diff --git a/advisories/github-reviewed/2025/02/GHSA-76p7-773f-r4q5/GHSA-76p7-773f-r4q5.json b/advisories/github-reviewed/2025/02/GHSA-76p7-773f-r4q5/GHSA-76p7-773f-r4q5.json index 5ebbfeae2c4..f720dcbd6e3 100644 --- a/advisories/github-reviewed/2025/02/GHSA-76p7-773f-r4q5/GHSA-76p7-773f-r4q5.json +++ b/advisories/github-reviewed/2025/02/GHSA-76p7-773f-r4q5/GHSA-76p7-773f-r4q5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-76p7-773f-r4q5", - "modified": "2025-06-04T03:30:26Z", + "modified": "2025-06-04T21:31:03Z", "published": "2025-02-10T18:30:47Z", "aliases": [ "CVE-2024-11831" @@ -76,6 +76,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:8479" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:8544" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-11831" diff --git a/advisories/unreviewed/2022/05/GHSA-2955-cp7r-7qw6/GHSA-2955-cp7r-7qw6.json b/advisories/unreviewed/2022/05/GHSA-2955-cp7r-7qw6/GHSA-2955-cp7r-7qw6.json index 6cefab115a2..025d9ca0913 100644 --- a/advisories/unreviewed/2022/05/GHSA-2955-cp7r-7qw6/GHSA-2955-cp7r-7qw6.json +++ b/advisories/unreviewed/2022/05/GHSA-2955-cp7r-7qw6/GHSA-2955-cp7r-7qw6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2955-cp7r-7qw6", - "modified": "2022-05-24T17:28:54Z", + "modified": "2025-06-04T21:31:01Z", "published": "2022-05-24T17:28:54Z", "aliases": [ "CVE-2020-14506" ], "details": "Philips Clinical Collaboration Platform, Versions 12.2.1 and prior. The product receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data safely and correctly.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -17,10 +22,16 @@ { "type": "WEB", "url": "https://us-cert.cisa.gov/ics/advisories/icsma-20-261-01" + }, + { + "type": "WEB", + "url": "https://www.philips.com/a-w/security/security-advisories/product-security-2020.html#2020_archive" } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4gc9-p44x-vcgg/GHSA-4gc9-p44x-vcgg.json b/advisories/unreviewed/2022/05/GHSA-4gc9-p44x-vcgg/GHSA-4gc9-p44x-vcgg.json index 76532588238..f33ac583886 100644 --- a/advisories/unreviewed/2022/05/GHSA-4gc9-p44x-vcgg/GHSA-4gc9-p44x-vcgg.json +++ b/advisories/unreviewed/2022/05/GHSA-4gc9-p44x-vcgg/GHSA-4gc9-p44x-vcgg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4gc9-p44x-vcgg", - "modified": "2022-05-24T17:40:12Z", + "modified": "2025-06-04T21:31:01Z", "published": "2022-05-24T17:40:12Z", "aliases": [ "CVE-2020-27298" ], "details": "Philips Interventional Workspot (Release 1.3.2, 1.4.0, 1.4.1, 1.4.3, 1.4.5), Coronary Tools/Dynamic Coronary Roadmap/Stentboost Live (Release 1.0), ViewForum (Release 6.3V1L10). The software constructs all or part of an OS command using externally influenced input from an upstream component but does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when sent to a downstream component.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -17,6 +22,14 @@ { "type": "WEB", "url": "https://us-cert.cisa.gov/ics/advisories/icsma-21-019-01" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-21-019-01" + }, + { + "type": "WEB", + "url": "https://www.philips.com/a-w/security/security-advisories/product-security-2021.html#2021_archive" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-j347-m6ww-35jg/GHSA-j347-m6ww-35jg.json b/advisories/unreviewed/2024/02/GHSA-j347-m6ww-35jg/GHSA-j347-m6ww-35jg.json index 3b0bb615040..73c6a2e6c16 100644 --- a/advisories/unreviewed/2024/02/GHSA-j347-m6ww-35jg/GHSA-j347-m6ww-35jg.json +++ b/advisories/unreviewed/2024/02/GHSA-j347-m6ww-35jg/GHSA-j347-m6ww-35jg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j347-m6ww-35jg", - "modified": "2024-04-19T09:30:47Z", + "modified": "2025-06-04T21:31:01Z", "published": "2024-02-15T06:31:35Z", "aliases": [ "CVE-2024-25940" ], "details": "`bhyveload -h ` may be used to grant loader access to the directory tree on the host. Affected versions of bhyveload(8) do not make any attempt to restrict loader's access to , allowing the loader to read any file the host user has access to. In the bhyveload(8) model, the host supplies a userboot.so to boot with, but the loader scripts generally come from the guest image. A maliciously crafted script could be used to exfiltrate sensitive data from the host accessible to the user running bhyhveload(8), which is often the system root.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-922" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-15T05:15:11Z" diff --git a/advisories/unreviewed/2024/08/GHSA-2mh3-x6j9-j554/GHSA-2mh3-x6j9-j554.json b/advisories/unreviewed/2024/08/GHSA-2mh3-x6j9-j554/GHSA-2mh3-x6j9-j554.json index 41e5451f1f6..3bcfd1c40e0 100644 --- a/advisories/unreviewed/2024/08/GHSA-2mh3-x6j9-j554/GHSA-2mh3-x6j9-j554.json +++ b/advisories/unreviewed/2024/08/GHSA-2mh3-x6j9-j554/GHSA-2mh3-x6j9-j554.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2mh3-x6j9-j554", - "modified": "2024-08-20T18:31:26Z", + "modified": "2025-06-04T21:31:01Z", "published": "2024-08-20T18:31:26Z", "aliases": [ "CVE-2024-27186" ], "details": "The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-20T16:15:10Z" diff --git a/advisories/unreviewed/2025/02/GHSA-52c6-vx83-rc69/GHSA-52c6-vx83-rc69.json b/advisories/unreviewed/2025/02/GHSA-52c6-vx83-rc69/GHSA-52c6-vx83-rc69.json index 86a6eaf667f..99a71cd3d60 100644 --- a/advisories/unreviewed/2025/02/GHSA-52c6-vx83-rc69/GHSA-52c6-vx83-rc69.json +++ b/advisories/unreviewed/2025/02/GHSA-52c6-vx83-rc69/GHSA-52c6-vx83-rc69.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-35" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/05/GHSA-37c5-cj42-grq7/GHSA-37c5-cj42-grq7.json b/advisories/unreviewed/2025/05/GHSA-37c5-cj42-grq7/GHSA-37c5-cj42-grq7.json index 2297aa850c1..1d24a7f3f43 100644 --- a/advisories/unreviewed/2025/05/GHSA-37c5-cj42-grq7/GHSA-37c5-cj42-grq7.json +++ b/advisories/unreviewed/2025/05/GHSA-37c5-cj42-grq7/GHSA-37c5-cj42-grq7.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-4p3r-7jgv-wgrw/GHSA-4p3r-7jgv-wgrw.json b/advisories/unreviewed/2025/05/GHSA-4p3r-7jgv-wgrw/GHSA-4p3r-7jgv-wgrw.json index 83b5adaddb4..34083864ee8 100644 --- a/advisories/unreviewed/2025/05/GHSA-4p3r-7jgv-wgrw/GHSA-4p3r-7jgv-wgrw.json +++ b/advisories/unreviewed/2025/05/GHSA-4p3r-7jgv-wgrw/GHSA-4p3r-7jgv-wgrw.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-4xfq-xhxp-pxrw/GHSA-4xfq-xhxp-pxrw.json b/advisories/unreviewed/2025/05/GHSA-4xfq-xhxp-pxrw/GHSA-4xfq-xhxp-pxrw.json index d827ba33494..0f6f850f9c3 100644 --- a/advisories/unreviewed/2025/05/GHSA-4xfq-xhxp-pxrw/GHSA-4xfq-xhxp-pxrw.json +++ b/advisories/unreviewed/2025/05/GHSA-4xfq-xhxp-pxrw/GHSA-4xfq-xhxp-pxrw.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-5336-w9c9-9274/GHSA-5336-w9c9-9274.json b/advisories/unreviewed/2025/05/GHSA-5336-w9c9-9274/GHSA-5336-w9c9-9274.json index 8252562bc8f..8e7165b8a9f 100644 --- a/advisories/unreviewed/2025/05/GHSA-5336-w9c9-9274/GHSA-5336-w9c9-9274.json +++ b/advisories/unreviewed/2025/05/GHSA-5336-w9c9-9274/GHSA-5336-w9c9-9274.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-57c2-2x5j-8gpq/GHSA-57c2-2x5j-8gpq.json b/advisories/unreviewed/2025/05/GHSA-57c2-2x5j-8gpq/GHSA-57c2-2x5j-8gpq.json index a9d7145ccdf..10ca98fbf11 100644 --- a/advisories/unreviewed/2025/05/GHSA-57c2-2x5j-8gpq/GHSA-57c2-2x5j-8gpq.json +++ b/advisories/unreviewed/2025/05/GHSA-57c2-2x5j-8gpq/GHSA-57c2-2x5j-8gpq.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-5c2w-vf3p-r6vw/GHSA-5c2w-vf3p-r6vw.json b/advisories/unreviewed/2025/05/GHSA-5c2w-vf3p-r6vw/GHSA-5c2w-vf3p-r6vw.json index b4729f81c06..796e7e34eed 100644 --- a/advisories/unreviewed/2025/05/GHSA-5c2w-vf3p-r6vw/GHSA-5c2w-vf3p-r6vw.json +++ b/advisories/unreviewed/2025/05/GHSA-5c2w-vf3p-r6vw/GHSA-5c2w-vf3p-r6vw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5c2w-vf3p-r6vw", - "modified": "2025-05-22T15:34:49Z", + "modified": "2025-06-04T21:31:09Z", "published": "2025-05-22T15:34:49Z", "aliases": [ "CVE-2025-3940" diff --git a/advisories/unreviewed/2025/05/GHSA-62cm-c2h4-rg2m/GHSA-62cm-c2h4-rg2m.json b/advisories/unreviewed/2025/05/GHSA-62cm-c2h4-rg2m/GHSA-62cm-c2h4-rg2m.json index e5b1240d6a3..d9f6b8085de 100644 --- a/advisories/unreviewed/2025/05/GHSA-62cm-c2h4-rg2m/GHSA-62cm-c2h4-rg2m.json +++ b/advisories/unreviewed/2025/05/GHSA-62cm-c2h4-rg2m/GHSA-62cm-c2h4-rg2m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-62cm-c2h4-rg2m", - "modified": "2025-05-22T15:34:49Z", + "modified": "2025-06-04T21:31:10Z", "published": "2025-05-22T15:34:49Z", "aliases": [ "CVE-2025-3942" @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-116", "CWE-117" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/05/GHSA-6c4h-4fjm-m75j/GHSA-6c4h-4fjm-m75j.json b/advisories/unreviewed/2025/05/GHSA-6c4h-4fjm-m75j/GHSA-6c4h-4fjm-m75j.json index 8507208afca..43289f69446 100644 --- a/advisories/unreviewed/2025/05/GHSA-6c4h-4fjm-m75j/GHSA-6c4h-4fjm-m75j.json +++ b/advisories/unreviewed/2025/05/GHSA-6c4h-4fjm-m75j/GHSA-6c4h-4fjm-m75j.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-6hrx-7mgg-5cvp/GHSA-6hrx-7mgg-5cvp.json b/advisories/unreviewed/2025/05/GHSA-6hrx-7mgg-5cvp/GHSA-6hrx-7mgg-5cvp.json index 0284170f079..b3e74b8db46 100644 --- a/advisories/unreviewed/2025/05/GHSA-6hrx-7mgg-5cvp/GHSA-6hrx-7mgg-5cvp.json +++ b/advisories/unreviewed/2025/05/GHSA-6hrx-7mgg-5cvp/GHSA-6hrx-7mgg-5cvp.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-203", "CWE-204" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/05/GHSA-6vhr-vrr2-gfrx/GHSA-6vhr-vrr2-gfrx.json b/advisories/unreviewed/2025/05/GHSA-6vhr-vrr2-gfrx/GHSA-6vhr-vrr2-gfrx.json index 0014a2693d3..34f631c1dcb 100644 --- a/advisories/unreviewed/2025/05/GHSA-6vhr-vrr2-gfrx/GHSA-6vhr-vrr2-gfrx.json +++ b/advisories/unreviewed/2025/05/GHSA-6vhr-vrr2-gfrx/GHSA-6vhr-vrr2-gfrx.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-79vg-2g4j-h2vr/GHSA-79vg-2g4j-h2vr.json b/advisories/unreviewed/2025/05/GHSA-79vg-2g4j-h2vr/GHSA-79vg-2g4j-h2vr.json index e7b7a21905e..f6046b8e592 100644 --- a/advisories/unreviewed/2025/05/GHSA-79vg-2g4j-h2vr/GHSA-79vg-2g4j-h2vr.json +++ b/advisories/unreviewed/2025/05/GHSA-79vg-2g4j-h2vr/GHSA-79vg-2g4j-h2vr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-7fp8-7q2p-mmxm/GHSA-7fp8-7q2p-mmxm.json b/advisories/unreviewed/2025/05/GHSA-7fp8-7q2p-mmxm/GHSA-7fp8-7q2p-mmxm.json index 23cafdad460..ff5ec0b43c8 100644 --- a/advisories/unreviewed/2025/05/GHSA-7fp8-7q2p-mmxm/GHSA-7fp8-7q2p-mmxm.json +++ b/advisories/unreviewed/2025/05/GHSA-7fp8-7q2p-mmxm/GHSA-7fp8-7q2p-mmxm.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-857x-55vg-m6q9/GHSA-857x-55vg-m6q9.json b/advisories/unreviewed/2025/05/GHSA-857x-55vg-m6q9/GHSA-857x-55vg-m6q9.json index 8b56e38fc20..d8d13305990 100644 --- a/advisories/unreviewed/2025/05/GHSA-857x-55vg-m6q9/GHSA-857x-55vg-m6q9.json +++ b/advisories/unreviewed/2025/05/GHSA-857x-55vg-m6q9/GHSA-857x-55vg-m6q9.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-8wg7-qxc6-838c/GHSA-8wg7-qxc6-838c.json b/advisories/unreviewed/2025/05/GHSA-8wg7-qxc6-838c/GHSA-8wg7-qxc6-838c.json index 70659d6a354..5a37706de4c 100644 --- a/advisories/unreviewed/2025/05/GHSA-8wg7-qxc6-838c/GHSA-8wg7-qxc6-838c.json +++ b/advisories/unreviewed/2025/05/GHSA-8wg7-qxc6-838c/GHSA-8wg7-qxc6-838c.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-8xqm-w2cq-fmc6/GHSA-8xqm-w2cq-fmc6.json b/advisories/unreviewed/2025/05/GHSA-8xqm-w2cq-fmc6/GHSA-8xqm-w2cq-fmc6.json index 6f0b91f3bc1..91cec1f74d4 100644 --- a/advisories/unreviewed/2025/05/GHSA-8xqm-w2cq-fmc6/GHSA-8xqm-w2cq-fmc6.json +++ b/advisories/unreviewed/2025/05/GHSA-8xqm-w2cq-fmc6/GHSA-8xqm-w2cq-fmc6.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-8xr7-6x2j-wgq9/GHSA-8xr7-6x2j-wgq9.json b/advisories/unreviewed/2025/05/GHSA-8xr7-6x2j-wgq9/GHSA-8xr7-6x2j-wgq9.json index 221470ffce4..f24dd070391 100644 --- a/advisories/unreviewed/2025/05/GHSA-8xr7-6x2j-wgq9/GHSA-8xr7-6x2j-wgq9.json +++ b/advisories/unreviewed/2025/05/GHSA-8xr7-6x2j-wgq9/GHSA-8xr7-6x2j-wgq9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8xr7-6x2j-wgq9", - "modified": "2025-05-22T15:34:49Z", + "modified": "2025-06-04T21:31:10Z", "published": "2025-05-22T15:34:49Z", "aliases": [ "CVE-2025-3944" diff --git a/advisories/unreviewed/2025/05/GHSA-9mpf-r669-m5wq/GHSA-9mpf-r669-m5wq.json b/advisories/unreviewed/2025/05/GHSA-9mpf-r669-m5wq/GHSA-9mpf-r669-m5wq.json index bea31b7594d..3f00a1297c6 100644 --- a/advisories/unreviewed/2025/05/GHSA-9mpf-r669-m5wq/GHSA-9mpf-r669-m5wq.json +++ b/advisories/unreviewed/2025/05/GHSA-9mpf-r669-m5wq/GHSA-9mpf-r669-m5wq.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-c3vv-fgcp-2m26/GHSA-c3vv-fgcp-2m26.json b/advisories/unreviewed/2025/05/GHSA-c3vv-fgcp-2m26/GHSA-c3vv-fgcp-2m26.json index ed1bdb3bf99..3473658b804 100644 --- a/advisories/unreviewed/2025/05/GHSA-c3vv-fgcp-2m26/GHSA-c3vv-fgcp-2m26.json +++ b/advisories/unreviewed/2025/05/GHSA-c3vv-fgcp-2m26/GHSA-c3vv-fgcp-2m26.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c3vv-fgcp-2m26", - "modified": "2025-05-28T21:30:43Z", + "modified": "2025-06-04T21:31:10Z", "published": "2025-05-28T21:30:43Z", "aliases": [ "CVE-2025-27703" ], "details": "CVE-2025-27703 is a privilege escalation vulnerability in the management\n console of Absolute Secure Access prior to version 13.54. Attackers \nwith administrative access to a specific subset of privileged features \nin the console can elevate their permissions to access additional \nfeatures in the console. The attack complexity is low, there are no \npreexisting attack requirements; the privileges required are high, and \nthere is no user interaction required. The impact to system \nconfidentiality is low, the impact to system integrity is high and the \nimpact to system availability is low.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:L" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2025/05/GHSA-chgf-rv7c-3x2f/GHSA-chgf-rv7c-3x2f.json b/advisories/unreviewed/2025/05/GHSA-chgf-rv7c-3x2f/GHSA-chgf-rv7c-3x2f.json index 91a6a112bf5..ce4ef3c3ba1 100644 --- a/advisories/unreviewed/2025/05/GHSA-chgf-rv7c-3x2f/GHSA-chgf-rv7c-3x2f.json +++ b/advisories/unreviewed/2025/05/GHSA-chgf-rv7c-3x2f/GHSA-chgf-rv7c-3x2f.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-f87f-4wg8-gxhp/GHSA-f87f-4wg8-gxhp.json b/advisories/unreviewed/2025/05/GHSA-f87f-4wg8-gxhp/GHSA-f87f-4wg8-gxhp.json index d1998b2ea8d..7ffd3052597 100644 --- a/advisories/unreviewed/2025/05/GHSA-f87f-4wg8-gxhp/GHSA-f87f-4wg8-gxhp.json +++ b/advisories/unreviewed/2025/05/GHSA-f87f-4wg8-gxhp/GHSA-f87f-4wg8-gxhp.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-g2qp-8c9p-46fv/GHSA-g2qp-8c9p-46fv.json b/advisories/unreviewed/2025/05/GHSA-g2qp-8c9p-46fv/GHSA-g2qp-8c9p-46fv.json index dadf334ee17..9e20a2b297f 100644 --- a/advisories/unreviewed/2025/05/GHSA-g2qp-8c9p-46fv/GHSA-g2qp-8c9p-46fv.json +++ b/advisories/unreviewed/2025/05/GHSA-g2qp-8c9p-46fv/GHSA-g2qp-8c9p-46fv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g2qp-8c9p-46fv", - "modified": "2025-05-30T09:30:27Z", + "modified": "2025-06-04T21:31:12Z", "published": "2025-05-30T09:30:27Z", "aliases": [ "CVE-2025-4943" diff --git a/advisories/unreviewed/2025/05/GHSA-gvfm-39fx-4qm6/GHSA-gvfm-39fx-4qm6.json b/advisories/unreviewed/2025/05/GHSA-gvfm-39fx-4qm6/GHSA-gvfm-39fx-4qm6.json index 4456bbebc18..fc31f6c212f 100644 --- a/advisories/unreviewed/2025/05/GHSA-gvfm-39fx-4qm6/GHSA-gvfm-39fx-4qm6.json +++ b/advisories/unreviewed/2025/05/GHSA-gvfm-39fx-4qm6/GHSA-gvfm-39fx-4qm6.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-hcrg-qr57-hr37/GHSA-hcrg-qr57-hr37.json b/advisories/unreviewed/2025/05/GHSA-hcrg-qr57-hr37/GHSA-hcrg-qr57-hr37.json index a8fafbe2688..072c3e96f55 100644 --- a/advisories/unreviewed/2025/05/GHSA-hcrg-qr57-hr37/GHSA-hcrg-qr57-hr37.json +++ b/advisories/unreviewed/2025/05/GHSA-hcrg-qr57-hr37/GHSA-hcrg-qr57-hr37.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hcrg-qr57-hr37", - "modified": "2025-05-22T15:34:49Z", + "modified": "2025-06-04T21:31:09Z", "published": "2025-05-22T15:34:48Z", "aliases": [ "CVE-2025-3938" @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-325" + "CWE-325", + "CWE-327" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-j46h-hw72-jxqh/GHSA-j46h-hw72-jxqh.json b/advisories/unreviewed/2025/05/GHSA-j46h-hw72-jxqh/GHSA-j46h-hw72-jxqh.json index 54b746d2d0f..4ade2cff875 100644 --- a/advisories/unreviewed/2025/05/GHSA-j46h-hw72-jxqh/GHSA-j46h-hw72-jxqh.json +++ b/advisories/unreviewed/2025/05/GHSA-j46h-hw72-jxqh/GHSA-j46h-hw72-jxqh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j46h-hw72-jxqh", - "modified": "2025-05-22T15:34:49Z", + "modified": "2025-06-04T21:31:10Z", "published": "2025-05-22T15:34:49Z", "aliases": [ "CVE-2025-3943" diff --git a/advisories/unreviewed/2025/05/GHSA-j4jp-4rjc-6479/GHSA-j4jp-4rjc-6479.json b/advisories/unreviewed/2025/05/GHSA-j4jp-4rjc-6479/GHSA-j4jp-4rjc-6479.json index fc417b7d5be..0e18baf29cf 100644 --- a/advisories/unreviewed/2025/05/GHSA-j4jp-4rjc-6479/GHSA-j4jp-4rjc-6479.json +++ b/advisories/unreviewed/2025/05/GHSA-j4jp-4rjc-6479/GHSA-j4jp-4rjc-6479.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-j7x7-89ff-3cf7/GHSA-j7x7-89ff-3cf7.json b/advisories/unreviewed/2025/05/GHSA-j7x7-89ff-3cf7/GHSA-j7x7-89ff-3cf7.json index 4807450db09..de5625c32bf 100644 --- a/advisories/unreviewed/2025/05/GHSA-j7x7-89ff-3cf7/GHSA-j7x7-89ff-3cf7.json +++ b/advisories/unreviewed/2025/05/GHSA-j7x7-89ff-3cf7/GHSA-j7x7-89ff-3cf7.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-jf96-p3p6-vcwv/GHSA-jf96-p3p6-vcwv.json b/advisories/unreviewed/2025/05/GHSA-jf96-p3p6-vcwv/GHSA-jf96-p3p6-vcwv.json index 146b2b12071..21e6f851e5c 100644 --- a/advisories/unreviewed/2025/05/GHSA-jf96-p3p6-vcwv/GHSA-jf96-p3p6-vcwv.json +++ b/advisories/unreviewed/2025/05/GHSA-jf96-p3p6-vcwv/GHSA-jf96-p3p6-vcwv.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-jr34-3463-3cxq/GHSA-jr34-3463-3cxq.json b/advisories/unreviewed/2025/05/GHSA-jr34-3463-3cxq/GHSA-jr34-3463-3cxq.json index aa13e5de952..5d2cc57b032 100644 --- a/advisories/unreviewed/2025/05/GHSA-jr34-3463-3cxq/GHSA-jr34-3463-3cxq.json +++ b/advisories/unreviewed/2025/05/GHSA-jr34-3463-3cxq/GHSA-jr34-3463-3cxq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jr34-3463-3cxq", - "modified": "2025-05-22T15:34:48Z", + "modified": "2025-06-04T21:31:09Z", "published": "2025-05-22T15:34:48Z", "aliases": [ "CVE-2025-3937" diff --git a/advisories/unreviewed/2025/05/GHSA-m33j-944f-82fq/GHSA-m33j-944f-82fq.json b/advisories/unreviewed/2025/05/GHSA-m33j-944f-82fq/GHSA-m33j-944f-82fq.json index 754abda1ab0..8b94530e71e 100644 --- a/advisories/unreviewed/2025/05/GHSA-m33j-944f-82fq/GHSA-m33j-944f-82fq.json +++ b/advisories/unreviewed/2025/05/GHSA-m33j-944f-82fq/GHSA-m33j-944f-82fq.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-m9q7-vjr4-rfp2/GHSA-m9q7-vjr4-rfp2.json b/advisories/unreviewed/2025/05/GHSA-m9q7-vjr4-rfp2/GHSA-m9q7-vjr4-rfp2.json index 865d0f2f2c9..169135de8b7 100644 --- a/advisories/unreviewed/2025/05/GHSA-m9q7-vjr4-rfp2/GHSA-m9q7-vjr4-rfp2.json +++ b/advisories/unreviewed/2025/05/GHSA-m9q7-vjr4-rfp2/GHSA-m9q7-vjr4-rfp2.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-mhxf-hgvm-m8mj/GHSA-mhxf-hgvm-m8mj.json b/advisories/unreviewed/2025/05/GHSA-mhxf-hgvm-m8mj/GHSA-mhxf-hgvm-m8mj.json index b0e2f2c632d..2d2e5b1a290 100644 --- a/advisories/unreviewed/2025/05/GHSA-mhxf-hgvm-m8mj/GHSA-mhxf-hgvm-m8mj.json +++ b/advisories/unreviewed/2025/05/GHSA-mhxf-hgvm-m8mj/GHSA-mhxf-hgvm-m8mj.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-pqgc-jxwr-49w4/GHSA-pqgc-jxwr-49w4.json b/advisories/unreviewed/2025/05/GHSA-pqgc-jxwr-49w4/GHSA-pqgc-jxwr-49w4.json index 3fb8a070ed6..0ed859fe3dc 100644 --- a/advisories/unreviewed/2025/05/GHSA-pqgc-jxwr-49w4/GHSA-pqgc-jxwr-49w4.json +++ b/advisories/unreviewed/2025/05/GHSA-pqgc-jxwr-49w4/GHSA-pqgc-jxwr-49w4.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pqgc-jxwr-49w4", - "modified": "2025-05-29T00:30:34Z", + "modified": "2025-06-04T21:31:10Z", "published": "2025-05-28T21:30:43Z", "aliases": [ "CVE-2025-27706" ], "details": "CVE-2025-27706 is a cross-site scripting vulnerability in the management\n console of Absolute Secure Access prior to version 13.54. Attackers \nwith system administrator permissions can interfere with another system \nadministrator’s use of the management console when the second \nadministrator visits the page. Attack complexity is low, there are no \npreexisting attack requirements, privileges required are high and active\n user interaction is required. There is no impact on confidentiality, \nthe impact on integrity is low and there is no impact on availability.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:L/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2025/05/GHSA-prr2-m2fh-3hv6/GHSA-prr2-m2fh-3hv6.json b/advisories/unreviewed/2025/05/GHSA-prr2-m2fh-3hv6/GHSA-prr2-m2fh-3hv6.json index c31a0b7e22b..a9f42bc5cb4 100644 --- a/advisories/unreviewed/2025/05/GHSA-prr2-m2fh-3hv6/GHSA-prr2-m2fh-3hv6.json +++ b/advisories/unreviewed/2025/05/GHSA-prr2-m2fh-3hv6/GHSA-prr2-m2fh-3hv6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-prr2-m2fh-3hv6", - "modified": "2025-05-22T15:34:48Z", + "modified": "2025-06-04T21:31:09Z", "published": "2025-05-22T15:34:48Z", "aliases": [ "CVE-2025-3936" diff --git a/advisories/unreviewed/2025/05/GHSA-q4jv-p3r8-p9rx/GHSA-q4jv-p3r8-p9rx.json b/advisories/unreviewed/2025/05/GHSA-q4jv-p3r8-p9rx/GHSA-q4jv-p3r8-p9rx.json index 8d18b94b5c1..81b43a01e03 100644 --- a/advisories/unreviewed/2025/05/GHSA-q4jv-p3r8-p9rx/GHSA-q4jv-p3r8-p9rx.json +++ b/advisories/unreviewed/2025/05/GHSA-q4jv-p3r8-p9rx/GHSA-q4jv-p3r8-p9rx.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-q524-5rg8-2j6p/GHSA-q524-5rg8-2j6p.json b/advisories/unreviewed/2025/05/GHSA-q524-5rg8-2j6p/GHSA-q524-5rg8-2j6p.json index b5caf654f59..f3d693d6ef9 100644 --- a/advisories/unreviewed/2025/05/GHSA-q524-5rg8-2j6p/GHSA-q524-5rg8-2j6p.json +++ b/advisories/unreviewed/2025/05/GHSA-q524-5rg8-2j6p/GHSA-q524-5rg8-2j6p.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-69" + "CWE-69", + "CWE-706" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-qmpm-vw3w-fpxq/GHSA-qmpm-vw3w-fpxq.json b/advisories/unreviewed/2025/05/GHSA-qmpm-vw3w-fpxq/GHSA-qmpm-vw3w-fpxq.json index 2b8e8915531..32c974e3e65 100644 --- a/advisories/unreviewed/2025/05/GHSA-qmpm-vw3w-fpxq/GHSA-qmpm-vw3w-fpxq.json +++ b/advisories/unreviewed/2025/05/GHSA-qmpm-vw3w-fpxq/GHSA-qmpm-vw3w-fpxq.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-79", "CWE-80" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/05/GHSA-r43x-w85h-p334/GHSA-r43x-w85h-p334.json b/advisories/unreviewed/2025/05/GHSA-r43x-w85h-p334/GHSA-r43x-w85h-p334.json index 9520745114b..7657ef2b462 100644 --- a/advisories/unreviewed/2025/05/GHSA-r43x-w85h-p334/GHSA-r43x-w85h-p334.json +++ b/advisories/unreviewed/2025/05/GHSA-r43x-w85h-p334/GHSA-r43x-w85h-p334.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-rrc3-jxqw-99qh/GHSA-rrc3-jxqw-99qh.json b/advisories/unreviewed/2025/05/GHSA-rrc3-jxqw-99qh/GHSA-rrc3-jxqw-99qh.json index bcb0f40506e..481d2dc9159 100644 --- a/advisories/unreviewed/2025/05/GHSA-rrc3-jxqw-99qh/GHSA-rrc3-jxqw-99qh.json +++ b/advisories/unreviewed/2025/05/GHSA-rrc3-jxqw-99qh/GHSA-rrc3-jxqw-99qh.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-v9mc-4jxq-vw83/GHSA-v9mc-4jxq-vw83.json b/advisories/unreviewed/2025/05/GHSA-v9mc-4jxq-vw83/GHSA-v9mc-4jxq-vw83.json index 0be21ff8cd2..5ae4fc79edb 100644 --- a/advisories/unreviewed/2025/05/GHSA-v9mc-4jxq-vw83/GHSA-v9mc-4jxq-vw83.json +++ b/advisories/unreviewed/2025/05/GHSA-v9mc-4jxq-vw83/GHSA-v9mc-4jxq-vw83.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v9mc-4jxq-vw83", - "modified": "2025-05-30T09:30:27Z", + "modified": "2025-06-04T21:31:12Z", "published": "2025-05-30T09:30:27Z", "aliases": [ "CVE-2025-4431" @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-vgrm-7j7m-pjmg/GHSA-vgrm-7j7m-pjmg.json b/advisories/unreviewed/2025/05/GHSA-vgrm-7j7m-pjmg/GHSA-vgrm-7j7m-pjmg.json index f5de3548e17..bceee08732e 100644 --- a/advisories/unreviewed/2025/05/GHSA-vgrm-7j7m-pjmg/GHSA-vgrm-7j7m-pjmg.json +++ b/advisories/unreviewed/2025/05/GHSA-vgrm-7j7m-pjmg/GHSA-vgrm-7j7m-pjmg.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-w3jx-4fjp-hqjc/GHSA-w3jx-4fjp-hqjc.json b/advisories/unreviewed/2025/05/GHSA-w3jx-4fjp-hqjc/GHSA-w3jx-4fjp-hqjc.json index ca15a3911bc..79bf8c5abb2 100644 --- a/advisories/unreviewed/2025/05/GHSA-w3jx-4fjp-hqjc/GHSA-w3jx-4fjp-hqjc.json +++ b/advisories/unreviewed/2025/05/GHSA-w3jx-4fjp-hqjc/GHSA-w3jx-4fjp-hqjc.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-w4w8-5w5f-5gvr/GHSA-w4w8-5w5f-5gvr.json b/advisories/unreviewed/2025/05/GHSA-w4w8-5w5f-5gvr/GHSA-w4w8-5w5f-5gvr.json index e7dbf8b74e8..6fc503bac53 100644 --- a/advisories/unreviewed/2025/05/GHSA-w4w8-5w5f-5gvr/GHSA-w4w8-5w5f-5gvr.json +++ b/advisories/unreviewed/2025/05/GHSA-w4w8-5w5f-5gvr/GHSA-w4w8-5w5f-5gvr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-wpp3-qg8g-86cw/GHSA-wpp3-qg8g-86cw.json b/advisories/unreviewed/2025/05/GHSA-wpp3-qg8g-86cw/GHSA-wpp3-qg8g-86cw.json index 44b2fd20e49..c1ff38dbe9e 100644 --- a/advisories/unreviewed/2025/05/GHSA-wpp3-qg8g-86cw/GHSA-wpp3-qg8g-86cw.json +++ b/advisories/unreviewed/2025/05/GHSA-wpp3-qg8g-86cw/GHSA-wpp3-qg8g-86cw.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-x633-33m2-p743/GHSA-x633-33m2-p743.json b/advisories/unreviewed/2025/05/GHSA-x633-33m2-p743/GHSA-x633-33m2-p743.json index 5c762d2ffc8..fb4728e1d1e 100644 --- a/advisories/unreviewed/2025/05/GHSA-x633-33m2-p743/GHSA-x633-33m2-p743.json +++ b/advisories/unreviewed/2025/05/GHSA-x633-33m2-p743/GHSA-x633-33m2-p743.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-x7pf-mv6r-v5x9/GHSA-x7pf-mv6r-v5x9.json b/advisories/unreviewed/2025/05/GHSA-x7pf-mv6r-v5x9/GHSA-x7pf-mv6r-v5x9.json index 5964f0fdb49..44d419410ba 100644 --- a/advisories/unreviewed/2025/05/GHSA-x7pf-mv6r-v5x9/GHSA-x7pf-mv6r-v5x9.json +++ b/advisories/unreviewed/2025/05/GHSA-x7pf-mv6r-v5x9/GHSA-x7pf-mv6r-v5x9.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-xc5x-xvcr-5h87/GHSA-xc5x-xvcr-5h87.json b/advisories/unreviewed/2025/05/GHSA-xc5x-xvcr-5h87/GHSA-xc5x-xvcr-5h87.json index 402b0dfc397..b90c369ecee 100644 --- a/advisories/unreviewed/2025/05/GHSA-xc5x-xvcr-5h87/GHSA-xc5x-xvcr-5h87.json +++ b/advisories/unreviewed/2025/05/GHSA-xc5x-xvcr-5h87/GHSA-xc5x-xvcr-5h87.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/06/GHSA-2jrq-xcm6-56wv/GHSA-2jrq-xcm6-56wv.json b/advisories/unreviewed/2025/06/GHSA-2jrq-xcm6-56wv/GHSA-2jrq-xcm6-56wv.json new file mode 100644 index 00000000000..e0d6d61b354 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-2jrq-xcm6-56wv/GHSA-2jrq-xcm6-56wv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2jrq-xcm6-56wv", + "modified": "2025-06-04T21:31:15Z", + "published": "2025-06-04T21:31:15Z", + "aliases": [ + "CVE-2025-46011" + ], + "details": "Listmonk v2.4.0 through v4.1.0 is vulnerable to SQL Injection in the QuerySubscribers function which allows attackers to escalate privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46011" + }, + { + "type": "WEB", + "url": "https://github.com/kevinroleke/security/tree/main/CVE-2025-46011" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-04T20:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-43mc-8f4r-rrm4/GHSA-43mc-8f4r-rrm4.json b/advisories/unreviewed/2025/06/GHSA-43mc-8f4r-rrm4/GHSA-43mc-8f4r-rrm4.json new file mode 100644 index 00000000000..6c1718a3c9b --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-43mc-8f4r-rrm4/GHSA-43mc-8f4r-rrm4.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-43mc-8f4r-rrm4", + "modified": "2025-06-04T21:31:16Z", + "published": "2025-06-04T21:31:16Z", + "aliases": [ + "CVE-2025-5608" + ], + "details": "A vulnerability classified as critical has been found in Tenda AC18 15.03.05.05. Affected is the function formsetreboottimer of the file /goform/SetSysAutoRebbotCfg. The manipulation of the argument rebootTime leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5608" + }, + { + "type": "WEB", + "url": "https://lavender-bicycle-a5a.notion.site/Tenda-AC18-formsetreboottimer-20653a41781f801ab9e2e022dd089d69?source=copy_link" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311094" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311094" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.588935" + }, + { + "type": "WEB", + "url": "https://www.tenda.com.cn" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-04T20:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-4ggm-6pw7-9w49/GHSA-4ggm-6pw7-9w49.json b/advisories/unreviewed/2025/06/GHSA-4ggm-6pw7-9w49/GHSA-4ggm-6pw7-9w49.json new file mode 100644 index 00000000000..8821559764a --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-4ggm-6pw7-9w49/GHSA-4ggm-6pw7-9w49.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4ggm-6pw7-9w49", + "modified": "2025-06-04T21:31:16Z", + "published": "2025-06-04T21:31:16Z", + "aliases": [ + "CVE-2025-5612" + ], + "details": "A vulnerability has been found in PHPGurukul Online Fire Reporting System 1.2 and classified as critical. This vulnerability affects unknown code of the file /reporting.php. The manipulation of the argument fullname leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5612" + }, + { + "type": "WEB", + "url": "https://github.com/YZS17/CVE/blob/main/Online_Fire_Reporting_System/sqli_reporting_fullname.md" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311098" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311098" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.589105" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-04T21:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-4p4w-6hg8-63wx/GHSA-4p4w-6hg8-63wx.json b/advisories/unreviewed/2025/06/GHSA-4p4w-6hg8-63wx/GHSA-4p4w-6hg8-63wx.json index d2eb2819f9e..ae20c79cd62 100644 --- a/advisories/unreviewed/2025/06/GHSA-4p4w-6hg8-63wx/GHSA-4p4w-6hg8-63wx.json +++ b/advisories/unreviewed/2025/06/GHSA-4p4w-6hg8-63wx/GHSA-4p4w-6hg8-63wx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4p4w-6hg8-63wx", - "modified": "2025-06-04T18:30:58Z", + "modified": "2025-06-04T21:31:14Z", "published": "2025-06-04T18:30:58Z", "aliases": [ "CVE-2025-2336" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://www.herodevs.com/vulnerability-directory/cve-2025-2336" + }, + { + "type": "WEB", + "url": "https://www.herodevs.com/vulnerability-directory/cve-2025-2336?angularjs-nes" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/06/GHSA-4x7w-r9g5-mvxv/GHSA-4x7w-r9g5-mvxv.json b/advisories/unreviewed/2025/06/GHSA-4x7w-r9g5-mvxv/GHSA-4x7w-r9g5-mvxv.json index 3b3639e0192..6dae470fdb5 100644 --- a/advisories/unreviewed/2025/06/GHSA-4x7w-r9g5-mvxv/GHSA-4x7w-r9g5-mvxv.json +++ b/advisories/unreviewed/2025/06/GHSA-4x7w-r9g5-mvxv/GHSA-4x7w-r9g5-mvxv.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/06/GHSA-5fg2-hvm9-wgqj/GHSA-5fg2-hvm9-wgqj.json b/advisories/unreviewed/2025/06/GHSA-5fg2-hvm9-wgqj/GHSA-5fg2-hvm9-wgqj.json new file mode 100644 index 00000000000..03563ef99b1 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-5fg2-hvm9-wgqj/GHSA-5fg2-hvm9-wgqj.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5fg2-hvm9-wgqj", + "modified": "2025-06-04T21:31:16Z", + "published": "2025-06-04T21:31:16Z", + "aliases": [ + "CVE-2025-5611" + ], + "details": "A vulnerability, which was classified as critical, was found in CodeAstro Real Estate Management System 1.0. This affects an unknown part of the file /submitpropertyupdate.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5611" + }, + { + "type": "WEB", + "url": "https://codeastro.com" + }, + { + "type": "WEB", + "url": "https://github.com/YZS17/CVE/blob/main/CodeAstro_Real_Estate_Management_System/sqli_submitpropertyupdate.php.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311097" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311097" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.589103" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-04T21:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-7568-mf5j-25rp/GHSA-7568-mf5j-25rp.json b/advisories/unreviewed/2025/06/GHSA-7568-mf5j-25rp/GHSA-7568-mf5j-25rp.json new file mode 100644 index 00000000000..0ad950d127c --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-7568-mf5j-25rp/GHSA-7568-mf5j-25rp.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7568-mf5j-25rp", + "modified": "2025-06-04T21:31:15Z", + "published": "2025-06-04T21:31:15Z", + "aliases": [ + "CVE-2025-5604" + ], + "details": "A vulnerability was found in Campcodes Hospital Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /user-login.php. The manipulation of the argument Username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5604" + }, + { + "type": "WEB", + "url": "https://github.com/YZS17/CVE/blob/main/Hospital_Management_System/user-login.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311090" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311090" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.588844" + }, + { + "type": "WEB", + "url": "https://www.campcodes.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-04T19:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-7fq6-gf52-6m77/GHSA-7fq6-gf52-6m77.json b/advisories/unreviewed/2025/06/GHSA-7fq6-gf52-6m77/GHSA-7fq6-gf52-6m77.json index 430b089e130..c7e185c7cfe 100644 --- a/advisories/unreviewed/2025/06/GHSA-7fq6-gf52-6m77/GHSA-7fq6-gf52-6m77.json +++ b/advisories/unreviewed/2025/06/GHSA-7fq6-gf52-6m77/GHSA-7fq6-gf52-6m77.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7fq6-gf52-6m77", - "modified": "2025-06-03T21:30:38Z", + "modified": "2025-06-04T21:31:13Z", "published": "2025-06-03T21:30:38Z", "aliases": [ "CVE-2025-23100" ], "details": "An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400. The absence of a NULL check leads to a Denial of Service.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-03T20:15:21Z" diff --git a/advisories/unreviewed/2025/06/GHSA-7jp6-72rv-7m74/GHSA-7jp6-72rv-7m74.json b/advisories/unreviewed/2025/06/GHSA-7jp6-72rv-7m74/GHSA-7jp6-72rv-7m74.json index 95fd0d0bcf1..78f6bef1b79 100644 --- a/advisories/unreviewed/2025/06/GHSA-7jp6-72rv-7m74/GHSA-7jp6-72rv-7m74.json +++ b/advisories/unreviewed/2025/06/GHSA-7jp6-72rv-7m74/GHSA-7jp6-72rv-7m74.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7jp6-72rv-7m74", - "modified": "2025-06-04T15:30:41Z", + "modified": "2025-06-04T21:31:14Z", "published": "2025-06-04T15:30:40Z", "aliases": [ "CVE-2025-23101" ], "details": "An issue was discovered in Samsung Mobile Processor Exynos 1380. A Use-After-Free in the mobile processor leads to privilege escalation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-04T15:15:23Z" diff --git a/advisories/unreviewed/2025/06/GHSA-7wc4-mx57-5w73/GHSA-7wc4-mx57-5w73.json b/advisories/unreviewed/2025/06/GHSA-7wc4-mx57-5w73/GHSA-7wc4-mx57-5w73.json index f76c81037e6..4a375f8eeeb 100644 --- a/advisories/unreviewed/2025/06/GHSA-7wc4-mx57-5w73/GHSA-7wc4-mx57-5w73.json +++ b/advisories/unreviewed/2025/06/GHSA-7wc4-mx57-5w73/GHSA-7wc4-mx57-5w73.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7wc4-mx57-5w73", - "modified": "2025-06-03T21:30:38Z", + "modified": "2025-06-04T21:31:13Z", "published": "2025-06-03T21:30:38Z", "aliases": [ "CVE-2025-23098" ], "details": "An issue was discovered in Samsung Mobile Processor Exynos 980, 990, 1080, 2100, 1280, 2200, 1380. A Use-After-Free in the mobile processor leads to privilege escalation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-03T20:15:21Z" diff --git a/advisories/unreviewed/2025/06/GHSA-7xxr-hvw9-96cr/GHSA-7xxr-hvw9-96cr.json b/advisories/unreviewed/2025/06/GHSA-7xxr-hvw9-96cr/GHSA-7xxr-hvw9-96cr.json index 32b74f24943..0a36c45609f 100644 --- a/advisories/unreviewed/2025/06/GHSA-7xxr-hvw9-96cr/GHSA-7xxr-hvw9-96cr.json +++ b/advisories/unreviewed/2025/06/GHSA-7xxr-hvw9-96cr/GHSA-7xxr-hvw9-96cr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7xxr-hvw9-96cr", - "modified": "2025-06-03T15:31:26Z", + "modified": "2025-06-04T21:31:12Z", "published": "2025-06-03T15:31:26Z", "aliases": [ "CVE-2025-43924" ], "details": "Cross Site Scripting vulnerability was discovered in Unicom Focal Point 7.6.1. The val parameter in SettingController (for /fp/admin/settings/loginpage) and the rootserviceurl parameter in FriendsController (for /fp/admin/settings/friends), entered by an admin, allow stored XSS.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-03T15:15:58Z" diff --git a/advisories/unreviewed/2025/06/GHSA-8hrc-27p3-wvxr/GHSA-8hrc-27p3-wvxr.json b/advisories/unreviewed/2025/06/GHSA-8hrc-27p3-wvxr/GHSA-8hrc-27p3-wvxr.json index 4e422f21d7b..2e864f8627c 100644 --- a/advisories/unreviewed/2025/06/GHSA-8hrc-27p3-wvxr/GHSA-8hrc-27p3-wvxr.json +++ b/advisories/unreviewed/2025/06/GHSA-8hrc-27p3-wvxr/GHSA-8hrc-27p3-wvxr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8hrc-27p3-wvxr", - "modified": "2025-06-04T18:30:57Z", + "modified": "2025-06-04T21:31:14Z", "published": "2025-06-04T18:30:57Z", "aliases": [ "CVE-2025-29093" ], "details": "File Upload vulnerability in Motivian Content Mangment System v.41.0.0 allows a remote attacker to execute arbitrary code via the Content/Gallery/Images component.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-434" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-04T16:15:36Z" diff --git a/advisories/unreviewed/2025/06/GHSA-9qvj-rpj8-v5c8/GHSA-9qvj-rpj8-v5c8.json b/advisories/unreviewed/2025/06/GHSA-9qvj-rpj8-v5c8/GHSA-9qvj-rpj8-v5c8.json index 038bf287c5f..79ca99c4446 100644 --- a/advisories/unreviewed/2025/06/GHSA-9qvj-rpj8-v5c8/GHSA-9qvj-rpj8-v5c8.json +++ b/advisories/unreviewed/2025/06/GHSA-9qvj-rpj8-v5c8/GHSA-9qvj-rpj8-v5c8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9qvj-rpj8-v5c8", - "modified": "2025-06-03T18:30:41Z", + "modified": "2025-06-04T21:31:13Z", "published": "2025-06-03T15:31:27Z", "aliases": [ "CVE-2025-46548" ], "details": "If you enable Basic Authentication in Pekko Management using the Java DSL, the authenticator may not be properly applied.\n\n\nUsers that rely on authentication instead of making sure the Management API ports are only available to trusted users are recommended to upgrade to version 1.1.1, which fixes this issue.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -35,7 +40,7 @@ "cwe_ids": [ "CWE-287" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-03T15:15:59Z" diff --git a/advisories/unreviewed/2025/06/GHSA-9r29-3wx2-q747/GHSA-9r29-3wx2-q747.json b/advisories/unreviewed/2025/06/GHSA-9r29-3wx2-q747/GHSA-9r29-3wx2-q747.json new file mode 100644 index 00000000000..9c7e4458fe3 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-9r29-3wx2-q747/GHSA-9r29-3wx2-q747.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9r29-3wx2-q747", + "modified": "2025-06-04T21:31:15Z", + "published": "2025-06-04T21:31:15Z", + "aliases": [ + "CVE-2025-46203" + ], + "details": "An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /students/edit/{id} endpoint.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46203" + }, + { + "type": "WEB", + "url": "https://github.com/changeweb/Unifiedtransform" + }, + { + "type": "WEB", + "url": "https://github.com/spbavarva/CVE-2025-46203" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-04T20:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-ccxh-4mwr-475q/GHSA-ccxh-4mwr-475q.json b/advisories/unreviewed/2025/06/GHSA-ccxh-4mwr-475q/GHSA-ccxh-4mwr-475q.json new file mode 100644 index 00000000000..1ff06e4cad1 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-ccxh-4mwr-475q/GHSA-ccxh-4mwr-475q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ccxh-4mwr-475q", + "modified": "2025-06-04T21:31:15Z", + "published": "2025-06-04T21:31:15Z", + "aliases": [ + "CVE-2025-22243" + ], + "details": "VMware NSX Manager UI is vulnerable to a stored Cross-Site Scripting (XSS) attack due to improper input validation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22243" + }, + { + "type": "WEB", + "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25738" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-04T20:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-hg9v-648p-2828/GHSA-hg9v-648p-2828.json b/advisories/unreviewed/2025/06/GHSA-hg9v-648p-2828/GHSA-hg9v-648p-2828.json index 9bf116d259f..487c99319d4 100644 --- a/advisories/unreviewed/2025/06/GHSA-hg9v-648p-2828/GHSA-hg9v-648p-2828.json +++ b/advisories/unreviewed/2025/06/GHSA-hg9v-648p-2828/GHSA-hg9v-648p-2828.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/06/GHSA-j6q9-g64f-w437/GHSA-j6q9-g64f-w437.json b/advisories/unreviewed/2025/06/GHSA-j6q9-g64f-w437/GHSA-j6q9-g64f-w437.json index 7bb2018696f..5a2fb255b68 100644 --- a/advisories/unreviewed/2025/06/GHSA-j6q9-g64f-w437/GHSA-j6q9-g64f-w437.json +++ b/advisories/unreviewed/2025/06/GHSA-j6q9-g64f-w437/GHSA-j6q9-g64f-w437.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j6q9-g64f-w437", - "modified": "2025-06-04T18:30:57Z", + "modified": "2025-06-04T21:31:14Z", "published": "2025-06-04T18:30:57Z", "aliases": [ "CVE-2025-23106" ], "details": "An issue was discovered in Samsung Mobile Processor Exynos 2200, 1480, and 2400. A Use-After-Free in the mobile processor leads to privilege escalation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-04T16:15:35Z" diff --git a/advisories/unreviewed/2025/06/GHSA-jw2w-q42r-444f/GHSA-jw2w-q42r-444f.json b/advisories/unreviewed/2025/06/GHSA-jw2w-q42r-444f/GHSA-jw2w-q42r-444f.json index 98d61497e4d..765bfa548e2 100644 --- a/advisories/unreviewed/2025/06/GHSA-jw2w-q42r-444f/GHSA-jw2w-q42r-444f.json +++ b/advisories/unreviewed/2025/06/GHSA-jw2w-q42r-444f/GHSA-jw2w-q42r-444f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jw2w-q42r-444f", - "modified": "2025-06-04T15:30:41Z", + "modified": "2025-06-04T21:31:14Z", "published": "2025-06-04T15:30:40Z", "aliases": [ "CVE-2025-23095" ], "details": "An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400. A Double Free in the mobile processor leads to privilege escalation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-415" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-04T15:15:23Z" diff --git a/advisories/unreviewed/2025/06/GHSA-mfw6-88f6-x9r5/GHSA-mfw6-88f6-x9r5.json b/advisories/unreviewed/2025/06/GHSA-mfw6-88f6-x9r5/GHSA-mfw6-88f6-x9r5.json new file mode 100644 index 00000000000..5be1deed49e --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-mfw6-88f6-x9r5/GHSA-mfw6-88f6-x9r5.json @@ -0,0 +1,60 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mfw6-88f6-x9r5", + "modified": "2025-06-04T21:31:15Z", + "published": "2025-06-04T21:31:15Z", + "aliases": [ + "CVE-2025-5606" + ], + "details": "A vulnerability was found in Tenda AC18 15.03.05.05. It has been declared as critical. This vulnerability affects the function formSetIptv of the file /goform/SetIPTVCfg. The manipulation of the argument list leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5606" + }, + { + "type": "WEB", + "url": "https://lavender-bicycle-a5a.notion.site/Tenda-AC18-formSetIptv-20653a41781f8077b67af003423cf1da" + }, + { + "type": "WEB", + "url": "https://lavender-bicycle-a5a.notion.site/Tenda-AC18-formSetIptv-20653a41781f8077b67af003423cf1da?source=copy_link" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311092" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311092" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.588933" + }, + { + "type": "WEB", + "url": "https://www.tenda.com.cn" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-04T19:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-p5wf-c3gw-cq7c/GHSA-p5wf-c3gw-cq7c.json b/advisories/unreviewed/2025/06/GHSA-p5wf-c3gw-cq7c/GHSA-p5wf-c3gw-cq7c.json new file mode 100644 index 00000000000..972fcca46ac --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-p5wf-c3gw-cq7c/GHSA-p5wf-c3gw-cq7c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p5wf-c3gw-cq7c", + "modified": "2025-06-04T21:31:15Z", + "published": "2025-06-04T21:31:15Z", + "aliases": [ + "CVE-2025-22245" + ], + "details": "VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the router port due to improper input validation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22245" + }, + { + "type": "WEB", + "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25738" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-04T20:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-p8p3-j22q-vxg2/GHSA-p8p3-j22q-vxg2.json b/advisories/unreviewed/2025/06/GHSA-p8p3-j22q-vxg2/GHSA-p8p3-j22q-vxg2.json new file mode 100644 index 00000000000..1cf5b0deb5e --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-p8p3-j22q-vxg2/GHSA-p8p3-j22q-vxg2.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p8p3-j22q-vxg2", + "modified": "2025-06-04T21:31:15Z", + "published": "2025-06-04T21:31:15Z", + "aliases": [ + "CVE-2025-46204" + ], + "details": "An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /course/edit/{id} endpoint.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46204" + }, + { + "type": "WEB", + "url": "https://github.com/changeweb/Unifiedtransform" + }, + { + "type": "WEB", + "url": "https://github.com/spbavarva/CVE-2025-46204" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-04T20:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-pfgm-6vwx-85w9/GHSA-pfgm-6vwx-85w9.json b/advisories/unreviewed/2025/06/GHSA-pfgm-6vwx-85w9/GHSA-pfgm-6vwx-85w9.json new file mode 100644 index 00000000000..ff441e4bb07 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-pfgm-6vwx-85w9/GHSA-pfgm-6vwx-85w9.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pfgm-6vwx-85w9", + "modified": "2025-06-04T21:31:16Z", + "published": "2025-06-04T21:31:16Z", + "aliases": [ + "CVE-2025-5609" + ], + "details": "A vulnerability classified as critical was found in Tenda AC18 15.03.05.05. Affected by this vulnerability is the function fromadvsetlanip of the file /goform/AdvSetLanip. The manipulation of the argument lanMask leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5609" + }, + { + "type": "WEB", + "url": "https://lavender-bicycle-a5a.notion.site/Tenda-AC18-fromadvsetlanip-20653a41781f800fbc7bf9ca193c08e3?source=copy_link" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311095" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311095" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.588936" + }, + { + "type": "WEB", + "url": "https://www.tenda.com.cn" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-04T20:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-rgq8-gx4r-vwrw/GHSA-rgq8-gx4r-vwrw.json b/advisories/unreviewed/2025/06/GHSA-rgq8-gx4r-vwrw/GHSA-rgq8-gx4r-vwrw.json new file mode 100644 index 00000000000..293af5f5436 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-rgq8-gx4r-vwrw/GHSA-rgq8-gx4r-vwrw.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rgq8-gx4r-vwrw", + "modified": "2025-06-04T21:31:16Z", + "published": "2025-06-04T21:31:16Z", + "aliases": [ + "CVE-2025-5610" + ], + "details": "A vulnerability, which was classified as critical, has been found in CodeAstro Real Estate Management System 1.0. Affected by this issue is some unknown functionality of the file /submitpropertydelete.php. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5610" + }, + { + "type": "WEB", + "url": "https://codeastro.com" + }, + { + "type": "WEB", + "url": "https://github.com/YZS17/CVE/blob/main/CodeAstro_Real_Estate_Management_System/sqli_submitpropertydelete.php.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311096" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311096" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.589102" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-04T21:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-rwg8-8j6r-ggfw/GHSA-rwg8-8j6r-ggfw.json b/advisories/unreviewed/2025/06/GHSA-rwg8-8j6r-ggfw/GHSA-rwg8-8j6r-ggfw.json new file mode 100644 index 00000000000..2717deedc5d --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-rwg8-8j6r-ggfw/GHSA-rwg8-8j6r-ggfw.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rwg8-8j6r-ggfw", + "modified": "2025-06-04T21:31:16Z", + "published": "2025-06-04T21:31:16Z", + "aliases": [ + "CVE-2025-5607" + ], + "details": "A vulnerability was found in Tenda AC18 15.03.05.05. It has been rated as critical. This issue affects the function formSetPPTPUserList of the file /goform/setPptpUserList. The manipulation of the argument list leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5607" + }, + { + "type": "WEB", + "url": "https://lavender-bicycle-a5a.notion.site/Tenda-AC18-formSetPPTPUserList-20653a41781f809fba95ff2c0a5c921b?source=copy_link" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311093" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311093" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.588934" + }, + { + "type": "WEB", + "url": "https://www.tenda.com.cn" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-04T20:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-rxpg-c894-3g4j/GHSA-rxpg-c894-3g4j.json b/advisories/unreviewed/2025/06/GHSA-rxpg-c894-3g4j/GHSA-rxpg-c894-3g4j.json index 61e9bf7c6f6..d7958b0ada8 100644 --- a/advisories/unreviewed/2025/06/GHSA-rxpg-c894-3g4j/GHSA-rxpg-c894-3g4j.json +++ b/advisories/unreviewed/2025/06/GHSA-rxpg-c894-3g4j/GHSA-rxpg-c894-3g4j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rxpg-c894-3g4j", - "modified": "2025-06-03T21:30:38Z", + "modified": "2025-06-04T21:31:13Z", "published": "2025-06-03T21:30:38Z", "aliases": [ "CVE-2025-23097" ], "details": "An issue was discovered in Samsung Mobile Processor Exynos 1380. The lack of a length check leads to out-of-bounds writes.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-03T20:15:20Z" diff --git a/advisories/unreviewed/2025/06/GHSA-vpq6-j9hp-2h3w/GHSA-vpq6-j9hp-2h3w.json b/advisories/unreviewed/2025/06/GHSA-vpq6-j9hp-2h3w/GHSA-vpq6-j9hp-2h3w.json index c31a8366bea..1152c5943bc 100644 --- a/advisories/unreviewed/2025/06/GHSA-vpq6-j9hp-2h3w/GHSA-vpq6-j9hp-2h3w.json +++ b/advisories/unreviewed/2025/06/GHSA-vpq6-j9hp-2h3w/GHSA-vpq6-j9hp-2h3w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vpq6-j9hp-2h3w", - "modified": "2025-06-04T15:30:41Z", + "modified": "2025-06-04T21:31:14Z", "published": "2025-06-04T15:30:41Z", "aliases": [ "CVE-2025-23096" ], "details": "An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400. A Double Free in the mobile processor leads to privilege escalation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-415" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-04T15:15:23Z" diff --git a/advisories/unreviewed/2025/06/GHSA-wwpq-55w5-4fj5/GHSA-wwpq-55w5-4fj5.json b/advisories/unreviewed/2025/06/GHSA-wwpq-55w5-4fj5/GHSA-wwpq-55w5-4fj5.json index 2d5d6920977..d72d4bd1532 100644 --- a/advisories/unreviewed/2025/06/GHSA-wwpq-55w5-4fj5/GHSA-wwpq-55w5-4fj5.json +++ b/advisories/unreviewed/2025/06/GHSA-wwpq-55w5-4fj5/GHSA-wwpq-55w5-4fj5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wwpq-55w5-4fj5", - "modified": "2025-06-04T18:30:57Z", + "modified": "2025-06-04T21:31:14Z", "published": "2025-06-04T18:30:57Z", "aliases": [ "CVE-2025-29094" ], "details": "Cross Site Scripting vulnerability in Motivian Content Mangment System v.41.0.0 allows a remote attacker to execute arbitrary code via the Marketing/Forms, Marketing/Offers and Content/Pages components.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-04T16:15:36Z" diff --git a/advisories/unreviewed/2025/06/GHSA-x56h-2x3p-c97x/GHSA-x56h-2x3p-c97x.json b/advisories/unreviewed/2025/06/GHSA-x56h-2x3p-c97x/GHSA-x56h-2x3p-c97x.json index 789868ac8d1..96e087becd4 100644 --- a/advisories/unreviewed/2025/06/GHSA-x56h-2x3p-c97x/GHSA-x56h-2x3p-c97x.json +++ b/advisories/unreviewed/2025/06/GHSA-x56h-2x3p-c97x/GHSA-x56h-2x3p-c97x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x56h-2x3p-c97x", - "modified": "2025-06-03T15:31:26Z", + "modified": "2025-06-04T21:31:12Z", "published": "2025-06-03T15:31:26Z", "aliases": [ "CVE-2025-43923" ], "details": "An issue was discovered in ReportController in Unicom Focal Point 7.6.1. A user who has administrative privilege in Focal Point can perform SQL injection via the image parameter during a delete report image operation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-03T15:15:58Z" diff --git a/advisories/unreviewed/2025/06/GHSA-xr62-x8gm-j2h5/GHSA-xr62-x8gm-j2h5.json b/advisories/unreviewed/2025/06/GHSA-xr62-x8gm-j2h5/GHSA-xr62-x8gm-j2h5.json new file mode 100644 index 00000000000..b6b53ad5044 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-xr62-x8gm-j2h5/GHSA-xr62-x8gm-j2h5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xr62-x8gm-j2h5", + "modified": "2025-06-04T21:31:15Z", + "published": "2025-06-04T21:31:15Z", + "aliases": [ + "CVE-2025-22244" + ], + "details": "VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the gateway firewall due to improper input validation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22244" + }, + { + "type": "WEB", + "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25738" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-04T20:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-xxvc-6xwm-7prp/GHSA-xxvc-6xwm-7prp.json b/advisories/unreviewed/2025/06/GHSA-xxvc-6xwm-7prp/GHSA-xxvc-6xwm-7prp.json index 8c4b4c4fd7a..030e41889e9 100644 --- a/advisories/unreviewed/2025/06/GHSA-xxvc-6xwm-7prp/GHSA-xxvc-6xwm-7prp.json +++ b/advisories/unreviewed/2025/06/GHSA-xxvc-6xwm-7prp/GHSA-xxvc-6xwm-7prp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xxvc-6xwm-7prp", - "modified": "2025-06-04T15:30:40Z", + "modified": "2025-06-04T21:31:14Z", "published": "2025-06-04T15:30:40Z", "aliases": [ "CVE-2025-27811" ], "details": "A local privilege escalation in the razer_elevation_service.exe in Razer Synapse 4 through 4.0.86.2502180127 allows a local attacker to escalate their privileges via a vulnerable COM interface in the target service.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-04T14:15:28Z"