-hmxm-mp3w-5hrg/GHSA-hmxm-mp3w-5hrg.json new file mode 100644 index 00000000000..bdfd545e78a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hmxm-mp3w-5hrg/GHSA-hmxm-mp3w-5hrg.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hmxm-mp3w-5hrg", + "modified": "2025-05-08T18:30:42Z", + "published": "2025-05-08T18:30:42Z", + "aliases": [ + "CVE-2023-51328" + ], + "details": "PHPJabbers Cleaning Business Software v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the \"c_name, name\" parameters.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51328" + }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/176507" + }, + { + "type": "WEB", + "url": "https://www.phpjabbers.com/cleaning-business-software/#sectionDemo" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p9w4-qh4j-6cx3/GHSA-p9w4-qh4j-6cx3.json b/advisories/unreviewed/2025/05/GHSA-p9w4-qh4j-6cx3/GHSA-p9w4-qh4j-6cx3.json new file mode 100644 index 00000000000..170cb8f8394 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p9w4-qh4j-6cx3/GHSA-p9w4-qh4j-6cx3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p9w4-qh4j-6cx3", + "modified": "2025-05-08T18:30:42Z", + "published": "2025-05-08T18:30:42Z", + "aliases": [ + "CVE-2025-4132" + ], + "details": "Rapid7 Corporate Website prior to May 2nd 2025, suffered from a URL Redirection to Untrusted Site ('Open Redirect') vulnerability whereby, due to misconfigured headers, an attacker could successfully redirect users to a malicious site of their control. \nThis vulnerability has been fixed as of May 2nd 2025.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4132" + }, + { + "type": "WEB", + "url": "https://cwe.mitre.org/data/definitions/601.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q3m2-crgq-5p3q/GHSA-q3m2-crgq-5p3q.json b/advisories/unreviewed/2025/05/GHSA-q3m2-crgq-5p3q/GHSA-q3m2-crgq-5p3q.json new file mode 100644 index 00000000000..c05c8d407c8 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q3m2-crgq-5p3q/GHSA-q3m2-crgq-5p3q.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q3m2-crgq-5p3q", + "modified": "2025-05-08T18:30:42Z", + "published": "2025-05-08T18:30:42Z", + "aliases": [ + "CVE-2025-44021" + ], + "details": "OpenStack Ironic before 29.0.1 can write unintended files to a target node disk during image handling (if a deployment was performed via the API). A malicious project assigned as a node owner can provide a path to any local file (readable by ironic-conductor), which may then be written to the target node disk. This is difficult to exploit in practice, because a node deployed in this manner should never reach the ACTIVE state, but it still represents a danger in environments running with non-default, insecure configurations such as with automated cleaning disabled. The fixed versions are 24.1.3, 26.1.1, and 29.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44021" + }, + { + "type": "WEB", + "url": "https://bugs.launchpad.net/ironic/+bug/2107847" + }, + { + "type": "WEB", + "url": "https://security.openstack.org/ossa/OSSA-2025-001.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T17:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q787-4mx6-96qg/GHSA-q787-4mx6-96qg.json b/advisories/unreviewed/2025/05/GHSA-q787-4mx6-96qg/GHSA-q787-4mx6-96qg.json index a45d4c743aa..1520e580ab7 100644 --- a/advisories/unreviewed/2025/05/GHSA-q787-4mx6-96qg/GHSA-q787-4mx6-96qg.json +++ b/advisories/unreviewed/2025/05/GHSA-q787-4mx6-96qg/GHSA-q787-4mx6-96qg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q787-4mx6-96qg", - "modified": "2025-05-07T21:31:45Z", + "modified": "2025-05-08T18:30:42Z", "published": "2025-05-07T21:31:45Z", "aliases": [ "CVE-2025-45388" ], "details": "Wagtail CMS 6.4.1 is vulnerable to a Stored Cross-Site Scripting (XSS) in the document upload functionality. Attackers can inject malicious code inside a PDF file. When a user clicks the document in the CMS interface, the payload executes.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-07T19:16:08Z" diff --git a/advisories/unreviewed/2025/05/GHSA-qjp8-wwq5-32hp/GHSA-qjp8-wwq5-32hp.json b/advisories/unreviewed/2025/05/GHSA-qjp8-wwq5-32hp/GHSA-qjp8-wwq5-32hp.json new file mode 100644 index 00000000000..4cb4faa58ca --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qjp8-wwq5-32hp/GHSA-qjp8-wwq5-32hp.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qjp8-wwq5-32hp", + "modified": "2025-05-08T18:30:42Z", + "published": "2025-05-08T18:30:42Z", + "aliases": [ + "CVE-2025-26844" + ], + "details": "An issue was discovered in Znuny through 7.1.3. A cookie is set without the HttpOnly flag.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26844" + }, + { + "type": "WEB", + "url": "https://www.znuny.com" + }, + { + "type": "WEB", + "url": "https://www.znuny.org/en/advisories/zsa-2025-05" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qpff-5v24-gq8p/GHSA-qpff-5v24-gq8p.json b/advisories/unreviewed/2025/05/GHSA-qpff-5v24-gq8p/GHSA-qpff-5v24-gq8p.json new file mode 100644 index 00000000000..3068427b1fc --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qpff-5v24-gq8p/GHSA-qpff-5v24-gq8p.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qpff-5v24-gq8p", + "modified": "2025-05-08T18:30:42Z", + "published": "2025-05-08T18:30:42Z", + "aliases": [ + "CVE-2025-45847" + ], + "details": "ALFA AIP-W512 v3.2.2.2.3 was discovered to contain an authenticated stack overflow via the targetAPMac parameter in the formWsc function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45847" + }, + { + "type": "WEB", + "url": "https://files.alfa.com.tw/?dir=%5B2%5D%20WiFi%20Home%20Router/AIP-W512" + }, + { + "type": "WEB", + "url": "https://github.com/regainer27/CVE-key/tree/main/ALFA/AIP%20W512/bo1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T16:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vp89-77x6-5qqm/GHSA-vp89-77x6-5qqm.json b/advisories/unreviewed/2025/05/GHSA-vp89-77x6-5qqm/GHSA-vp89-77x6-5qqm.json new file mode 100644 index 00000000000..9b053abc467 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vp89-77x6-5qqm/GHSA-vp89-77x6-5qqm.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vp89-77x6-5qqm", + "modified": "2025-05-08T18:30:42Z", + "published": "2025-05-08T18:30:42Z", + "aliases": [ + "CVE-2025-45842" + ], + "details": "TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid5g parameter in the setWiFiEasyCfg function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45842" + }, + { + "type": "WEB", + "url": "https://github.com/regainer27/CVE-key/tree/main/bo3" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + }, + { + "type": "WEB", + "url": "https://www.totolink.net/home/menu/detail/menu_listtpl/download/id/225/ids/36.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w7v2-r8f5-7h23/GHSA-w7v2-r8f5-7h23.json b/advisories/unreviewed/2025/05/GHSA-w7v2-r8f5-7h23/GHSA-w7v2-r8f5-7h23.json new file mode 100644 index 00000000000..2fe75e60d95 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w7v2-r8f5-7h23/GHSA-w7v2-r8f5-7h23.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w7v2-r8f5-7h23", + "modified": "2025-05-08T18:30:42Z", + "published": "2025-05-08T18:30:42Z", + "aliases": [ + "CVE-2025-45845" + ], + "details": "TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid5g parameter in the setWiFiEasyGuestCfg function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45845" + }, + { + "type": "WEB", + "url": "https://github.com/regainer27/CVE-key/tree/main/bo5" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + }, + { + "type": "WEB", + "url": "https://www.totolink.net/home/menu/detail/menu_listtpl/download/id/225/ids/36.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wrvq-mh4x-7wf8/GHSA-wrvq-mh4x-7wf8.json b/advisories/unreviewed/2025/05/GHSA-wrvq-mh4x-7wf8/GHSA-wrvq-mh4x-7wf8.json new file mode 100644 index 00000000000..05a4c7a1c3b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wrvq-mh4x-7wf8/GHSA-wrvq-mh4x-7wf8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wrvq-mh4x-7wf8", + "modified": "2025-05-08T18:30:43Z", + "published": "2025-05-08T18:30:43Z", + "aliases": [ + "CVE-2025-4098" + ], + "details": "Horner Automation Cscape version 10.0 (10.0.415.2) SP1 is vulnerable to an out-of-bounds read vulnerability that could allow an attacker to disclose information and execute arbitrary code on affected installations of Cscape.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4098" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-128-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T18:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-x9rr-xwxc-jcjf/GHSA-x9rr-xwxc-jcjf.json b/advisories/unreviewed/2025/05/GHSA-x9rr-xwxc-jcjf/GHSA-x9rr-xwxc-jcjf.json index c832795e4ea..529b5031a55 100644 --- a/advisories/unreviewed/2025/05/GHSA-x9rr-xwxc-jcjf/GHSA-x9rr-xwxc-jcjf.json +++ b/advisories/unreviewed/2025/05/GHSA-x9rr-xwxc-jcjf/GHSA-x9rr-xwxc-jcjf.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-434" + "CWE-434", + "CWE-602" ], "severity": "MODERATE", "github_reviewed": false,